PRIVACY POLICY – COMPREHENSIVE DATA PROTECTION FRAMEWORK
GENERAL SCOPE
This document sets out the principles and practices by which our international British food enterprise processes personal data in connection with online purchases, payment security, delivery logistics, returns administration, and related support functions.
DIRECT DATA COLLECTION CATEGORIES
Data subjects provide personal information during account registration and checkout, including full name, postal and billing addresses, telephone number, delivery preferences, return-related data, and other elements necessary for transaction fulfilment.
AUTOMATED DATA ACQUISITION
We capture technical data including IP addresses, session identifiers, device and browser characteristics, page interaction histories, cart event logs, and diagnostic telemetry for system stability and security.
PAYMENT INFORMATION PROCESSING
Payment operations are delegated to PCI DSS-certified third-party processors. We neither retain full PAN data nor store CVV codes. Transaction references and masked payment data are preserved for reconciliation and audit purposes.
CARD DATA SECURITY CONTROLS
All payment communications are secured via TLS encryption and tokenisation. Infrastructure is logically segmented, and access to payment-sensitive systems is governed by least-privilege access controls.
CONTACT INFORMATION PROTECTION
Contact data is utilised exclusively for delivery execution and transactional notifications. Access is role-restricted, and sharing is permitted only with carriers essential to order fulfilment.
LAWFUL PROCESSING PURPOSES
Personal data is processed for the following purposes: order execution, logistics coordination, returns and refunds administration, fraud mitigation, accounting compliance, and platform experience enhancement.
FRAUD AND ABUSE PREVENTION
We monitor behavioural and transactional risk signals – including repeated attempts, data mismatches, and session anomalies – and may implement enhanced identity verification procedures where risk profiles indicate elevated exposure.
THIRD-PARTY DATA SHARING
Data is shared with payment processors, carriers, warehouse operators, hosting infrastructure providers, and security/analytics service providers – strictly on a need-to-know and contractual basis.
INTERNATIONAL DATA TRANSFERS
Personal information may be transferred to and processed in jurisdictions outside the customer’s region. Such transfers are governed by Standard Contractual Clauses and supplementary technical measures.
COOKIE POLICY
Essential cookies support session continuity and cart persistence. Non-essential cookies (analytics, personalisation) are deployed subject to preference settings. Cookie controls are available via browser configuration.
RETENTION SCHEDULE
Data is retained for periods consistent with operational requirements and applicable statutory obligations. Upon completion of retention periods, data is either securely deleted or anonymised for statistical analysis.
CUSTOMER DATA MANAGEMENT
Registered customers may update their primary data via self-service account tools. Transaction-related data may be retained for compliance with legal and accounting standards.
SECURITY MEASURES
We deploy a multi-layered security architecture incorporating encryption, access-control frameworks, comprehensive audit logging, continuous monitoring, and documented backup/restoration procedures to safeguard personal information.