This policy explains what we do with your personal information when you visit nibblers.co.uk, place an order, create an account, or get in touch. We’ve aimed to keep it short, plain, and honest.
In this policy, “we”, “us”, and “Nibblers” refer to the business operating nibblers.co.uk. We act as the data controller for personal information collected through this site. You can contact us any time via our contact page.
What we collect
- Order information. Name, billing and delivery addresses, email address, phone number, order items and totals, and any notes you add at checkout. Collected when you place an order, whether as a guest or through an account.
- Account information. Email address, a hashed password, saved addresses, order history, Nibbles Rewards balance and transaction log, pinned favourites, and any venue/trade details you choose to provide. Collected only if you register.
- Payment details. Card details are entered directly with our payment processor (Stripe, via WooCommerce Payments) and never reach our servers. We store only the transaction reference, the last four digits of the card, and the outcome.
- Newsletter subscriptions. Your email address if you sign up to hear about new products and offers. Passed straight to Klaviyo, our email service provider, where the subscription is managed.
- Contact form submissions. Your name, email, and the message you send us.
- Reviews. If you leave a review after a purchase, your name (or initials), email, and the review content are collected and processed by Reviews.io, our reviews provider.
- Technical information. Browser type, device, IP address, pages viewed, and the referring URL. Collected automatically in server logs, and — with your consent — by analytics cookies.
- Local preferences. Your device stores a few lightweight preferences in its own localStorage so the site remembers you: chosen theme (light/dark), last-viewed strip tab, grid-vs-list choice, and your cookie-banner answer. These never leave your device.
How we use it
- Fulfilling your order. We use your contact and delivery details to take payment, pack your order, and arrange delivery with DPD. Legal basis: performance of a contract.
- Running your account. Login, order history, Nibbles Rewards, favourites, and saved addresses. Legal basis: performance of a contract.
- Customer service. Responding to contact form messages, order queries, and complaints. Legal basis: our legitimate interests in looking after our customers.
- Order-related emails. Order confirmations, dispatch notifications, Nibbles notices, and the occasional service email (e.g. a delivery date change). Legal basis: performance of a contract.
- Marketing emails. Only if you opt in, via the newsletter form or a tick-box at checkout. You can unsubscribe any time using the link in every marketing email. Legal basis: consent.
- Fraud & spam prevention. Google reCAPTCHA protects our forms from automated abuse. It sends browser behaviour signals and your IP to Google. Legal basis: our legitimate interests in a secure site.
- Analytics and advertising. With your consent (via the cookie banner), Google Analytics and the Meta Pixel help us understand how the site is used and reach you with relevant ads elsewhere. Under Google Consent Mode v2, these are denied by default until you accept. Legal basis: consent.
- Legal obligations. Keeping order records for HMRC, handling data-subject requests, and responding to lawful requests from public authorities. Legal basis: legal obligation.
Who we share it with
- Stripe (via WooCommerce Payments). Handles card payments. Card details are collected by Stripe directly in your browser. Stripe privacy policy.
- DPD. Our delivery partner. Receives your name, delivery address, and phone number (for missed-delivery SMS) when we dispatch your order.
- Klaviyo. Sends our marketing emails and stores newsletter subscriber lists. US-based; transfers are covered by the UK Extension to the EU-US Data Privacy Framework. Klaviyo privacy notice.
- Reviews.io. Invites you to review products after a purchase and stores the review you leave. Receives your name, email, and order reference. UK-based. Reviews.io privacy policy.
- Google. With your consent, Google Analytics and Google Ads receive standard browser / device data via Google Tag Manager. reCAPTCHA (always on, for spam prevention) also sends data to Google. Google privacy policy.
- Meta (Facebook). With your consent, the Meta Pixel receives page-view and conversion events for advertising. Meta privacy policy.
- Our hosting and email infrastructure. Managed by 20i (UK) for hosting and our configured SMTP provider for outbound email.
- Authorities. If required by law, we share information with courts, regulators, and law enforcement.
We don’t sell your personal data, and we don’t share it for any purpose not listed above.
Cookies and local storage
- Essential (always on). WooCommerce session, cart contents, login, cookie-consent state, and CSRF/nonce tokens. Without these the site can’t function.
- Preferences (on device only). Theme choice, sidebar state, strip-tab selection, grid/list view. Stored in your browser’s localStorage and never transmitted back to us.
- Analytics & advertising (opt-in). Google Analytics, Google Ads remarketing, and the Meta Pixel. Default is denied under Google Consent Mode v2; they start firing only after you click Accept in the cookie banner.
- Fraud prevention. Google reCAPTCHA v3 runs on forms regardless of consent; it’s classed as a strictly-necessary security measure.
You can change your cookie answer any time by clearing your browser’s site data for nibblers.co.uk — the banner will reappear on your next visit.
How long we keep it
- Order records. Six years after the last transaction, to meet HMRC record-keeping requirements.
- Accounts. Until you ask us to delete your account, or after six years of inactivity.
- Newsletter subscriptions. Until you unsubscribe.
- Contact form messages. Up to 24 months after our last reply, then deleted.
- Reviews. Kept by Reviews.io for as long as the product or company is listed, unless you ask for removal.
- Server and security logs. Typically 30–90 days, then rotated out automatically.
Your rights
Under the UK GDPR and the Data Protection Act 2018, you have the right to:
- Access. Ask for a copy of the personal data we hold about you.
- Correct. Ask us to fix anything that’s wrong or out of date.
- Delete. Ask us to erase your personal data. We may need to keep order records for the legal retention period, but the account itself can be closed on request.
- Restrict or object. Ask us to stop or limit a particular use of your data.
- Port. Receive your data in a portable format (e.g. CSV) so you can move it elsewhere.
- Withdraw consent. For anything that relies on consent (marketing, analytics / advertising cookies), withdraw it at any time.
- Complain. If you think we’ve mishandled your data, you can complain to the UK’s Information Commissioner’s Office at ico.org.uk. We’d prefer a chance to sort it first — drop us a line via the contact page.
Security
- Encryption in transit. The whole site runs over HTTPS. Passwords are stored hashed (never in plain text).
- Payment isolation. Card data is entered directly into Stripe’s hosted fields; it doesn’t pass through our servers.
- Access controls. Staff accounts use role-based permissions; only the people who need access to customer data have it.
- Backups. Daily site and database backups are retained on encrypted storage for disaster recovery.
International transfers
Some of our providers operate outside the UK (notably Klaviyo, Stripe, Google, and Meta — all with US operations). Where personal data moves outside the UK, it’s covered by the UK Extension to the EU-US Data Privacy Framework, by Standard Contractual Clauses, or by equivalent safeguards recognised under UK data protection law.
Children
Nibblers is a trade-leaning supplier and isn’t aimed at children. We don’t knowingly collect personal data from anyone under 16. If you believe your child has provided personal data to us, please contact us and we’ll delete it.
Changes to this policy
We may update this policy from time to time — usually to reflect a new integration, a change in the law, or a clarification. The current version is always this page. If a change materially affects how we use your data, we’ll tell you (via a site notice or an email to account holders) before it takes effect.
Last updated: April 2026.
Questions? Get in touch.