Privacy Policy

Data Protection & Your Rights

How we collect, use and protect your personal data in compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR), more specifically the Data Protection Authority (Jersey) Law 2018.

Last updated: 05/11/2025

Information We Collect

We collect only the information necessary to process your orders and provide excellent customer service.

  • Personal details (name, email, phone number)

  • Order information and delivery preferences

  • Website usage data through cookies

  • Communication history for customer service

How We Use Your Data

Your data is used solely for order processing, customer communication, and service improvement.

  • Process and manage your orders efficiently

  • Contact you about orders and collection times

  • Improve our services and website experience

  • Provide customer support when needed

Data Storage & Security

We store your data securely using industry-standard encryption and access controls.

  • Supabase-hosted secure databases with encryption

  • Encrypted connections (SSL/TLS) for all data

  • Restricted access to authorised personnel only

  • Regular security audits and updates

Your Data Rights

Under GDPR and the Data Protection Authority (Jersey) Law 2018, you have comprehensive rights regarding your personal data.

  • Access your personal data at any time

  • Request corrections or updates to your data

  • Request deletion of your personal data

  • Object to processing or withdraw consent

Legal Basis & Detailed Information

Comprehensive details about our data handling practices

Legal Basis for Processing

We process your personal data based on: Contract (to fulfil your orders), Consent (for marketing communications if opted-in), Legal obligation (where required by Jersey law), and Legitimate interest (to improve customer service and prevent fraud).

Data Sharing & Third Parties

We do not sell or rent your personal data. We may share information with essential service providers (Supabase for data storage, Resend for emails, Vercel for hosting) and regulatory authorities if required by law. All third parties are contractually bound to protect your data.

Data Retention Policy

We keep personal data only as long as necessary to fulfil the purposes we collected it for, including satisfying legal, accounting, or reporting requirements. Order data is typically retained for 7 years for tax and legal compliance.

International Data Transfers

Your data may be processed outside Jersey by our service providers (e.g., Supabase). We ensure adequate protection through standard contractual clauses and adequacy decisions where applicable.

Cookies & Website Data

How we use cookies and similar technologies

Cookie Types We Use

  • Strictly necessary cookies for site functionality

  • Functionality cookies for user preferences

  • Performance cookies for site improvement

  • Security cookies for fraud prevention

Your Cookie Choices

You can control cookie preferences through our cookie consent banner or browser settings. Essential cookies cannot be disabled as they're required for basic site functionality.

Read Full Cookie Policy →

Exercising Your Rights

How to access, update, or delete your personal data

Access Your Data

Request a copy of all personal data we hold about you

Data Subject Access Request

Update Information

Correct or update any inaccurate personal information

Request Data Correction

Delete Your Data

Request deletion of your personal data (right to be forgotten)

Request Data Deletion

Withdraw Consent

Withdraw consent for marketing emails or optional data processing

Manage Preferences
Privacy Questions?

Contact Our Data Protection Officer

For privacy inquiries or to exercise your data rights, contact us directly

hello@tjsbakeandbrowse.co.uk

We'll respond to privacy inquiries within 28 days as required by the Data Protection Authority (Jersey) Law 2018.

Your Rights & Complaints

Jersey Office of the Information Commissioner

Further information on your rights can be found on the website of the Jersey Office of the Information Commissioner:

www.jerseyoic.org

Making a Complaint

You can complain to the Jersey Office of the Information Commissioner (JOIC) if you are unhappy with how we have used your personal data.

JOIC Address:

2nd Floor,
5 Castle Street,
St Helier,
Jersey
JE2 3BT

Changes to This Privacy Notice

We reserve the right to modify our privacy notice at any time, which will be updated and reflected on our website accordingly. We encourage you to review this privacy notice periodically to stay informed about how we protect your personal information.

Last updated: 5 November 2025