Privacy Policy
Last updated 3 September 2026. This policy explains what we do with your personal data when you use murphyprint.com, and what rights you have. It is written to be read, not to be survived.
Who we are
Murphy Print & Graphic Design Ltd is the data controller for the information described here.
- Unit 3, IDA Business & Technology Park, Tiernaboul, Killarney, Co. Kerry, V93 PA44
- Company registration 330387, VAT 6350387K
- Email: sales@murphyprint.com
- Phone: (064) 663 4650
If you have a question about your data, or want to exercise any of the rights below, contact us at sales@murphyprint.com and we will respond within one month.
What we collect, why, and for how long
Orders
When you place an order we collect your name, email address, phone number, delivery or billing address, and the details of what you ordered.
We need this to take payment, produce your job and deliver it. The legal basis is performance of a contract with you. We keep order records for seven years, because Irish tax law requires us to retain records of sales.
Payment details
Payments are processed by Stripe on Stripe's own secure checkout page. Card numbers are never sent to us and we never store them. Stripe tells us only that a payment succeeded, along with the name, email and address you gave them.
The legal basis is performance of a contract. Stripe retains payment records under its own policy.
Artwork and files you upload
When you upload artwork for a job, or store files in your account, we hold those files and their filenames.
Please note that artwork often contains personal data. A business card carries a name and phone number; a photograph may show identifiable people. Where that is the case, we process it only to produce your job, on the basis of performance of a contract.
- Artwork uploaded for an order is kept for 12 months after the order is completed, then deleted, so that reprints and corrections are straightforward.
- Files you deliberately store in your account under Brand assets are kept until you delete them, or until your account has been inactive for three years.
You can delete files stored in your account yourself at any time from the Brand assets section. To have artwork from a past order deleted sooner, email us.
Your account
You do not need an account to buy from us and we never ask you to create one.
If you choose to sign in, you enter your email address and we send you a single-use link. We do not use passwords, so there is no password for us to store or for anyone to steal. Signing in sets one cookie that keeps you signed in for 30 days.
Your order history is not a separate database. It is read directly from Stripe using your email address at the moment you look at it. The legal basis is performance of a contract and our legitimate interest in letting you see and repeat your own orders.
Quotes and enquiries
If you use a contact or quote form, or email us, we collect your name, email address, phone number and whatever you tell us, so that we can reply.
The legal basis is our legitimate interest in responding to enquiries, and where you go on to order, taking steps prior to entering a contract. We keep enquiries for two years.
Keeping the site working and secure
Our forms use Cloudflare Turnstile to tell people from bots, and we limit how often the same visitor can submit a form or upload a file. This briefly processes your IP address.
The legal basis is our legitimate interest in protecting the site from abuse. These records are short-lived.
Analytics and advertising
None of this happens unless you accept it. The legal basis is your consent, you can withdraw it at any time using the cookie settings link in the footer, and withdrawing does not affect anything done before you withdrew it. If you decline, none of these are loaded at all and the site works exactly the same.
Google Analytics tells us how many people visit, which pages they read and where they arrived from. Our property is configured with two features you should know about:
- Google signals is switched on. Where a visitor is signed in to a Google account and has allowed ads personalisation, Google may associate their visit here with that account, and with information Google holds from its own services and partner sites, including location, search history and YouTube history. This lets us see visits across a person's devices rather than counting each device separately.
- City-level location and device details are collected, so we can see roughly where our customers are.
Google signals only operates if you accept the advertising category. Accepting analytics on its own does not switch it on.
We ask Google to keep event data for 2 months and data tied to individual visitors for 14 months, after which it is deleted.
Google Ads and the Meta pixel tell us whether our advertising works, and let us show ads to people who have visited the site before.
Beyond our own cookie settings, you can control this directly with Google at myactivity.google.com and adssettings.google.com, and with Meta in your Facebook or Instagram ad preferences. Google also publishes a browser add-on that opts you out of Google Analytics on every website.
Who else sees your data
We do not sell your data, ever, and we do not share it for anyone else's marketing.
We use a small number of service providers who process data on our instructions:
- Stripe Payments Europe Ltd, Dublin, for taking payment
- Cloudflare, Inc. for hosting the website, storing uploaded files and blocking malicious traffic
- Resend for sending order confirmations and sign-in links
- Anu Internet Services for our own email
- Google and Meta, for analytics and advertising, and only if you consent
We may also share information where we are legally required to, or with our accountants and professional advisers where necessary.
Data outside the European Economic Area
Cloudflare, Google and Meta are headquartered in the United States and may process data there. Where that happens, transfers are covered by the EU-US Data Privacy Framework or by the European Commission's standard contractual clauses. You can ask us for details.
Stripe processing is carried out by its Irish entity.
How we protect it
The site is served entirely over HTTPS. We hold no passwords. Files you upload are stored under long random paths that cannot be guessed, and files in your account can only be reached by a signed-in browser holding a valid session for that email address. Access to our systems is limited to people who need it.
Your rights
Under the GDPR you have the right to:
- Be informed about what we do with your data, which is what this page is for
- Access the personal data we hold about you
- Rectification of anything inaccurate or incomplete
- Erasure of your data, where we have no continuing legal reason to keep it
- Restrict how we use it while a question about it is resolved
- Portability of data you gave us, in a machine-readable form
- Object to processing carried out on the basis of legitimate interests
- Withdraw consent to analytics and advertising at any time
To exercise any of these, email sales@murphyprint.com. We will ask you to confirm your identity, so that we do not disclose or delete someone else's data by mistake.
Note that we cannot delete records we are legally required to keep, such as invoices needed for tax, until that period has passed.
Automated decisions
We do not make any decision about you by automated means, and we do not profile you.
Complaints
If you are unhappy with how we have handled your data, please tell us first and we will try to put it right. You also have the right to complain to the Irish supervisory authority:
Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28. Telephone 01 765 0100. www.dataprotection.ie
Changes
If we change how we use your data we will update this page and change the date at the top. Where a change is significant, we will make it obvious rather than quietly amending the text.