Privacy Policy

Last updated: 08/03/26

Bean & Barrel is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store and protect personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Bean & Barrel is an England-based mobile cafe and bar business providing services at weddings, private and corporate events, festivals and street trading locations.

By using our website or contacting us, you confirm that you have read and understood this Privacy Policy.

1. Data Controller

Bean & Barrel is the data controller responsible for your personal data. If you have any questions about this Privacy Policy or your personal data, please contact us at enquiries@beanandbarrel.co.uk

You have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) if you believe your data has been handled incorrectly: www.ico.org.uk

2. Scope of this Policy

This Privacy Policy applies to all personal data processed by Bean & Barrel in connection with:

  • Use of our website

  • Website contact form enquiries

  • Email enquiries

  • Instagram and TikTok enquiries

  • Booking enquiries and confirmed bookings

  • Weddings, private and corporate events

  • Festivals and street trading operations

  • Payment processing and accounting

  • Business administration and communications

This policy applies whether data is collected online, via social media, by email, by telephone or in person.

When contacting us via social media platforms, your data is also subject to the privacy policies of those platforms.

3. Personal Data We Collect

We only collect personal data necessary to operate our business and provide services.

3.1 Enquiry and Booking Data

When you contact us or make an enquiry, we may collect:

  • Name

  • Email address

  • Telephone number

  • Event type and requirements

  • Event date and location

  • Estimated number of guests

  • High-level dietary requirements

  • Any additional information you choose to provide


Enquiries may be received via: 

  • Website contact form

  • Email

  • Instagram

  • TikTok

This information is used solely to respond to enquiries and manage bookings.

3.2 Event Information

For confirmed bookings we may collect:

  • Booking contact details

  • Event location or venue address

  • Number of guests

  • High-level dietary requirements 

We do not collect names of guests or attendee lists.

Dietary information is collected only in aggregate form and is not linked to identifiable individuals. 

Where Bean & Barrel provides services at corporate events, we do not require or process employee personal data beyond the details provided by the booking contact.

3.3 Website Technical Data

When you visit our website, we may automatically collect:

  • IP address

  • Browser type and version

  • Device type and operating system

  • Referring website

  • Pages visited

  • Navigation behaviour

  • Date and time of visit

This helps us maintain and improve website functionality.

3.4 Cookies and Analytics

We use cookies and similar technologies to collect:

  • Website usage data

  • Page interaction data

  • Website performance analytics

  • Non-essential cookies are not placed unless you provide consent.

3.5 Special Category Data

Bean & Barrel does not intentionally collect special category personal data such as:

  • Health information

  • Racial or ethnic origin

  • Religious beliefs

  • Biometric data

We request that customers do not provide unnecessary sensitive personal data.

4. Lawful Basis for Processing

Under UK GDPR, we rely on the following lawful bases:

Where processing is based on consent (such as cookies), consent can be withdrawn at any time.

5. How We Use Personal Data

We use personal data to:

  • Respond to enquiries

  • Provide quotes

  • Manage bookings and events

  • Deliver services

  • Communicate before and after bookings

  • Process payments

  • Maintain accounting and tax records

  • Improve our website and services

  • Comply with legal obligations

We do not sell personal data and we do not use personal data for marketing purposes.

6. Sharing of Personal Data

We may share personal data with trusted service providers where necessary to operate the business. 

Website Hosting: Squarespace

Email & Business Operations: Google (Gmail / Google Workspace)

Social Media Platforms: Instagram (Meta) and TikTok

Payment Processing: Square

Accounting: QuickBooks

Banking: Monzo

We may also share personal data if required by law or regulatory authorities.

7. International Data Transfers

Some of our service providers may process personal data outside the United Kingdom.

Where this occurs, appropriate safeguards are in place in accordance with UK GDPR, such as:

  • UK adequacy regulations

  • International Data Transfer Agreements (IDTAs)

  • Standard contractual clauses

Further information about safeguards can be requested by contacting us.

8. Data Security

We take appropriate technical and organisational measures to protect personal data.

Online Systems

Data stored within third-party systems is protected using industry-standard security measures.

Devices and Offline Data

Business data may be stored securely on:

  • A password-protected MacBook

  • An iPhone used for business communications

Security measures include:

  • Password-protected devices

  • Access restricted to the business owner

  • Least-privilege access

  • Secure handling of booking and payment information

  • Regular device and software updates

Payment details are processed securely by payment providers and not stored by Bean & Barrel unless required for accounting purposes. In the unlikely event of a personal data breach, we will assess risk and notify affected individuals and regulators where required by law.

9. Data Retention

We retain personal data only as long as necessary:

  • Enquiries not resulting in booking: up to 12 months

  • Booking and invoice records: up to 6 years (legal and tax requirements)

  • Communications: as required for business operations

  • Website analytics: in line with cookie provider retention settings

Data is securely deleted or anonymised when no longer required.

10. Your Rights

Under UK GDPR, you have the right to:

  • Access your personal data

  • Correct inaccurate data

  • Request deletion

  • Restrict processing

  • Object to processing

  • Withdraw consent where applicable

  • Request data portability where applicable

To exercise your rights, contact: enquiries@beanandbarrel.co.uk

You have the right to complain to the Information Commissioner’s Office: www.ico.org.uk

11. Cookies

Our website uses cookies to improve functionality and analyse usage.

Our cookie banner:

  • Provides a direct link to this Privacy Policy

  • Explains cookie categories

  • Allows acceptance of all cookies

  • Allows rejection of non-essential cookies

  • Allows granular preference control

  • Non-essential cookies are not set unless consent is provided.

You can update your cookie preferences at any time via the website cookie settings.

12. Changes to this Policy

We may update this Privacy Policy from time to time.

The latest version will always be available on our website.