Privacy Policy
This policy explains what personal data we collect, why we collect it, and your rights under the UK GDPR and Data Protection Act 2018.
1. Who we are (data controller)
The Rustic Table Company Ltd. Contact: hello@therustictable.com.
2. What we collect
- Order data: name, billing & delivery address, email, phone number, items ordered, payment confirmation reference (we do not store card numbers).
- Account data: if you create an admin account, your email and a hashed password.
- Technical data: IP address, browser type, pages visited, captured by server logs and (where you consent) analytics.
3. Why we use it (lawful basis)
- Performance of contract — to take and fulfil your order, contact you about delivery, and provide aftercare.
- Legal obligation — to keep accounting records (HMRC requires us to retain order and invoice data for 6 years), and to handle complaints.
- Legitimate interest — to secure the site against fraud and abuse, and to improve our service.
- Consent — for any marketing emails or non-essential cookies. You can withdraw consent at any time.
4. Who we share it with
- Our payment processor (handles card payment; we do not see your card number).
- Our delivery partner, where applicable, to arrange your delivery slot.
- Our hosting and email providers, as data processors acting on our instructions.
- HMRC and other authorities, where required by law.
We do not sell your personal data.
5. International transfers
Our hosting and email infrastructure is based in the UK and/or EEA. Where any processor is outside the UK/EEA we rely on UK adequacy regulations or the International Data Transfer Agreement to safeguard your data.
6. How long we keep it
- Order & invoice data: 6 years from the end of the relevant tax year (HMRC requirement).
- Marketing consent records: until you unsubscribe, plus 12 months for audit.
- Server logs: up to 90 days.
7. Your rights
Under UK GDPR you have the right to: access your data, correct inaccurate data, ask us to delete data we no longer need, restrict or object to processing, and request a copy in a portable format. To exercise any of these, email hello@therustictable.com. We will respond within one month.
You can also complain to the Information Commissioner's Office (ico.org.uk, helpline 0303 123 1113), though we would prefer the chance to put things right first.
8. Cookies
See our Cookies page.
9. Changes
We may update this policy. The "last updated" date in the sidebar reflects the current version.