Kebab Carvery
Website: https://kebabcarvery.com
Effective date: 28 July 2026
Last updated: 28 July 2026
1. About this Privacy Policy
This Privacy Policy explains how Kebab Carvery (Bognor Branch) ("Kebab Carvery", "we", "us" or "our") collects, uses, stores and shares personal data when you:
visit or use kebabcarvery.com;
create or use a customer account;
place an order for delivery or collection;
contact us, make an enquiry or submit a complaint;
request customer support or track an order;
subscribe to promotional email or SMS messages; or
otherwise interact with our restaurant and online ordering services.
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (PECR), as amended, and other applicable UK data protection law.
2. Who is responsible for your personal data?
For personal data processed in connection with the restaurant and your orders, the data controller is:
Kebab Carvery (Bognor Branch)
226 Chichester Road
Bognor Regis
West Sussex
PO21 5BE
United Kingdom
Telephone: +44 1243 822822
Privacy contact: The Manager
Email: bognorregis@kebabcarvery.co.uk
Our website, ordering system, hosting, payment, communications and support suppliers may process personal data for us as data processors or, in some cases, as independent controllers.
3. Personal data we collect
Depending on how you use our services, we may collect the following categories of personal data.
3.1 Identity and account data
title, first name and surname;
username, account identifier and password credentials in encrypted or hashed form;
account status and verification information;
age or date of birth where voluntarily provided or legally required.
3.2 Contact data
email address;
mobile or telephone number;
delivery address, collection details and postcode;
communication preferences.
3.3 Order and transaction data
products, options and quantities ordered;
order number, order date, delivery or collection choice and requested time;
delivery instructions, special requests and order notes;
subtotal, discounts, delivery charges, service or processing charges, bag charges and total price;
payment status, refund status and limited payment transaction references;
loyalty points, vouchers, promotional codes and campaign usage;
previous orders and customer service history.
We do not normally receive or store your full payment card number or card security code. Card payments are processed by an authorised third-party payment provider.
3.4 Dietary and allergen information
If you tell us about an allergy, intolerance, dietary preference or other food-related requirement, that information may reveal health-related information. We use it only to assess and respond to your request, manage your order and help protect your vital interests. You should always contact the restaurant directly before ordering if you have a serious allergy or intolerance. We cannot guarantee that any product is completely free from allergens or cross-contamination.
3.5 Technical and usage data
IP address;
browser type and version;
device type, operating system and device identifiers;
login, session and security data;
pages viewed, interactions, referring pages and timestamps;
cookie identifiers, consent preferences and similar technology data;
approximate location inferred from IP address.
3.6 Communications data
messages sent through contact forms;
emails, SMS messages and telephone enquiries;
complaints, reviews, feedback and support requests;
records of marketing consent, withdrawal and suppression preferences.
3.7 Fraud prevention and security data
suspected fraudulent activity;
failed login or payment attempts;
device, IP and transaction risk signals;
records needed to protect customers, our business and payment providers.
4. How we collect personal data
We collect personal data:
directly from you when you register, order, contact us or set preferences;
automatically through cookies, server logs and similar technologies;
from payment providers when they confirm or reject a transaction;
from delivery, communications, fraud-prevention and technical service providers;
from publicly available sources where lawful;
from another person placing an order for you, where applicable.
If you provide personal data about another person, you must have authority to do so and should make this Privacy Policy available to them.
5. Why we use personal data and our lawful bases
PurposePersonal data usedLawful basisCreate and manage customer accountsIdentity, contact, account and security dataPerformance of a contract; legitimate interests in administering accounts and preventing misuseAccept, prepare, fulfil and deliver ordersIdentity, contact, address, order, transaction and instruction dataPerformance of a contract; compliance with legal obligationsProcess payments, refunds and chargebacksTransaction, payment status, contact and fraud-prevention dataPerformance of a contract; legal obligation; legitimate interests in payment administration and fraud preventionProvide order tracking and customer supportContact, order and communications dataPerformance of a contract; legitimate interests in customer serviceHandle allergies and dietary requestsOrder notes and allergy/dietary informationExplicit consent where required; vital interests; substantial public interest or establishment/defence of legal claims where applicableSend service messagesContact, account and order dataPerformance of a contract; legitimate interests in providing operational informationSend email or SMS marketingContact details, preferences and limited purchase historyConsent, or the PECR soft opt-in where legally availablePersonalise offers and improve servicesOrder history, usage and preference dataConsent where cookies or similar technologies require it; otherwise legitimate interests, subject to your rightsMaintain website security and prevent fraudTechnical, account, transaction and security dataLegitimate interests; legal obligationComply with tax, accounting, food safety, regulatory and legal dutiesIdentity, order, transaction and communications dataLegal obligation; establishment, exercise or defence of legal claimsAnalyse service performanceTechnical and usage dataConsent where required for analytics technologies; otherwise legitimate interests for strictly limited, privacy-preserving analysis where lawful
Where we rely on legitimate interests, we balance our interests against your rights and reasonable expectations.
6. Marketing communications
We may send promotional emails or SMS messages only where permitted by PECR and data protection law. This may be because:
you actively consented; or
we obtained your contact details during a sale or sales enquiry, market only similar products or services, and gave you a clear opportunity to opt out when the details were collected and in every message.
You can opt out at any time by:
using the unsubscribe link in an email;
replying STOP to a promotional SMS where available;
changing your account preferences; or
contacting us.
Opting out of marketing does not stop essential service messages about your account or orders. We may retain a minimal suppression record to ensure we respect your opt-out.
7. Cookies and similar technologies
We use cookies and similar technologies for essential website functions, account sessions, security, order baskets, preferences, analytics and, where enabled, marketing.
Non-essential technologies will not be used unless you have given valid consent or another specific PECR exemption applies. You can accept, reject or manage non-essential categories through the website's cookie controls and can withdraw consent at any time.
For details, see our Cookie Policy.
8. Who we share personal data with
We may share personal data with:
website, ordering platform, hosting, cloud storage and IT support providers;
payment processors, banks, card schemes and fraud-prevention providers;
delivery drivers or delivery service providers where necessary to fulfil an order;
email, SMS, push notification and customer support providers;
accountants, insurers, auditors, legal advisers and professional consultants;
regulators, local authorities, law-enforcement bodies, courts and government agencies where required;
prospective buyers, sellers or advisers in connection with a business reorganisation, sale or transfer;
other parties where you direct us to share data or give valid consent.
Service providers acting on our instructions must process personal data only for authorised purposes, apply appropriate security and confidentiality measures and comply with applicable data protection law.
9. International transfers
Some suppliers may process personal data outside the United Kingdom. Where personal data is transferred internationally, we use safeguards required by UK data protection law, which may include:
UK adequacy regulations;
the UK International Data Transfer Agreement;
the UK Addendum to approved EU Standard Contractual Clauses;
contractual, organisational and technical supplementary measures.
You may contact us for further information about relevant transfer safeguards.
10. Data retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including legal, accounting, food safety, fraud-prevention and dispute-resolution requirements.
Our indicative retention periods are:
RecordTypical retention periodCustomer accountWhile active, then normally up to 24 months after closure or last activity, unless a longer period is neededOrders, invoices, payments and refundsNormally 6 years after the end of the relevant financial year or transaction relationshipCustomer service and complaint recordsNormally up to 3 years after resolution, or longer if a dispute or claim remains possibleMarketing consent and suppression recordsConsent evidence while relied upon; suppression record for as long as needed to honour the opt-outSecurity and server logsNormally 30 to 180 days, unless required for an investigationCookie consent recordsNormally up to 24 months, or until consent is refreshed or withdrawnUnsuccessful or abandoned checkout dataNormally up to 90 days, unless needed for fraud prevention or customer supportAllergy or dietary notesFor the order lifecycle and any reasonable complaint or legal claim period; not used for unrelated purposes
These periods may be shortened or extended where required by law, litigation, regulatory guidance, fraud investigation or a valid preservation request.
11. Security
We use appropriate technical and organisational measures designed to protect personal data, including, where suitable:
encryption in transit;
password hashing and access controls;
role-based access and authentication;
backups, logging, monitoring and vulnerability management;
supplier due diligence and data-processing agreements;
staff confidentiality and data-protection procedures;
incident response and breach-management processes.
No system is completely secure. You are responsible for keeping your password confidential and for notifying us promptly if you suspect unauthorised account use.
12. Your data protection rights
Subject to applicable conditions and exemptions, you may have the right to:
be informed about our processing;
request access to your personal data;
request correction of inaccurate or incomplete data;
request deletion of personal data;
request restriction of processing;
object to processing based on legitimate interests;
object at any time to direct marketing;
request transfer of data you provided in a structured, commonly used and machine-readable format;
withdraw consent at any time, without affecting earlier lawful processing;
request human review of certain solely automated decisions that produce legal or similarly significant effects;
complain to the Information Commissioner's Office.
To exercise a right, contact us using the details in section 2. We may ask for information needed to verify your identity. We normally respond within one month, although the law permits extensions for complex or numerous requests.
13. Automated decision-making
We do not intend to make decisions based solely on automated processing that have legal or similarly significant effects on you. Payment and fraud-prevention providers may use automated risk tools. Where they act as independent controllers, their own privacy information applies.
14. Children's privacy
Our online ordering service is intended for people who can lawfully enter into a purchase contract. We do not knowingly use children's personal data for behavioural advertising. A parent or guardian who believes a child has provided personal data without appropriate authority should contact us.
15. Third-party websites and services
Our website may link to third-party websites, maps, payment pages or social platforms. Those parties control their own processing and privacy practices. You should read their privacy notices before providing personal data.
16. Changes to this Privacy Policy
We may update this Policy when our practices, suppliers or legal obligations change. The latest version will be published on the website with a revised effective date. Where required, we will provide additional notice or request renewed consent.
17. Complaints and contact
Please contact us first so that we can try to resolve your concern:
FAO: The Manager – Privacy Request
Kebab Carvery (Bognor Branch)
226 Chichester Road
Bognor Regis
West Sussex
PO21 5BE
United Kingdom
Telephone: +44 1243 822822
Email: bognorregis@kebabcarvery.co.uk
You also have the right to complain to the UK Information Commissioner's Office (ICO). Current contact and complaint information is available at ico.org.uk.
