1Who we are
This Privacy Policy explains how Handaran (“we”, “us”, “our”) collects, uses and protects your personal information when you visit our website, place an order, or contact us. Handaran is a fresh-food bakery and café based at 297–299 Ecclesall Road, Sheffield, S11 8NX.
We are the “data controller” for the information you share with us. If you have any questions about this policy, you can reach us any time at hello@handaran.co.uk.
We keep things simple: we only collect what we genuinely need to bake your order, deliver it, and keep in touch — nothing more.
2What we collect
Depending on how you use Handaran, we may collect:
- Order & account details — your name, email, phone number, delivery/collection address and order history.
- Payment information — processed securely by our payment provider. We never see or store your full card number.
- Messages & reviews — anything you send us through our contact form or leave as a customer review.
- Technical data — basic information your browser shares automatically, such as device type and pages visited, used to keep the site working and secure.
3How we use your information
We use your information to:
- Prepare, process and deliver your orders.
- Keep you updated about the status of an order or enquiry.
- Manage your account and save your delivery preferences.
- Respond to your messages, reviews and custom-cake requests.
- Improve our menu, website and service.
- Meet our legal and tax obligations.
We will only send you marketing messages if you have asked us to, and you can unsubscribe at any time.
4Our legal basis
Under UK GDPR, we rely on the following lawful bases for using your data:
- Contract — to fulfil an order you’ve placed with us.
- Legitimate interests — to run and improve our business in ways you’d reasonably expect.
- Consent — for optional things like marketing emails, which you can withdraw whenever you like.
- Legal obligation — to keep records required by law.
7How long we keep it
We keep your information only for as long as we need it. Order and tax records are kept for the period required by UK law (typically six years). Account information is kept until you ask us to close your account. Contact messages are kept while we deal with your enquiry and for a reasonable period afterwards.
8Your rights
You have the right to:
- Ask for a copy of the personal data we hold about you.
- Have inaccurate information corrected.
- Ask us to delete your data where there’s no reason for us to keep it.
- Object to or restrict how we use it.
- Withdraw consent for marketing at any time.
To exercise any of these, just email us. You also have the right to complain to the UK’s Information Commissioner’s Office (ICO).
9Keeping your data safe
We use appropriate technical and organisational measures — including encryption, secure hosting and restricted access — to protect your information against loss, misuse or unauthorised access.
Payments on our site are encrypted end-to-end and handled by a PCI-compliant provider.
10Contact us
If you’d like to ask a question, make a request, or raise a concern about your privacy, we’re happy to help.
Questions about your privacy?
We aim to respond to every request within 30 days.