Collection of information about you
The data that we may obtain and process about you is as follows:
- Information obtained from you through the completion of forms on our website both at the time of registering or at any subsequent point. As part of the registration process you complete forms that provide us with your name and contact details followed by your coffee preferences, delivery address and payment card details. By filling in these details, you consent for us to use them to the extent necessary to fulfill our service to you;
- once you’ve signed up, we keep a record of all billings and shipments made to you including the types and grinds of coffee you’ve received.
- if you contact us, we may keep a record of that correspondence;
- we may also ask you to complete surveys that we use for research purposes, although you do not have to respond to them;
- device-specific information (such as your hardware model, operating system version, unique device identifiers, and mobile network information); and
- details of your visits to our website.
We will hold the above information for as long as is necessary in order to provide you with our services, deal with any specific issues that you may raise or otherwise as is required by law or any relevant regulatory body.
Information we may collect about others
We may collect information about your computer, including where available your IP address, operating system and browser type, for system administration. This is statistical information about our users’ browsing actions and patterns, and does not identify any individual.
Where we store your personal information
The data we collect from you is stored in the European Economic Area (“EEA”) but may be transferred to and stored at a destination outside of the EEA. It may also be processed by staff operating outside of the EEA. By submitting your personal data, you agree to this transfer, storing and processing.
Your passwords are stored on Crave servers in encrypted form. We do not disclose your account details, postal or email addresses to anyone except when legally required to do so.
Sensitive information between your browser and our website is transferred in encrypted form using Secure Socket Layer (“SSL”). When transmitting sensitive information, you should always make sure that your browser can validate the Crave certificate.
It is your responsibility to keep your password secure. Unfortunately, the transmission of information via the internet is not completely secure. Although Crave will do its best to protect your personal data, we cannot guarantee the security of your data transmitted to our website, any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try and prevent any unauthorised access.
How we use your information
We use information held about you (and information about others) in the following ways:
- to provide you with our services;
- to ensure you receive information relevant to you;
- to ensure the content on our website is presented in the most effective manner for you and your computer or mobile device; and
- to notify you about changes to our service.
Disclosure of your information
We may disclose your personal information to third parties:
- in the event that we sell or buy any business or assets;
- if Crave or substantially all of its assets are acquired by a third party; or
- if we are under a duty to disclose or share your personal data in order to comply with any legal obligation or to protect the rights, property, or safety of Crave, our customers, or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection.
You have the right to ask us not to process your personal data by contacting us at firstname.lastname@example.org
The Data Protection Act 1998 gives you the right to access information held about you by submitting a request in accordance with the act and is subject to a £10 administrative fee. All such requests should be sent to email@example.com
Changes to this policy