Privacy Policy
Last updated: 12 August 2026
This policy explains how Pasture handles personal data for the people who use it — both shoppers who order from a butcher’s shop and the shop owners who run those shops. It is written to comply with the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR).
1. Who is responsible for your data
Pasture is a trading name of LRC Innovation Ltd(“Pasture”, “we”, “us”), company number 15072688, registered office 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ. Because the Platform connects shops with their customers, who is the “controller” depends on the data:
- Pasture is the controller for: shop owner (merchant) account and billing data; the login and identity data of everyone who holds an account (we operate the sign-in system); and technical and usage data about how the Platform is used.
- Each Shop is the controller for the personal data of its own Customers — the customer book and order history inside its back office. For that data Pasture acts as the Shop’s processor, handling it only on the Shop’s instructions under a Data Processing Agreement. If you ordered from a Shop and want to exercise your rights over that data, contact the Shop; we will support them.
- Stripe is an independent controller for the card and payment data it processes, under its own privacy policy.
2. What data we collect
- Account & identity — name, email, password (stored only as a secure hash), role and shop association.
- Order data — items ordered, amounts, collection or delivery details and order history.
- Payment data — handled by Stripe. We receive confirmation and limited metadata (such as a payment reference and the last four digits / card type); we do not store full card numbers.
- Marketing preferences — whether you have opted in to marketing from a Shop and your contact preferences, stored for future use — no marketing is currently sent.
- Technical data — IP address, device and browser information, and logs needed to run and secure the Platform, plus strictly-necessary cookies (see section 9).
3. How and why we use your data
We use personal data on these legal bases:
- Performance of a contract — to create your account, take and fulfil orders, process payments and provide the service.
- Legitimate interests — to run, secure, support and improve the Platform and prevent fraud and abuse, where these interests are not overridden by your rights.
- Consent — where you opt in to marketing. We do not currently send marketing emails; if we introduce them, consent will be the basis we or a Shop rely on (see section 10). You can withdraw consent at any time.
- Legal obligation — to keep accounting and tax records and to comply with the law.
5. International transfers
Where a provider processes data outside the UK, we make sure an appropriate safeguard is in place before the transfer. The position for each provider is:
- Neon, Supabase Storage, OVHcloud and Sentry — data is held in UK or EU regions, covered by UK adequacy regulations;
- Stripe — an independent controller, operating under its own transfer safeguards; and
- Resend — a US provider. Resend is certified under the UK Extension to the EU–US Data Privacy Framework, which is our transfer safeguard; if that certification ever lapses, we will rely on the UK Addendum to the EU Standard Contractual Clauses instead.
6. How long we keep data
How long we keep personal data depends on what it is:
- Account and identity data — kept while the account is active, and for 12 months after it closes, then deleted or anonymised;
- Our own billing and accounting records (invoices to Shops and related financial data, for which we are controller) — 6 years from the end of the financial year they relate to, being the statutory accounting period;
- Customer and order data we hold for Shops— we hold this as the Shop’s processor, for as long as the Shop’s subscription lasts and its instructions require, and then delete or return it under our Data Processing Agreement. Retention of your data with a particular Shop is that Shop’s decision as controller;
- Technical and usage logs — 12 months; and
- Marketing preference — your opt-in or opt-out is held as a setting on your customer record, and is honoured for as long as that record exists. It is not kept separately, so it is deleted or anonymised with the rest of the record.
When data is no longer needed we delete or anonymise it.
7. Your rights
Under UK data protection law you have the right to:
- access a copy of your personal data;
- have inaccurate data corrected;
- have data erased in certain circumstances;
- restrict or object to certain processing;
- data portability; and
- withdraw consent at any time where we rely on it.
To exercise these rights for data we control, contact us at support@pastureapp.co.uk. Where the data is held by a Shop as controller (your customer/order data with that Shop), please contact the Shop and we will assist.
8. How we keep data secure
We use appropriate technical and organisational measures, including encryption of data in transit, hashing of passwords, and access controls so staff and shops only see what they need. No system is perfectly secure, but we work to protect your data and will notify you and the ICO of a personal data breach where the law requires.
10. Marketing
We do not currently send marketing emails. If we introduce marketing features, any marketing to a Shop’s customers will be sent by the Shop (as controller) with Pasture acting as its processor, and only where the Shop has your consent or another lawful basis such as the “soft opt-in” PECR allows for its own existing customers. Every marketing email will include an unsubscribe link, and opting out will never affect service messages about your orders or account. We will update this policy before any marketing features launch.
11. Children
The Platform is intended for adults and is not directed at children under 18. We do not knowingly collect data from under-18s.
12. Contact and complaints
For any privacy question, or to exercise your rights, contact us at support@pastureapp.co.uk, or write to LRC Innovation Ltd, 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ. Our data protection contact is the Directors.
If you are unhappy with how we handle your data you can complain to the Information Commissioner’s Office (ICO) at ico.org.uk, though we would welcome the chance to address your concern first.
13. Changes to this policy
We may update this policy from time to time. The “last updated” date above shows when it last changed, and we will notify you of material changes where required.