Last updated 16 September 2026
1. Who we are
This website, asylumcoffee.co.uk, is run by Asylum Coffee Limited, a specialty coffee roastery in Swindon, Wiltshire. In this policy, "we", "us" and "our" mean Asylum Coffee Limited.
We are the data controller for the personal information described here, which means we decide how it is used and are responsible for looking after it under UK data protection law (the UK GDPR and the Data Protection Act 2018).
You can contact us about anything in this policy:
- By email: [email protected]
- By post: Asylum Coffee Limited, Unit 64a BSS House, Cheney Manor, Swindon SN2 2PJ
2. The information we collect
When you place an order
To sell you coffee we need your email address, the name and address the parcel is going to, what you ordered and what you paid. Payment is taken by Stripe on a page they host: your card details go straight to Stripe and never touch our servers. Stripe passes back the delivery details you typed, a confirmation that payment succeeded and a reference we use to match the payment to your order.
When you create an account
An account stores your name, email address and a password. We only keep a scrambled (hashed) version of the password, so we cannot read it. Your account also holds your order history and, if you subscribe, a reference to your customer record at Stripe.
When you take out a subscription
A coffee subscription keeps the same details as an order, plus the delivery address it ships to each month and the Stripe references that let the recurring payment run. You can change the address from your account page and cancel through the billing portal linked there.
When we invoice you for wholesale
If you buy from us as a trade customer we raise invoices by hand. Those hold the name, email address and postal address you gave us, the invoice lines, any notes we added, and the payment record when it is settled.
When you sign up for emails
If you give us your email address for news about roasts and offers, we keep that address and a record of when and how you signed up until you unsubscribe.
When you visit the website
Like almost every website, our servers record technical information about each request: your IP address, browser type, the page requested and when. We use this to keep the site running, investigate faults and spot abuse.
Some forms (creating an account, resetting a password, checking out) are protected against bots by Cloudflare Turnstile. When you submit one of those forms Turnstile checks signals from your browser to decide whether you are a person. It does not set cookies for this and does not track you across other sites. See section 6.
Please only give us what we need to fulfil your order. Do not send bank details, health information or anything similarly sensitive through the site or by email.
3. How we use your information and our legal basis
UK data protection law requires a lawful basis for each use. Ours are:
- To take and deliver your order, run your subscription and manage your account - because it is necessary to perform our contract with you.
- To send you order confirmations, dispatch notices, tracking, failed-payment notices and account emails (such as password resets) - contract, and our legitimate interest in keeping you informed about something you have bought.
- To keep records of sales, invoices, refunds and payments - because we are legally required to for tax and accounting purposes.
- To keep the website secure, prevent fraud and block bots - our legitimate interest in protecting the site, our customers and ourselves.
- To send you marketing emails - only with your consent, which you can withdraw at any time using the unsubscribe link in every email or by contacting us.
- To respond when you contact us - our legitimate interest in replying to you.
We do not sell your information, we do not share it with third parties for their own marketing, and we do not make decisions about you using solely automated means.
4. Who we share it with
We use a small number of specialist companies to run the shop. Each one processes your information only on our instructions and only for the purpose described:
- Stripe - takes your payment on their hosted checkout, runs subscriptions and the billing portal where you manage them, and holds your card details on our behalf. Stripe is also a data controller in its own right for the payment itself; see Stripe's privacy policy.
- Shippo - the service we use to buy postage labels. We send your name, delivery address and email address to Shippo, which passes them to the carrier (for example Royal Mail) that delivers your parcel and may send you tracking updates.
- SMTP2GO - sends our transactional emails: order confirmations, dispatch and tracking notices, invoices, password resets and account notices.
- Mailchimp - holds our marketing list and sends the emails you have signed up for.
- Cloudflare - provides the Turnstile bot check on our forms. Cloudflare sees your IP address and browser signals when a check runs.
- Railway - hosts the website and its database, and stores the server logs described above.
- Google Fonts - the typefaces on this site are served from Google's servers, so your browser sends your IP address to Google when it fetches them.
We may also share information where the law requires it - for example with HMRC, a court, the police or a regulator - or to enforce our terms, and with our accountants and professional advisers under a duty of confidence.
If the business is sold or restructured, customer records may transfer to the new owner as part of that, under the same protections.
5. International transfers
We are based in the UK and your information is stored in the UK or the European Economic Area wherever possible. Some of the companies in section 4 - including Stripe, Shippo, Mailchimp, Cloudflare and Railway - are based in or process data in the United States, and SMTP2GO in New Zealand.
Where information leaves the UK, we rely on the safeguards UK law allows: the UK Extension to the EU–US Data Privacy Framework where the company is certified under it, an adequacy decision (the EEA and New Zealand), or the UK International Data Transfer Agreement or Addendum built into our contract with the provider.
6. Cookies
We only set cookies that are strictly necessary for the shop to work, which is why there is no cookie banner. We do not use analytics, advertising or social-media tracking cookies.
| Cookie | What it does | How long |
|---|---|---|
cart | Remembers what is in your basket. Signed so it cannot be tampered with. | 30 days |
session_token | Keeps you logged in to your account. | Until you log out or close the browser; sessions expire after 7 days |
csrf | Protects forms against cross-site request forgery. | 24 hours |
hamr_flash | Carries a one-off status message (such as "Added to cart") to the next page. | Deleted as soon as it is shown; at most 60 seconds |
You can block or delete cookies in your browser settings, but the basket and login will stop working if you do.
Cloudflare Turnstile
Turnstile is the bot check on our account, password-reset and checkout forms. It runs in a small frame served by Cloudflare and looks at browser signals rather than asking you to solve puzzles. Cloudflare does not use it to build a profile of you and it does not set tracking cookies. Our legal basis is our legitimate interest in stopping automated abuse of the shop. Cloudflare's own notice is at cloudflare.com/turnstile-privacy-policy.
7. How long we keep it
- Orders, subscriptions, invoices, refunds and payment records - six years after the end of the financial year they relate to, as HMRC requires. This applies whether or not you still have an account.
- Your account - for as long as you keep it. You can delete it from your account page: we cancel any subscriptions and email you a confirmation, then keep the account for 30 days in case you change your mind. After that we remove your name, email address and password from it. Your order records are kept for the period above, but are no longer attached to a live account.
- Abandoned checkouts - if you start a checkout and never pay, the incomplete order is deleted after four days.
- Password-reset links - one hour.
- Marketing list - until you unsubscribe, after which Mailchimp keeps your address on a suppression list so we do not email you again.
- Server logs - a short period, typically a few weeks, set by our hosting provider.
8. Keeping it secure
The site is served over HTTPS only. Passwords are hashed with a modern algorithm and cannot be recovered by us. Card details are handled entirely by Stripe. Access to the admin side of the shop is limited to the people who run it and is password protected.
No method of transmission over the internet or of electronic storage is completely secure, so we cannot guarantee absolute security, but we take reasonable steps to protect your information and will tell you and the ICO if a breach puts you at risk, as the law requires.
9. Your rights
Under UK data protection law you have the right to:
- access the personal information we hold about you and get a copy;
- correct anything that is inaccurate or incomplete;
- erase it, where we no longer have a reason to keep it - you can delete your account yourself from your account page;
- restrict how we use it while a query is resolved;
- object to uses based on our legitimate interests, and to marketing at any time;
- port the information you gave us to another provider in a machine-readable form;
- withdraw consent at any time where consent is the basis we rely on.
To exercise any of these, email us at [email protected]. We will respond within one month. We may need to confirm your identity first, and some records (such as invoices) we are required to keep even if you ask us to delete them.
10. Complaints
If you are unhappy with how we have handled your information, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection regulator: ico.org.uk/make-a-complaint or 0303 123 1113.
11. Links to other websites
This site links to other websites - Stripe's checkout, Instagram, Google Maps and carriers' tracking pages, among others. They have their own privacy policies and we are not responsible for how they handle your information.
12. Changes to this policy
We will update this page when our practices change and update the date at the top. If a change significantly affects you, we will let you know by email or with a notice on the site.