Privacy Notice
Effective Date: 01/03/2026
Ellie's Oats is committed to protecting your personal data. This Privacy Notice explains how we collect, use, and protect your information in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
1. The Information We Collect
When you place an order through our website, we collect:
- Your full name
- Your delivery address
- Your phone number
This information is required so we can process and deliver your oat bowl order.
2. Lawful Basis for Processing
Under UK GDPR, our lawful basis for collecting and using your personal data is:
Contractual necessity – we need your personal information to fulfil your order and deliver your products.
3. How We Use Your Information
We use your personal information to:
- Process and manage your order
- Deliver your products
- Contact you regarding your order if necessary
We do not sell, rent, or share your personal data with third parties for marketing purposes.
4. Payments
We use SumUp to securely process card payments.
When you make a payment, your payment details (such as your card information) are processed directly by SumUp. We do not store or have access to your full card details.
SumUp acts as a separate data controller for payment processing and handles your data in accordance with its own privacy policy. We recommend reviewing SumUp's privacy policy on their website for more information about how they process your personal data.
We only receive confirmation that your payment has been successful, along with limited transaction details necessary for our records.
5. How We Store Your Information
Your personal information is stored securely on our business phone and is only accessed for order and delivery purposes.
We take reasonable steps to protect your data from loss, misuse, or unauthorised access.
6. How Long We Keep Your Data
We retain your personal data only for as long as necessary to:
- Fulfil your order
- Maintain basic business and financial records
You may request deletion of your data at any time by contacting us (see Section 9).
7. Your Data Protection Rights
Under UK data protection law, you have the right to:
- Request access to your personal data
- Request correction of inaccurate data
- Request erasure of your data
- Request restriction or object to processing in certain circumstances
- Lodge a complaint with the Information Commissioner's Office (ICO)
If you are unhappy with how we handle your data, you may contact the ICO:
8. Contact Us
If you have any questions about this Privacy Notice or your personal data, please contact: