Privacy notice · effective 9 September 2026

Your food can be local. Your data should stay purposeful.

This notice explains what foodforfolk collects, why it is needed, and the controls available to you.

Privacy choices

Review or change analytics preferences for this device at any time.

Who is responsible

Charlie Broadbent, trading as Foodforfolk, is the marketplace data controller. This notice covers the foodforfolk website and its iOS and Android apps. Privacy requests can be sent to [email protected] or by post to Office 10419, 321–323 High Road, Chadwell Heath, Essex RM6 6AX, United Kingdom. A vendor is separately responsible for customer information they receive and use to fulfil an order.

Information used to run foodforfolk

For shoppers, this can include name, email, phone number, profile photo, sign-in details, basket, orders, subscriptions, payment references, collection or delivery information, signed collection codes, reviews, support messages, notification settings and security events. For vendors, it can also include application answers, identity and business contact details, private address, products, prices, availability, public photos and descriptions, fulfilment records, and Stripe onboarding and payout status. Public listings, product media and reviews are user-provided content.

We also retain the agreement type and version, document fingerprint, acceptance method and time. Optional “How did you hear about us?” answers are deliberately supplied by the user and are kept separate from automatic campaign attribution.

How orders connect shoppers and vendors

Foodforfolk gives a vendor the shopper identity, contact, order and collection or delivery information reasonably needed to accept, fulfil and support that order. Shoppers see the vendor's public business information; a private collection address is revealed only when needed after purchase. Stripe processes checkout, card payments, subscriptions, seller verification and payouts. Foodforfolk receives payment and account references and status, but Stripe handles card numbers, bank credentials and high-risk identity documents. Stripe may act as a separate controller where it uses information for its own legal, identity-verification, fraud-prevention or regulatory duties.

What you need to provide

Identity, contact, security and fulfilment information marked as required is needed to create or protect an account, enter a marketplace agreement, place or fulfil an order, or meet a legal requirement. Without it, the relevant account, sale, payout or support action may not be possible. Marketing, detailed analytics, device location, profile images, reviews, discovery answers and most notification choices are optional; declining them does not prevent ordinary marketplace use.

Nearby results and maps

Cloudflare may infer a city or regional location from the connection before a request reaches Foodforfolk. For anonymous site-activity statistics, Foodforfolk reduces this to a coarse area and does not store the IP address or precise connection coordinates in the analytics record. A vendor's separately supplied business locality is used for its public listing, marketplace search and fulfilment settings—not to identify the vendor in live analytics.

If you actively choose “Use my location” in Explore, the precise device position is used to request nearby results but is not written to the application database or application access logs. Map tiles are supplied by OpenFreeMap (or another map provider identified in the map attribution), which receives the network request needed to deliver the map.

Service providers and overseas processing

Foodforfolk uses carefully selected providers for hosting and network protection, authentication, maps, media storage, email and push delivery, and payment and payout processing. This may include Cloudflare, Stripe, Apple and Google. We share only what is needed for the relevant service, do not sell personal information, and may disclose information where required by law or to protect users and the service.

Some providers may process information outside the United Kingdom. Where UK adequacy regulations do not apply, Foodforfolk requires an approved transfer safeguard, such as the UK International Data Transfer Agreement or UK Addendum, together with appropriate security measures.

Analytics and device choices

Essential technologies keep sign-in, two-factor security, private-beta access, baskets, checkout and saved privacy choices working. The normal sign-in cookie lasts up to seven days, a two-factor challenge cookie up to ten minutes, and the private-beta access cookie up to seven days. A vendor setup tutorial uses session storage only for that browser session.

On the website, informational home, editorial, privacy and help pages do not show the first-visit privacy banner or start service analytics. The compact banner appears when an undecided visitor enters an interactive marketplace area such as Explore, a shop, signup, basket, checkout, account or seller workspace. The iOS and Android apps present the same explanation on first use. After that notice is presented, anonymous service analytics are enabled by default under the statistical-purpose exception in the Privacy and Electronic Communications Regulations unless a browser privacy signal or your saved objection disables them. This is used solely to improve Foodforfolk's navigation, capacity, reliability and marketplace experience—not for advertising, profiling, personalised offers or sharing with advertising platforms.

Where enabled, an active browser tab or app sends a random identifier held only for that app process or browser tab, its platform, and a broad screen or workspace category. The request is deliberately sent without the Foodforfolk login cookie or app access token, so the category describes the screen rather than confirming the user's account role. Cloudflare supplies an approximate connection area at the edge; Foodforfolk does not put the IP address in the analytics record. A visit may contribute a broad entry channel and tightly limited source or campaign label. Values containing email-address or URL punctuation are rejected and only short label-like values are accepted. Temporary rows are removed after ten minutes; session and checkout-start totals are promptly aggregated by day and retained for up to 90 days. They are never joined to an account, basket, registration, order, vendor identity or individual purchase. For the live admin map, each recently active located session becomes a short-lived approximate activity area: its identifier and all route, platform, timestamp, campaign and account context are omitted, its stable coarse centre is surrounded by a 30 km uncertainty radius, and it cannot be selected or linked into a session trail. The radius communicates an approximate region rather than a person's location. Retained signup locations and named campaign rows are shown only for groups of at least five. You can object at any time by turning Service analytics off.

Individual journey insights remain off until you affirmatively switch them on in Privacy choices. If accepted, first-touch campaign parameters, the landing path and external referring hostname may be held in browser session storage and associated with a registration, mailing signup or purchase. Aggregate campaign and source totals do not depend on this consent. We do not retain a landing-page query string or full referring URL. Consent is versioned and recorded when individual attribution is submitted. Withdrawing consent stops future collection, clears session attribution and removes automatic account or subscriber attribution where it is held. Foodforfolk keeps only the most recent consent version and grant time on the applicable account or mailing record and, after withdrawal, the withdrawal time as minimal accountability evidence. This historical evidence does not enable analytics and is excluded from acquisition reporting. Your privacy-choice cookie lasts 183 days on that device. If an unsigned visitor submits a mailing address with consented attribution, a separate opaque HttpOnly withdrawal receipt may remain for up to 400 days so the same browser can remove that attribution later; it contains no email or campaign data and is deleted when used.

Reasons for processing

Core account, ordering, fulfilment and seller services are processed to provide the marketplace contract. Accounting, tax and regulatory records are processed to meet legal obligations. Security, fraud prevention, support, service administration and strictly aggregate marketplace planning rely on Foodforfolk's legitimate interests where those interests are not overridden by users' rights. Aggregate service analytics also relies on the PECR statistical-purpose exception subject to the safeguards and objection described above. Individual journey insights, optional marketing and device permissions are used only when the required consent or permission has been given. Seller onboarding answers guide support but do not make automated approval decisions.

Messages and social sign-in

Order updates, receipts, security alerts, agreement notices and other service messages are part of operating an account. App push notifications use a device token and can be disabled in the app or operating-system settings. Marketing email is a separate, optional choice; every update includes an unsubscribe control, and unsubscribing does not affect service messages.

If you choose Google or Apple sign-in, Foodforfolk receives the basic identity details made available for authentication, such as name, email address (which may be an Apple private-relay address), profile image where available and the provider identifier. Foodforfolk does not request Gmail, Drive, Calendar, Contacts or iCloud content. Use of information received from Google APIs follows the Google API Services User Data Policy, including Limited Use.

How long information is kept

Account and active marketplace data is kept while the account or service relationship continues. Public media remains until removed or replaced. Agreement, transaction, payment, tax, fraud and dispute records are kept only for the applicable legal, accounting or claims period and are then deleted or anonymised. A deleted account is held for the stated seven-day recovery period before login and personal profile data is removed; information that must be retained is minimised or anonymised.

Email delivery content, including the recipient, subject and message body, is normally replaced with non-identifying placeholders 30 days after the message is sent, suppressed or reaches permanent delivery failure. Limited evidence such as the event, delivery status, attempt count, related order reference and timestamps may be kept for the applicable operational, security or claims period.

For terminal orders, delivery addresses and delivery notes are normally removed 30 days after payment failure or expiry, 180 days after cancellation or refund, and 365 days after collection or delivery. A documented, time-limited hold may delay that removal where the information remains necessary for a live dispute, safety matter or legal obligation. Order items, amounts, payment references, status and timestamps may be kept separately for the applicable accounting, tax, fraud or claims period. The shorter analytics periods are described above. Minimal detailed-analytics consent evidence is reviewed at least annually and retained only while the related account or mailing record, or a proportionate accountability or claims need, remains.

Security and younger users

Foodforfolk uses proportionate technical and organisational measures including encrypted transport, access controls, signed and expiring credentials, privileged-account safeguards, restricted administrative tools, media sanitisation, monitoring and protected backups. No internet service can promise absolute security, so suspected account or data misuse should be reported promptly.

The marketplace is intended for adults arranging food purchases or operating food businesses and is not designed specifically for children. If you believe a child has supplied personal information inappropriately, contact Foodforfolk so the circumstances and any appropriate deletion can be assessed.

Your choices and rights

Account settings provide privacy choices, email preferences, a portable data export and account deletion. Depending on the circumstances, you may ask for access, correction, erasure, restriction or portability, or object to processing and withdraw consent. Withdrawal does not affect processing that was lawful beforehand. Foodforfolk may need to confirm your identity and will normally respond within one month.

Contact [email protected] to exercise a right or raise a concern. You may also complain to the UK Information Commissioner's Office.

Changes to this notice

The effective date at the top identifies the current notice. Foodforfolk will update this page when processing changes and will use an appropriate in-app, account or email notice where a change materially affects users or requires a new choice.

If our legal terms change, we'll notify you in your account and ask you to accept the updated terms before you can continue with actions like ordering, payments, and collection.