Skip to content
Three RootsCOFFEE · EST 2026
Our story Menu Events Gallery Credentials FAQs Check your date
Legal

Privacy Policy

Last updated: 27 August 2026

On this page

  1. Who we are
  2. What information we collect
  3. How we use it, and our lawful basis
  4. Allergy and dietary information
  5. Photography and video at events
  6. Payments
  7. WhatsApp, email and social media
  8. Our website, cookies and analytics
  9. Who we share information with
  10. How long we keep information
  11. How we keep information safe
  12. Sending information outside the UK
  13. Children's information
  14. Your rights
  15. How to complain
  16. Changes to this policy

We are a small family business and we treat your information the way we would want ours treated: we ask for as little as possible, we use it only for what you contacted us about, we never sell it, and we delete it when we no longer need it. The detail is below.

1. Who we are

Three Roots Coffee is a mobile coffee business based in Buckinghamshire, serving barista coffee and refreshments from our horsebox unit at weddings, private parties, corporate events, markets, fêtes and other events.

This policy explains what personal information we collect about you, why we collect it, what we do with it and what rights you have. It applies to our website at www.threerootscoffee.co.uk, to enquiries and bookings, and to serving customers at events.

For the purposes of UK data protection law, Three Roots Coffee is the data controller for the information described in this policy. That means we decide what information is collected and how it is used, and we are responsible for looking after it.

Three Roots Coffee

Email: threerootscoffeeltd@gmail.com

Phone: 07585 707305

Location: Buckinghamshire, United Kingdom

2. What information we collect

We keep this deliberately minimal. We only ask for what we need to answer your enquiry and run your event well.

When you make an enquiry or book us:

  • Your name
  • Your phone number and, if you give it, your email address
  • Details of your event — the date, location or venue, approximate guest numbers, timings and the type of event
  • Anything else you choose to tell us in your message, such as the drinks you would like on the menu or where we should park

If you go ahead with a booking, we may also hold correspondence about your event, an invoice or payment record, and any contact details you give us for a venue, wedding planner or on-site coordinator.

When you buy a drink from us at a public event, we do not normally collect any personal information at all. If you pay by card, the payment is handled by our card payment provider — see section 6.

When you visit our website, our hosting provider automatically records basic technical information such as your IP address, browser type and the pages you viewed. This is standard server logging used to keep the site running and secure. See section 8.

3. How we use it, and our lawful basis

UK data protection law requires us to have a valid reason — a "lawful basis" — for every use of your information. Here is exactly what we do and why.

What we doWhyOur lawful basis
Reply to your enquiry and discuss your event So we can tell you whether we are free and what we can offer Legitimate interests — you have contacted us and expect a reply
Confirm and deliver your booking To agree timings, plan the menu, find the site and turn up on the day Contract — necessary to provide the service you have booked
Take payment and keep accounting records To be paid, and to meet our tax and accounting duties Contract and legal obligation
Note an allergy or dietary requirement you have told us about To serve you safely Explicit consent — see section 4
Take photographs or video at an event To show what we do on our website and social media Legitimate interests, and consent where someone is clearly identifiable — see section 5
Keep our website working and secure To prevent abuse and fix faults Legitimate interests
Deal with a complaint, insurance matter or legal claim To resolve it properly and defend our position if needed Legitimate interests and legal obligation

Where we rely on legitimate interests, we have considered whether our interest is fair to you and whether you would reasonably expect it. You can object to any of this at any time — see section 14.

We do not send marketing emails or texts, we do not build customer profiles, and we do not use your information for automated decision-making or profiling. If we ever start sending marketing, we will ask for your consent first and every message will have a one-click way to stop it.

We never sell your personal information, and we never pass it to anyone for their own marketing.

4. Allergy and dietary information

If you tell us that you or a guest has a food allergy, an intolerance or a dietary requirement, that is information about someone's health. Under UK data protection law, health information is a "special category" and gets extra protection.

We use it for one purpose only: to serve you safely. We ask for your explicit consent to record it, we tell only the staff working on your event, and we delete it once your event has finished and any related queries are closed.

Please always tell us about allergies in person on the day as well. Our unit is small and handles milk, nuts, soya, gluten and other allergens in a shared space, so we cannot guarantee that any drink is completely free from traces. If your allergy is severe, please speak to us directly before ordering.

5. Photography and video at events

We sometimes take photographs or short videos of our unit at work — the van, the drinks, the queue — and use them on our website, on Instagram and in enquiries to future customers.

Where people appear in the background of a general scene, we rely on our legitimate interests in showing what we do. Where someone is clearly identifiable and is the subject of the photograph, we ask for their consent before we use it.

For weddings and private events we will always check with the host first, and we will not post anything from a private event without agreement. If you are the host and would prefer we take no photographs at all, just tell us — it is not a problem.

If a photograph of you is already published and you would like it taken down, email us and we will remove it from anything we control, usually within a few days.

6. Payments

We accept cash, card and contactless payments.

We never see or store your full card number. Card payments are processed by Zettle by PayPal using their own card reader and systems. Zettle is responsible for that information and handles it under their own privacy policy and card industry (PCI DSS) security standards. We only receive confirmation that a payment succeeded, along with the amount, the date and the last few digits of the card.

For event bookings paid by bank transfer or invoice, we hold the invoice and payment record. We are required to keep accounting records for six years.

7. WhatsApp, email and social media

Most of our enquiries come through WhatsApp, because it is the quickest way to reach us. The enquiry form on our website gives you two ways to reach us, and they work differently:

  • Send via WhatsApp — this simply opens WhatsApp with your message ready for you to send. Nothing is submitted to our website; you send it yourself.
  • Send by email — this sends your enquiry to us by email through a form service called Web3Forms, operated by Anlminds Media LLP. They pass the message straight to our inbox and do not store a copy. Their privacy policy is at web3forms.com/privacy.

Our website itself has no database and stores no enquiries.

When you message us on WhatsApp, the message travels through WhatsApp's systems and is handled under WhatsApp's own privacy policy, which we do not control. The same applies if you message us on Instagram. If you would rather not use WhatsApp, please email or ring us instead — the details are in section 1.

If you leave a public review or comment on a social media page, that content is public and is governed by that platform's terms as well as this policy.

8. Our website, cookies and analytics

Our website does not use cookies. We do not run advertising trackers, analytics cookies, pixels or any similar tracking technology, and nothing is stored on your device to follow you around the web. That is why you are not shown a cookie banner — there is nothing to consent to.

Two technical points, for completeness:

  • Server logs. Our hosting provider records standard technical information — IP address, browser type, time of visit and pages requested — to keep the site running, diagnose faults and protect it from abuse. These logs are kept for a short period and are not used to identify individual visitors.
  • Fonts. Our website loads its typefaces from Google Fonts. When your browser requests a font, your IP address is visible to Google as part of that request. No cookie is set. If you would prefer to avoid this entirely, the fonts can be hosted on our own site instead — see the note in section 12.

Our site also links out to other websites, such as the Food Standards Agency's ratings register and our Instagram page. We are not responsible for the privacy practices of other websites.

9. Who we share information with

We keep sharing to the minimum. We may share your information with:

  • Zettle by PayPal, for processing card and contactless payments
  • Our website host, which stores and serves the website
  • Web3Forms, which delivers enquiries sent using the email option on our contact form
  • Our email and messaging providers, which carry our correspondence
  • Our accountant, and HMRC, for invoices, tax and accounting records
  • Our insurer or legal advisers, but only if there is a claim, an incident or a dispute
  • A venue or event organiser, where it is necessary to arrange access, parking or timings for your event — and only what they need to know
  • Our team, meaning the family members and staff working at your event

We may also disclose information where we are required to by law, for example to a local authority environmental health officer, the police or a court.

Anyone who handles information on our behalf is required to keep it secure and to use it only for the purpose we have given it to them for.

10. How long we keep information

InformationHow long we keep it
Enquiries that do not lead to a bookingUp to 12 months, then deleted
Booking and event correspondenceUp to 2 years after the event, so we can help with repeat bookings
Invoices, payment and accounting records6 years, as required by HMRC
Allergy and dietary informationDeleted once the event is finished and any queries are closed
Photographs and video used publiclyUntil they are no longer useful, or until you ask us to remove them
Records of a complaint, incident or insurance claim6 years from resolution
Website server logsA short period set by our hosting provider, typically under 3 months
Where a legal claim or insurance matter is ongoing, we may keep relevant information for longer until it is resolved.

11. How we keep information safe

We are a small business and we keep our systems simple, which helps. In practice:

  • Our website is served over an encrypted HTTPS connection
  • Our website has no database and no contact form storage, so there is no customer database on it to be breached
  • Phones and devices used for enquiries are protected by a passcode or biometric lock
  • Only the people who need access to your booking details have it
  • Paper notes taken at events are destroyed once they are no longer needed

No system can be guaranteed completely secure. If a breach of your personal information were to happen and it were likely to put you at risk, we would tell you without undue delay, and we would report it to the Information Commissioner's Office within 72 hours where required.

12. Sending information outside the UK

We are a UK business and we keep your information in the UK wherever we can. Some of the everyday services we use — email, messaging and website fonts — are provided by companies based outside the UK, which can mean information is processed abroad.

Where that happens, we rely on the safeguards recognised under UK data protection law, such as UK adequacy regulations or the International Data Transfer Agreement, so that your information keeps an equivalent level of protection.

13. Children's information

Our services are aimed at adults booking events, and our website is not directed at children. We do not knowingly collect personal information from children.

Children are of course welcome at our van, and we serve them like anyone else — but we do not ask them for personal details. If you believe we hold information about a child, please contact us and we will delete it.

14. Your rights

Under UK data protection law you have the following rights over your personal information. They are free to use.

  • Be informed — to know what we do with your information, which is what this policy is for
  • Access — to get a copy of the information we hold about you
  • Rectification — to have anything inaccurate corrected
  • Erasure — to ask us to delete your information, where there is no good reason for us to keep it
  • Restrict processing — to ask us to pause using your information while something is being sorted out
  • Object — to object to us using your information where we rely on legitimate interests, including for photographs
  • Data portability — to receive information you gave us in a portable format
  • Withdraw consent — where we rely on your consent, you can withdraw it at any time, without affecting anything done beforehand
  • Rights around automated decisions — although we do not make any automated decisions or carry out profiling

To use any of these, just email threerootscoffeeltd@gmail.com or ring 07585 707305. We may ask you to confirm your identity so we do not give your information to the wrong person. We will respond within one month. If your request is unusually complex we may need longer, and we will tell you if so.

15. How to complain

If you are unhappy with how we have handled your personal information, please tell us first — we would much rather put it right.

You have a right to complain directly to us. Email threerootscoffeeltd@gmail.com with "Data protection complaint" in the subject line, or ring us. You can also raise a complaint by WhatsApp or through our Instagram page if that is easier — we accept complaints however they reach us.

We will:

  • Acknowledge your complaint within 30 days of receiving it
  • Look into it and respond without undue delay
  • Keep you updated on progress and tell you the outcome in plain language

If you are not satisfied with our response, you can complain to the Information Commissioner's Office, the UK's data protection regulator. You can contact the ICO at ico.org.uk/make-a-complaint or on 0303 123 1113. You are free to go to the ICO at any point — you do not have to come to us first, although we would appreciate the chance to help.

16. Changes to this policy

We review this policy from time to time, and we will update it if what we do with your information changes or if the law changes. The date at the top shows when it was last updated. If we make a significant change, we will make that clear on this page.

This policy is written to reflect the UK GDPR, the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025, and the Privacy and Electronic Communications Regulations.

Three Roots Coffee logo Three Roots CoffeeEST. 2026 · BUCKINGHAMSHIRE

Rooted in community. Crafted with care. Mobile barista coffee served from our vintage horsebox van at events across Buckinghamshire and beyond.

Explore

  • Our story
  • Menu
  • Events we serve
  • Gallery
  • How booking works
  • Our credentials
  • FAQs

Get in touch

  • 07585 707305
  • threerootscoffeeltd@gmail.com
  • @_threerootscoffee_
  • Check your date
© 2026 Three Roots Coffee. All rights reserved. Privacy Policy Website by Emilyn AI