Privacy notice
Privacy.
Controller
Jamescape Limited, Innovation Centre, 131 Mount Pleasant, Liverpool, L3 5TF. Privacy requests: hello@jamescape.net.
Information we use
We use order reference, product, batch, price, payment and fulfilment records. Stripe supplies the email needed for confirmation. For local delivery, we also collect name, phone, delivery address and optional access instructions. Do not include health details, access codes or other sensitive information in instructions.
Purposes and legal bases
Quote, payment, contract, pickup, local delivery, support and refunds are processed to perform the contract. Accounting, tax, regulator and product-safety records are kept for legal obligations. Proportionate fraud, security, audit, dispute and recall records use legitimate interests. We do not create a marketing list and no advertising, session replay or non-essential analytics are enabled.
Service providers
Vercel hosts the application; Neon stores application records; Stripe processes payment; the local courier receives only delivery-required information; Bird receives only transactional-email information; and Better Auth protects the administrator area. Vendor processing, locations, subprocessors, retention, security terms, DPAs and any UK transfer mechanism must be recorded in the launch register before checkout is enabled.
Security and minimisation
Phone numbers, addresses and instructions are encrypted by the application. Secrets are separated by environment. Public order tokens are hashed in storage, excluded from indexing and protected by no-referrer/no-store headers. Administrator access is restricted, rate-limited and audited. We do not place personal information in payment metadata, URLs, analytics events or email subject lines beyond a short order reference.
Retention
Access instructions are deleted after fulfilment or refund and no later than seven days, unless needed for an open safety case. Operational phone and full-address fields, plus public tokens, are removed after 90 days. Payment, accounting, product-batch, safety, dispute and audit records are retained only for their confirmed legal, insurance and tax periods. Open safety incidents suspend automated deletion of relevant order data.
Cookies
The public store uses no advertising or analytics cookies. Strictly necessary secure session and security storage is used only for administrator authentication and abuse prevention.
Your rights
You may request access, correction, deletion, restriction, objection or a portable copy where applicable. You may make the request in free text by email and are not required to use an online form. We may retain information where a legal obligation or active product-safety issue requires it. You can also complain to the UK Information Commissioner's Office.
Incidents
The operator maintains a breach register and a 72-hour ICO assessment procedure covering containment, processor escalation, risk assessment, notification decisions and communications to affected people.