Privacy Policy
Version 1 · Effective from 7 September 2026
CLICKMEATS LIMITED (Company Number 17328291) · Registered office: 140 Caldervale Avenue, Manchester, England, M21 7PY, United Kingdom · ICO registration reference: ZC232709
1. Who we are
ClickMeats (we, us, our) is a UK-based online marketplace and mobile application connecting customers with independent butcher shops for click-and-collect orders. We are collection-only at launch; if we introduce delivery in future, the "Delivery data" part of section 3 explains what would change. This Privacy Policy explains how we collect, use, share and protect personal data when you use our website at clickmeats.co.uk and our mobile app (together, the Platform), and what rights you have.
The Platform is operated by CLICKMEATS LIMITED, Company Number 17328291, registered in England and Wales with registered office at 140 Caldervale Avenue, Manchester, England, M21 7PY, United Kingdom. We are the data controller responsible for your personal data when you use the Platform. The butcher shop you order from is also a controller of the order information we send it, and for one limited step we and the shop are joint controllers — see section 2. You can reach us about anything in this policy at admin@clickmeats.co.uk.
This policy applies to customers, merchants (butcher shops) and their authorised users, and visitors to the Platform. It does not cover our own employees, workers, contractors or job applicants — we handle their personal data under a separate workforce privacy notice. It should be read together with our Cookie Policy, our Website Terms of Use and, if you order or sell through the Platform, our Platform Terms and Conditions (including, for merchants, its Schedule 1 (Data Processing Schedule)).
2. Our role and the butcher’s role
ClickMeats is a marketplace: the butcher shop you order from is the seller of record of the meat you buy. Both of us process some of your personal data, but for different reasons and with different responsibilities.
ClickMeats processes your data to run your account, take payment through our payment provider, route your order to the correct shop, send you order-status notifications (including push notifications if you turn them on), provide support, and improve the Platform.
The butcher shop processes a limited subset of your data (name, phone number, order details, any order notes, cut preferences and collection time) to prepare and hand over your order. The shop does not receive your email address, your card details or your order history with other shops. Shops agree not to use your contact details for anything beyond fulfilling your specific order and meeting their own legal obligations as the seller — for example its tax and accounting records, and records it needs in order to deal with complaints or legal claims.
For almost everything we each do with your data, ClickMeats and the butcher shop are separate, independent controllers. Each of us decides on its own why and how it uses the information: we run the Platform, your account and the payment process; the shop uses the order details we send it to prepare your order and to meet its own legal duties as the seller. We do not share a common customer database, and the shop has no say in what we collect, how we collect it or how long we keep it. There is one exception. For the limited step of making your order details available to the shop through the Platform so that your order can be fulfilled, we and the shop are joint controllers within the meaning of Article 26 UK GDPR. That is because we decide together, through the Platform Terms and Conditions, which details are passed on, when, and for how long the shop can see them. Joint controllership applies to that step only. It does not extend to what the shop does with the order afterwards, which is the shop’s responsibility alone. What each of us is responsible for is set out in Schedule 1 (Data Processing Schedule) to the Platform Terms and Conditions, at https://www.clickmeats.co.uk/legal/terms. In practice: we give you this privacy notice, and we are the easiest first point of contact for any request or complaint (see section 12); the shop is responsible for the order information once it has received it. You can contact either of us directly about your rights, and if you come to us about a shop we will help you reach them.
What we have agreed with the shops (the "essence" of our joint arrangement). Article 26 UK GDPR requires us to tell you the substance of how we and the shops divide up our data protection duties for that shared step. It is this: this privacy policy is the main privacy notice for order data, and shops must not display a conflicting one on their Platform shop page; we are the first point of contact for requests about your rights and we coordinate the answer, and a shop must pass any request it receives to us within 5 working days and help us respond; we coordinate any contact with the Information Commissioner’s Office, with the shop’s help where the problem started in the shop’s systems; we are responsible for the security of the Platform and the shop is responsible for securing its own devices and log-in credentials; and we keep your contact details for the periods in section 8, while the shop must not keep them after your order is fulfilled except where it needs them to meet a legal obligation, to keep its own tax, accounting, food-safety and traceability records, or to bring or defend a legal claim. You can exercise your rights against either of us. Whichever of us you contact, we will help you get an answer — email admin@clickmeats.co.uk.
3. The personal data we collect
Account data
Email address — required to create an account, sign in and receive order receipts.
Name — shown to the butcher you order from so they know who is collecting.
Phone number — used to contact you about collection orders (for example, when your order is ready).
Order data
Order history — items, quantities, prices, free-text notes, cut preferences and timestamps for every order you place, linked to your account.
Order status events — when your order moves through the confirmed / preparing / ready / collected stages.
Location and postcode data
Postcode or town searches — when you type a postcode or town into the website or the app to find nearby shops, we process what you type, together with your IP address, to return a list of shops and distances.
Precise device location (mobile app only) — if you turn on location permission in the app, the app reads your device's location and uses it on the device to sort shops by distance. Your precise coordinates are not sent to our servers and we do not store them. You can turn this off at any time in your device settings, and the app will fall back to postcode search.
Location on the website — the website does not read your location unless you choose “Use my location”. If you do, your browser passes your coordinates to the page, which holds them in the page address only for as long as it takes to work out distances to nearby shops. We do not keep them as a location history and they are not included in our analytics page-view events, although they may appear in our server and security logs, which are kept for 90 days. Otherwise the website works from the postcode or town you type in, and from the approximate, city-level location that can be inferred from your IP address by our hosting, security and analytics providers.
Payment data
Your full card details are never stored on our servers, and we never receive them. Payments are processed by Stripe; your card details go directly from your browser or device to Stripe. From Stripe we receive the order amount and currency, the payment status (for example authorised, succeeded, failed or refunded), Stripe's transaction and customer reference identifiers, the card brand, the last four digits and the expiry month and year, the country of issue, refund and chargeback information, and receipt details — but never your full card number or security code (CVV).
Merchant data
For merchants and their authorised users: business name, company number, trading address, opening hours, contact details of the shop's own staff who are authorised to use the Platform, and the onboarding documents a shop uploads to us — for example food business registration details, food hygiene rating evidence, certification evidence (such as halal or organic certification), proof of address, insurance documents and, where the shop is a sole trader or partnership, identity documents for the individuals behind it. For a dietary or religious certification we keep only the certifying body, the type of certification and the expiry date as structured fields: the uploaded certificate is permanently deleted once an administrator has verified it, and customers only ever see the verification status, the certifying authority and the expiry date. We also hold the shop's Stripe onboarding status. Where a shop gives us the details of its own staff or owners, we get that information from the shop rather than from the individual concerned. We require shops to give those individuals this privacy policy when they provide us with their details, and we will provide it to them directly on request. Stripe collects identity-verification and bank details directly under its own privacy notice.
Technical data
Browser and app session data — IP address, device and app version, user agent and basic interaction analytics (page and screen views, clicks and taps), recorded against a pseudonymous identifier and collected via PostHog (EU-hosted). This is opt-in on both the website and the mobile app, and we collect it only if you accept analytics. The data is pseudonymous, not anonymous: it is not directly identifying, but it can still be linked back to a device or an account, so we treat it as personal data.
Error reports — when the Platform hits an unexpected error, a technical report is sent to Sentry. Sentry Session Replay is switched off, so we do not record your screen or your session. Ordinary error reporting stays on. We configure Sentry to strip authorisation headers, cookies, payment details and common sensitive fields before reports are sent, but we cannot guarantee that personal data will never appear in an error report — for example where it forms part of an error message or a web address, and Sentry’s own service may see the IP address your device connects from. These are data-minimisation measures rather than a guarantee. Anything that does appear is kept for a short period and handled under our incident process.
Device and notification data
Push notification tokens — if you turn on notifications in the app, the operating system issues a token that identifies your installation of the app: a registration token from Google Firebase Cloud Messaging on Android, or a device token from the Apple Push Notification service on iOS. We store that token against your account so we can tell you when your order is ready. When we send a notification, the token, an internal order reference and the notification type are passed to Apple or Google so the app can open the right order. The notification you see is deliberately generic: it does not include your name, the shop’s name, your address, your collection time or what you bought. We treat these tokens as personal data. You can turn notifications off at any time in your device settings, which stops them appearing on your device. We mark a stored token inactive when the notification service tells us it is no longer valid — for example after you uninstall the app — which we can't always detect immediately, so a token may remain on file until the next delivery attempt fails. When you close your account, we delete your stored notification tokens.
Support and complaints data
Support correspondence — the emails, messages and any attachments you send us when you contact us for help or to make a complaint, together with our replies and our internal notes about the issue and how we resolved it.
Special category data
We do not ask you for special category data, and we ask you not to put sensitive information into free-text order notes. We do not offer a dietary preference field or filter, and the cut preference box is there for preparation instructions such as how you would like something cut, trimmed or portioned. Please do not use it for health information, or to tell us about a religious or philosophical belief. If you do give us that kind of information anyway, we will use it only to prepare and hand over that order and to pass it to the shop making it up, we will not use it for anything else: we store it and pass it to the shop word for word, we do not read, analyse, search or sort by it, and we redact it after 3 months as set out in section 8. Where we keep it for that short period, or for longer because a complaint or claim about the order is open, we do so to establish, exercise or defend legal claims under Article 9(2)(f) UK GDPR. Three months reflects the period within which a complaint, a payment dispute or a claim about a perishable order would normally come to light. We have recorded our assessment of this and will provide it on request. You can ask us to remove it sooner. We do not treat the fact that you have ordered from a shop we show as holding halal or kosher certification as, by itself, information revealing a religious belief — certified shops sell to the public for all sorts of reasons, the certification is a fact about the shop rather than a statement by you, and we do not use it to draw any inference about you. If we ever introduce a halal, kosher or similar dietary preference or filter, we will ask for your explicit consent at that point under Article 9(2)(a) UK GDPR and update this policy before we do. The Platform is not intended for children (see section 10).
Do you have to give us this information?
You have to give us your name, email address and phone number to open an account and place an order. This is a requirement of our contract with you: without it we cannot take your order, tell you when it is ready, or let the shop identify you at collection, so we would not be able to provide the Platform to you. Merchants have to provide the onboarding information described above in order to sell through the Platform. Everything else is optional — analytics, precise location and push notifications are all opt-in, and nothing happens to your account if you say no.
Delivery data — only if and when we introduce delivery
ClickMeats is collection-only at launch, and none of the processing described under this heading is happening today. We may in future allow shops to offer delivery, either using their own staff or a third-party courier. If we do, this part will apply — but only to customers who actually choose delivery on a particular order. If you continue to collect your orders, none of it applies to you.
Where you choose delivery, we would additionally process: your delivery address; the contact name and phone number for the delivery; any delivery instructions you give (for example "leave with a neighbour"); which shop or courier the delivery has been assigned to; the delivery status and the timestamps for each stage; and delivery evidence, which may include the location or GPS coordinates recorded at the point of handover, a photograph of where the order was left, or a name captured on delivery.
We would share this data with the shop and, where one is used, with the courier, so that they can deliver your order. We will update this policy and its effective date, and tell account holders in advance, before delivery goes live.
4. How we use your data and our lawful bases
| Purpose | Lawful basis (UK GDPR Article 6) |
|---|---|
| Run your account and fulfil your orders (including sharing order details with the shop you order from) | Performance of a contract — Art. 6(1)(b) |
| Send transactional emails (receipts, order-ready notifications, refund confirmations, security alerts) | Performance of a contract — Art. 6(1)(b) |
| Onboard and pay merchants via Stripe Connect | Performance of a contract — Art. 6(1)(b) |
| Prevent fraud and abuse and secure the Platform | Legitimate interests — Art. 6(1)(f) |
| Verify merchant identity, business, registration and certification details | Legitimate interests — Art. 6(1)(f) |
| Improve the Platform via pseudonymous product analytics on our website and mobile app, which are off unless you switch them on and can be switched off again through Cookie settings on the website or Account settings in the app | Consent — Art. 6(1)(a) |
| Comply with legal obligations (tax and accounting records, handling data protection complaints, and responding to regulators and other lawful requests) | Legal obligation — Art. 6(1)(c) |
| Show you shops near a postcode or town you type in, or near your location if you choose to share it | Legitimate interests — Art. 6(1)(f) for the postcode or town you type in. Where you choose “Use my location”: Consent — Art. 6(1)(a), and consent under regulation 6 of the Privacy and Electronic Communications Regulations 2003 for the website to read your device’s location |
| Use your device's precise location in the app to sort shops by distance (the app does this on your device; we do not receive the coordinates) | Consent — Art. 6(1)(a), and consent under regulation 6 of the Privacy and Electronic Communications Regulations 2003 (together with your device permission) for the app to read your device’s location; we do not receive or process the coordinates |
| Send you push notifications about your order, if you turn them on | Consent — Art. 6(1)(a), together with regulation 6 of the Privacy and Electronic Communications Regulations 2003 (PECR) for storing the notification token on your device |
| Handle your support enquiries, and receive, investigate and respond to data protection complaints | Performance of a contract — Art. 6(1)(b); Legitimate interests — Art. 6(1)(f) (responding to people who contact us) where you do not have an account with us; Legal obligation — Art. 6(1)(c) (section 164A Data Protection Act 2018) |
| Arrange, carry out and evidence delivery — only if we introduce delivery and you choose it | Performance of a contract — Art. 6(1)(b) |
| Diagnose and fix technical faults through error monitoring | Legitimate interests — Art. 6(1)(f) |
| Disclose data to law enforcement, regulators or a court | Legal obligation — Art. 6(1)(c) where we are required to; otherwise legitimate interests — Art. 6(1)(f) (preventing fraud, protecting our rights, protecting someone's safety) |
| Transfer data if we sell or reorganise the business | Legitimate interests — Art. 6(1)(f) |
| Marketing communications (only if introduced in future) | Consent — Art. 6(1)(a); you can withdraw at any time |
We do not use your data for marketing without your explicit consent, and we do not sell, rent or trade your data to third parties. Where we rely on legitimate interests, those interests are in keeping the Platform secure and free from fraud, checking that merchants are who they say they are, running and improving the service, and dealing with complaints and legal claims. We have weighed those interests against your rights and freedoms, and you can ask us for a copy of that assessment at admin@clickmeats.co.uk. We do not ask for special category data and do not offer a dietary preference field or filter; how we handle anything sensitive that you give us anyway is described under "Special category data" in section 3.
5. Automated decision-making
We do not use profiling to decide whether to accept or refuse your business in a way that produces a legal effect for you, or affects you in a similarly significant way. Order routing and order-status updates are rule-based and involve no profiling.
Payments are a partial exception, and you should know about it. Our payment provider, Stripe, screens every payment for fraud using Stripe Radar, which gives each payment an automated risk score, and payments Stripe scores as high risk can be declined automatically without anyone looking at them first. Stripe carries out this screening as a controller in its own right, for its own fraud-prevention and regulatory purposes as well as ours. A declined payment does not stop you ordering — you can use a different card or contact us — so we do not consider it a "significant decision" within Articles 22A to 22D UK GDPR. Even so, if a payment of yours is declined and you think that is wrong, email admin@clickmeats.co.uk. A person here will look at what happened, tell you what we can, and — where we are satisfied the payment was legitimate — add it to our allow list so that future payments from the same card or email address are not blocked. That does not retry the declined payment, so you will need to place the order again. You are also free to try a different payment method.
6. Who we share your data with
The butcher you order from
When you place an order, the shop receives your name, phone number and order details (items, quantities, any order notes, cut preferences, collection time). The shop cannot see your email address, your card details, or orders you have placed with other shops. Shops agree in the Platform Terms and Conditions (including the Schedule 1 (Data Processing Schedule)) not to use your contact details for any purpose beyond fulfilling the specific order you placed with them and meeting their own legal obligations. The shop is a controller of that information in its own right, and we are joint controllers with the shop for the limited step of passing it on — see section 2.
Couriers — only if we introduce delivery
We do not use couriers today. If we introduce delivery and you choose it, we would share your delivery address, contact details and delivery instructions with the shop and, where one is used, with its courier, so that your order can be delivered. We will update this policy before that happens.
Service providers (processors and sub-processors)
The following third parties process personal data for us to keep the Platform running. Most act as our processors, which means they may only use the data on our instructions. Two are different. Stripe acts as a controller in its own right for the payment services it provides, including fraud prevention and meeting its own legal and regulatory duties. Apple accepts no processor obligations for its Push Notification service, so we treat Apple as a separate recipient acting as its own controller rather than as our processor.
| Provider | What they do | Data they process | Location |
|---|---|---|---|
| Amazon Web Services | Application hosting, database, file storage | All personal data we hold | UK (eu-west-2, London) |
| Amazon Cognito | User authentication (sign-in and password reset) | Email, phone, name and your sign-in credentials; your password is never stored in readable form | UK (eu-west-2, London) |
| Vercel | Website hosting and global CDN | IP address, requested web address and browser metadata in request logs, and any personal data processed by our website’s server-side code; order data is stored in our AWS UK environment | United Kingdom (London function region), with global CDN edge locations |
| Stripe (Stripe Payments Europe, Limited; Stripe Payments UK Ltd for UK regulated payment services) | Card payment processing, fraud screening and merchant payouts | Card details, name, email, order amount, payment status, transaction identifiers, refund and chargeback data | Ireland and the United States (Stripe, LLC), with onward transfers within the Stripe group |
| Resend (Plus Five Five, Inc.) | Transactional email delivery | Recipient email address, message content | United States — all account data, email metadata and logs are stored in the US, whichever sending region is used |
| PostHog (EU Cloud) | Pseudonymous product analytics on the website and app (opt-in only) | Pseudonymous session identifier, IP address and request metadata, page views, clicks; no name, email or postal address, though the record can be linked to your account | European Union (Frankfurt); the vendor is incorporated in the United States |
| Sentry | Error monitoring (Session Replay is switched off) | Technical error data; we configure Sentry to strip sensitive fields before transmission, but personal data can still appear in a report, and Sentry’s service may see the IP address your device connects from | United States or European Union (Frankfurt), depending on the region selected for our account; in either case Sentry holds our user accounts, access tokens, two-factor authenticators, organisation settings and audit logs in the United States |
| Cloudflare (Cloudflare, Inc.) | DNS and security/DDoS protection | Personal data contained in requests and responses passing through the network, including names and order details, plus IP address and request metadata in logs | Global |
| Google Firebase Cloud Messaging | Delivering push notifications to Android devices | Notification registration token and the content of the notification | Google data centres worldwide |
| Apple Push Notification service (Apple Distribution International Limited) | Delivering push notifications to Apple devices | Device notification token and the content of the notification | Apple infrastructure; Ireland and the United States |
We also use Namecheap (Namecheap, Inc., United States) for domain registration and for the business email service we use to correspond with you, which means it processes the content of that correspondence. We keep a current list of our service providers, with what each does and where it processes data, at https://www.clickmeats.co.uk/legal/subprocessors. We may add or replace service providers from time to time. When we do, we will update this table and the effective date of this policy and, where the change is material, notify account holders in advance so you can review it.
Law enforcement and regulators
We disclose personal data to law enforcement, regulators (including the ICO) or a court only where we are legally required to do so, or where we reasonably believe disclosure is necessary to prevent fraud, protect our rights or protect the safety of a person.
Business changes
If we sell or reorganise our business, personal data may be transferred to the new operator on terms no less protective than this policy.
Professional advisers and insurers. We may share personal data with our lawyers, accountants, auditors and insurers where they need it to advise us or to handle a claim, and with debt recovery agents where an amount is properly owed to us. They are bound by confidentiality obligations.
7. International data transfers
Most of your data stays in the UK: our primary data store is in the AWS London region (eu-west-2). Our analytics data is held in Frankfurt, in the EU. Some providers — including Stripe, Resend, Sentry, Cloudflare, Vercel, Google and Apple — process personal data outside the UK, mainly in the European Economic Area and the United States. Some of our UK and EU hosted providers, such as PostHog, are companies based outside the UK whose support staff may need access to the systems holding your data; we treat that access in the same way as any other transfer.
Where we transfer personal data outside the UK, we make sure that one of the following applies. Either UK adequacy regulations cover the destination — these cover the European Economic Area, and cover the United States where the receiving organisation is certified under the UK Extension to the EU–US Data Privacy Framework. Or we have in place the ICO's international data transfer agreement (IDTA). Or we have in place the ICO's international data transfer addendum to the European Commission's standard contractual clauses for international data transfers. Where we rely on the IDTA or the addendum, we also carry out a transfer risk assessment and put in place any additional measures it identifies. Which one applies depends on the provider: adequacy under the UK Extension to the Data Privacy Framework where the provider is currently certified for the data in question, and otherwise the IDTA or the addendum. The provider table in section 6 shows where each provider processes data, and we will tell you the mechanism that applies to any particular provider on request. You can ask us for a copy of the safeguards we rely on at admin@clickmeats.co.uk.
8. How long we keep your data
| Data | Retention period |
|---|---|
| Account data | For as long as your account is open. You can delete your account at any time in the mobile app, and deletion takes effect immediately. If you cannot get into the app, email admin@clickmeats.co.uk and we will do it for you. We do not operate a recovery period, so once we delete an account it cannot be restored — apart from the order records below, which we must keep. |
| Order data | Up to 7 years from the end of the financial year in which the order was placed. Paragraph 21 of Schedule 18 to the Finance Act 1998 requires us to preserve the records supporting our tax return for 6 years from the end of the accounting period, and we may be required to keep VAT records for up to 6 years. We may keep an order record for up to a further year where that is necessary to deal with a dispute or to bring or defend a legal claim, because a claim on a simple contract can be brought within 6 years of the date it arises (section 5, Limitation Act 1980). We do not keep every part of an order record for that long. We redact free-text order notes, cut preferences and any delivery instructions after 3 months, and your name, email address, telephone number and any delivery address after 24 months, leaving the core order, payment, tax, dispute and fraud record. We may keep contact details or notes for longer only where a legal hold applies, or where they are needed for a live dispute, chargeback or fraud investigation, or where the law requires it — and we will delete them sooner if you ask us to and no exception applies |
| Analytics events | 12 months from collection |
| Error reports | 30 days from receipt |
| Support correspondence | Up to 3 years after the issue is resolved, or up to 6 years where it relates to a dispute, a complaint or a potential legal claim |
| Merchant and merchant onboarding data | For as long as the shop sells through the Platform, plus 6 years, to meet our tax and accounting obligations and to deal with any dispute or legal claim. Identity documents are deleted once onboarding checks are complete, and uploaded certificates are deleted once an administrator has verified them |
| Postcode and town searches | We do not keep a history of your searches. What you type is used to return results and then appears only in our server and security logs, which are kept for 90 days. Precise device location is used on your device, or in the page address for as long as it takes to calculate distances; we keep no location history, and any coordinates that reach our server or security logs are deleted with those logs after 90 days |
| Push notification tokens | For as long as you keep notifications turned on. Deleted when you turn them off, uninstall the app or close your account |
| Delivery data (only if we introduce delivery) | Kept as part of the order record it relates to — see "Order data" above. Delivery photographs and GPS handover evidence are kept for 6 months, or longer where they relate to a dispute, a complaint or a potential legal claim |
| Notification tokens | Kept while valid; marked inactive when the push service reports the token is no longer valid; deleted when you close your account — Only stored if you turn on push notifications. |
When data is no longer needed, we delete it or irreversibly anonymise it. Backup copies are overwritten on our standard backup cycle, so a copy may remain in a backup for a short period after deletion; during that period it is not used for any other purpose.
Other records. Server, request and security logs are kept for 90 days. Records of your consents, including cookie and analytics consent and, if we introduce one, any explicit consent under Article 9, are kept for 3 years after the consent ends, so that we can show what you agreed to. Records of personal data breaches are kept for 6 years. Article 33(5) UK GDPR requires us to document every breach but does not set a period; we have chosen 6 years to match the limitation period. Where support correspondence contains information of the kind described under “Special category data” in section 3, we redact it on the same timetable as the order record unless a dispute or claim is open. Records of requests you make about your rights, and of data protection complaints, are kept for 3 years after the matter is closed. If you ask us not to send you marketing, we keep a record of that indefinitely so that we do not contact you again. Our backup cycle is 35 days.
9. Marketing communications
We send transactional emails (receipts, order-ready notifications, refund confirmations, security alerts) as part of running your account — these are necessary to perform our contract with you and cannot be turned off while you have an active account.
We do not currently send promotional or marketing emails. If we introduce marketing communications (or new marketing channels such as SMS, WhatsApp or marketing push notifications) in the future, we will ask for your explicit opt-in first, every marketing message will include a simple way to unsubscribe, and we will update this policy before the change takes effect.
10. Children
The Platform is for adults. You must be 18 or over to open an account or place an order. We do not aim the Platform at children, we do not design it to appeal to them, and we do not knowingly collect personal data from anyone under 18. If we discover that an account belongs to someone under 18, we will close it and delete the personal data, apart from anything we are required by law to keep. If you believe a child has given us personal data, please contact us at admin@clickmeats.co.uk and we will deal with it. We have assessed whether the Platform is likely to be accessed by children within the meaning of the Information Commissioner’s Age Appropriate Design Code, and concluded that it is not: it is aimed at adults buying food and at butcher shop owners and their staff, it carries no child-focused content and no social features, and analytics is off unless you switch it on. We do not offer accounts to anyone under 18, and we act on any indication that a user is under 18; we do not treat a self-declared age as age assurance. That assessment is documented and dated and we keep it under review, in particular if we introduce ratings and reviews or any loyalty or referral feature.
11. Security and data breaches
We protect personal data using measures appropriate to the risk, including encryption in transit (TLS 1.2 or above) and at rest (AES-256), role-based access controls with individually authenticated accounts and multi-factor authentication for administrative access, the principle of least privilege, secrets management, automated backups with point-in-time recovery, logging and monitoring, security checks on the providers we use, staff training, and a documented incident-response process. We review and test these measures regularly. No system can be guaranteed completely secure, but we take these obligations seriously.
Where a personal data breach is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of becoming aware of it. Where a breach is likely to result in a high risk to your rights and freedoms, we will also tell you without undue delay, unless one of the exceptions in Article 34(3) UK GDPR applies — for example where the affected data was encrypted, or where we have since taken steps that mean the high risk is no longer likely to materialise. We keep a record of every personal data breach, including those we are not required to report.
12. Your rights
Under the UK GDPR and the Data Protection Act 2018, you have the right to:
ask for a copy of the personal data we hold about you (access);
ask us to correct inaccurate data (rectification);
ask us to delete your data (erasure). This is not an absolute right: we can refuse where we still need the data to comply with a legal obligation, or to bring or defend legal claims (Article 17(3) UK GDPR) — for example the order records described in section 8. You can delete your account in the mobile app, and deletion takes effect immediately, with no recovery period afterwards; if you cannot get into the app, email us and we will do it for you;
ask us to restrict how we use your data while a concern about it is looked into (restriction);
object, on grounds relating to your particular situation, to processing we carry out for our legitimate interests (objection). We will stop unless we can show compelling legitimate grounds that override your interests, rights and freedoms, or that we need the data for legal claims;
receive the personal data you have given us in a structured, commonly used, machine-readable format, where we process it by automated means on the basis of your consent or of our contract with you (portability); and
withdraw any consent you have previously given, at any time, without affecting processing before withdrawal.
Beyond these legal rights, if a payment of yours is declined by automated fraud screening we will have a person look at what happened and help you take it up with our payment provider — see section 5.
Your right to object to direct marketing. Separately from the rights above, you have the right to object at any time to us using your personal data for direct marketing, including any profiling connected with it. This right is absolute: if you object, we will stop. We do not send marketing at the moment; if we start, every message will carry a simple unsubscribe, and you can object at any time by emailing admin@clickmeats.co.uk.
To exercise any of these rights, email admin@clickmeats.co.uk. We will respond within one month. We can extend that by up to two further months where a request is complex or where you have made a number of requests — if we need to, we will tell you within the first month and explain why. We may ask you to verify your identity, or for more information to help us find what you are looking for, and the time limit pauses until you give it to us. Exercising your rights is free of charge, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act on it — and it is for us to show why a request meets that test.
Complaining to us. If you are unhappy with how we have handled your personal data, you have the right to complain to us under section 164A of the Data Protection Act 2018. Email admin@clickmeats.co.uk. We will acknowledge your complaint within 30 days, make appropriate enquiries into it, keep you updated on progress and tell you the outcome.
Complaining to the ICO. You can also complain to the Information Commissioner's Office under section 165 of the Data Protection Act 2018 — at ico.org.uk/make-a-complaint, by calling 0303 123 1113 (textphone 18001 0303 123 1113), or by writing to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. You do not have to come to us first, but we would appreciate the chance to put things right.
13. Cookies
We use strictly necessary cookies and similar technologies — including storage on your device and in our mobile app — to keep you signed in and remember your basket. Everything else is opt-in: we ask for your consent before we store anything on your device, or read anything already stored on it, that is not strictly necessary. That includes analytics identifiers on the website and in the app, your push notification token, and access to your device's precise location. Analytics is switched off unless you actively accept it, and it stays off if you do nothing. You can change or withdraw your choices at any time — on the website through Cookie settings, and in the mobile app through Account settings. We rely on your consent for analytics and do not rely on the exception for statistical purposes in Schedule A1 to the Privacy and Electronic Communications Regulations 2003, because our analytics can include event-level and pseudonymous user and device information. Full details are in our Cookie Policy at clickmeats.co.uk/legal/cookies.
14. Changes to this policy
If we ever want to use your personal data for a new purpose that is not described in this policy, we will tell you about that purpose, and give you the information listed in Article 13 UK GDPR, before we start. We will update the effective date below when we make material changes. For substantive changes (new purposes or new categories of recipient), we will also email registered users at least 14 days before the change takes effect.
15. Contact
Questions, requests or complaints: admin@clickmeats.co.uk or by post to CLICKMEATS LIMITED, 140 Caldervale Avenue, Manchester, England, M21 7PY. Section 12 explains how to complain to us, and how to complain to the Information Commissioner's Office. We are not required to appoint a data protection officer and have not appointed one; data protection is the responsibility of our directors, who can be reached at the address above.
Version 1. Effective from: 7 September 2026. Previous versions of this policy are available on request from admin@clickmeats.co.uk.
