Legal
Privacy Policy
How Ordernised collects, uses and protects personal data, both for people who contact us and for the ordering and delivery data we handle on behalf of the venues and retailers we work with.
Last updated 24 August 2026
The short version
We collect the details you send us through our enquiry form, by email or by phone, so we can reply and quote for work. We use a small amount of website analytics to understand how the site is used. If you ordered food or goods from a business that runs on Ordernised, we handle your order and delivery details on that business's instructions, not our own.
We never sell personal data. You can ask us for a copy of your data, ask us to correct or delete it, or tell us to stop marketing to you, at any time, by emailing hello@ordernised.com.
Summary only. The full policy below is what governs.
01 Who we are and how to contact us
Ordernised ("we", "us", "our") provides marketing, ecommerce, ordering, payments, delivery logistics, software and support services to hospitality and retail businesses. In this policy, "you" means anyone whose personal data we handle, including website visitors, people who make an enquiry, and the staff of the businesses we work with.
For the personal data described in this policy where we decide why and how it is used, Ordernised is the data controller.
Our details
- Trading name
- Ordernised
- Registered office
- 2 Orchard Place, Nottingham Business Park, Nottingham, Nottinghamshire, England, NG8 6PX
- Also registered in
- United Arab Emirates
- Operational base
- Derby, East Midlands, United Kingdom
- hello@ordernised.com
- Contact
- All the ways to reach us
- Privacy contact
- hello@ordernised.com
Our registered office in Nottingham is the address at which the company is registered and where statutory records are held. It is not a public office and it is not where our team works day to day. Our operational base, and the location we serve clients from, is Derby in the East Midlands.
We are not currently required to appoint a statutory Data Protection Officer. If that changes, we will publish their details here.
02 When we are a data controller and when we are a data processor
This distinction matters, because it decides who you should contact about your data.
- We act as a data controller
- For personal data we decide the purpose of ourselves. That means visitors to this website, people who submit our enquiry form or email or call us, our marketing contacts, the staff contacts at our client businesses, our suppliers, and job applicants. Everything in this policy applies directly to that data.
- We act as a data processor
- For personal data belonging to the customers of the venues and retailers who use our platform. When someone places an order with a restaurant that runs on Ordernised, that restaurant is the controller and decides how the data is used. We process it on their documented instructions under a written contract that meets Article 28 of the UK GDPR, and we do not use it for our own purposes.
Ordered from a business that uses Ordernised? The venue or retailer you ordered from is responsible for your data, and their own privacy notice applies. Please contact them first. If you contact us instead, we will pass your request to them promptly and help them respond.
03 The personal data we collect
Enquiry and contact data
When you complete the form on our Get Started page, or email or call us, we collect your name, your business name, your email address, your phone number, the area of interest you select, the content of your message, and anything else you choose to tell us.
Client and account data
For businesses we work with, we hold the contact details of the people we deal with, billing and account details, account settings and login identifiers, and a record of support requests and correspondence.
Ordering and delivery data (handled for client venues)
Where a venue or retailer uses our platform, we process order and delivery information on their behalf. This can include the customer's name, delivery address, phone number, email address, order contents and value, delivery notes and timings, the driver allocated to a job and location data related to that delivery, and confirmation that a payment succeeded or failed.
We do not store complete payment card numbers. Card payments are handled by regulated payment providers using their own secure systems.
Notes left on an order, for example an allergy or a dietary requirement, may reveal information about health. Where that happens we process it only so the order can be prepared and delivered correctly, and we do not use it for anything else.
Website and technical data
When you browse our website we may collect your IP address, device and browser type, operating system, the pages you viewed and how long for, the page that referred you, an approximate location derived from your IP address, and cookie or similar identifiers.
Marketing data
Your contact preferences, whether you have opted in or out, and basic engagement information such as whether an email we sent was opened or a link was clicked.
We do not deliberately collect special category data, such as information about health, race, religion, political opinions, trade union membership, sex life or sexual orientation, or biometric or genetic data, other than the order notes described above. Please do not send us that kind of information unless we have asked for it.
04 How we collect it
- Directly from you. Through our enquiry form, by email, by phone, in meetings, or when you sign up for a service or event.
- Automatically. Through cookies and similar technologies when you use our website, as described in section 6.
- From our clients. Where we act as a processor, order and delivery data reaches us through the venue or retailer's use of our platform.
- From third parties. For example delivery partners, payment providers, integration partners and platforms our clients connect to, and publicly available business sources such as company websites and business directories.
05 How we use personal data and our lawful bases
Under UK data protection law we must have a lawful basis for everything we do with personal data. The table below sets out what we use data for and which basis applies.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Replying to your enquiry and preparing a quote | Enquiry and contact data | Our legitimate interests in responding to people who ask about our services, and taking steps at your request before entering into a contract |
| Delivering the services we have agreed | Client and account data, ordering and delivery data | Performance of a contract with the client. For end customer data we act as a processor on the client's instructions |
| Billing, invoicing and collecting payment | Client and account data | Performance of a contract, and legal obligation for accounting and tax records |
| Providing support and handling live delivery issues | Client, account, ordering and delivery data | Performance of a contract, and our legitimate interests in running a reliable service |
| Sending marketing emails and product updates | Contact and marketing data | Your consent, or our legitimate interests in telling existing business customers about similar services. You can opt out at any time |
| Measuring and improving our website | Website and technical data | Your consent for non essential cookies and analytics |
| Keeping our systems and data secure, and preventing fraud | Website, technical and account data | Our legitimate interests in protecting our business and our clients, and legal obligation |
| Meeting legal duties and handling disputes or claims | Any relevant data | Legal obligation, and our legitimate interests in establishing, exercising or defending legal claims |
Where we rely on legitimate interests, we have considered whether those interests are outweighed by your rights and freedoms, and we have concluded that they are not. You can ask us for more detail on that assessment, and you can object at any time using the process in section 11.
We do not make decisions about you using solely automated processing that produce legal effects or similarly significant effects.
06 Cookies and similar technologies
Cookies are small files stored on your device when you visit a website. This website is deliberately built so that it does not need them.
- We set no advertising or tracking cookies. We do not use advertising pixels, and we do not track you across other websites.
- Our analytics are cookieless. We measure which pages are visited using a privacy focused tool that stores nothing on your device and does not build a profile of you or follow you between sites. Because it sets no cookies and does not identify you, it does not require your consent under the Privacy and Electronic Communications Regulations.
- Strictly necessary cookies. If we later add a feature that genuinely needs one, for example to keep a session secure, it would fall into this category. Strictly necessary cookies do not require consent.
This means you will not see a cookie banner on this website, because there is nothing for you to consent to. If that ever changes, and we introduce analytics, functional or marketing cookies that are not strictly necessary, we will ask for your consent first and publish a full cookie list here before we do.
Separately, our platform pages used by restaurants and retailers to take orders may set strictly necessary cookies to keep a basket and a checkout session working. Those are essential to a service you have asked for.
You can control cookies through your browser settings, including blocking them or deleting ones already stored. Blocking strictly necessary cookies may stop parts of the site working. Guidance for every major browser, plus general information about cookies, is available at ico.org.uk.
07 Who we share personal data with
We do not sell personal data and we do not share it for other organisations' own marketing. We do share it with the following categories of recipient, only as far as is needed.
- Hosting and infrastructure providers who run the servers and storage our website and platform depend on.
- Email, messaging and communications providers who deliver our email and notifications.
- Payment providers who process card and other payments. These providers are regulated and generally act as controllers in their own right for the payment data they hold.
- Delivery partners and courier networks who carry out deliveries, and who need enough information to reach the customer.
- Analytics, advertising and marketing platform providers who help us measure and promote our services.
- Software, integration and IT support suppliers who help us build, maintain and secure our systems.
- Professional advisers such as accountants, auditors, insurers and lawyers, where they need the information to advise us.
- Regulators, law enforcement, courts and other authorities where we are required or permitted by law to disclose.
- A buyer or successor if we sell, reorganise or transfer part of our business, in which case your data would remain protected by this policy or an equivalent one.
Where a recipient acts as our processor, we put a written contract in place requiring them to keep the data secure, use it only on our instructions, and delete or return it when the work ends.
08 International transfers
We aim to keep personal data within the United Kingdom and the European Economic Area. Some of our suppliers, particularly hosting, analytics and communications providers, may store or access data outside the UK.
Where that happens, we make sure at least one appropriate safeguard is in place. That will normally be UK adequacy regulations covering the destination country, or the International Data Transfer Agreement, or the UK Addendum to the European Commission's Standard Contractual Clauses, together with any additional technical and organisational measures the transfer requires.
You can ask us for details of the safeguards used for a particular transfer by emailing hello@ordernised.com.
09 How long we keep personal data
We keep personal data only for as long as we need it for the purpose we collected it for, or for as long as the law requires. Our normal periods are set out below.
- Enquiries that do not become work. Up to 24 months from our last contact with you, so we can pick the conversation back up if you return.
- Client contracts and account records. For the length of the relationship, then 6 years, which matches the limitation period for contract claims in England and Wales.
- Accounting and tax records. 6 years after the end of the accounting period they relate to, as required by HMRC.
- Ordering and delivery data held for client venues. For the period agreed with that client in our contract with them. At the end of the contract we delete it or return it to them, as they instruct.
- Marketing contacts. Until you unsubscribe or ask us to stop. We then keep a minimal suppression record so we do not contact you again by mistake.
- Website analytics. Typically no more than 26 months.
When a retention period ends we securely delete the data, or anonymise it so it can no longer identify anyone.
10 How we keep personal data secure
We use appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration and disclosure. These include encryption of data in transit using TLS, access controls that give people only the access their role needs, authentication controls on our systems, monitoring and logging, regular software updates, backups, and reputable hosting providers.
Only staff and suppliers who need access to personal data have it, and they are bound by confidentiality obligations.
If a personal data breach occurs and it is likely to result in a risk to people's rights and freedoms, we will report it to the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of becoming aware. Where the risk is high, we will also tell the people affected. Where we act as a processor, we will notify the client controller without undue delay so they can meet their own duties.
No method of transmitting data over the internet is completely secure, so we cannot guarantee absolute security of anything you send us.
11 Your rights
Under UK data protection law you have the following rights. Some of them apply only in certain circumstances.
- Right of access
- You can ask whether we hold personal data about you and, if we do, receive a copy of it together with information about how we use it.
- Right to rectification
- You can ask us to correct personal data that is inaccurate, and to complete data that is incomplete.
- Right to erasure
- Also called the right to be forgotten. You can ask us to delete personal data where we no longer need it, where you withdraw consent we relied on, or where you object and we have no overriding reason to continue. It does not apply where we must keep the data for a legal duty or for legal claims.
- Right to restrict processing
- You can ask us to pause our use of your data, for example while we check the accuracy of something you have challenged.
- Right to data portability
- Where we process data you gave us by consent or under a contract, and by automated means, you can ask for it in a structured, commonly used, machine readable format, or ask us to send it to another organisation where that is technically feasible.
- Right to object
- You can object to processing based on our legitimate interests, and we will stop unless we can show compelling grounds that override your interests. You have an absolute right to object to direct marketing, and we will always stop.
- Right to withdraw consent
- Where we rely on consent, you can withdraw it at any time. Doing so does not affect the lawfulness of anything we did before you withdrew it.
- Rights around automated decisions
- You have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make decisions of that kind.
- Right to complain
- You can complain to the Information Commissioner's Office, the UK supervisory authority for data protection. Details are in section 16.
How to exercise your rights
Email hello@ordernised.com or write to us at our registered office. Please tell us which right you want to use and give us enough detail to find your data. We may ask for proof of identity so we do not disclose data to the wrong person.
We will respond within one month. If your request is complex, or you have made several requests, we may extend that by up to two further months and will tell you why within the first month. There is no charge, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse it, and we will explain our reasons.
If your request concerns data we hold as a processor for a client venue, we will pass it to that client without undue delay, because the decision is theirs to make.
12 Marketing choices
We only send marketing where you have agreed to it, or where you are an existing business customer and the message is about services similar to those we already provide to you.
Every marketing email includes an unsubscribe link, and you can also email hello@ordernised.com at any time and ask us to stop. Opting out of marketing does not stop service messages such as invoices, support replies or notices about a live delivery, which we need to send in order to run your account.
13 Children's data
Our website and our services are aimed at businesses and the adults who run them. They are not directed at children, and we do not knowingly collect personal data from anyone under 13. If you believe a child has given us personal data, please contact us and we will delete it.
Where a venue sells age restricted goods through our platform, the venue is responsible for verifying the customer's age at the point of sale and on delivery, in line with its own licences and the law.
14 Other websites we link to
Our website and the ordering pages we build may link to sites we do not control, including client websites, delivery partners, payment providers and social platforms. Those sites have their own privacy notices, and we are not responsible for how they handle your data. Please read their notices before you share anything with them.
15 Changes to this policy
We review this policy regularly and may update it as our services, our suppliers or the law change. The current version is always the one published on this page, and the date it was last changed is shown at the top.
If we make a change that materially affects how we use your personal data, we will take reasonable steps to tell you, for example by email or a notice on the website.
16 How to complain
If you are unhappy with how we have handled your personal data, please tell us first at hello@ordernised.com. We will look into it and reply.
You also have the right to complain to the Information Commissioner's Office at any time. You do not have to come to us first.
Information Commissioner's Office
- Address
- Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
- Helpline
- 0303 123 1113
- Website
- ico.org.uk