Privacy Policy
Last updated: 27 August 2026
We are a small family business and we treat your information the way we would want ours treated: we ask for as little as possible, we use it only for what you contacted us about, we never sell it, and we delete it when we no longer need it. The detail is below.
1. Who we are
Three Roots Coffee is a mobile coffee business based in Buckinghamshire, serving barista coffee and refreshments from our horsebox unit at weddings, private parties, corporate events, markets, fêtes and other events.
This policy explains what personal information we collect about you, why we collect it, what we do with it and what rights you have. It applies to our website at www.threerootscoffee.co.uk, to enquiries and bookings, and to serving customers at events.
For the purposes of UK data protection law, Three Roots Coffee is the data controller for the information described in this policy. That means we decide what information is collected and how it is used, and we are responsible for looking after it.
Three Roots Coffee
Email: threerootscoffeeltd@gmail.com
Phone: 07585 707305
Location: Buckinghamshire, United Kingdom
2. What information we collect
We keep this deliberately minimal. We only ask for what we need to answer your enquiry and run your event well.
When you make an enquiry or book us:
- Your name
- Your phone number and, if you give it, your email address
- Details of your event — the date, location or venue, approximate guest numbers, timings and the type of event
- Anything else you choose to tell us in your message, such as the drinks you would like on the menu or where we should park
If you go ahead with a booking, we may also hold correspondence about your event, an invoice or payment record, and any contact details you give us for a venue, wedding planner or on-site coordinator.
When you buy a drink from us at a public event, we do not normally collect any personal information at all. If you pay by card, the payment is handled by our card payment provider — see section 6.
When you visit our website, our hosting provider automatically records basic technical information such as your IP address, browser type and the pages you viewed. This is standard server logging used to keep the site running and secure. See section 8.
3. How we use it, and our lawful basis
UK data protection law requires us to have a valid reason — a "lawful basis" — for every use of your information. Here is exactly what we do and why.
| What we do | Why | Our lawful basis |
|---|---|---|
| Reply to your enquiry and discuss your event | So we can tell you whether we are free and what we can offer | Legitimate interests — you have contacted us and expect a reply |
| Confirm and deliver your booking | To agree timings, plan the menu, find the site and turn up on the day | Contract — necessary to provide the service you have booked |
| Take payment and keep accounting records | To be paid, and to meet our tax and accounting duties | Contract and legal obligation |
| Note an allergy or dietary requirement you have told us about | To serve you safely | Explicit consent — see section 4 |
| Take photographs or video at an event | To show what we do on our website and social media | Legitimate interests, and consent where someone is clearly identifiable — see section 5 |
| Keep our website working and secure | To prevent abuse and fix faults | Legitimate interests |
| Deal with a complaint, insurance matter or legal claim | To resolve it properly and defend our position if needed | Legitimate interests and legal obligation |
Where we rely on legitimate interests, we have considered whether our interest is fair to you and whether you would reasonably expect it. You can object to any of this at any time — see section 14.
We do not send marketing emails or texts, we do not build customer profiles, and we do not use your information for automated decision-making or profiling. If we ever start sending marketing, we will ask for your consent first and every message will have a one-click way to stop it.
We never sell your personal information, and we never pass it to anyone for their own marketing.
4. Allergy and dietary information
If you tell us that you or a guest has a food allergy, an intolerance or a dietary requirement, that is information about someone's health. Under UK data protection law, health information is a "special category" and gets extra protection.
We use it for one purpose only: to serve you safely. We ask for your explicit consent to record it, we tell only the staff working on your event, and we delete it once your event has finished and any related queries are closed.
Please always tell us about allergies in person on the day as well. Our unit is small and handles milk, nuts, soya, gluten and other allergens in a shared space, so we cannot guarantee that any drink is completely free from traces. If your allergy is severe, please speak to us directly before ordering.
5. Photography and video at events
We sometimes take photographs or short videos of our unit at work — the van, the drinks, the queue — and use them on our website, on Instagram and in enquiries to future customers.
Where people appear in the background of a general scene, we rely on our legitimate interests in showing what we do. Where someone is clearly identifiable and is the subject of the photograph, we ask for their consent before we use it.
For weddings and private events we will always check with the host first, and we will not post anything from a private event without agreement. If you are the host and would prefer we take no photographs at all, just tell us — it is not a problem.
If a photograph of you is already published and you would like it taken down, email us and we will remove it from anything we control, usually within a few days.
6. Payments
We accept cash, card and contactless payments.
We never see or store your full card number. Card payments are processed by Zettle by PayPal using their own card reader and systems. Zettle is responsible for that information and handles it under their own privacy policy and card industry (PCI DSS) security standards. We only receive confirmation that a payment succeeded, along with the amount, the date and the last few digits of the card.
For event bookings paid by bank transfer or invoice, we hold the invoice and payment record. We are required to keep accounting records for six years.
7. WhatsApp, email and social media
Most of our enquiries come through WhatsApp, because it is the quickest way to reach us. The enquiry form on our website gives you two ways to reach us, and they work differently:
- Send via WhatsApp — this simply opens WhatsApp with your message ready for you to send. Nothing is submitted to our website; you send it yourself.
- Send by email — this sends your enquiry to us by email through a form service called Web3Forms, operated by Anlminds Media LLP. They pass the message straight to our inbox and do not store a copy. Their privacy policy is at web3forms.com/privacy.
Our website itself has no database and stores no enquiries.
When you message us on WhatsApp, the message travels through WhatsApp's systems and is handled under WhatsApp's own privacy policy, which we do not control. The same applies if you message us on Instagram. If you would rather not use WhatsApp, please email or ring us instead — the details are in section 1.
If you leave a public review or comment on a social media page, that content is public and is governed by that platform's terms as well as this policy.
8. Our website, cookies and analytics
Our website does not use cookies. We do not run advertising trackers, analytics cookies, pixels or any similar tracking technology, and nothing is stored on your device to follow you around the web. That is why you are not shown a cookie banner — there is nothing to consent to.
Two technical points, for completeness:
- Server logs. Our hosting provider records standard technical information — IP address, browser type, time of visit and pages requested — to keep the site running, diagnose faults and protect it from abuse. These logs are kept for a short period and are not used to identify individual visitors.
- Fonts. Our website loads its typefaces from Google Fonts. When your browser requests a font, your IP address is visible to Google as part of that request. No cookie is set. If you would prefer to avoid this entirely, the fonts can be hosted on our own site instead — see the note in section 12.
Our site also links out to other websites, such as the Food Standards Agency's ratings register and our Instagram page. We are not responsible for the privacy practices of other websites.
10. How long we keep information
| Information | How long we keep it |
|---|---|
| Enquiries that do not lead to a booking | Up to 12 months, then deleted |
| Booking and event correspondence | Up to 2 years after the event, so we can help with repeat bookings |
| Invoices, payment and accounting records | 6 years, as required by HMRC |
| Allergy and dietary information | Deleted once the event is finished and any queries are closed |
| Photographs and video used publicly | Until they are no longer useful, or until you ask us to remove them |
| Records of a complaint, incident or insurance claim | 6 years from resolution |
| Website server logs | A short period set by our hosting provider, typically under 3 months |
11. How we keep information safe
We are a small business and we keep our systems simple, which helps. In practice:
- Our website is served over an encrypted HTTPS connection
- Our website has no database and no contact form storage, so there is no customer database on it to be breached
- Phones and devices used for enquiries are protected by a passcode or biometric lock
- Only the people who need access to your booking details have it
- Paper notes taken at events are destroyed once they are no longer needed
No system can be guaranteed completely secure. If a breach of your personal information were to happen and it were likely to put you at risk, we would tell you without undue delay, and we would report it to the Information Commissioner's Office within 72 hours where required.
12. Sending information outside the UK
We are a UK business and we keep your information in the UK wherever we can. Some of the everyday services we use — email, messaging and website fonts — are provided by companies based outside the UK, which can mean information is processed abroad.
Where that happens, we rely on the safeguards recognised under UK data protection law, such as UK adequacy regulations or the International Data Transfer Agreement, so that your information keeps an equivalent level of protection.
13. Children's information
Our services are aimed at adults booking events, and our website is not directed at children. We do not knowingly collect personal information from children.
Children are of course welcome at our van, and we serve them like anyone else — but we do not ask them for personal details. If you believe we hold information about a child, please contact us and we will delete it.
14. Your rights
Under UK data protection law you have the following rights over your personal information. They are free to use.
- Be informed — to know what we do with your information, which is what this policy is for
- Access — to get a copy of the information we hold about you
- Rectification — to have anything inaccurate corrected
- Erasure — to ask us to delete your information, where there is no good reason for us to keep it
- Restrict processing — to ask us to pause using your information while something is being sorted out
- Object — to object to us using your information where we rely on legitimate interests, including for photographs
- Data portability — to receive information you gave us in a portable format
- Withdraw consent — where we rely on your consent, you can withdraw it at any time, without affecting anything done beforehand
- Rights around automated decisions — although we do not make any automated decisions or carry out profiling
To use any of these, just email threerootscoffeeltd@gmail.com or ring 07585 707305. We may ask you to confirm your identity so we do not give your information to the wrong person. We will respond within one month. If your request is unusually complex we may need longer, and we will tell you if so.
15. How to complain
If you are unhappy with how we have handled your personal information, please tell us first — we would much rather put it right.
You have a right to complain directly to us. Email threerootscoffeeltd@gmail.com with "Data protection complaint" in the subject line, or ring us. You can also raise a complaint by WhatsApp or through our Instagram page if that is easier — we accept complaints however they reach us.
We will:
- Acknowledge your complaint within 30 days of receiving it
- Look into it and respond without undue delay
- Keep you updated on progress and tell you the outcome in plain language
If you are not satisfied with our response, you can complain to the Information Commissioner's Office, the UK's data protection regulator. You can contact the ICO at ico.org.uk/make-a-complaint or on 0303 123 1113. You are free to go to the ICO at any point — you do not have to come to us first, although we would appreciate the chance to help.
16. Changes to this policy
We review this policy from time to time, and we will update it if what we do with your information changes or if the law changes. The date at the top shows when it was last updated. If we make a significant change, we will make that clear on this page.
This policy is written to reflect the UK GDPR, the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025, and the Privacy and Electronic Communications Regulations.