The Grain Store Lewes Privacy Policy

Please take a moment to read our privacy policy. It’ll reassure you how The Grain Store handles your personal data and:

  • What we (trading as The Grain Store Lewes) do to keep your data secure

  • The type of personal information we hold and why

  • Your rights over any personal information we keep on you

Our privacy policy complies with the rules laid out by the GDPR (General Data Protection Regulation.) It outlines how we handle data in each of these cases:

  • You’re a guest at The Grain Store Lewes

  • You’re a supplier to The Grain Store Lewes

  • You’ve asked to receive marketing information from The Grain Store Lewes in the form of email newsletters

1) Privacy information if you are a guest at The Grain Store Lewes

How and why The Grain Store Lewes collects personal data

We collect personal data from you so that we can:

  • Communicate with you about your requirements

  • Send you payment requests for your hire of The Grain Store

  • Keep records for The Grain Store Lewes, HMRC and other official bodies

If you are a guest, we ask you for your:

  • First name

  • Last name

  • Home address

  • Email address

  • Your mobile number

  • Organisation name (corporate clients only)

  • Organisation address

  • Organisation phone number

For tax reasons, we are legally required to hold specific information on you for seven years.

After this time, you can ask for your details to be deleted from my system. You can do this by emailing business@thegrainstorelewes.com

2) Privacy information if you are a supplier to The Grain Store Lewes

How and why The Grain Store Lewes collects personal data

We collect personal data from you so that we can:

  • Pay you for the work you do

  • Keep records for The Grain Store Lewes, HMRC and other official bodies

If you are a supplier, we might ask you for your:

  • First name

  • Last name

  • Email address

  • Organisation name

  • Organisation address

  • Organisation phone number

  • Your mobile number

For tax reasons, we are legally required to hold specific information on you for seven years. After this time, you can ask for your details to be deleted from my system. You can do this by emailing business@thegrainstorelewes.com

3) Privacy information if you have asked to receive marketing information from The Grain Store Lewes in the form of our email newsletter (mailing list)

How and why The Grain Store Lewes collects personal data

We collect personal data when you become a guest and on our website, www.thegrainstorelewes.com when you ask to join our mailing list to receive seasonal offers and news by email newsletter

We ask you for your:

  • First name

  • Email address

We do this so that we can send emails to you and greet you by your first name in the emails I send.

We comply with GDPR and the Privacy and Electronic Communications Regulations (PECR) in that when we send you our marketing emails, we are sending them because you have given us your consent to do so.

Any email marketing messages we send are done so through an email service provider (EMS). An EMS is a third-party service provider of software/applications that allows marketers to send out email marketing campaigns to a list of users.

The Grain Store’s EMS provider is Mailchimp. We hold the following information about you within this EMS system:

  • Email address

  • I.P address

  • Subscription time & date

  • First Name

You should know that email marketing messages we send may contain tracking beacons/tracked clickable links or similar server technologies to track subscriber activity within email marketing messages.

Where used, such marketing messages may record a range of data such as;

  • Times

  • Dates

  • I.P addresses

  • Opens

  • Clicks

  • Forwards

  • Geographic and demographic data

Such data, within its limitations, will show the activity each subscriber made for that email campaign.

We provide you with an easy method to withdraw your consent (unsubscribe) or manage your preferences/the information we hold about you at any time, using the link that is in every marketing email we send to you.

You can ask to see any information we hold on you at any time by emailing business@thegrainstorelewes.com

We respect the fact you’ve chosen to share your contact details with The Grain Store Lewes. We will not take your contact details, or your request to receive information from us – for granted.

When you sign up to our mailing list, we will hold your details for two years. After two years we will email you to ask you to opt-in to continue to receive it.

4) Data security and protection

We take the security of your personal data seriously. We use secure data storage technologies and apply best practice procedures in how we store, access and manage information. Our methods meet the GDPR compliance requirement. We hold personal data in several places:

  • We use SuperControl to manage our bookings

  • We use Holiday Rent Payment (a Yapstone company) to manage payments from guests

  • We use Xero to manage our accounts, and we store details of guests and suppliers on it

  • We use MailChimp to send our email newsletters, and we store details of people who have asked to receive information from The Grain Store on it

We have chosen these applications because they offer us the tools we need and because they are widely recognised to be among the most reliable and most secure solutions available in each case. We also take all reasonable precautions to keep the data we hold on you in these places safe, including having appropriately complicated passwords.

5) Sharing your information

We do not share your information with third parties.

Your rights

Under the GDPR your rights are as follows. You can read more about your rights in details here: https://ico.org.uk/media/for-organisations/data-protection-reform/overview-of-the-gdpr-1-13.pdf

  • The right to be informed

  • The right of access

  • The right to rectification

  • The right to erasure

  • The right to restrict processing

  • The right to data portability

  • The right to object

  • The right not to be subject to automated decision-making including profiling

You also have the right to complain to the ICO if you feel there is a problem with the way we are handling your data.

We handle subject access requests in keeping with the GDPR.