Welcome to the Carluccio’s Limited privacy and cookies policy

Carluccio’s (UK) Limited and Carluccio’s (ROI) Limited (we, us, our) take your privacy seriously, and we are committed to protecting your personal data.

This privacy and cookie policy (together with any other documents referred to on our website or which we have sent you) tells you:

  • Who we are.
  • How we collect, use, store and share your personal data.
  • Your privacy and other related rights under the provisions of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
  • How to contact the UK Information Commissioner’s Office if you have a complaint.
  • Please read this privacy and cookie policy, and any other privacy notice or policy that we may have provided to you. We want to be sure that you are fully aware of how and why we are using your data.
  • Please note that this website is not intended for children, and we do not knowingly collect data relating to children. If you are a minor under 16 years of age, please obtain consent from your parent or guardian before you submit any personal information to us. If you are a parent or guardian of a minor and you have reason to believe your child or ward has provided us with their personal information without your prior consent, please contact us to request for erasure of their personal data or for the minor to be unsubscribed from our mailing lists.

 

Who are we?

  • We are Carluccio’s (UK) Limited and Carluccio’s (ROI) Limited. Our contact details are as follows: contact@boparanrestaurants.com.
  • We are the ‘data controller’ for the information that we collect when you visit our website. That means that we decide how to use information about you (referred to as ‘personal data’) and we are responsible for looking after your personal data in accordance with data protection legislation. We will explain below how we collect and use your personal data, and what we mean by the term ‘personal data’. Please note that when we refer to ‘processing’ your personal data, what we mean is using your personal data in connection with this website (including the mobile optimised version of the website accessible from your portable hand-held device), our app(s), or our in-restaurant WiFi Service, by acquiring it, using it, storing it, communicating it to other people (with your consent or as part of our service to you) or deleting it.
  • If you do have any questions, or you would like to exercise any of your legal rights in relation to your personal data, then please contact at: contact@boparanrestaurants.com
  • By visiting our website or using our WiFi Service you are accepting and consenting to the practices described in this policy. Please note that we may update this privacy and cookie policy at any time. Any changes we may make to our policy in the future will be posted on this page. Please check back frequently to see any updates or changes made.

 

Complaints

Should you have any complaints or queries about anything relating to the privacy of your personal data, or any other data protection issues, please let us know using the contact details above and we will do our best to deal with them. However, you also have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK’s supervisory authority for data protection issues. The ICO may be contacted by the contact methods as set out on their website: www.ico.org.uk.

 

Personal data we collect about you

The term personal data means any information about an individual from which that individual may be identified. It does not, therefore, include data where the identity has been removed (anonymised data).

We may collect, store and use some or all of the following categories of data about you.

When you use our website, we may record:

  • technical information, including the type of device you use to access our website, the Internet Protocol (IP) address, your login data, the type and version of your browser, your time zone setting and location, browser plug-in types and versions, operating system, platform and mobile network information; and
  • your usage of our website, including the full Uniform Resource Locators (URL), the pages you viewed, the page response times, any download errors, the length of time you were on a particular page, how you interacted with the page (such as scrolling, clicks and mouse-overs), page response times, timestamp marking at restaurant, download errors, customer session duration, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), and how you browsed away from the page; and
  • marketing and communications data, including your preferences in receiving marketing from us and our third parties and your communication preferences.

 

When you contact us or and purchase any of our products:

  • your name and contact information, including email address and telephone number;
  • business/company details if you have contacted us on behalf of a business/company;
  • your gender information, if you choose to give this to us;
  • your personal or professional interests;
  • your professional and/or personal online presence (e.g. LinkedIn, Instagram or Facebook profile);
  • information about how you use our website, IT, communication and other systems; and
  • your responses to surveys, competitions and promotions.

This personal data is needed so that we can provide services and supply products to you. If you do not provide the personal data asked for, we may be delayed or prevented from providing those products and services.

 

How we collect your data

We will collect most of your personal data directly from you, whether in person, by telephone, text or email and/or via our website. This might be when you:

  • create an account on our website or mobile applications;
  • complete an online form;
  • respond to a promotion or subscribe to one of our publications/newsletters/mailing list;
  • request that information be sent to you;
  • enter a competition or contest;
  • take part in a survey;
  • write to us with information;
  • send a postal form to us;
  • communicate with us by telephone, text, email, via our website or through other communication channels (for example, through social media platforms);
  • send information to us using social media; or
  • provide feedback on products and services.

 

We may also collect information:

  • from publicly-accessible sources (for example the internet, LinkedIn or Companies House);
  • directly from a third party where the issue involves someone else (for example referees for a job);
  • from automated technologies or interactions with our website through the use of cookies and similar; and
  • via our systems (for example door entry systems and reception logs, CCTV and access control systems).
  • When you make a reservation at any of our restaurants;
  • When you purchase gift vouchers;
  • When you visit or make transactions in the establishments that we own or manage;
  • When you respond to our promotions, or subscribe to our mailing lists;
  • When you attend events or functions organised by us, or conducted at our establishments, for example, property launches, private dining, ticketed events and hosted events, promotional and marketing events and other social events;
  • When you use our services (or express an interest in doing so) including services and transactions in respect of properties that we own or manage;
  • When we seek information about you and receive your personal data in connection with your relationship with us; and
  • When you submit your personal data to us for any other reason.

 

How we use your data

We will only use your personal data when the law allows us to do so, and where we have a proper reason for doing so. Most often, we will use your personal data in the following circumstances:

  • Where you give us your consent to using your personal data; for example when you correspond with us or request a newsletter (your consent may be withdrawn by you at any time as set out in this policy).
  • For the performance of our contract with you (e.g. to administer and manage your account), or to take steps at your request before entering into a contract.
  • Where it is necessary for our legitimate interests (or those of a third party); for example, we have a business or commercial reason for using your personal data and your interests and fundamental rights do not override those interests (e.g. to administer our Site or provide you with information about other products and services we offer that are similar to those that you have already purchased or enquired about).
  • Where we need to comply with a legal or regulatory obligation.

 

We have set out below, in a table format, a description of ways we plan to use your personal data, and which of the legal bases we rely on to do so. 

Note that we may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data. Please contact us if you need details about the specific legal ground we are relying on to process your personal data where more than one ground has been set out in the table below. 

Purpose/Activity

Lawful basis for processing including basis of legitimate interest

To confirm a table booking

Necessary for our legitimate interests

To provide you with access to our WiFi Service

(a) Performance of a contract with you 

(b) Necessary for our legitimate interests

To manage our relationship with you which will include:

(a) Notifying you about changes to our terms or privacy policy

(b) Asking you to leave a review or take a survey

(a) Performance of a contract with you 

(b) Necessary to comply with a legal obligation

(c) Necessary for our legitimate interests (to keep our records updated and to study how customers use our products/services)

To enable you to partake in a prize draw, competition or complete a survey

(a) Performance of a contract with you 

(b) Necessary for our legitimate interests (to study how customers use our products/services, to develop them and grow our business)

To administer and protect our business and our website and app(s) (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data)  

(a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise)

(b) Necessary to comply with a legal obligation

To deliver relevant website and app content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you

Necessary for our legitimate interests (to study how customers use our services, to develop them, to grow our business and to inform our marketing strategy)

To use data analytics to improve our website, products/services, marketing, customer relationships and experiences

Necessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy)

To make suggestions and recommendations to you about services that may be of interest to you

Necessary for our legitimate interests (to develop our products/services and grow our business)

CCTV in our restaurants

(a) Necessary for our legitimate interests (for security, crime prevention and customer and staff safety)

(b) Necessary to comply with legal obligations

 

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us.

We do not carry out automated decision making.

 

Sharing your data

We may share your personal data with the parties set out below:

  • Other companies in our Group, including those which provide IT and system administration services and undertake leadership reporting.
  • External third parties including:
    • service providers who provide IT and system administration services, social media networks, data management companies, digital agencies, reservation booking platforms, gift voucher solutions providers, and professional advisers,
    • HM Revenue & Customs, regulators and other authorities;
    • business partners, suppliers and sub-contractors for the performance of any contract we enter into with them or you. This includes our WiFi providers for the purposes of the WiFi Service in our restaurants and business partners for the purpose of administering customer satisfaction surveys;
    • advertisers and advertising networks that require the data to select and serve relevant adverts to you and others; and
    • analytics and search engine providers that assist us in the improvement and optimisation of our site.
  • Third parties to whom we may choose to sell, transfer, or merge parts of our business or our assets.

If we are under a duty to disclose or share your personal data in order to comply with any legal obligation, or in order to enforce or apply our terms of use and other agreements; or to protect our rights, property, or safety, or that of our customers or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction.

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.

 

Storing your data

Personal data is stored on our secure servers and/or at our premises. Special rules will apply to the protection of your data if it is stored outside the UK/EEA. Special rules will also apply where, for example, we need to contact third parties on your behalf who have offices outside the UK/EEA, where electronic services and resources are based outside the UK/EEA, or where there is an international element to your matter.

We will keep your personal data only for as long as is necessary. In working out how long we need to keep your personal data we take into account the amount, nature and sensitivity of the personal data, the potential for harm to arise from its unauthorised use or disclosure, the purposes for which we process it, and as to whether those purposes may be achieved by other means, and the applicable legal requirements. Since retention periods will differ for different types of personal data please contact us for further details.

In order to ensure that your personal data is kept secure, and to prevent there being any breach of confidentiality or unauthorised use, we have put in place security measures which are intended to prevent your personal data from being accidentally lost or used or accessed unlawfully. Access to your personal data is restricted to those with a need to access it, and regard will be had to the need for confidentiality when that personal data is processed.

Please bear in mind that the transmission of information via the internet is not completely secure, and whilst we will do our best to protect your personal data, we cannot guarantee the security of data transmitted via our website, or by email, and any such transmission is at your own risk.

 

Your legal rights

You have the right to ask us not to process your personal data for marketing purposes. You can also exercise the right at any time by contacting us at contact@boparanrestaurants.com. We will usually inform you (before collecting your data) if we intend to use your data for such purposes or if we intend to disclose your information to any third party for such purposes. 

Our site may, from time to time, contain links to and from the websites of our partner networks, advertisers and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies.  Please check these policies before you submit any personal data to these websites.

You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance.

You also have the right to:

  • Request access to your data: sometimes called a ‘subject access request’; this allows you to receive, from us, confirmation as to whether or not your personal data is being processed, and if so to gain access to that personal data and various other information about it, including the purpose for the processing, with whom the data is shared, how long the data will be retained, and the existence of various other rights.
  • Request correction of your data: sometimes called a ‘right to rectification’, this is a right to obtain from us, without undue delay, the putting right of inaccurate personal data concerning you.
  • Request erasure of your data: sometimes referred to as the ‘right to be forgotten’; this is the right for you to request that, in certain circumstances, we delete data relating to you.
  • Restrict processing of your data: the right to request that, in certain circumstances, we restrict the processing of your data.
  • Object to the processing of your data where we are relying on our legitimate interests: this is, a right, in certain circumstances, to object to personal data being processed by us where it is in relation to direct marketing, or in relation to processing supported by the argument of legitimate interest.
  • Request the transfer of your data to another party: the right, in certain circumstances, to receive that personal data which you have provided to us, in a structured, commonly used and machine-readable format, and the right to have that personal data transmitted to another controller.
  • A right not to be subject to automated decision making: that is to say, a right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you, or similarly significantly affects you.

In some circumstances we may not be able to do what you have asked; for example, where there is a statutory or contractual requirement for us to process your data and it would not be possible to fulfil our legal obligations if we were to stop.

You may obtain further information on your rights from the website of the Information Commissioner’s Office.

 

 

Cookies

We use cookies in connection with the operation of our website. A cookie is a small file that is sent by a web server (where we host our website) to a web browser (from where you view our website), and which is then stored by the browser.

Usually, cookies do not hold any data by which you can be identified, although if we do hold personal data about you (for example, because you have subscribed to a service that we offer) the cookie may be linked to that data.

We use cookies for the following purposes:

We use the following cookies:

  • Strictly necessary cookies. These are cookies that are required for the operation of our website. They include, for example, cookies that enable you to log into secure areas of our website, use a shopping cart or make use of e-billing services. 
  • Analytical/performance cookies (e.g. traffic log cookies). They allow us to recognise and count the number of visitors and to see how visitors move around our website when they are using it. This helps us to improve the way our website works, for example, by ensuring that users are finding what they are looking for easily. 
  • Functionality cookies. These are used to recognise you when you return to our website. This enables us to personalise our content for you, greet you by name and remember your preferences (for example, your choice of language or region).
  • Targeting cookies. These cookies record your visit to our website, the pages you have visited and the links you have followed. We will use this information to make our website and the advertising displayed on it more relevant to your interests. We may also share this information with third parties for this purpose.

We also use software called Google Analytics which is a web analytics service provided by Google Inc. in order to understand how visitors to our website use the site. The Google Analytics cookies remember you from one page request to the next, for example to differentiate between ‘new’ and ‘returning’ visitors. We receive reports from Google Inc. about website usage (such as the number of visitors to our site or the number of unique page views).

In addition to cookies used by us, our service providers may also use cookies, and those cookies may also be stored in your browser when you visit our website.

If you wish to do so then usually you can prevent cookies from being downloaded to your browser and may delete those that have already been downloaded. How this is achieved varies between different browsers. Consult the website of your browser provider for more details. However, you should be aware that if you block or delete cookies this may have a detrimental impact upon your ability to access our website and the services that we provide. It may mean that not all of the facilities on our website will be accessible by you, or it may mean that you are unable to access any member services which we provide.

You can find more information about the individual cookies we use and the purposes for which we use them in the table below:

 

Cookie type

Source

Name

Purpose

Expiry

Analytical/ performance

carluccios.com

_ga
_gat
_gid
ajs%3Acookies
ajs%3Atest
ajs_group_properties
ajs_user_traits

We use Google Analytics to understand how visitors use our website

Expiry ranges from 1 day to persistent

Analytical/ performance

carluccios.com

ajs_anonymous_id

To identify the number of visitors on the site

1 year

Analytical/ performance

doubleclick.net

r/collect

To monitor visitors’ devices and behaviour on our site via Google Analytics

Expiry

Analytical/ performance

google-analytics.com

Collect

To monitor visitors’ devices and behaviour on our site via Google Analytics

Session

Analytical/ performance

carluccios.com

_hjIncludedInSample

To analyse visitors’ behaviour on our site

Expiry

Targeting

carluccios.com

_gcl_au

To monitor ad performance

3 months

Targeting

google.com

ads/ga-audiences

For ad targeting

Session

Targeting

carluccios.com

_fbp

Used by Facebook for ad targeting

1 day

Targeting

carluccios.com

ajs_group_id

To assign specific visitors in to segments, based on visitor behaviour on the website

1 year

Targeting

carluccios.com

ajs_user_id

To collect data on the visitor’s behaviour and then assign them to a segment

3 months

Targeting

facebook.com

fr

Used by Facebook for ad targeting

Session

Targeting

facebook.com

tr

Used by Facebook for ad targeting

Session

Functionality

twitter.com

personalization_id

Allows the visitor to share content from the website on his/her Twitter profile

2 years

Functionality

sharethis.com

    ab12#

To share content to social networks

1 year

Functionality

carluccios.com

sharethis_cookie_test

To share content to social networks

Session

Functionality

carluccios.com

tld

Unclassified

1 year

Functionality

twitter.com

i/adsct

Used by Twitter to share content

9 months

Functionality

carluccios.com

unam

Used to share content to social networks

1 year

Functionality

carluccios.com

stid

Used to share content to social networks

1 month

Functionality

carluccios.com

CNL

Controls the pop up newsletter subscribe form

1 day

Functionality

carluccios.com

CLastViewed

To gather last viewed product data to recommend products to other users

2 years

Strictly necessary

Shopify - carluccios.com

_ab

Shopify - Used in connection with access to admin.

2y

Strictly necessary

Shopify - carluccios.com

_customer_account_shop_sessions

Shopify - Used in combination with the _secure_account_session_id cookie to track a user's session for new customer accounts

30d

Strictly necessary

Shopify - carluccios.com

_secure_account_session_id

Shopify - Used to track a user's session for new customer accounts

30d

Strictly necessary

Shopify - carluccios.com

_secure_session_id

Shopify - Used to track a user's session through the multi-step checkout process and keep their order payment and shipping details connected.

24h

Strictly necessary

Shopify - carluccios.com

_shopify_country

Shopify - For shops where pricing currency/country set from GeoIP that cookie stores the country we've detected. This cookie helps avoid doing GeoIP lookups after the first request.

session

Strictly necessary

Shopify - carluccios.com

_shopify_m

Shopify - Used for managing customer privacy settings.

1y

Strictly necessary

Shopify - carluccios.com

_shopify_tm

Shopify - Used for managing customer privacy settings.

30min

Strictly necessary

Shopify - carluccios.com

_shopify_tw

Shopify - Used for managing customer privacy settings.

2w

Strictly necessary

Shopify - carluccios.com

_storefront_u

Shopify - Used to facilitate updating customer account information.

1min

Strictly necessary

Shopify - carluccios.com

_tracking_consent

Shopify - Used to store a user's preferences if a merchant has set up privacy rules in the visitor's region.

1y

Strictly necessary

Shopify - carluccios.com

_cmp_a

Shopify - Used for managing customer privacy settings.

1d

Strictly necessary

Shopify - carluccios.com

c

Shopify - Used in connection with checkout.

1y

Strictly necessary

Shopify - carluccios.com

cart

Shopify - Used in connection with shopping cart.

2w

Strictly necessary

Shopify - carluccios.com

cart_currency

Shopify - Set after a checkout is completed to ensure that new carts are in the same currency as the last checkout.

2w

Strictly necessary

Shopify - carluccios.com

cart_sig

Shopify - A hash of the contents of a cart. This is used to verify the integrity of the cart and to ensure performance of some cart operations.

2w

Strictly necessary

Shopify - carluccios.com

cart_ts

Shopify - Used in connection with checkout.

2w

Strictly necessary

Shopify - carluccios.com

cart_ver

Shopify - Used in connection with shopping cart.

2w

Strictly necessary

Shopify - carluccios.com

checkout

Shopify - Used in connection with checkout.

4w

Strictly necessary

Shopify - carluccios.com

checkout_token

Shopify - Used in connection with checkout.

1y

Strictly necessary

Shopify - carluccios.com

customer_account_locale

Shopify - Used in connection with new customer accounts

1y

Strictly necessary

Shopify - carluccios.com

dynamic_checkout_shown_on_cart

Shopify - Used in connection with checkout.

30min

Strictly necessary

Shopify - carluccios.com

hide_shopify_pay_for_checkout

Shopify - Used in connection with checkout.

session

Strictly necessary

Shopify - carluccios.com

keep_alive

Shopify - Used in connection with buyer localization.

2w

Strictly necessary

Shopify - carluccios.com

master_device_id

Shopify - Used in connection with merchant login.

2y

Strictly necessary

Shopify - carluccios.com

previous_step

Shopify - Used in connection with checkout.

1y

Strictly necessary

Shopify - carluccios.com

discount_code

Shopify - Used in connection with checkout.

session

Strictly necessary

Shopify - carluccios.com

remember_me

Shopify - Used in connection with checkout.

1y

Strictly necessary

Shopify - carluccios.com

secure_customer_sig

Shopify - Used to identify a user after they sign into a shop as a customer so they do not need to log in again.

1y

Strictly necessary

Shopify - carluccios.com

shopify_pay

Shopify - Used in connection with checkout.

1y

Strictly necessary

Shopify - carluccios.com

shopify_pay_redirect

Shopify - Used in connection with checkout.

1 hour 3w or 1y depending on value

Strictly necessary

Shopify - carluccios.com

shop_pay_accelerated

Shopify - Used in connection with checkout.

1y

Strictly necessary

Shopify - carluccios.com

tracked_start_checkout

Shopify - Used in connection with checkout.

1y

Strictly necessary

Shopify - carluccios.com

checkout_session_lookup

Shopify - Used in connection with checkout.

3w

Strictly necessary

Shopify - carluccios.com

checkout_prefill

Shopify - Used in connection with checkout.

5m

Strictly necessary

Shopify - carluccios.com

checkout_queue_token

Shopify - Used in connection with checkout.

1y

Strictly necessary

Shopify - carluccios.com

checkout_queue_checkout_token

Shopify - Used in connection with checkout.

1y

Strictly necessary

Shopify - carluccios.com

checkout_worker_session

Shopify - Used in connection with checkout.

3d

Strictly necessary

Shopify - carluccios.com

checkout_session_token

Shopify - Used in connection with checkout.

3w

Strictly necessary

Shopify - carluccios.com

checkout_session_token_<>

Shopify - Used in connection with checkout.

3w

Strictly necessary

Shopify - carluccios.com

cookietest

Shopify - Used to ensure our systems are working correctly

1m

Strictly necessary

Shopify - carluccios.com

order

Shopify - Used in connection with order status page.

3w

Strictly necessary

Shopify - carluccios.com

identity-state

Shopify - Used in connection with customer authentication

24h

Strictly necessary

Shopify - carluccios.com

identity-state-<>

Shopify - Used in connection with customer authentication

24h

Strictly necessary

Shopify - carluccios.com

identity_customer_account_number

Shopify - Used in connection with customer authentication

12w

Strictly necessary

Shopify - carluccios.com

card_update_verification_id

Shopify - Used in connection with checkout.

20m

Strictly necessary

Shopify - carluccios.com

customer_account_new_login

Shopify - Used in connection with customer authentication

20m

Strictly necessary

Shopify - carluccios.com

customer_account_preview

Shopify - Used in connection with customer authentication

7d

Strictly necessary

Shopify - carluccios.com

customer_payment_method

Shopify - Used in connection with checkout.

1h

Strictly necessary

Shopify - carluccios.com

customer_shop_pay_agreement

Shopify - Used in connection with checkout.

20m

Strictly necessary

Shopify - carluccios.com

pay_update_intent_id

Shopify - Used in connection with checkout.

20m

Strictly necessary

Shopify - carluccios.com

localization

Shopify - Used in connection with checkout.

2w

Strictly necessary

Shopify - carluccios.com

profile_preview_token

Shopify - Used in connection with checkout.

5m

Strictly necessary

Shopify - carluccios.com

login_with_shop_finalize

Shopify - Used in connection with customer authentication

5m

Strictly necessary

Shopify - carluccios.com

wpm-test-cookie

Shopify - Used to ensure our systems are working correctly.

session

Strictly necessary

carluccios.com

catAccCookies

To record that you accept the fact that the site uses cookies

Session

Strictly necessary

carluccios.com

wordpress_test_cookie

Checks if cookies are enabled to provide appropriate user experience

Session

Strictly necessary

carluccios.com

wordpress_logged_in*

Checks whether or not the current visitor is logged in

Session

Strictly necessary

carluccios.com

wp-settings*

Sets various settings for logged in users

1 month

 

You can block cookies by activating the setting on your browser that allows you to refuse the setting of all or some cookies. However, if you use your browser settings to block all cookies (including essential cookies) you may not be able to access all or parts of our site.