General Bilimoria’s Canteen – Privacy Policy

Effective Date: 29 August 2025

General Bilimoria’s Canteen (“GBC”, “we”, “our”, or “us”) is committed to safeguarding the privacy of our customers, restaurant partners, delivery partners, and visitors to our website and mobile application (collectively referred to as the “Platform”). This Privacy Policy explains how we collect, use, store, and share personal information and outlines your rights in relation to that information.

By using our platform, you agree to the practices described in this privacy policy. If you do not agree, please refrain from using our platform.

1. Contact Details

If you have questions or concerns about this privacy policy or how your personal data is handled, please contact us at:

Email: hello@gbcanteen.com
Postal Address: 9 Berners Place, London, United Kingdom, W1T 3AD

2. Information We Collect About You

At General Bilimoria’s Canteen (“GBC”), protecting your privacy is a core priority. To provide you with safe, reliable and personalised services, we collect and process certain categories of information. This collection happens when you use our website, mobile application, or interact with us in any way.

Information You Provide Directly

We may collect information that you voluntarily give us, including:

Account Creation: When you sign up or update your profile, you provide details such as your name, email address, mobile number, delivery addresses, and account password.

Placing Orders: When you order through our platform, we collect details of the items you select, special delivery notes you provide, and payment-related information (processed securely by third-party providers; GBC does not store your full card details).

Customer Support: When you contact our support team, whether by email, phone, or chat, we record the information you share so we can resolve your query.

Reviews & Feedback: When you leave ratings, comments, or reviews on our platform, this information is linked to your account and may be visible to other users.

Promotions & Participation: If you enter a competition, referral scheme, loyalty program, or membership such as the “GBC Club”, we collect the information required to administer your participation.

Information We Collect Automatically

When you interact with our website, app, or services, we automatically gather certain technical and usage data to improve your experience and keep our platform secure:

Device Information: Type of device, operating system and version, IP address, browser type, and unique device identifiers.

Usage Data: Pages viewed, buttons clicked, search history, and navigation within the app or website.

Location Information: If you enable location services, we may collect your approximate or precise location to suggest nearby restaurants, improve delivery accuracy, and enhance fraud detection.

Cookies & Similar Technologies: We use cookies and tracking tools to analyse traffic, store your preferences, improve our services, and display relevant promotions. You may manage these settings through your browser or device preferences.

Information We Receive From Third Parties

We may receive information about you from trusted partners, including:

Payment Providers: To confirm and process your transactions securely.

Fraud Detection Services: To help us protect against suspicious or unauthorised activity.

Restaurant Partners: Where necessary to fulfil your orders or manage complaints.

Advertising & Analytics Providers: To better understand user behaviour, improve our platform, and serve you relevant offers.

3. Use of Your Information

We collect and use your personal information only where it is necessary to provide you with our services, fulfil our contractual and legal obligations, and improve your overall experience with General Bilimoria’s Canteen (“GBC”). The ways in which we may use your information include:

a) Processing and Delivering Orders

Your information is essential for preparing, processing, and delivering the food you order. This includes confirming your order, sharing the necessary details with our partner restaurants, and ensuring your items reach you safely and on time.

b) Managing Your Account

We use the details you provide to create and maintain your account with GBC, allowing you to log in securely, save preferences, view order history, and use other features of our platform. This also helps us provide a seamless experience across the app and website.

c) Providing Customer Support

To handle your requests, questions, or complaints, we may use your contact details, order information, and any communication history with our support team. This allows us to resolve issues quickly and provide you with the best possible assistance.

d) Service-Related Communications

We send you important notifications about your orders, such as confirmations, delivery updates, or changes to services. These messages are necessary for us to fulfil our commitment to you and cannot generally be opted out of.

e) Research and Service Improvement

We may analyze customer behavior, feedback, and interactions on our platform to identify trends and improve our services. This can involve surveys, reviews, or anonymized usage data, all aimed at enhancing the quality and reliability of GBC’s offerings.

f) Marketing and Promotions

Where permitted by law and with your consent (or where you have not opted out), we may send you marketing communications about promotions, discounts, new restaurant partners, or membership benefits such as the GBC Club. You always have the option to manage or withdraw your preferences regarding such communications.

g) Fraud Prevention and Security

We use your information to help detect, investigate, and prevent fraudulent activities, misuse of our platform, or other illegal actions. This may include verifying payment details, monitoring suspicious transactions, and taking steps to ensure the integrity of our systems and the safety of our users.

h) Legal and Regulatory Compliance

We may also process your information to comply with applicable laws, regulations, and reporting obligations. For example, this includes tax compliance, preventing unlawful activity, and responding to requests from regulatory or law enforcement authorities where legally required.

4. Cookies and Tracking Technologies

Like most online services, General Bilimoria’s Canteen (“GBC”) uses cookies and similar tracking tools on our website, app, and related services. Cookies are small text files placed on your device when you browse or interact with our platform. These technologies allow us to recognize your device, remember your preferences, and provide you with a smoother and more personalized experience.

Why We Use Cookies

We use cookies and tracking tools for several purposes, including

Essential Functionality

To enable core features of our website and app (such as secure login, order processing, and payment functionality).

Without these cookies, some services may not work properly.

Performance and Analytics

To understand how customers use our website and app, including which pages are most popular, how users navigate, and where improvements are needed.

This helps us improve speed, reliability, and user experience.

Personalisation

To remember your settings and preferences (e.g., language, location, or saved items).

This ensures you don’t need to re-enter details every time you visit.

Marketing and Advertising

To deliver content and promotions tailored to your interests on our platform sites or apps.

These cookies may track your browsing habits across websites to help us provide more relevant advertising.

Types of Cookies We Use

Session cookies (which expire once you close your browser).

Persistent cookies (which remain on your device until deleted or they expire).

First-party cookies (set by us) and third-party cookies (set by trusted partners such as analytics providers or advertising networks).

Your Choices

You have control over cookies:

You can adjust your browser or device settings to block or delete cookies.

You may also manage advertising preferences by opting out of certain third-party networks.

Please note: if you disable cookies, some parts of our website or app may not function as intended (for example, you may not be able to place an order or save preferences).

Transparency and Updates

We are committed to being transparent about how cookies are used. We may update this Cookies section from time to time to reflect changes in technology or legal requirements. Updates will be posted on this page, and in some cases we may notify you directly.

5. Marketing and Advertising

At General Bilimoria’s Canteen (“GBC”), we may use your personal information to keep you updated about new offers, restaurant launches, seasonal promotions, discounts, and membership benefits, including the GBC Club. These communications are designed to enhance your experience with us by letting you know about opportunities that may be relevant to your tastes and ordering habits.

Types of Marketing Communications

Service Updates: Information about new features of our app or website, improvements to our ordering process, or important service announcements.

Promotions and Discounts: Notifications about limited-time offers, special discounts, or bundle deals available on our platform.

Restaurant and Menu Updates: News about new restaurants, cuisines, or popular dishes that become available in your area.

Membership Benefits: Updates about loyalty schemes, referral rewards, or exclusive benefits under GBC Club.

Your Choice and Control

You are always in control of whether and how you receive marketing messages. You can opt out or change your preferences at any time by:

Adjusting your settings in your GBC account;

Clicking “unsubscribe” in promotional emails;

Disabling push notifications in your mobile device settings; or

Contact us directly at hello@gbcanteen.com.

Advertising and Personalisation

We may also work with trusted advertising and analytics partners to tailor the offers you see, both within our app and on other websites or social media platforms. This may involve the use of cookies or tracking technologies (see our Cookies section). These tools help us ensure that the promotions you receive are relevant and not repetitive.

Legal Basis for Marketing

Our marketing practices are carried out in line with the UK General Data Protection Regulation (UK GDPR) and the Privacy and Electronic Communications Regulations (PECR). We will only send you direct marketing where you have provided consent or where you have made a purchase from us and have not opted out.

6. Use of Automated Systems

To keep General Bilimoria’s Canteen (“GBC”) safe, fair, and reliable for all users, we use automated systems and decision-making tools. These systems help us detect unusual or potentially harmful activity, protect against fraud, and maintain the integrity of our platform.

7. Retention of Your Information

General Bilimoria’s Canteen (“GBC”) will only keep your personal information for as long as it is reasonably necessary to fulfil the purposes set out in this Privacy Policy. The exact retention period will depend on the nature of the information, the purpose for which it was collected, and any legal, accounting, or regulatory requirements that apply.

Why We Retain Data

We may keep your personal data for the following reasons:

Legal, Regulatory and Tax Obligations: Certain records must be retained to comply with laws, financial reporting, and tax rules.

Customer Service and Disputes: To respond to complaints, resolve disputes, or enforce our Terms & Conditions.

Service Improvement and Analytics: To analyse usage patterns and improve our platform while ensuring historical accuracy of services provided.

Examples of Retention Periods

To provide transparency, here are some examples of how long we may retain certain categories of data:

Transaction and Payment Records: Retained for up to 6 years after your order, in line with tax and accounting regulations.

Customer Reviews and Ratings: Retained for up to 2 years to ensure relevance and accuracy for future users.

Account Information: Retained for as long as your account is active. If your account becomes inactive, we may retain certain details for up to 12 months before deletion or anonymisation.

Customer Service Communications: Retained for up to 3 years after the issue is resolved, to assist with training, dispute handling, and service improvement.

What Happens After Retention

When personal data is no longer required, we will either:

Securely delete it from our systems, or

Anonymise it so it can no longer be linked to you. Anonymised data may be used for research, service improvements, or statistical reporting.

8. Sharing Your Information

We respect your privacy and only share your personal information where it is necessary, lawful, and consistent with this privacy policy. At General Bilimoria’s Canteen (“GBC”), sharing information helps us operate effectively, deliver your orders, and improve our services.

Who We Share Your Data With

Restaurant Partners

We share order details (such as items ordered, special requests, and delivery instructions) with the restaurant you have chosen so they can prepare your food correctly.

We do not share your full payment details with restaurants.

Delivery Partners

To deliver your order, we share essential information such as your name, delivery address, contact number, and order reference.

Delivery partners only receive the data necessary to complete the delivery safely and efficiently.

Payment Providers

We work with secure, regulated third-party payment processors to handle your transactions.

While your payment is processed by these providers, GBC itself does not store your full debit or credit card details.

Technology and Service Providers

We rely on trusted third-party providers for hosting, cloud storage, analytics, fraud prevention, IT support, and customer service tools.

These partners are only permitted to use your data in accordance with our instructions and for the purposes of providing their services to us.

Advertising and Marketing Partners

With your consent, we may share limited information (such as device identifiers or hashed email addresses) with advertising platforms to deliver relevant promotions and measure the effectiveness of campaigns.

We always put safeguards in place to protect your information in this process.

When We May Be Required to Share

In addition to the above, we may disclose your information:

For Legal Compliance: Where we are legally required to do so under UK law, regulation, or a court order.

For Fraud and Security: To investigate, detect, or prevent fraudulent or illegal activity, including protecting the safety of our customers, staff, and partners.

For Business Transactions: In the event of a business merger, acquisition, restructuring, or sale, your information may be transferred to the new owner or successor, subject to continued protection under this Privacy Policy.

9. Transfers of Your Information

General Bilimoria’s Canteen (“GBC”) operates primarily in the United Kingdom, but we may sometimes need to transfer and store your personal information outside the UK or the European Economic Area (“EEA”). This may happen, for example, where our cloud hosting, IT infrastructure, or service providers are located in other countries.

Safeguards for International Transfers

Whenever we transfer your data internationally, we ensure that your information remains secure and protected in line with UK data protection laws. This includes:

Adequacy Decisions: Only transferring data to countries that the UK Government or the European Commission has formally recognised as providing an adequate level of protection for personal data.

Contractual Protections: Where adequacy decisions do not apply, we use legally binding agreements such as the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses (SCCs). These contracts require the receiving party to protect your data to the same standards as if it were being handled in the UK.

Additional Safeguards: Where needed, we apply further technical and organizational measures such as encryption, access controls, and strict data minimization to keep your information safe.

Your Rights and Transparency

If you would like more information about the specific safeguards we use when transferring your personal data outside the UK or EEA, you may contact us at hello@gbcanteen.com.

10. Security

At General Bilimoria’s Canteen (“GBC”), protecting your personal data is one of our highest priorities. We apply a combination of technical, organizational, and procedural safeguards to reduce the risk of loss, misuse, or unauthorized access to your information.

Technical Measures

Encryption: Sensitive data such as payment details is encrypted both in transit (when being sent) and at rest (when stored on our systems).

Access Controls: Only authorized employees, contractors, and service providers with a legitimate business need are granted access to your personal data.

Secure Servers and Firewalls: We host information on secure servers with industry-standard protections to prevent unauthorized intrusion.

Monitoring: Our systems are monitored for unusual activity, and we use fraud-detection tools to identify and prevent suspicious transactions.

Organisational Measures

Training: All staff handling personal data receive training on data protection and confidentiality obligations.

Policies: Internal data security and privacy policies govern how information is collected, stored, shared, and deleted.

Third-Party Contracts: Service providers handling your data on our behalf are contractually required to apply equivalent safeguards.

Limitations

While we take reasonable steps to protect your data, no system or transmission over the internet can be completely secure. You acknowledge that information you send to us online is done at your own risk. Once we receive your data, we apply strict procedures and security features to try to prevent unauthorized access.

11. Your Rights

As a user of General Bilimoria’s Canteen (“GBC”), you have specific rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. These rights ensure that you remain in control of your personal information.

Your Rights in Detail

Right of Access

You have the right to request confirmation of whether we hold personal data about you, and if so, to receive a copy of that information together with details of how we use it.

Right to Rectification (Correction)

If any of your personal details are inaccurate, incomplete, or out of date, you can request that we correct or update them.

Right to Erasure (“Right to be Forgotten”)

You may request that we delete your personal information in certain circumstances, for example, if you close your account, withdraw consent (where processing was based on consent), or if the information is no longer needed for the purpose for which it was collected.

Right to Restrict Processing

In certain cases, you can ask us to limit how we process your data (for example, while a dispute is being resolved or if you contest the accuracy of the information).

Right to Object

You have the right to object to our processing of your personal information when it is based on our legitimate interests, including for direct marketing purposes. If you object to direct marketing, we will stop sending you promotional communications immediately.

Right to Data Portability

You can request that we transfer your personal data to you or another service provider in a structured, commonly used, and machine-readable format, where technically feasible. This applies to data processed with your consent or under a contract with you.

Right to Withdraw Consent

Where our processing relies on your consent (e.g. for marketing emails or push notifications), you may withdraw this consent at any time. Withdrawing consent will not affect the lawfulness of processing carried out before the withdrawal.

Right to Complain to a Supervisory Authority

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) in the UK if you are unhappy with how we handle your personal data. Further details can be found at www.ico.org.uk.

How to Exercise Your Rights

To exercise any of the above rights, please contact us at hello@gbcanteen.com. We may request proof of identity before fulfilling your request to protect your privacy and security. We aim to respond to all valid requests within one month, although this may be extended in complex cases.

12. Changes to This Privacy Policy

We may update or revise this Privacy Policy from time to time to reflect changes in our business practices, legal or regulatory requirements, or improvements to our services. Any changes will take effect once the updated version is published on our website and mobile application.

How We Will Notify You

Minor Updates: For small updates (for example, clarifications or formatting changes), we will update the version date at the top of this policy and publish it on our platform.

Significant Changes: For material changes that affect how we handle your personal information (such as introducing new data uses, expanding sharing with partners, or altering your rights), we will take additional steps to inform you. This may include sending a notification by email, app message, or a clear notice on our platform before the changes take effect.

Your Responsibility to Stay Informed

We encourage you to check this privacy policy regularly so that you remain informed about how we collect, use, and protect your personal information. Your continued use of the Platform after changes have been posted means that you accept and agree to the updated terms.