Brewing-recipe card · Policy privacy
Privacy Pilsner
A.K.A. Privacy Policy · Vintage 2026-05-19
Brewer's notes: What data we collect when you brew with us, why we collect it, and how to take it back.
1. Data controller
The data controller is OBAN ALES LIMITED ("we"). You can reach our data protection contact at support@obanalesco.com.
2. What we collect
Account data: name, email, postal address, phone (optional), order history, recipe PDF download history.
Payment data: handled by our PCI-DSS-compliant payment processor (Stripe, PayPal). We do not store card numbers.
Technical data: IP address, browser type, device, referring URL, performance telemetry. Aggregated analytics are anonymised.
Marketing data (if you opt in): email preferences, open/click telemetry on our newsletters.
3. Why we collect it
To fulfil orders (contract): processing payments, packing kits, shipping, customer support.
To run the Site (legitimate interest): security, fraud prevention, analytics for product improvement.
To meet legal obligations: tax records, accounting, age-verification records.
To send marketing (consent): only when you opt in. You can withdraw consent at any time using the link in any email.
4. Who we share it with
Payment processors (Stripe Inc., PayPal Ltd.), shipping carriers (Royal Mail, UPS, DHL, USPS, Canada Post, Australia Post), email service provider, analytics processors (privacy-friendly analytics provider).
We do not sell or rent personal data. We disclose data to law enforcement only on lawful request.
5. Your rights
Under UK / EU GDPR you may: access, rectify, erase, restrict processing, port, or object to processing. Under CCPA / CPRA (California) you may know, delete, correct, and opt out of sale. We never sell personal information.
To exercise a right, email support@obanalesco.com from the email address on your account. We respond within 30 days (45 days under CCPA).
6. International transfers
Some processors are located outside the UK / EEA. We use Standard Contractual Clauses and require equivalent technical safeguards.
7. Retention
Order records are retained for 7 years to meet UK tax obligations. Marketing data is held until you opt out. Analytics are aggregated after 14 months.
8. Children
Our Site is not directed at people under 21. If we learn that we have inadvertently collected data on a minor we will delete it.