Last updated: 22/04/2026
This Privacy Policy explains how Roam Cafe Bistro (“we”, “us”, “our”) collects, uses and protects your personal data when you visit our website at roamcafebistro.co.uk (the “Website”), make a booking, apply for a job or otherwise get in touch.
We are committed to protecting your privacy and handling your data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
For the purposes of UK data protection law, Roam Cafe Bistro is the “data controller” of the personal data you provide via this Website.
We may collect and process the following categories of personal data:
We do not knowingly collect personal data from children under 16. If you believe a child has provided data through our Website, please contact us and we will delete it.
We collect personal data when you:
We use your personal data for the following purposes, each under one of the lawful bases set out in UK GDPR:
|
Purpose |
Lawful basis |
|---|---|
|
To confirm, manage and amend your booking |
Contract — taking steps at your request prior to entering a contract with you |
|
To respond to general enquiries or feedback |
Legitimate interests — responding to people who contact us |
|
To consider your careers application and communicate with you about it |
Legitimate interests — hiring staff, or pre-contract steps if we make you an offer |
|
To operate, secure and improve the Website |
Legitimate interests — running and maintaining a functional, secure site |
|
To send marketing communications (only if you opt in) |
Consent |
|
To meet our legal or regulatory obligations (e.g. tax, health and safety, complaints) |
Legal obligation |
You can withdraw your consent at any time where we rely on consent (see Section 10).
We do not sell your personal data. We may share it with:
Where a service provider is based outside the UK, we take steps to ensure your data is protected to UK GDPR standards, for example through approved transfer mechanisms such as the UK International Data Transfer Agreement.
We only keep your personal data for as long as we need it for the purpose we collected it for, and to meet any legal obligations.
We use appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access or disclosure. These include secure hosting, access controls, staff training and regular review of our processes. No transmission of data over the internet can be guaranteed 100% secure, but we work to minimise the risks.
Our Website uses cookies and similar technologies to make it work, to remember your preferences and to help us understand how it’s used.
You can manage or withdraw your cookie consent at any time via the cookie banner or your browser settings.
Our Website may contain links to external sites (e.g. Google Maps, Instagram, TikTok, Facebook). We are not responsible for the privacy practices of those sites. Please review their privacy policies before providing any personal data.
Under UK GDPR you have the following rights in relation to your personal data:
To exercise any of these rights, please contact us using the details in Section 12. We will respond within one month, in line with UK GDPR.
If you have a concern about how we handle your personal data, please contact us first so we can try to resolve it. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s data protection regulator:
For any questions about this Privacy Policy or your personal data, please contact us:
We may update this Privacy Policy from time to time. The latest version will always be available on this page, with the “Last updated” date refreshed accordingly. Where changes are significant, we will make reasonable efforts to let you know directly (e.g. by email if we have your address for that purpose).