Privacy Policy

Last updated: 10 August 2026

This policy explains what personal data Norman's Coffee collects when you order coffee, book an event, get in touch, or look up a booking through our website, why we use it, who we share it with, and what rights you have over it. It's written to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

It sits alongside, and doesn't replace, our Terms of Use and Event Booking Terms.

1. Who we are

Norman's Coffee is operated by Norman's Coffee Ltd (Company Number 16829381), registered at 29 Horseshoe Way, Yapton, West Sussex, BN18 0XR ("we", "us", "our"). We're the data controller for the personal data described in this policy — meaning we decide why and how it's used.

You can contact us about anything in this policy at hello@normanscoffee.co.uk or via the contact form on our site. We haven't appointed a separate Data Protection Officer — as a small business, data protection queries are handled directly by us at the address above.

2. The personal data we collect, and why

We only collect what we need to fulfil an order or booking, reply to an enquiry, or verify who you are before taking a payment. Here's every place on the site that collects personal data:

Ordering coffee online or at your table

Your name and a contact number, which our kitchen uses to prepare and identify your order — both required. Your email address is optional, and if you give it, we use it only to send you an order confirmation and tracking link.

Booking an event

Your name, phone number, and (if given) email address, plus the date, time, package, and guest details you choose, and the address of the venue itself — we need the venue address to confirm the pod can get on site. If you tell us the occasion (e.g. "Sarah & Tom's wedding"), we'll use that too, purely to identify the booking.

Getting in touch

Your name and email address (required), and a phone number and message if you choose to give them, so we can reply to your enquiry.

Looking up an event booking to pay a balance

Your booking reference and phone number — used only to verify you're the person the booking belongs to before showing any details or taking a payment. A booking reference on its own isn't treated as secret (it's shown in a confirmation email, which could be forwarded or seen by someone else), which is why we always check it against the phone number on file too.

Payment card details

We don't collect or store your card details ourselves. Card payments are tokenised on your own device and sent directly and securely to Square, our payment processor — your full card number never reaches or passes through our servers. See "Who we share your data with" below for more on Square's role.

3. Our legal basis for using your data

For ordering, event bookings, and balance payments, we use your data because it's necessary to perform a contract with you — we can't make you a coffee, hold your event date, or take your payment without your name, contact details, and (for events) your venue address. For replying to a contact form enquiry, our basis is legitimate interest — responding to people who've asked us a question is a normal and expected part of running the business, and doesn't override your own rights and interests. For fraud-prevention checks on card payments, both we and Square rely on legitimate interest in preventing fraudulent transactions. We don't currently rely on your consent to process any personal data described in this policy — see "Analytics and marketing" below for why.

4. Who we share your data with

We keep the number of people and services who see your data as small as possible. We share it with:

Square— our point-of-sale, payments, and booking provider. Square processes your card payment, holds a customer profile of your name, phone number, and email (so we have a record of your order or booking history — see "How long we keep your data" below), and, for events, holds your booking and venue address. Square is a regulated payment service provider and its own systems are PCI-DSS compliant, the industry standard for handling card data safely. See Square's own privacy policy for full detail on how it handles data.

Resend — the service we use to send transactional emails: order tracking links, event booking confirmations, contact form replies, and balance-payment confirmations. Resend only ever processes the specific email and content needed to send that one message. See Resend's own privacy policy for more detail.

We don't sell your data, and we don't share it with anyone for their own marketing purposes. We may disclose it if required by law — for example to HMRC, a court, or a regulator.

5. International transfers

Square and Resend may store and process data outside the UK, including in the United States. [Confirm current wording against each provider's Data Processing Addendum before publishing —] where that happens, both rely on safeguards recognised as adequate under UK GDPR, such as the UK International Data Transfer Addendum or Standard Contractual Clauses approved for UK use. You can ask us for more detail on the safeguards in place using the contact details in section 1.

6. How long we keep your data

We keep your Square customer profile (name, phone, email, and order/booking history) for as long as you continue to order from us, so we have a record if you query a past order and so we're ready if we introduce a loyalty scheme in future that you can join using the same details. If you'd like us to delete it sooner, contact us using the details in section 1 — this is currently a manual process we action for you, not something you can do yourself on the site.

Transaction records (orders, payments, and bookings) are kept for at least six years after the relevant tax year, in line with our statutory recordkeeping obligations under UK tax law (HMRC requires business records to be kept for this long). Contact form enquiries exist only as the two emails they generate (to us, and to you if you asked for a reply) — we don't store them anywhere else.

7. Cookies

Browsing the site, ordering, or booking an event doesn't set any cookie on your device. The only cookie our own website sets is a staff login cookie used to access our internal admin tools — it's strictly necessary for that login to work, contains no personal data about customers, isn't set for anyone browsing the public site, and expires automatically after seven days. We don't use advertising or tracking cookies of any kind.

Our home and about pages show a map using OpenStreetMap, a free third-party mapping service — loading it makes a direct request from your browser to OpenStreetMap's own servers, which may see your IP address as a result, in the same way loading any embedded external content would. This is governed by OpenStreetMap's own privacy policy, not ours.

8. Analytics and marketing

We don't currently use any analytics, tracking, or advertising tools on this site, and there's no newsletter or marketing email signup anywhere on it — every email we send is transactional (relating to an order, booking, enquiry, or payment you've made). If that ever changes, we'll update this policy first and, where the law requires your consent (for example for non-essential cookies), we'll ask for it before anything is switched on.

9. Automated decision-making

We don't use your data for any automated decision-making or profiling that has a legal or similarly significant effect on you. A real person is always involved in preparing your order, confirming your event booking, and replying to your enquiry.

10. Children's privacy

Our site and services are aimed at adults, and we don't knowingly collect personal data from children. If you believe a child has given us personal data, please contact us using the details in section 1 and we'll delete it.

11. Your rights

Under UK GDPR, you have the right to: ask us for a copy of the personal data we hold about you; ask us to correct anything that's inaccurate or incomplete; ask us to delete your data, or restrict how we use it, in certain circumstances; receive a copy of the data you've given us in a portable format; and object to us processing your data where we rely on legitimate interest, as set out in section 3. Where we ever rely on your consent for something, you can withdraw it at any time.

To exercise any of these rights, contact us using the details in section 1. We'll respond within one month, as required by law. There's normally no charge for this.

12. Keeping your data secure

Our checkout and booking pages are encrypted with TLS, and card details never touch our own servers (see section 2). We limit access to the personal data we do hold — for example, our internal admin tools are password-protected and only used by staff who need them to run the business. No method of transmission or storage is completely secure, but we take reasonable steps appropriate to a small business to protect your data.

13. Changes to this policy

We may update this policy from time to time, for example if we start using a new service or change how we handle your data. We'll update the "last updated" date above whenever we do, and if a change is significant we'll make that clear on the site.

14. How to complain

If you have concerns about how we've handled your personal data, please contact us first using the details in section 1 so we can try to put it right. You also have the right to complain directly to the UK's data protection regulator, the Information Commissioner's Office (ICO), at ico.org.uk/make-a-complaint or by calling 0303 123 1113.

15. Contact us

Norman's Coffee Ltd, 29 Horseshoe Way, Yapton, West Sussex, BN18 0XR. hello@normanscoffee.co.uk