Steam and Story Cafe

Privacy Policy

Last updated: [Insert Date]

  1. Introduction Steam and Story Cafe ("we", "us", "our") is committed to protecting your privacy and handling your personal data transparently and lawfully. This Privacy Policy explains how we collect, use, store, and share your personal information when you visit our cafe, use our website, interact with us on social media, or otherwise engage with our services.

We operate in England and process your personal data in accordance with applicable UK data protection law, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

By using our services, you acknowledge that you have read and understood this Privacy Policy.

  1. Who we are Controller: Steam and Story Cafe Category: Coffee shop (Café) Region: England

Steam and Story Cafe is the controller of your personal data, meaning we decide how and why your data is processed.

  1. Information we may collect about you We may collect and process the following categories of personal data:

3.1 Information you provide to us directly

  • Contact details: name, email address, phone number.
  • Booking details: date and time of visit, number of guests, any special requests.
  • Payment information: limited payment details (for example, last four digits of your card number and transaction details). Card information is usually processed directly by our payment provider and is not fully accessible to us.
  • Communication data: information contained in emails, messages via social media or contact forms, reviews, feedback, and other correspondence.
  • Loyalty and promotions: information related to loyalty schemes, promotional sign-ups, or competitions (such as your name, contact details, and participation history).

3.2 Information we collect automatically When you visit our website or use our Wi‑Fi (if provided), we may automatically collect:

  • Technical data: IP address, browser type and version, device type, operating system, time zone setting, and similar technical information.
  • Usage data: pages visited, time spent on our website, links clicked, and general interaction with our online content.

3.3 Information from third parties We may receive information about you from:

  • Reservation or delivery platforms (if you book or order through third-party services).
  • Payment providers and banks (to confirm payments and prevent fraud).
  • Social media platforms, if you interact with our official pages and choose to share information with us.
  1. Legal bases for processing We process your personal data only when we have a lawful basis to do so under UK GDPR, including:

    • Performance of a contract: to provide our services, such as managing your booking, fulfilling your order, or handling your participation in loyalty programmes.
    • Legitimate interests: to run and improve our business, communicate with you, ensure security, prevent fraud, and understand how our services are used, provided that your interests and fundamental rights do not override our interests.
    • Consent: where required by law (for example, for certain marketing communications). You can withdraw your consent at any time.
    • Legal obligations: to comply with laws, regulations, and requests from competent authorities.
  2. How we use your personal data We may use your personal data for the following purposes:

    • To provide our services: process reservations, orders, and payments; manage customer accounts; respond to enquiries and complaints.
    • To communicate with you: send confirmations, service messages, and updates relating to your bookings or orders.
    • To improve our services: analyse how customers use our website, menu, and services to improve quality, safety, and customer experience.
    • To run promotions and loyalty schemes: manage sign-ups, participation, and rewards, subject to your preferences and applicable law.
    • For marketing (with your consent where required): send you news, special offers, or event information that may be relevant to you.
    • For security and fraud prevention: protect our business, staff, and customers, and to detect or investigate potential fraud or misuse of our services.
    • To comply with legal and regulatory requirements and to establish, exercise, or defend legal claims.
  3. Marketing communications We may use your contact details to send you marketing communications about our products, events, offers, or other information we think may interest you.

We will only send you electronic marketing (such as email or SMS) where we have your consent or where the law otherwise permits. You can opt out of marketing communications at any time by:

  • Using the unsubscribe link in our emails; or
  • Contacting us using the details provided in the "Contact us" section.

Opting out of marketing will not affect service-related communications (such as booking confirmations or essential notices).

  1. Cookies and similar technologies If we use cookies or similar technologies on our website, we may collect certain technical and usage data as described above.

Cookies are small text files stored on your device that help the website function properly, remember your preferences, and understand how you use our website.

Where required by law, we will ask for your consent before using non-essential cookies. You can manage or disable cookies in your browser settings. However, some parts of our website may not function correctly without certain cookies.

  1. How we share your personal data We may share your personal data with:
    • Service providers who help us operate our business and provide our services, such as IT providers, website hosting, booking platforms, payment processors, Wi‑Fi providers, and marketing support services.
    • Professional advisers, including lawyers, accountants, and insurers, where necessary.
    • Authorities, regulators, law enforcement agencies, or courts, where we are legally required to do so or where necessary to establish, exercise, or defend legal claims.
    • Third parties in connection with a business transaction, such as a merger, acquisition, or sale of assets, where your data may be transferred as part of that transaction, in accordance with data protection laws.

We require third parties who process data on our behalf to handle your personal data securely and only according to our instructions and applicable law.

We do not sell your personal data.

  1. International data transfers If we transfer your personal data outside the United Kingdom or European Economic Area (EEA), we will ensure that appropriate safeguards are in place to protect your information, such as:
    • An adequacy decision by the UK Government (or relevant authority) confirming that the destination country offers an adequate level of data protection; or
    • Standard contractual clauses or other approved transfer mechanisms under UK data protection law.

You may contact us for more information about international transfers and the safeguards used.

  1. Data retention We keep your personal data only for as long as is reasonably necessary for the purposes for which it was collected and to comply with our legal, regulatory, tax, accounting, and reporting obligations.

Retention periods may vary depending on the type of data and the context in which it was collected, for example:

  • Booking and order records: retained for a period necessary for accounting, tax, and business records.
  • Marketing data: retained whilst you remain subscribed to receive marketing from us and for a limited period thereafter, or until you withdraw your consent or object to processing.
  • Legal and security-related data: retained as long as needed in connection with actual or potential legal claims or investigations.

When data is no longer required, we will delete it or anonymise it so that it can no longer be associated with you.

  1. How we protect your data We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, alteration, or disclosure. These may include:
    • Access controls and authentication measures.
    • Secure networks and encryption where appropriate.
    • Staff training and internal policies on data protection and confidentiality.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. However, we take data protection seriously and strive to protect your information to the best of our ability.

  1. Your rights Under UK data protection law, you have certain rights in relation to your personal data, subject to conditions and exceptions.

These rights may include:

  • Right of access: to obtain confirmation as to whether we process your personal data and, if so, to receive a copy.
  • Right to rectification: to ask us to correct inaccurate or incomplete personal data.
  • Right to erasure: to request that we delete your personal data in certain circumstances.
  • Right to restriction: to ask us to restrict processing of your personal data in certain situations.
  • Right to data portability: to receive certain personal data in a structured, commonly used, and machine-readable format, and to have it transmitted to another controller where technically feasible.
  • Right to object: to object to processing based on our legitimate interests or for direct marketing purposes.
  • Rights related to consent: where we rely on your consent, you have the right to withdraw that consent at any time.

To exercise your rights, please contact us using the details in the "Contact us" section. We may need to verify your identity before responding to your request. We aim to respond within the time limits set by law.

  1. Complaints If you are concerned about how we handle your personal data, please contact us first so that we can try to resolve your concerns.

You also have the right to lodge a complaint with the UK supervisory authority: Information Commissioner's Office (ICO) Website: https://www.ico.org.uk

  1. Children’s privacy Our services are not primarily directed at children. If you are under 16, please ensure that you have consent from a parent or guardian before providing any personal information to us.

If we become aware that we have collected personal data from a child without appropriate consent, we will take steps to delete it as soon as reasonably possible.

  1. Changes to this Privacy Policy We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or other reasons. The most current version will always be available [on our website / at our premises].

When we make significant changes, we will take appropriate steps to bring them to your attention (for example, by posting a notice or, where appropriate, contacting you directly).

  1. Contact us If you have any questions, requests, or concerns about this Privacy Policy or how we process your personal data, please contact us at:

Steam and Story Cafe [Insert postal address] [Insert email address] [Insert telephone number]

We recommend that you keep a copy of this Privacy Policy for your records.

We use cookies to improve your experience

Steam and Story Cafe uses cookies and similar technologies to personalise content, analyse website traffic and remember your preferences between visits. Some cookies are essential for the site to function correctly, while others help us understand how our pages are used so we can make continuous improvements. You can choose to accept or decline non‑essential cookies at any time. For full details about what data we collect, how we use it, and your rights under applicable data‑protection laws in England and the wider UK, please read our Privacy Policy. View full Privacy Policy