Privacy Policy
Your privacy is important to us. This policy explains how we collect, use, and protect your personal information.
Last updated:
Version: 1.1
Quick Summary
We collect your data to provide our food delivery service, process orders, and improve your experience. You have rights to access, correct, or delete your data. We never sell your personal information.
1. Introduction
Ironbite ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our mobile applications, or order our food services.
We are the data controller responsible for your personal data. Our registered address is 42 Far Gosford Street, Coventry, CV1 5DW, UK.
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, phone number, delivery address
- Order Information: Food preferences, order history, payment details
- Communication: Messages, feedback, support requests
- Marketing Preferences: Newsletter subscriptions, promotional preferences
2.2 Information We Automatically Collect
- Technical Data: IP address, browser type, device information, operating system
- Usage Data: Pages visited, time spent, interactions, app usage patterns
- Performance Data: Page load times, error logs, Core Web Vitals
- Location Data: Delivery location, approximate location for service area verification
3. How We Use Your Information
We use your information for the following purposes:
- Service Provision: Process orders, deliver food, manage your account
- Communication: Send order confirmations, delivery updates, customer support
- Improvement: Analyze usage patterns, improve our services, develop new features
- Marketing & Loyalty: Operate our loyalty/rewards programme and send you offers, rewards, tier updates and reminders by email, SMS, push notification and in-app message, personalised using your order history (see Section 13)
- Legal Compliance: Meet legal obligations, prevent fraud, ensure food safety
4. Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Contract: To fulfill our service agreement with you
- Legitimate Interest: To improve our services and prevent fraud
- Consent: For marketing communications and optional features
- Legal Obligation: To comply with food safety and tax regulations
5. Data Sharing and Disclosure
We may share your information with:
- Service Providers: Payment processors, delivery partners, IT services
- Legal Authorities: When required by law or to protect rights
- Business Partners: Only with your explicit consent
We never sell your personal information to third parties.
6. Data Retention
We retain your personal data for as long as necessary to:
- Provide our services to you
- Comply with legal obligations
- Resolve disputes and enforce agreements
- Improve our services
Typically, we retain data for 7 years for accounting purposes and 3 years for marketing data.
7. Your Rights
Under GDPR, you have the following rights:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data
- Portability: Receive your data in a structured format
- Objection: Object to processing based on legitimate interests
- Restriction: Limit how we process your data
- Withdraw Consent: Withdraw consent for marketing communications
8. Cookies and Tracking
We use cookies and similar technologies to enhance your experience, analyze usage, and provide personalized content. For detailed information about our use of cookies, please see our Cookie Policy.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These include encryption, access controls, and regular security assessments.
10. International Transfers
Your data is primarily processed within the UK and European Economic Area (EEA). If we transfer data outside the EEA, we ensure adequate protection through approved mechanisms such as Standard Contractual Clauses.
11. Children's Privacy
Our services are not intended for children under 16. We do not knowingly collect personal information from children under 16. If you believe we have collected such information, please contact us immediately.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on our website and updating the "Last updated" date. Your continued use of our services constitutes acceptance of the updated policy.
13. Loyalty Programme & Marketing Communications
We operate a loyalty and rewards programme ("IronBite Rewards") and may send you marketing communications about it. This section explains how that works and how to control it.
13.1 Channels
Where we have the appropriate lawful basis (see 13.3), we may contact you through:
- Email — offers, rewards, tier updates and reminders
- SMS — occasional reward or offer texts
- Push notifications — if you have our app installed and have allowed notifications
- In-app messages — shown inside the app (for example your loyalty status and available rewards)
13.2 How we personalise offers
To keep rewards relevant, we use your order history and purchase behaviour — such as your loyalty tier, how many orders you have placed, and the items you order most — to decide which rewards, offers and reminders to show you. We do not use this to make automated decisions that produce legal or similarly significant effects on you.
13.3 Lawful basis
- Consent: where you have opted in to marketing, we rely on your consent.
- Soft opt-in (existing customers): where you are an existing customer who has bought (or negotiated to buy) from us, we may send you marketing about our own similar products and rewards on the basis of our legitimate interests and the "soft opt-in" under the Privacy and Electronic Communications Regulations (PECR), unless you tell us to stop. Every message includes an easy way to opt out.
13.4 Providers who help us send these
We use trusted processors to deliver these communications, under written data-processing terms:
- Brevo (Sendinblue SAS/GmbH): email and SMS delivery.
- OneSignal: push and in-app messages.
These providers process your data only on our instructions. Where data is transferred outside the UK/EEA, we rely on approved safeguards (see Section 10).
13.5 How to opt out
You can stop marketing at any time:
- Email: click the Unsubscribe link in any marketing email (one click, no login needed).
- SMS: use the opt-out link in the message.
- Push: turn off notifications for the app in your device settings.
- Anything else: email marketing@ironbite.co.uk and we will action it.
Opting out of marketing will not affect order confirmations, delivery updates or other service messages you need.
13.6 The rewards programme
Rewards, tiers, promo codes and offers are provided at our discretion and are governed by our Terms of Service. We may change, pause or end the programme, or individual offers, at any time.
14. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
Email: marketing@ironbite.co.uk
Phone: 024 7775 2915
Address: 42 Far Gosford Street, Coventry, CV1 5DW, UK
Data Protection Officer: marketing@ironbite.co.uk
15. Complaints
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
This Privacy Policy is compliant with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018.