Privacy Policy
Last updated: [Insert Date]
- Introduction Rustic Ember Grill ("we", "us", "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, share and protect your personal data when you visit our restaurant, use our website, make a reservation, order food, or otherwise interact with us in England.
By using our services, you agree to the collection and use of information in accordance with this Privacy Policy.
- Data Controller The data controller responsible for your personal data is:
Rustic Ember Grill [Insert Postal Address] England [Insert Contact Email] [Insert Contact Telephone]
- Personal Data We Collect We may collect and process the following categories of personal data:
3.1. Identification and Contact Details
- Name
- Email address
- Telephone number
- Postal address (if provided for deliveries, invoices or correspondence)
3.2. Reservation and Order Information
- Date and time of booking
- Number of guests
- Special requests (e.g. seating preferences, occasions)
- Food and drink orders
- Takeaway or delivery details (if applicable)
3.3. Payment Information
- Limited payment details necessary to process transactions (e.g. partial card details, payment method)
- We do not store full card numbers or security codes; these are processed by our payment service providers.
3.4. Technical and Usage Data When you use our website or online services, we may automatically collect:
- IP address
- Browser type and version
- Device type and operating system
- Pages visited and time spent on our website
- Referral source (how you arrived at our website)
- Cookies and similar tracking technologies (see Section 9)
3.5. Marketing and Communication Data
- Your marketing preferences (e.g. whether you wish to receive promotional emails)
- Records of communications with you (e.g. email correspondence, feedback, complaints)
3.6. Special Category Data We generally do not seek to collect special category data (such as health information). However, if you choose to inform us of dietary requirements, allergies, or other health-related information, we will process this data only to provide a safe and suitable dining experience.
- How We Use Your Personal Data We use your personal data for the following purposes and legal bases:
4.1. To Provide Our Services
- Managing reservations and table bookings
- Processing and delivering food and drink orders
- Managing takeaway or delivery services
- Responding to your enquiries and requests Legal basis: Performance of a contract; Legitimate interests
4.2. Payments and Billing
- Processing payments for your purchases
- Handling billing, receipts and refunds Legal basis: Performance of a contract; Legal obligation (accounting and tax records)
4.3. Customer Support and Communication
- Responding to your queries, feedback and complaints
- Notifying you of changes to our services, opening hours or policies Legal basis: Legitimate interests; Performance of a contract
4.4. Marketing and Promotions
- Sending you news, offers, promotions and event information (where permitted)
- Managing your marketing preferences Legal basis: Consent (for electronic direct marketing where required by law); Legitimate interests (for certain offline or non-electronic marketing)
You may withdraw your consent to marketing at any time by following the unsubscribe instructions in our communications or by contacting us directly.
4.5. Safety, Security and Legal Compliance
- Ensuring the security of our premises, staff and customers
- Preventing, detecting and investigating fraud or other unlawful activity
- Complying with legal obligations, court orders and lawful requests from authorities Legal basis: Legal obligation; Legitimate interests
4.6. Website Operation and Improvement
- Operating, maintaining and improving our website and online services
- Analysing how customers use our website to enhance user experience Legal basis: Legitimate interests; Consent (for certain cookies and trackers where required)
- Sharing Your Personal Data We may share your personal data with the following categories of recipients, only to the extent necessary:
5.1. Service Providers
- Payment processors
- Reservation and booking platforms
- IT and website hosting providers
- Email and marketing service providers
- Delivery partners (if applicable)
5.2. Professional Advisors
- Accountants, auditors, legal advisers and consultants, where required for business and legal purposes.
5.3. Authorities and Law Enforcement
- Government bodies, regulators, law enforcement agencies or similar authorities if required by law or to protect our legal rights.
We do not sell your personal data to third parties.
- International Transfers of Data
If we transfer your personal data outside the United Kingdom or the European Economic Area, we will ensure that appropriate safeguards are in place, such as:
- Adequacy decisions by the UK Government or European Commission; or
- Standard contractual clauses or equivalent legally recognised safeguards.
You can contact us for more information on the safeguards used for international data transfers.
- Data Retention
We retain your personal data only for as long as necessary for the purposes described in this Privacy Policy, including:
- Reservations and orders: kept for a reasonable period after your visit or order to manage bookings, queries and service history.
- Financial records: kept for the period required by tax and accounting laws.
- Marketing data: kept until you withdraw consent or object to processing, subject to reasonable technical and administrative limits.
When personal data is no longer required, it will be securely deleted, anonymised or otherwise disposed of.
- Your Data Protection Rights Under UK data protection law, you have the following rights (subject to certain conditions and exceptions):
- Right of access: to obtain a copy of your personal data and information about how we process it.
- Right to rectification: to have inaccurate or incomplete data corrected.
- Right to erasure: to request deletion of your personal data in certain circumstances.
- Right to restriction: to request limitation of our processing of your data in certain situations.
- Right to data portability: to receive your personal data in a structured, commonly used and machine-readable format and transmit it to another controller where technically feasible.
- Right to object: to object to processing based on our legitimate interests or for direct marketing.
- Rights related to automated decision-making: we do not typically carry out automated decision-making that produces legal or similarly significant effects using your data.
To exercise any of these rights, please contact us using the details provided in Section 2. We may need to verify your identity before responding to your request.
If you are not satisfied with our response, you also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) in the UK:
Information Commissioner’s Office www.ico.org.uk
- Cookies and Similar Technologies
Our website may use cookies and similar technologies to:
- Enable core site functionality
- Remember your preferences
- Analyse website traffic and usage
- Support marketing and advertising activities (where applicable)
Where required by law, we will ask for your consent before placing non-essential cookies on your device. You can manage your cookie preferences through your browser settings or via any cookie banner or settings tool we provide.
For more details on the specific cookies we use, their purposes and how long they last, please refer to our separate Cookie Policy (if available) or contact us.
- Security of Your Personal Data
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction or damage. These measures may include:
- Access controls and staff training
- Secure networks and encryption where appropriate
- Regular monitoring and review of our security practices
However, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security.
-
Data Relating to Children Our services are primarily intended for adults. We do not knowingly collect personal data from children under 16 without appropriate parental or guardian consent. If you believe that we have collected personal data about a child without such consent, please contact us and we will take steps to delete the information.
-
Third-Party Websites Our website or communications may contain links to third-party websites, plugins or services that are not operated or controlled by Rustic Ember Grill. This Privacy Policy does not apply to those third parties. We recommend that you review the privacy policies of any third-party sites you visit.
-
Changes to This Privacy Policy We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements or other operational reasons. The updated version will be posted on our website with a revised "Last updated" date. We encourage you to review this policy periodically.
-
Contact Us If you have any questions, concerns or requests regarding this Privacy Policy or our handling of your personal data, please contact us at:
Rustic Ember Grill [Insert Postal Address] England Email: [Insert Contact Email] Telephone: [Insert Contact Telephone]