Privacy Policy

How we collect, utilize, and systematically safeguard your data under UK GDPR frameworks.

Last Updated: July 2, 2026

1Information We Collect About You

When you interact with our platform or purchase an analytical dataset from UK Restaurant Data, we gather minimal personal data required to process the business transaction and execute the delivery of your digital products:

  • Contact Information: Your professional email address, full name, and corporate identity.
  • Transaction Data: Specific purchase history, invoice records, total cost, and localized dataset selections.
  • Technical Logs: IP address, browser metadata, operating system details, and session tokens designed to secure download pathways.

2Lawful Bases for Processing

In accordance with Article 6 of the UK General Data Protection Regulation (UK GDPR), we rely on the following distinct legal pillars to manage your purchaser data:

  • Performance of a Contract: Necessary to generate secure download links and fulfill the data order you purchase.
  • Legal Obligation: Mandated for tracking financial entries, tax liabilities, and statutory accounting records.
  • Legitimate Interests: Utilized to monitor website security, prevent payment fraud, and run performance analytics.

3Payment Processing & Stripe Security

All transactional processing is safely handled off-site via our third-party merchant processor, Stripe. We do not capture, process, or store your credit card numbers, CVV codes, or expiry credentials on our personal servers.

Data processing operates under strict Payment Card Industry Data Security Standard (PCI-DSS) protocols. Stripe handles this information independently in conformance with their own comprehensive privacy frameworks.

4Data Retention Policy

We retain customer transactional histories, email addresses, and purchase variables for a mandatory period of six (6) years plus the current financial year. This timeline is strictly required to guarantee compliance with HM Revenue & Customs (HMRC) corporate auditing rules, corporate tax declarations, and legal dispute parameters. Technical log data is cleared or anonymized automatically within ninety (90) days.

5How We Use Your Operational Information

Your data is accessed exclusively for concrete business operations:

  • Configuring your personal account dashboard and managing access to digital files.
  • Diagnosing technical issues or delivering manual assistance via customer support.
  • Protecting the structural integrity of our site against automated scraping attempts and script injections.

We enforce a strict anti-brokerage rule: we never sell, lease, distribute, or monetize buyer contact profiles to outside groups.

6The B2B Hospitality Datasets We Compile

Crucial Notice on Commercial Product Data

The B2B indices offered for commercial download consist of standard company profiles, regional branch lines, corporate web pages, and public-facing business communications. This directory infrastructure is indexed entirely from open public records, national commercial registers, and public digital listings under the legal framework of Legitimate Interest.

We execute balanced Legitimate Interest Assessments (LIA) to respect baseline corporate privacy. If you operate an active UK hospitality venue and require your business listing to be omitted from future dataset updates, you can contact our team for immediate removal.

7International Data Transfers

Because our website architecture relies on globally scaled cloud hosting nodes (such as Vercel) and cross-border clearing services (Stripe), collected buyer data may sometimes be moved to servers deployed outside the UK or EEA. Whenever data is moved cross-border, we ensure valid protection measures are implemented—specifically using approved UK International Data Transfer Agreements (IDTA) or standard contractual safeguards—to guarantee your privacy rights remain fully uncompromised.

8Cookies and Analytics

We maintain a lightweight tracking ecosystem. We use strictly necessary, functional cookies and local memory tokens solely to track payment verification states and maintain browser sessions securely. Because these micro-cookies are functionally essential to make digital file delivery possible, they operate automatically. We do not integrate invasive social ad retargeting scripts or behavior tracking elements on this site.

9Your UK GDPR Rights & Regulatory Recourse

As a citizen or registered company inside the UK, you wield full statutory governance rights over your collected information:

  • Right of Access: Obtain clear copies of all personal records we hold for you.
  • Right to Rectification: Force corrections to incomplete or inaccurate data blocks.
  • Right to Erasure ("Right to be Forgotten"): Order us to purge files, provided it does not clash with our standard HMRC tax accounting obligations.
  • Right to Object: Halt any directory processing grounded under Legitimate Interest paths.

If you believe your details were handled incorrectly, you possess the full legal right to lodge a formal complaint with the Information Commissioner's Office (ICO), the direct supervisory body managing data integrity inside the UK (www.ico.org.uk). We would, however, deeply appreciate the opportunity to handle your complications directly before you seek out official regulatory channels.

10Contact Our Data Protection Lead

If you wish to execute your legal rights, require clarification on our data processing protocols, or want to submit an opt-out request to permanently strip your restaurant metadata from our standard inventory lists, please drop an email directly to our operational center:

Email: support@ukrestdata.com