Privacy Policy
This policy explains what we do with your personal information when you visit baristabits.com, place an order, create an account, or get in touch. We’ve aimed to keep it short, plain, and honest.
In this policy, “we”, “us”, and “Barista Bits” refer to the business operating baristabits.com. We act as the data controller for personal information collected through this site. You can contact us any time via our contact page.
What we collect
- Order information. Name, billing and delivery addresses, email address, phone number, order items and totals, and any notes you add at checkout. Collected when you place an order, whether as a guest or through an account.
- Account information. Email address, a hashed password, saved addresses, order history, Beans Rewards balance and transaction log, pinned favourites, and any venue/trade details you choose to provide. Collected only if you register.
- Payment details. Card details are entered directly with our payment processor (Stripe, via WooCommerce Payments) and never reach our servers. We store only the transaction reference, the last four digits of the card, and the outcome.
- Contact form submissions. Your name, email, and the message you send us.
- Technical information. Browser type, device, IP address, pages viewed, and the referring URL. Collected automatically in server logs, and — with your consent — by analytics cookies.
- Local preferences. Your device stores a few lightweight preferences in its own localStorage so the site remembers you: chosen theme (light/dark), last-viewed strip tab, grid-vs-list choice, and your cookie-banner answer. These never leave your device.
How we use it
- Fulfilling your order. We use your contact and delivery details to take payment, pack your order, and arrange delivery. Legal basis: performance of a contract.
- Running your account. Login, order history, Beans Rewards, favourites, and saved addresses. Legal basis: performance of a contract.
- Customer service. Responding to contact form messages, order queries, and complaints. Legal basis: our legitimate interests in looking after our customers.
- Order-related emails. Order confirmations, dispatch notifications, Beans notices, and the occasional service email (e.g. a delivery date change). Legal basis: performance of a contract.
- Fraud & spam prevention. Google reCAPTCHA protects our forms from automated abuse. It sends browser behaviour signals and your IP to Google. Legal basis: our legitimate interests in a secure site.
- Legal obligations. Keeping order records for HMRC, handling data-subject requests, and responding to lawful requests from public authorities. Legal basis: legal obligation.
Who we share it with
- Stripe (via WooCommerce Payments). Handles card payments. Card details are collected by Stripe directly in your browser. Stripe privacy policy.
- DPD. Our delivery partner. Receives your name, delivery address, and phone number (for missed-delivery SMS) when we dispatch your order.
- Google. reCAPTCHA (always on, for spam prevention) sends data to Google. Google privacy policy.
- Our hosting and email infrastructure. Managed by 20i (UK) for hosting and our configured SMTP provider for outbound email.
- Authorities. If required by law, we share information with courts, regulators, and law enforcement.
We don’t sell your personal data, and we don’t share it for any purpose not listed above.
Cookies and local storage
- Essential (always on). WooCommerce session, cart contents, login, cookie-consent state, and CSRF/nonce tokens. Without these the site can’t function.
- Preferences (on device only). Theme choice, sidebar state, strip-tab selection, grid/list view. Stored in your browser’s localStorage and never transmitted back to us.
- Fraud prevention. Google reCAPTCHA v3 runs on forms regardless of consent; it’s classed as a strictly-necessary security measure.
You can change your cookie answer any time by clearing your browser’s site data for baristabits.com — the banner will reappear on your next visit.
How long we keep it
- Order records. Six years after the last transaction, to meet HMRC record-keeping requirements.
- Accounts. Until you ask us to delete your account, or after six years of inactivity.
- Contact form messages. Up to 24 months after our last reply, then deleted.
- Server and security logs. Typically 30–90 days, then rotated out automatically.
Your rights
Under the UK GDPR and the Data Protection Act 2018, you have the right to:
- Access. Ask for a copy of the personal data we hold about you.
- Correct. Ask us to fix anything that’s wrong or out of date.
- Delete. Ask us to erase your personal data. We may need to keep order records for the legal retention period, but the account itself can be closed on request.
- Restrict or object. Ask us to stop or limit a particular use of your data.
- Port. Receive your data in a portable format (e.g. CSV) so you can move it elsewhere.
- Withdraw consent. For anything that relies on consent, withdraw it at any time.
- Complain. If you think we’ve mishandled your data, you can complain to the UK’s Information Commissioner’s Office at ico.org.uk. We’d prefer a chance to sort it first — drop us a line via the contact page.
Security
- Encryption in transit. The whole site runs over HTTPS. Passwords are stored hashed (never in plain text).
- Payment isolation. Card data is entered directly into Stripe’s hosted fields; it doesn’t pass through our servers.
- Access controls. Staff accounts use role-based permissions; only the people who need access to customer data have it.
- Backups. Daily site and database backups are retained on encrypted storage for disaster recovery.
International transfers
Some of our providers operate outside the UK (notably Stripe and Google — both with US operations). Where personal data moves outside the UK, it’s covered by the UK Extension to the EU-US Data Privacy Framework, by Standard Contractual Clauses, or by equivalent safeguards recognised under UK data protection law.
Children
Barista Bits is a trade-leaning supplier and isn’t aimed at children. We don’t knowingly collect personal data from anyone under 16. If you believe your child has provided personal data to us, please contact us and we’ll delete it.
Changes to this policy
We may update this policy from time to time — usually to reflect a new integration, a change in the law, or a clarification. The current version is always this page. If a change materially affects how we use your data, we’ll tell you (via a site notice or an email to account holders) before it takes effect.
Questions? Get in touch.