Privacy Policy

Last updated September 2026


This policy explains how French & Day Delicatessen uses and protects personal information about customers, website visitors, event attendees, mailing-list subscribers and other people who contact or interact with us. It covers our shop, main website, Square online shop, events, subscriptions, customer Wi-Fi, CCTV, marketing, surveys, and competitions.


We have written it to explain what we actually do. We only use personal information where we have a lawful reason, keep it only for as long as we need it, and do not sell it.


1. WHO WE ARE

French & Day Delicatessen is the trading name of French & Day Ltd. French & Day Ltd is the controller of the personal information described in this policy. This means that we decide why and how it is used.


French & Day Ltd is registered in England and Wales under company number 12790059. Our registered office and shop are at 55 High Street, Ware, Hertfordshire, SG12 9BA.


You can contact us about privacy at delicatessen@frenchandday.co.uk or by writing to us at the address above. We are registered with the Information Commissioner’s Office.


2. THE INFORMATION WE COLLECT

The information we collect depends on how you interact with us. It may include:


  • your name, email address, telephone number, billing address and other contact details;
  • order, collection, event-booking, gift-card, Wine Club and other subscription information;
  • payment status and limited transaction information. Payments are processed by Square or another payment provider, and we do not receive your full payment-card details;
  • messages, enquiries, complaints, feedback, survey responses and competition entries;
  • marketing preferences and records of emails sent, opened or clicked;
  • allergy or dietary information that you choose to give us in connection with an order or event;
  • photographs taken at events where the arrangements described in section 5 apply;
  • CCTV images and short audio recordings;
  • technical information such as IP address, device and browser information, cookie identifiers, pages visited and interactions with our websites or adverts; and
  • limited network and security information generated when a device uses our guest Wi-Fi. Our guest network is password-protected and does not require a customer sign-up or contact details.


We do not copy or record identification documents when checking age. Our website may ask visitors to confirm that they are over 18, and Square allows age-restricted products to be identified, but the online age-confirmation pop-up is not proof of identity.


3. HOW WE COLLECT INFORMATION

We collect information directly from you when you order, book, subscribe, contact us, attend an event, enter a competition, complete a survey, or tell us about an allergy or dietary requirement.


We also receive information through service providers that operate on our behalf, including Square and Mailchimp, and through social-media platforms when you interact with us or enter a promotion there. We collect technical information automatically through cookies and similar technologies. Our main website is hosted by 123 Reg and uses website technology supplied by Duda. Our online shop is provided by Square Online.


4. HOW AND WHY WE USE INFORMATION


Orders, bookings, gift cards, and subscriptions

We use your information to take payment, confirm and prepare orders, arrange collection, manage event bookings, operate gift cards and subscriptions, provide customer service, issue refunds, and deal with problems. We do this because it is necessary to enter into or perform our contract with you.


We may also keep transaction and accounting records because the law requires us to do so, and use records to prevent fraud, recover money owed, handle complaints, or protect our legal rights. Those uses are based on legal obligations or our legitimate interests in running and protecting the business.

You do not have to provide personal information to us, but we may be unable to process an order, booking or subscription, take payment, arrange collection, or respond fully to an enquiry if you do not provide the information reasonably needed for that purpose.


Enquiries, feedback, and surveys

We use contact details and correspondence to answer enquiries, respond to complaints and act on feedback. Depending on the circumstances, this is necessary for a contract or in our legitimate interests in providing good service and improving the business.


We may invite customers to complete occasional surveys or give feedback. Participation is voluntary. We will explain at the time whether responses are anonymous and how any prize draw connected with a survey works. We generally rely on consent for optional surveys and on our legitimate interests when analysing feedback that does not identify an individual.


Competitions and prize draws

We use entry details to administer a competition or prize draw, check eligibility, select and contact winners and deliver prizes. This is necessary to run the promotion on the stated terms. We may also keep limited records where required for accounting, to demonstrate that the promotion was run fairly, or to deal with a dispute.


Safety, security, and fraud prevention

We use information where reasonably necessary to keep our customers, staff, premises, systems and business secure, prevent and investigate crime or misuse, and establish or defend legal claims. We rely on our legitimate interests and, where relevant, legal obligations.


5. ALLERGIES, PHOTOGRAPHS, AND OTHER SENSITIVE INFORMATION

Information about an allergy may reveal health information, which receives additional protection under data-protection law. We use allergy and dietary information that you choose to provide only to understand and, where reasonably possible, accommodate your requirements. We rely on your explicit consent as well as the relevant lawful basis for the order or event. You may withdraw that consent, although this may mean that we cannot safely accommodate the requirement.


For ordinary events, we may take photographs to record and promote French & Day’s activities. We will tell attendees in advance or at the event, provide a straightforward way to opt out, and avoid using an identifiable image if the person has objected. We rely on our legitimate interests in promoting the business, balanced against attendees’ privacy.


We will not take identifiable photographs at an LGBT+ Brunch, or at another event where the context could reveal sensitive information about an attendee, without that person’s express consent. Consent to attend the event is not consent to be photographed. A person who has consented may later ask us to stop using an image, although we may not be able to recall printed material already distributed or copies independently shared by others.


6. MARKETING

We send marketing emails only where you have chosen to receive them. Customers can opt in during Square checkout, and opted-in details may be synchronised with Mailchimp. Customers who do not opt in are not added to our marketing audience merely because they placed an order.


We use consent for email marketing. You can unsubscribe at any time by using the link in an email or contacting us. Unsubscribing does not affect service messages about an order, booking or subscription. We may retain a minimal suppression record so that we continue to respect your choice.


Mailchimp and Square may provide us with information about delivery, opens, clicks and other interactions with marketing messages. We use this to understand whether our communications are useful and to improve them, subject to applicable consent and privacy settings.


7. COOKIES, ANALYTICS, AND ADVERTISING

Our websites use essential technologies needed for security, checkout and core functions. With your consent, they may also use analytics and advertising technologies supplied by providers including Google and Meta. These can help us understand website use, measure advertising results and, depending on our campaign settings, show adverts to people who have previously interacted with French & Day online.


Google Analytics, Google Ads and Meta Pixel may collect identifiers and information about your device, browsing activity and interactions with our websites or adverts. These providers may combine that information with information from other services where their terms and your settings permit it.


Non-essential analytics and advertising technologies should not be used until you have made a choice through our cookie banner. You can change or withdraw that choice through the cookie settings on the relevant website. The cookie banner and settings provide further details about the technologies in use and their duration.


8. CCTV

We use CCTV to help prevent and investigate crime and protect customers, staff, and property. Cameras are motion-triggered rather than continuously recording. When triggered, the system records approximately 15 to 20 seconds of video and audio. We rely on our legitimate interests in safety and security.


CCTV footage is stored securely in cloud storage and is normally deleted after 30 days. We may retain a relevant clip for longer if it is needed to investigate an incident, respond to a request, support an insurance claim, or establish, exercise or defend legal rights. Access is restricted, and footage is disclosed only where there is a proper reason, such as to the police, an insurer or a person exercising a legal right. Signs at the premises inform visitors that CCTV is in operation.


9. WHO WE SHARE INFORMATION WITH

We share personal information only where it is necessary for the purposes described in this policy. Recipients may include:


  • Square, which provides our point-of-sale system, online shop, payment processing, and subscription services;
  • Mailchimp, which provides mailing-list and email-marketing services;
  • 123 Reg, Duda and other suppliers involved in hosting, maintaining or securing our websites;
  • Google and Meta, where you have consented to the relevant analytics or advertising technologies;
  • providers of cloud storage, CCTV, email, IT support, broadband and other business systems;
  • our accountants, insurers, professional advisers and other suppliers where they need the information to provide their services; and
  • the police, courts, regulators, tax authorities or other parties where disclosure is required by law or reasonably necessary to prevent crime, protect someone’s safety, or defend legal rights.


These organisations may act as our processors, following our instructions, or as separate controllers responsible for their own use of information. We do not sell or rent personal information.


10. INFORMATION PROCESSED OUTSIDE THE UNITED KINGDOM

Some of our service providers, including Square, Mailchimp, Google, and Meta, operate internationally. Personal information may therefore be processed outside the United Kingdom.


Where data-protection law requires it, we use providers that rely on a UK adequacy regulation or appropriate safeguards, such as approved contractual protections. We may also rely on a specific legal exception where appropriate. Further information about a provider’s arrangements is available in its privacy information, or you can contact us about the safeguards relevant to your information.


11. HOW LONG WE KEEP INFORMATION

We set retention periods according to why the information is needed, legal and accounting requirements, the risk involved and whether a record may be needed to resolve a dispute. Our usual periods are:


  • orders, payments, subscriptions, gift cards, and accounting records: normally six years after the relevant transaction or the end of the customer relationship;
  • routine enquiries and feedback: normally up to two years after the matter is closed;
  • complaints, incidents, and legal claims: for as long as reasonably needed to resolve the matter and meet any applicable legal limitation period;
  • marketing records: while you remain subscribed. A minimal suppression record may be kept after you unsubscribe so that we do not contact you again;
  • allergy and dietary information: normally until the relevant order or event has been completed, plus up to 30 days, unless an incident or complaint requires longer retention;
  • survey responses: for the period explained when the survey is run and normally no more than 12 months in identifiable form, after which they are deleted or anonymised;
  • competition entries: normally until six months after the prize has been delivered, with any accounting record relating to a prize kept for the applicable financial-record period;
  • event photographs: reviewed periodically and removed when they are no longer useful or appropriate. We will consider earlier removal following a valid objection or withdrawal of consent;
  • CCTV: normally 30 days, unless a relevant clip must be kept for an incident or legal reason; and
  • website and advertising information: according to the duration shown in the cookie settings and the retention controls of the relevant service. Aggregated reports that no longer identify an individual may be kept for longer.


We may keep information for longer where the law requires it, where litigation or an investigation is reasonably anticipated, or where you ask us to preserve it. We may anonymise information so that it no longer relates to an identifiable person and use that anonymous information for longer.


12. HOW WE PROTECT INFORMATION

We use reasonable technical and organisational measures to protect personal information. These include limiting access to people who need it, using password-protected and appropriately secured systems, keeping software and services under review, and selecting established providers. No internet or storage system is completely secure, but we take proportionate steps to reduce the risk of loss, misuse or unauthorised access.


13. YOUR RIGHTS

Depending on the circumstances, you may have the right to:


  • ask for a copy of your personal information and information about how we use it;
  • ask us to correct inaccurate or incomplete information;
  • ask us to delete information or restrict how it is used;
  • object to processing based on legitimate interests and object at any time to direct marketing;
  • withdraw consent at any time, without affecting processing that took place before withdrawal;
  • receive certain information in a portable format or ask us to send it to another organisation; and
  • raise a concern or complaint about how we use your information.


These rights are not absolute and may not apply in every situation. To exercise a right, contact us using the details in section 1. We may need to ask for enough information to confirm your identity and understand your request. We normally respond within one month, although the law allows longer in some circumstances. We do not use personal information to make solely automated decisions that have legal or similarly significant effects on people.


14. CHILDREN AND AGE-RESTRICTED PRODUCTS

Our websites and online shop are not intended to enable anyone under 18 to purchase alcohol or another age-restricted product. We may ask for proof of age when an order is collected or at an age-restricted event. We do not knowingly use children’s information for marketing. If you believe that a child has supplied personal information inappropriately, please contact us.


15. CHANGES TO THIS POLICY

We may update this policy when our services, suppliers or legal obligations change. The latest version will be published on our website with its revision date. If a change would materially affect how we use information already collected, we will take reasonable steps to bring it to the attention of the people affected and obtain consent where required.


16. QUESTIONS AND COMPLAINTS

Please contact us first if you have a question or concern. Write to French & Day Ltd at 55 High Street, Ware, Hertfordshire, SG12 9BA or email delicatessen@frenchandday.co.uk. We will investigate and respond as soon as reasonably possible.


You also have the right to complain to the Information Commissioner’s Office. You can find current contact details and guidance at www.ico.org.uk or telephone 0303 123 1113. If you are outside the United Kingdom, you may also have the right to contact the data-protection regulator where you live or work.