Effective Date: 04/0625
Business Name Grill Craft Co
Contact Email: Ricmit@icloud.com
This Privacy Policy explains how [Your Restaurant Name] (“we”, “us”, “our”) collects, uses, and protects your personal data when you interact with us, whether you dine in, place a takeaway or delivery order, visit our website, or engage with us on social media.
We are committed to protecting your privacy in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. What Data We CollectWe may collect the following types of personal data:
Identity Data: Name, title.
Contact Data: Phone number, email address, delivery address.
Order Details: Food and drink orders, allergy information, preferences.
Payment Information: Card details (processed securely via third-party providers).
Technical Data: IP address, browser type, operating system, device information (via cookies).
Marketing Data: Your preferences in receiving marketing communications.
2. How We Collect Your DataWe collect personal data when you:
Place an order (online, by phone, or in person)
Book a table or event
Join a loyalty programme or mailing list
Contact us with an enquiry
Interact with our website or social media
Apply for a job
3. How We Use Your DataWe use your data to:
Process and fulfil your orders and reservations
Communicate order updates or service issues
Respond to queries or complaints
Improve our services and customer experience
Send promotional offers or newsletters (with your consent)
Comply with legal obligations
4. Legal Basis for ProcessingWe only process your personal data where we have a legal basis, including:
Consent: For email marketing or promotions.
Contract: To process your food orders or reservations.
Legal obligation: To comply with law enforcement or tax regulations.
Legitimate interest: For business operations, such as improving services.
5. Sharing Your DataWe do not sell your data. We may share it with:
Payment providers: To process transactions securely.
Delivery partners: To fulfil takeaway/delivery orders.
IT and hosting providers: For data storage and systems support.
Regulatory or legal authorities: Where required by law.
All third parties are required to process your data securely and in accordance with the law.
6. Data RetentionWe retain your data only for as long as necessary for the purpose it was collected, or to meet legal, accounting, or reporting requirements. Typically:
Order and transaction data: up to 6 years
Marketing consent: until you opt-out
Job applications: 6 months unless hired
7. Your Data Protection RightsUnder UK GDPR, you have rights including:
Access: Request a copy of your personal data.
Rectification: Correct inaccurate or incomplete data.
Erasure: Request deletion of your data (subject to legal requirements).
Restriction: Ask us to limit how we use your data.
Portability: Transfer your data to another service provider.
Objection: Stop marketing communications at any time.
To exercise any of these rights, contact us at [email address].
8. CookiesOur website uses cookies to enhance user experience and analyse traffic. You can control cookie settings through your browser. For full details, please see our [Cookie Policy – insert link or section if applicable].
9. Data SecurityWe take appropriate technical and organisational measures to secure your personal data, including:
Secure servers and encrypted transmissions
Restricted access to personal data
Regular software updates and security checks
10. Changes to This PolicyWe may update this policy from time to time. Any changes will be posted on our website and, where appropriate, notified to you directly.
11. Contact UsIf you have questions about this policy or your data, contact:
Restaraunt direct
If you are not satisfied with our response, you have the right to contact the Information Commissioner’s Office (ICO):
www.ico.org.uk