Privacy policy

Last updated: 18 August 2026

This policy explains what personal data Patrick Bourke Premium Menswear collects when you visit or buy from patrickbourkemenswear.ie, why we collect it, who we share it with, how long we keep it, and what rights you have over it.

We’ve tried to write it in plain English. If anything is unclear, email us at info@patrickbourkemenswear.ie and we’ll explain it properly.

1. Who we are

Patrick Bourke (Ennis) Limited, trading as Patrick Bourke Premium Menswear, is the data controller for the personal data described in this policy. That means we decide what data is collected and why, and we’re accountable for it.

Patrick Bourke (Ennis) Limited
2 High Street, Ennis, Co. Clare, V95 X982, Ireland
Registered in Ireland, company number 256722
Email: info@patrickbourkemenswear.ie

This policy covers our website, patrickbourkemenswear.ie. Purchases made in person at our Ennis store are handled separately.

We are not required to appoint a Data Protection Officer, and we haven’t. Privacy queries go to the email address above and are handled by a member of our team.

2. What we collect

Information you give us

  • Name, email address, phone number, billing address and delivery address when you order
  • Account login details, if you create an account
  • Size, fit and product preferences you tell us
  • Items you save to your wishlist
  • Messages you send us by email, contact form, or social media
  • Newsletter and marketing preferences
  • Reviews and survey responses, if you choose to leave them
  • Returns and exchange information, including the reason for a return

Information collected automatically when you browse

  • Device and browser type, operating system, screen size, language and time zone
  • IP address, and the approximate location it indicates (typically city-level)
  • Pages and products viewed, searches run, filters applied, time on site
  • How you arrived — the referring website, search term or ad you clicked
  • Items added to and removed from your basket, including baskets you don’t complete
  • Cookie and similar identifiers

We collect this using cookies, log files, pixels, tags and web beacons. Non-essential collection only happens if you’ve consented — see section 7.

Information we receive from others

  • Payment confirmation and fraud risk signals from Shopify Payments and PayPal (we never see or store your full card number)
  • Delivery status updates from our delivery partners
  • Aggregated advertising performance data from Google, Meta and TikTok
  • Reviews submitted through Trustpilot

What we don’t collect

We don’t ask for and don’t want special category data — health, religious or political beliefs, or anything similar. We don’t knowingly collect data from anyone under 16. Our site is aimed at adults, and if you believe a child has given us their data, email us and we’ll delete it.

3. Why we use it, and our legal basis for each purpose

Under GDPR we must have a lawful basis for every use of your data. Here’s each one.

Taking and fulfilling your order — processing payment, arranging delivery, sending confirmations and dispatch notices, handling returns, refunds and exchanges.
Legal basis: performance of a contract with you.

Managing your account — letting you log in, view order history, save addresses and keep a wishlist.
Legal basis: performance of a contract with you.

Customer service — answering questions about orders, products, sizing, deliveries and returns.
Legal basis: performance of a contract with you, and our legitimate interest in running a business that answers its customers.

Preventing fraud and payment abuse — screening orders for risk indicators, handling chargebacks.
Legal basis: our legitimate interest in protecting the business from fraud, and our legal obligations in relation to payments.

Keeping accounting and tax records — retaining invoices and transaction records.
Legal basis: compliance with a legal obligation (Irish tax and company law).

Email and SMS marketing — newsletters, new arrivals, sale announcements, abandoned basket reminders and personalised product recommendations.
Legal basis: your consent. If you’ve bought from us before, we may email you about similar products under the “soft opt-in” in Regulation 13(11) of S.I. 336/2011 — and every message includes a one-click unsubscribe.

Analytics — understanding how the site is used so we can improve navigation, search, product pages and checkout.
Legal basis: your consent, given through our cookie banner.

Advertising and audience matching — showing you relevant ads on Google, YouTube, Facebook, Instagram and TikTok; measuring which ads lead to sales; and creating audience segments. This includes sharing a securely hashed (scrambled) version of your email address with Google and Meta so they can match you to their own users, either to show you ads or to exclude you from campaigns. The platforms cannot recover your email address from the hashed version.
Legal basis: your consent, given through our cookie banner. You can withdraw it at any time.

Reviews — inviting you to review a product or your experience after purchase.
Legal basis: our legitimate interest in gathering honest feedback and displaying it to other customers. You’re never obliged to respond.

Site security and stability — protecting against attacks, abuse and outages.
Legal basis: our legitimate interest in keeping the site safe and available.

Legal claims and regulatory obligations — establishing, exercising or defending legal claims, and responding to lawful requests from authorities.
Legal basis: our legitimate interests, and compliance with legal obligations.

Where we rely on legitimate interests, we’ve considered whether our interest is outweighed by your rights. You can ask us for details of that assessment, and you can object — see section 9.

4. Automated decision-making

We don’t make any decision about you purely by automated means that produces a legal effect or similarly significantly affects you. You will never be refused an order, refused a refund, or treated differently in any consequential way by an algorithm alone.

We do use automated processing for personalisation — deciding which products to recommend to you on the site, which products to feature in an email, or which audience segment you fall into. You have an absolute right to object to this, and objecting won’t affect your ability to shop with us.

5. Who we share it with

We don’t sell your personal data. We share it with the service providers below, each of whom is contractually required to protect it and use it only on our instructions.

Running the shop

  • Shopify — our e-commerce platform, which hosts the site and processes orders. Our contracting entity is Shopify International Limited, 2nd Floor, 1-2 Victoria Buildings, Haddington Road, Dublin 4. Privacy policy: shopify.com/legal/privacy
  • Shopify Payments and PayPal — payment processing and fraud screening. They act as independent controllers for payment data, under their own policies: shopify.com/legal/privacy and paypal.com/ie/legalhub/privacy-full
  • Klarna — provides the payment-option messaging shown on our product and basket pages. klarna.com/ie/privacy-policy
  • Our delivery partners — name, delivery address and phone number, so they can deliver your order and contact you if there’s a problem
  • Our order management and stock system — order details, to keep stock and fulfilment accurate

Marketing and communication

Site features

  • Boost AI Search & Discovery — powers on-site search and filtering, and processes search behaviour
  • Shopbox.ai — generates the product recommendations you see around the site, based on what you and other visitors have browsed
  • Swym — powers your wishlist
  • Kiwi Sizing — powers the size guide and fit recommendations on product pages
  • Cookiebot (Usercentrics A/S) — runs our cookie banner, records your consent choice and processes your IP address in order to do so. cookiebot.com/en/privacy-policy
  • Trustpilot  — review invitations and review collection

Others

We may also share data with our accountants, insurers and professional advisers, and with An Garda Síochána, the Revenue Commissioners, courts or regulators where we’re legally required to. If our business is ever sold or restructured, customer data may transfer to the new owner, who would remain bound by this policy.

6. Sending data outside the EEA

Some of the providers above are based in, or store data in, countries outside the European Economic Area — chiefly the United States and Canada.

Where that happens, we rely on one or more of the following safeguards, as required by Chapter V of GDPR:

  • The EU–US Data Privacy Framework, where the provider is certified under it. The European Commission’s adequacy decision for the Framework was upheld by the EU General Court in September 2025.
  • The European Commission’s Standard Contractual Clauses, together with supplementary technical and organisational measures where needed.
  • An adequacy decision, where the country has one. Canada holds a partial adequacy decision for commercial organisations.

You can ask us for a copy of the safeguards that apply to a particular transfer by emailing info@patrickbourkemenswear.ie.

7. Cookies and tracking

When you first visit, you’ll see a cookie banner. Nothing beyond strictly necessary cookies is set until you make a choice, and rejecting is as easy as accepting.

  • Strictly necessary — remember your basket, keep you logged in, secure checkout, load-balance the site, and record your cookie choice. These don’t require consent because the site can’t work without them. Typically session-length up to 12 months.
  • Analytics — tell us how many people visit, which pages and products they look at, where they arrive from, and where they drop off in checkout. Set by Shopify and Google Analytics. Typically up to 2 years.
  • Marketing and advertising — measure which ads bring people to the site, let us show you relevant ads on Google, Meta and TikTok, and let us send you abandoned-basket reminders if you’ve given us your email. Set by Google, Meta, TikTok and Klaviyo. Typically up to 13 months.
  • Functional — remember your wishlist, currency, recently viewed items, size preferences and search preferences, and generate product recommendations. Set by Swym, Boost, Kiwi Sizing, Shopbox.ai and Shopify. Typically up to 12 months.

Our cookie banner is provided by Cookiebot. It records your choice and applies it across the site.

Changing your mind

Use the Cookie Settings link in the footer of any page. Your choice takes effect immediately and applies until you change it again or clear your cookies. We’ll ask you again periodically.

You can also block or delete cookies in your browser settings, though this may stop parts of the site working. Because there’s no settled legal standard for browser “Do Not Track” signals, we don’t currently respond to them — the cookie banner is the reliable way to tell us your preference.

8. How long we keep it

  • Order and transaction records, invoices — 6 years from the end of the accounting period, as required by Irish tax law, then deleted or anonymised
  • Customer account and profile — for as long as your account is open; deleted after 3 years of inactivity, or sooner on request
  • Marketing contact details and preferences — until you unsubscribe, or after 24 months with no engagement, whichever comes first
  • Record of your unsubscribe or objection — kept indefinitely, so we don’t contact you again by mistake
  • Customer service correspondence — 24 months after the query is closed
  • Wishlist and browsing preferences — until your account is deleted, or 24 months of inactivity
  • Cookie and analytics data — as set out in section 7
  • Fraud and chargeback records — 6 years
  • Anything relevant to a live dispute or legal claim — until the matter is fully resolved, plus any applicable limitation period

9. Your rights

You have the following rights over your personal data. All of them are free to exercise, and we’ll respond within one month.

  • Access — get a copy of the data we hold about you, and an explanation of how we use it
  • Rectification — have inaccurate data corrected or incomplete data completed
  • Erasure — have your data deleted, where we’ve no overriding reason to keep it. Note that we can’t delete order records we’re legally required to retain for tax purposes, though we can remove you from marketing and close your account
  • Restriction — ask us to pause processing while a dispute about accuracy or legitimacy is resolved
  • Portability — receive the data you gave us in a structured, machine-readable format, or have it sent to another provider
  • Objection — object to processing based on our legitimate interests. Where you object to direct marketing, we must stop, immediately and unconditionally
  • Withdraw consent — at any time, for anything based on consent, including marketing and non-essential cookies. Withdrawing doesn’t affect processing that already happened

How to exercise them: email info@patrickbourkemenswear.ie, or write to us at 2 High Street, Ennis, Co. Clare, V95 X982. To unsubscribe from marketing you can also just click “unsubscribe” in any email. To change cookie preferences, use Cookie Settings in the footer.

We may need to verify your identity before acting on a request, to make sure we’re not handing your data to someone else.

If you’re unhappy with how we’ve handled it

Tell us first and we’ll try to put it right. You also have the right to complain to the Irish supervisory authority at any time:

Data Protection Commission
6 Pembroke Row, Dublin 2, D02 X963
or Canal House, Station Road, Portarlington, Co. Laois, R32 AP23
Phone: 01 765 0100 / 1800 437 737
Online: forms.dataprotection.ie/contact
Website: dataprotection.ie

10. Keeping your data secure

Our site runs entirely over encrypted HTTPS connections. Payment card details are handled by Shopify Payments and PayPal under PCI-DSS standards and never reach our systems. Access to customer data in our admin is limited to staff who need it for their job, protected by individual accounts and two-factor authentication. We review app permissions periodically and remove access for services we no longer use.

No system is perfectly secure, but if a breach ever occurred that posed a risk to your rights, we’d notify the Data Protection Commission within 72 hours and tell you directly where the law requires it.

11. Changes to this policy

We’ll update this policy when our practices change or the law does. The “last updated” date at the top always reflects the current version. If a change materially affects how we use your data, we’ll tell you directly — by email or a notice on the site — rather than relying on you to check.

12. Contact us

Questions, requests or complaints about privacy:

Patrick Bourke Premium Menswear
2 High Street, Ennis, Co. Clare, V95 X982, Ireland
info@patrickbourkemenswear.ie