Brewing-recipe card · Policy privacy

Privacy Pilsner

A.K.A. Privacy Policy · Vintage 2026-05-19

Contract / Legit. Interest / Consent
Bases
UK GDPR · EU GDPR · CCPA
Region
Account life + 7 yrs records
Retention

Brewer's notes: What data we collect when you brew with us, why we collect it, and how to take it back.

1. Data controller

The data controller is OBAN ALES LIMITED ("we"). You can reach our data protection contact at support@obanalesco.com.

2. What we collect

Account data: name, email, postal address, phone (optional), order history, recipe PDF download history.

Payment data: handled by our PCI-DSS-compliant payment processor (Stripe, PayPal). We do not store card numbers.

Technical data: IP address, browser type, device, referring URL, performance telemetry. Aggregated analytics are anonymised.

Marketing data (if you opt in): email preferences, open/click telemetry on our newsletters.

3. Why we collect it

To fulfil orders (contract): processing payments, packing kits, shipping, customer support.

To run the Site (legitimate interest): security, fraud prevention, analytics for product improvement.

To meet legal obligations: tax records, accounting, age-verification records.

To send marketing (consent): only when you opt in. You can withdraw consent at any time using the link in any email.

4. Who we share it with

Payment processors (Stripe Inc., PayPal Ltd.), shipping carriers (Royal Mail, UPS, DHL, USPS, Canada Post, Australia Post), email service provider, analytics processors (privacy-friendly analytics provider).

We do not sell or rent personal data. We disclose data to law enforcement only on lawful request.

5. Your rights

Under UK / EU GDPR you may: access, rectify, erase, restrict processing, port, or object to processing. Under CCPA / CPRA (California) you may know, delete, correct, and opt out of sale. We never sell personal information.

To exercise a right, email support@obanalesco.com from the email address on your account. We respond within 30 days (45 days under CCPA).

6. International transfers

Some processors are located outside the UK / EEA. We use Standard Contractual Clauses and require equivalent technical safeguards.

7. Retention

Order records are retained for 7 years to meet UK tax obligations. Marketing data is held until you opt out. Analytics are aggregated after 14 months.

8. Children

Our Site is not directed at people under 21. If we learn that we have inadvertently collected data on a minor we will delete it.

Conditioned on 2026-05-19 · Re-pour when policy changes