Legal
Privacy Policy
What we collect, why we collect it, how long we keep it — and the rights you have over it.
ConnectionCafe.com is a small coffee bar, kitchen and eight-room guest house on Kiln Street. In plain English: we hold your details when you fill in our enquiry form, book a room, join our email list or pay by card, and we record CCTV on the premises for safety. We do not sell your data, we run no advertising trackers on this website, and we keep as little as we reasonably can. This policy explains each of those in turn and tells you how to see, correct or delete what we hold.
Who we are and how to contact us
Connection Cafe Ltd, trading as ConnectionCafe.com, is the data controller for the personal information described here. You can reach us at:
- Post: Connection Cafe Ltd, 42 Kiln Street, Shoreditch, London E1 6QL, United Kingdom
- General and privacy enquiries: hello@connectionscafes.com
- Room bookings and guest records: stay@connectionscafes.com
- Phone: +44 20 7946 0958
We are not large enough to be required to appoint a Data Protection Officer, so privacy questions are handled by our general manager. Email us and put Data request in the subject line, so it does not sit behind the breakfast bookings. Our contact page lists our opening hours if you would rather speak to someone.
The information we collect
Website enquiry form
Our enquiry and table request form asks for your name, email address, an optional phone number, and whatever you write in the message box — usually a date, a group size or a question about the kitchen. That message is emailed to us and stored in our inbox. Nothing on this site asks for payment details, and nothing asks about your health or beliefs. If you volunteer an allergy or an access requirement so that we can look after you properly, we treat it as special category data and use it only to serve you safely.
Room bookings and guest records
When you book one of the eight rooms — The Kiln Double, The Roastery Room or The Loft Suite — we take your name, contact details, arrival and departure dates, the number of guests, any dietary notes for breakfast, and the key code issued for the street door. UK hospitality law also requires us to record the name and nationality of every guest aged sixteen or over, and for guests who are not British or Irish nationals, identity document details and their next destination. That is a legal obligation rather than a choice, and those records are kept apart from everything else.
Email newsletter
The monthly list tells you what is coming off the roaster, which single origins are landing on filter and when we are running a cupping. We collect your email address and, if you give it, your first name. It is opt-in only — we never add walk-in customers or hotel guests automatically — and every email carries a one-click unsubscribe link.
CCTV on the premises
Cameras cover the counter, the till, the street door, the stair up to the rooms and the basement roastery. They do not cover any guest room, any bathroom or the staff changing area. Signs at the entrance tell you the cameras are recording. Footage exists to protect staff, guests, stock and the building. It is never used to monitor how long individual customers sit at a table, and we run no facial recognition and no audio recording.
Card payments
Card payments in the cafe and for room balances go through our payment processor's terminals and hosted payment pages. We never see or store your full card number, expiry date or security code. What reaches us is a transaction reference, the last four digits, the amount and whether it succeeded — the same information printed on your receipt. Our processor is a PCI DSS compliant provider and holds the card data itself under its own terms.
Website technical data
Our host records standard server logs — IP address, timestamp, page requested, browser type — for security and troubleshooting. This site sets only essential cookies and carries no advertising or behavioural tracking; the detail is in our cookie policy.
Why we use your data, and our lawful basis
Under UK GDPR we must name a lawful basis for everything we do with your information. Ours are contract, legitimate interests, legal obligation and consent.
| What we do | Lawful basis |
|---|---|
| Take and manage a room booking, send confirmations, issue a door code | Contract |
| Reply to an enquiry, hold a table, answer a question about the menu | Legitimate interests — responding to someone who contacted us |
| Record guest names and, where required, identity document details | Legal obligation (UK hospitality and immigration rules) |
| Operate CCTV for the safety of staff, guests and property | Legitimate interests — security of people and premises |
| Take payment and keep accounting records | Contract, and legal obligation for tax and VAT records |
| Send the monthly newsletter | Consent — withdrawn at any time via the unsubscribe link |
| Keep the website secure and working | Legitimate interests — running a safe website |
Where we rely on legitimate interests, we have weighed what we gain against your privacy and kept the data to the minimum that achieves the purpose. You can object to any of it — see your rights below.
How long we keep each category
- Enquiry messages and email threads: 24 months from the last reply, then deleted.
- Table booking notes: cleared at the end of the following week.
- Room booking records: 12 months after checkout, for service and dispute reasons.
- Guest registration records required by law: 12 months, as the regulations require.
- Payment and accounting records: six full financial years, as HMRC requires.
- CCTV footage: overwritten automatically after 30 days, unless a specific clip has been retained for an incident, an insurance claim or a police request.
- Newsletter subscriptions: until you unsubscribe, plus a suppression record of your address so that we do not add you again by mistake.
- Job applications: six months if we do not offer you a role, unless you ask us to keep you on file.
Who we share it with
We do not sell personal data and we never trade mailing lists. We share it only with:
- Our payment processor, which handles card transactions and holds the card data we never see.
- Our booking and email providers, which host the room reservation system and send the newsletter on our instructions.
- Our accountants, who see transaction records in order to prepare our accounts and VAT returns.
- Our website host and IT support, for maintenance, security and backups.
- Insurers, the police or another public authority, where we are legally required to disclose something or where it is necessary to investigate an incident on the premises.
Every supplier works under a written contract that limits them to acting on our instructions, keeping the data secure and deleting it when the relationship ends.
International transfers
Our website host and some of our software suppliers operate servers outside the UK, including in the European Economic Area and the United States. Where data leaves the UK we rely on the UK adequacy regulations where they apply, or on the International Data Transfer Agreement and the UK Addendum to the EU Standard Contractual Clauses, alongside technical protections such as encryption in transit and at rest. Ask us and we will tell you which supplier handles a particular piece of your data, and on what basis.
How we protect it
Guest records and booking data sit in access-controlled accounts with two-factor authentication. Paper registration slips live in a locked office, not behind the bar. The CCTV recorder is in a locked cupboard in the basement and only two named managers can export footage. This website is served over HTTPS. Staff are briefed on data handling when they start and again each year, and anyone who leaves loses their access the same day.
Your rights under UK GDPR
You have the right to:
- Access — ask for a copy of the personal data we hold about you.
- Rectification — have anything inaccurate or incomplete corrected.
- Erasure — ask us to delete data we no longer have a reason to keep.
- Restriction — ask us to pause using your data while a dispute is sorted out.
- Portability — receive the data you gave us in a machine-readable format, or have it sent to another provider.
- Objection — object to processing we base on legitimate interests, including CCTV.
- Withdraw consent — unsubscribe from the newsletter at any time, without affecting anything we did before you withdrew.
To exercise any of these, email hello@connectionscafes.com or write to us at the Kiln Street address. We may ask a question or two to confirm it really is you. For a CCTV request, the date, the rough time and what you were wearing genuinely helps us find you. We respond within one month and it costs you nothing. If a request is repetitive or excessive we may charge a reasonable fee or refuse it, and we will explain why if we do.
One note on CCTV: footage usually shows other people as well as you, so we will blur or crop them before releasing anything.
Complaining to the ICO
If you think we have handled your data badly, please tell us first — most problems turn out to be a misunderstanding we can fix the same week. If you are not satisfied, you can complain to the Information Commissioner's Office, the UK's data protection regulator, at ico.org.uk. Complaining to the ICO does not affect any other legal remedy available to you.
Children's data
ConnectionCafe.com is family-friendly and children are welcome at the tables and in the rooms with an adult, but this website is not aimed at children. We do not knowingly collect personal data from anyone under 13, and our newsletter is for over-16s only. Room bookings must be made by an adult aged 18 or over, who remains responsible for any children in the party. If you believe a child has given us personal data, email us and we will delete it.
Changes to this policy
We review this policy once a year, and whenever we change a supplier or add something new to the website. The date at the top always shows the current version. If a change materially affects how we use data you have already given us, we will say so in the newsletter and at the top of this page. Continuing to use ConnectionCafe.com after a change means you accept the updated policy.
This policy sits alongside our cookie policy and our terms and conditions, which cover booking, cancellation and website use.