Privacy Policy

Last updated: 11 April 2026

1. Who We Are

The Sunset Society ("we", "us", "our") is the data controller responsible for your personal data.

2. What Data We Collect

CategoryDataWhen Collected
IdentityName, email address, phone numberWhen you place an order or sign up
OrderItems ordered, order history, dietary preferences, table numberWhen you use our ordering services
PaymentTransaction records (card details are processed by our payment provider — we do not see or store your full card number)When you make a payment
TechnicalIP address, browser type, device informationAutomatically when you visit our website
UsagePages visited, features used, session dataAutomatically when you browse our website
MarketingCommunication preferences, opt-in statusWhen you subscribe to our newsletter

3. Why We Use Your Data & Our Legal Basis

PurposeLegal Basis
Processing and fulfilling your orders (click & collect, pre-order, order & pay, pay at table)Contractual necessity
Processing paymentsContractual necessity
Managing your account and preferencesContractual necessity
Recording allergen and dietary requirements you tell us aboutLegitimate interest (food safety)
Sending marketing emails (where you have opted in)Consent
Sending marketing about similar services (existing customers, soft opt-in)Legitimate interest
Improving our website and servicesLegitimate interest
Preventing fraud and ensuring securityLegitimate interest
Complying with legal and tax obligationsLegal obligation

4. Who We Share Your Data With

We share your data only with the following categories of recipients who need it to provide our services:

We do not sell your personal data to third parties.

5. International Transfers

Some of our third-party service providers are based outside the UK. Where your data is transferred internationally, it is protected by appropriate safeguards such as Standard Contractual Clauses, an adequacy decision, or the UK-US Data Bridge, as applicable.

6. How Long We Keep Your Data

DataRetention Period
Order records & payment records6 years (HMRC tax requirements)
Account dataDuration of your account plus 30 days after deletion
Marketing consent recordsDuration of consent plus 6 months
Analytics dataUp to 26 months
Technical/usage dataUp to 12 months

7. Your Rights

Under UK data protection law, you have the right to:

To exercise any of these rights, contact us at [your email address]. We will respond within one month.

8. Marketing & Newsletters

9. Cookies

Our website uses cookies. For full details, please see our Cookie Policy.

10. Security

We take appropriate technical and organisational measures to protect your personal data, including encryption, secure hosting, and access controls. Payment card data is handled entirely by our PCI-DSS compliant payment processor.

11. Children

Our services are not directed at children under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.

12. Complaints

If you are unhappy with how we handle your data, please contact us at [your email address]. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO):

13. Changes to This Policy

We may update this policy from time to time. The latest version will always be available on our website with the date of the last update shown above.