Privacy Policy
Last Updated: 15 January 2026
Effective Date: 15 January 2026
Introduction
Organic Coffee Co Ltd ("we", "us", "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and share your information when you visit our website or purchase our products. We are registered in England and Wales under company number 12847392, and our registered office is at 157 High Street, Hornchurch, England, RM11 3YD.
This policy applies to all visitors and customers of our website. By using our website, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of this policy, please do not use our website or services.
Cookie Categories
We use three types of cookies on our website. Below is a detailed explanation of each category, their purpose, and how they are activated.
1. Essential Cookies
Purpose: Essential cookies are necessary for the core functionality of our website. They enable basic features such as page navigation, secure access to your account, and maintaining your shopping basket contents between pages.
Examples: session_id (maintains your logged-in session), csrf_token (prevents cross-site request forgery attacks), cookie_consent_status (remembers your cookie preferences).
Consent Required: No. Essential cookies are activated automatically because they are strictly necessary for the website to function properly. Without these cookies, services you have requested cannot be provided.
Retention: Session cookies expire when you close your browser. Preference cookies may be stored for up to 12 months.
2. Analytics Cookies
Purpose: Analytics cookies help us understand how visitors interact with our website. They collect information about which pages are visited most frequently, how long users spend on each page, and any error messages encountered. This data helps us improve the user experience and site performance.
Tools Used: We use Google Analytics 4 to collect and analyse usage data.
Examples: _ga (distinguishes unique users), _ga_XXXXXXX (maintains session state), _gid (distinguishes users), _gat (throttles request rate).
Consent Required: Yes. Analytics cookies are only activated after you explicitly accept them through our cookie consent banner.
Retention: Google Analytics cookies are retained for up to 14 months from your last visit.
3. Marketing / Advertising Cookies
Purpose: Marketing cookies enable us to deliver personalised advertisements based on your browsing behaviour and interests. They track your visits to our website and other sites across the internet to build a profile of your interests and show you relevant advertisements.
Consent Required: Yes. Marketing cookies are only activated after you explicitly accept them through our cookie consent banner.
Retention: Marketing cookies may be stored for up to 540 days, which is the default retention period for Google Ads conversion tracking.
Marketing Cookies — Detailed Disclosures
When you consent to marketing cookies, the following activities and data processing take place:
Third-Party Ad Serving
Third-party vendors, including Google, use cookies to serve advertisements based on your previous visits to this website and other websites you have visited on the internet. This allows us to reach potential customers who have shown interest in organic coffee or related products.
Advertising Partners
We work with advertising partners such as Google and Meta (Facebook/Instagram) to deliver advertisements tailored to your interests across various websites and platforms. These partners act as independent data controllers for data collected through their own tracking technologies.
Remarketing Services
We use remarketing services to advertise to previous visitors of our website. After visiting our site, you may see our advertisements on other websites, applications, or platforms you visit. This allows us to stay connected with potential customers and remind them of our products.
YouTube and Display Network
Our advertisements may appear across Google services including YouTube, Gmail, and the Google Display Network. This broad reach helps us connect with coffee enthusiasts wherever they spend time online.
Tracking Technologies
We use the following tracking technologies on this website:
- Cookies (both first-party and third-party)
- Tracking pixels (Google Ads tag / gtag.js, Meta Pixel)
- Device identifiers (browser fingerprint, IP address)
- Conversion event tags
Advertising Measurement
We use conversion tracking to understand which advertisements lead to meaningful actions on our website, such as newsletter signups, contact form submissions, or product purchases. This measurement allows us to evaluate campaign effectiveness and allocate our advertising budget appropriately. Conversion data may be shared with Google Ads and Meta for reporting and optimisation purposes.
Technologies in Use
The following advertising and analytics technologies are active on this website when you consent to marketing cookies:
- Google Ads (gtag.js / Google Tag Manager)
- Google Analytics 4
- Google Remarketing Tag
- Meta Pixel (Facebook / Instagram)
Opt-Out from Personalised Advertising
You may opt out of personalised advertising at any time through the following channels:
- Google Ads Settings: https://adssettings.google.com
- Your Online Choices (EU): https://www.youronlinechoices.eu
- Network Advertising Initiative: https://optout.networkadvertising.org
- Digital Advertising Alliance: https://optout.aboutads.info
Please note that opting out does not remove advertisements entirely. You will continue to see non-personalised advertisements that are not tailored to your interests or browsing history.
Cookie Preference Management
You can manage your cookie preferences at any time by clicking the link in our website footer. This opens a panel where you can accept or reject each cookie category independently. Essential cookies remain active at all times as they are necessary for core website functionality.
Consent Requirements
Cookie Consent Banner
When you first visit our website, you will see a cookie consent banner that offers three options:
- Accept All: Activates essential, analytics, and marketing cookies
- Reject Non-Essential: Activates only essential cookies; analytics and marketing cookies remain inactive
- Manage Preferences: Opens a detailed panel where you can select which cookie categories to accept
Analytics and marketing cookies are not activated until you explicitly click "Accept All" or toggle them on in the preferences panel. The banner can be dismissed without accepting, which is equivalent to selecting "Reject Non-Essential". Your choice is stored in your browser's local storage for 12 months.
Consent Statement
By clicking "Accept All Cookies", you consent to the storing of cookies on your device for analytics and advertising purposes, including personalised advertising delivered by Google and Meta. You may withdraw consent at any time through the cookie preferences panel without affecting the lawfulness of processing that occurred before withdrawal.
EEA / UK Users
Users in the European Economic Area and the United Kingdom receive this consent notice in compliance with the General Data Protection Regulation (GDPR) and UK GDPR. Marketing and analytics cookies are activated solely after explicit, informed, freely given consent under GDPR Article 6(1)(a). Consent is recorded with a timestamp and may be audited upon request.
Withdrawal of Consent
You may withdraw consent at any time by clicking "Manage Cookie Preferences" in the website footer, or by clearing cookies via your browser settings. Withdrawal does not affect processing that occurred whilst consent was valid. After withdrawing consent, analytics and marketing cookies will be deactivated, and no new data will be collected for those purposes.
Data Sharing with Advertising Partners
We share certain data with advertising partners for campaign delivery and measurement. The recipients and data categories shared include:
Google LLC
Data Shared: Cookie identifiers, conversion events, anonymised behavioural data, remarketing lists.
Purpose: To deliver and measure the effectiveness of advertisements shown through Google Ads across Google Search, YouTube, Gmail, and the Google Display Network.
Governed by Google's Privacy Policy: https://policies.google.com/privacy
Meta Platforms, Inc.
Data Shared: Pixel events, conversion data, custom audiences.
Purpose: To deliver and measure the effectiveness of advertisements shown on Facebook and Instagram.
Governed by Meta's Data Policy: https://www.facebook.com/privacy/policy
Important Notice: We do not sell personal data. All transfers to Google and Meta operate under Standard Contractual Clauses where applicable. Data is processed for advertisement targeting and campaign measurement only and is not resold to unaffiliated third parties.
Google and Meta may use this data across their own platforms in accordance with their respective privacy policies. We encourage users to review those policies directly through the links provided above.
Contact Forms and Data Collection
When you submit a contact form, request information about our products, or register interest in our services, we collect the information you voluntarily provide. This typically includes your full name, email address, phone number, and the content of your message or enquiry.
Legal Basis
We process your contact form data under two legal bases:
- Consent (GDPR Art. 6.1.a): By submitting the form, you provide explicit consent for us to process your data to respond to your enquiry.
- Performance of a Contract (GDPR Art. 6.1.b): Where a service relationship exists or you are requesting information to enter into a contract (such as placing an order), processing is necessary for contract performance.
Data Retention
Form submission data is retained for up to 2 years from the date of submission, unless a longer period is required by applicable law or regulatory requirements. After this period, data is securely deleted from our systems.
Your Rights
You may request deletion of your contact form data at any time by emailing us at [email protected]. We will process your request within 30 days and confirm when your data has been removed from our systems.
A link to this Privacy Policy appears adjacent to every submission button on our website. Submitting a form constitutes acknowledgment and acceptance of this policy.
Google Services — Full Disclosure
This website uses the following Google services to improve user experience and measure advertising effectiveness:
Google Analytics 4
Google Analytics 4 collects anonymised usage data, device information, and behavioural signals to help us understand how visitors interact with our website. This includes pages visited, time spent on site, traffic sources, and user demographics (age range, gender, interests).
Privacy Controls: IP anonymisation is enabled, which means your full IP address is never stored. Data retention is set to 14 months, after which historical data is automatically deleted.
Users may opt out of Google Analytics tracking by installing the Google Analytics Opt-out Browser Add-on: https://tools.google.com/dlpage/gaoptout
Google Ads Conversion Tracking
Google Ads conversion tracking records when a user completes a defined action on our website after clicking one of our advertisements. Actions tracked include newsletter signups, contact form submissions, and product purchases. This data is used solely for measuring advertising campaign performance and return on investment. Conversion data does not include personally identifiable information.
Google Remarketing
Google Remarketing allows us to show advertisements to previous visitors of our website across Google's advertising network. Remarketing lists are created based on pages visited and actions taken on our site. We do not create remarketing lists based on sensitive data categories such as health conditions, financial status, religion, or sexual orientation. All remarketing activities comply with Google's advertising policies.
Google Tag Manager
Google Tag Manager deploys tracking tags on our behalf. It acts as a container for the analytics and advertising tags listed above. Google Tag Manager itself does not collect or store personal data; it simply manages when and how other tags fire on our website.
All Google advertising products are governed by Google's Advertising Privacy Policy: https://policies.google.com/technologies/ads
Meta Advertising Services — Full Disclosure
This website uses the Meta Pixel to measure the effectiveness of our advertising on Facebook and Instagram. The pixel is a small piece of code that tracks user interactions on our website.
Data Collected by Meta Pixel
The Meta Pixel may record:
- Page views and time spent on our website
- Specific conversion events such as newsletter signups and contact form submissions
- Product views and add-to-cart actions
- Custom audience membership for retargeting purposes
Prohibited Data Collection
We do not use the Meta Pixel to collect sensitive personal data, nor to target users based on health status, financial situation, religion, political views, sexual orientation, or any other special-category attribute prohibited under Meta's advertising policies.
Meta as Independent Data Controller
Meta acts as an independent data controller for data collected via its Pixel and processed within its own platform. This means Meta makes its own decisions about how pixel data is used within Facebook and Instagram advertising systems.
Refer to Meta's Data Policy for detailed information: https://www.facebook.com/privacy/policy
Managing Ad Preferences
To manage your advertising preferences on Meta platforms, visit: https://www.facebook.com/adpreferences/
Prohibited Content Self-Declaration
This website does not promote, sell, or facilitate access to prohibited product or service categories including but not limited to:
- Weapons or ammunition
- Controlled substances or drugs
- Counterfeit goods
- Gambling services (unlicensed)
- Adult or sexually explicit content
- Services that make misleading health or financial claims
All advertising conducted through Google Ads and Meta Ads complies with the respective platform policies in full. We sell certified organic coffee products and related accessories only.
Landing Page Integrity Statement
The content of this website accurately represents the products and services advertised. We do not employ bait-and-switch practices. The experience delivered to users arriving from paid advertisements is identical to the experience for all other visitors.
Cloaking, automatic redirects, and content variation by traffic source are not used on this website. All visitors, regardless of how they arrive, see the same honest representation of our organic coffee products and values.
Children's Privacy
This website is not directed at individuals under the age of 16. We do not knowingly collect personal data from minors without verifiable parental consent.
If we discover that data has been collected from a person under 16 without proper consent, we will delete it promptly. Contact us at [email protected] if you believe we have received data from a minor, and we will investigate and take appropriate action immediately.
International Data Transfers
Personal data collected through this website may be transferred to and processed in countries outside the European Economic Area, including the United States, where Google LLC and Meta Platforms, Inc. are based.
These transfers are conducted under Standard Contractual Clauses (SCCs) approved by the European Commission, which provide appropriate safeguards for personal data in accordance with GDPR requirements.
A copy of the applicable Standard Contractual Clauses can be requested by contacting us at [email protected]. We will provide the documentation within 30 days of your request.
Your Rights Under GDPR (Articles 15-22)
If you are located in the European Economic Area or the United Kingdom, you have the following rights regarding your personal data:
Right of Access (Article 15)
You have the right to request a copy of all personal data we hold about you. We will provide this information in a clear, structured format within 30 days of your request.
Right to Rectification (Article 16)
You have the right to correct any inaccurate or incomplete personal data we hold about you. Contact us with the corrected information, and we will update our records promptly.
Right to Erasure (Article 17)
You have the right to request deletion of your personal data (the "right to be forgotten"). We will comply with this request unless we have a legal obligation to retain the data or another lawful basis for continued processing.
Right to Restriction (Article 18)
You have the right to request that we limit how we process your personal data in certain circumstances, such as whilst we verify the accuracy of data you have contested.
Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller without hindrance.
Right to Object (Article 21)
You have the right to object to processing of your personal data where we rely on legitimate interest as the legal basis. You also have the absolute right to object to processing for direct marketing purposes.
Right to Withdraw Consent (Article 7.3)
Where processing is based on consent, you have the right to withdraw that consent at any time without penalty. Withdrawal does not affect the lawfulness of processing before consent was withdrawn.
How to Exercise Your Rights
To exercise any of these rights, please email us at [email protected] with your request. Include your full name and the email address associated with your data. We will respond within 30 days and verify your identity before processing the request.
You also have the right to lodge a complaint with your local supervisory authority if you believe your data protection rights have been violated:
- EU users: European Data Protection Board — https://edpb.europa.eu
- UK users: Information Commissioner's Office — https://ico.org.uk
What Data We Collect
We collect and process the following categories of personal data:
Identity Data
- Full name
- Email address
- Phone number
Technical Data
- IP address
- Browser type and version
- Device type and operating system
- Cookies and tracking identifiers
Usage Data
- Pages visited
- Time spent on site
- Click paths and navigation patterns
Communication Data
- Form submission content
- Email correspondence
- Customer service enquiries
Transaction Data
- Purchase history
- Order details
- Delivery information
Marketing Data
- Newsletter subscription status
- Conversion events
- Advertising interaction data
Legal Basis for Processing (GDPR Art. 6)
For each category of data we collect, we rely on one or more of the following legal bases:
Contact Form Data
Legal Basis: Consent (Art. 6.1.a) and Performance of a Contract (Art. 6.1.b). When you submit a contact form, you provide explicit consent for us to respond to your enquiry. Where you are requesting information to enter into a contract (such as placing an order), processing is necessary for contract performance.
Analytics Data
Legal Basis: Consent (Art. 6.1.a). Analytics cookies and associated data processing only occur after you have explicitly consented through our cookie banner.
Marketing and Remarketing Data
Legal Basis: Consent (Art. 6.1.a). Marketing cookies and personalised advertising activities only occur after you have explicitly consented through our cookie banner.
Security and Fraud Prevention
Legal Basis: Legitimate Interest (Art. 6.1.f). We process certain technical data to protect our website from security threats, prevent fraud, and ensure the integrity of our systems. This processing is necessary for the legitimate interests of protecting our business and customers.
Order Processing
Legal Basis: Performance of a Contract (Art. 6.1.b). When you place an order, we process your personal data to fulfil that order, arrange delivery, and provide customer support.
Data Retention Periods
We retain different categories of data for specific periods based on legal requirements and business needs:
Contact Form Submissions
Retained for up to 2 years from the date of submission
Analytics Data (Google Analytics 4)
Retained for up to 14 months from your last visit
Marketing Cookies (Google Ads)
Retained for up to 540 days (18 months)
Email Communications
Retained for the duration of the customer relationship plus 1 year
Transaction and Order Data
Retained for up to 7 years to comply with UK tax and accounting regulations
Server Logs
Retained for up to 90 days for security and troubleshooting purposes
Cookie Consent Records
Retained for up to 3 years for audit and compliance purposes
After the applicable retention period expires, data is securely deleted or anonymised. You may request early deletion of your data at any time by exercising your right to erasure (see Your Rights section above).
Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or alteration. These measures include:
- SSL/TLS encryption for all data transmission
- Secure servers with restricted access controls
- Regular security audits and vulnerability assessments
- Staff training on data protection and confidentiality
- Secure backup and disaster recovery procedures
Whilst we take all reasonable precautions to protect your data, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security but will notify you promptly of any data breach that may affect your rights and freedoms.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or business operations. When we make material changes, we will notify you by displaying a prominent notice on our homepage for a minimum of 14 days before the changes take effect.
The "Last Updated" date at the top of this policy indicates when it was most recently revised. We encourage you to review this policy periodically to stay informed about how we protect your personal data.
Your continued use of our website after changes to this policy constitutes acceptance of those changes. If you do not agree with the updated policy, please discontinue use of our website.
Contact Information
If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or need to report a concern, please contact us:
Organic Coffee Co Ltd
Company Registration: 12847392
VAT Number: GB 356 4821 79
157 High Street
Hornchurch, England
RM11 3YD
We aim to respond to all enquiries within 30 days. For urgent data protection matters, please mark your communication as "URGENT: Data Protection Enquiry".
Important Notice
All coffee is certified organic by the Soil Association. Prices include VAT where applicable. Flavour profiles are tasting notes only — actual taste may vary slightly by batch. We roast in small batches to order, ensuring maximum freshness. Roast dates are clearly marked on every bag. Storage recommendations should be followed to maintain optimal flavour. If you have any concerns about allergens or specific dietary requirements, please contact us before ordering.