Privacy Policy
Last updated: 21 June 2026
This policy explains how Pasture handles personal data for the people who use it — both shoppers who order from a butcher’s shop and the shop owners who run those shops. It is written to comply with the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR).
1. Who is responsible for your data
Pasture is a trading name of LRC Innovation Ltd(“Pasture”, “we”, “us”), company number 15072688, registered office 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ. Because the Platform connects shops with their customers, who is the “controller” depends on the data:
- Pasture is the controller for: shop owner (merchant) account and billing data; the login and identity data of everyone who holds an account (we operate the sign-in system); and technical and usage data about how the Platform is used.
- Each Shop is the controller for the personal data of its own Customers — the customer book and order history inside its back office. For that data Pasture acts as the Shop’s processor, handling it only on the Shop’s instructions under a Data Processing Agreement. If you ordered from a Shop and want to exercise your rights over that data, contact the Shop; we will support them.
- Stripe is an independent controller for the card and payment data it processes, under its own privacy policy.
2. What data we collect
- Account & identity — name, email, password (stored only as a secure hash), role and shop association.
- Order data — items ordered, amounts, collection or delivery details and order history.
- Payment data — handled by Stripe. We receive confirmation and limited metadata (such as a payment reference and the last four digits / card type); we do not store full card numbers.
- Marketing preferences — whether you have opted in to marketing and your contact preferences.
- Technical data — IP address, device and browser information, and logs needed to run and secure the Platform, plus strictly-necessary cookies (see section 9).
3. How and why we use your data
We use personal data on these legal bases:
- Performance of a contract — to create your account, take and fulfil orders, process payments and provide the service.
- Legitimate interests — to run, secure, support and improve the Platform and prevent fraud and abuse, where these interests are not overridden by your rights.
- Consent — to send you marketing by email where you have opted in (see section 10). You can withdraw consent at any time.
- Legal obligation — to keep accounting and tax records and to comply with the law.
5. International transfers
Where a provider processes data outside the UK, we make sure an appropriate safeguard is in place before the transfer. The position for each provider is:
- Neon, Supabase Storage and OVHcloud — data is held in UK or EU regions, covered by UK adequacy regulations;
- Stripe — an independent controller, operating under its own transfer safeguards; and
- Resend — a US provider, so UK adequacy regulations do not apply. We rely on the UK Extension to the EU–US Data Privacy Framework where the provider is certified under it, and otherwise on the UK Addendum to the EU Standard Contractual Clauses.
6. How long we keep data
How long we keep personal data depends on what it is:
- Account and identity data — kept while the account is active, and for 12 months after it closes, then deleted or anonymised;
- Order and financial records — 6 years from the end of the financial year they relate to, being the statutory accounting period;
- Technical and usage logs — 12 months; and
- Marketing suppression records — kept indefinitely, because we must go on honouring an opt-out after the rest of the data is deleted.
When data is no longer needed we delete or anonymise it.
7. Your rights
Under UK data protection law you have the right to:
- access a copy of your personal data;
- have inaccurate data corrected;
- have data erased in certain circumstances;
- restrict or object to certain processing;
- data portability; and
- withdraw consent at any time where we rely on it.
To exercise these rights for data we control, contact us at support@pastureapp.co.uk. Where the data is held by a Shop as controller (your customer/order data with that Shop), please contact the Shop and we will assist.
8. How we keep data secure
We use appropriate technical and organisational measures, including encryption of data in transit, hashing of passwords, and access controls so staff and shops only see what they need. No system is perfectly secure, but we work to protect your data and will notify you and the ICO of a personal data breach where the law requires.
10. Marketing
We only send marketing emails where you have opted in, or under the limited “soft opt-in” PECR allows for similar products to an existing customer. Every marketing email has an unsubscribe link, and you can opt out at any time in your account or by contacting us — this will not affect service messages about your orders or account.
11. Children
The Platform is intended for adults and is not directed at children under 18. We do not knowingly collect data from under-18s.
12. Contact and complaints
For any privacy question, or to exercise your rights, contact us at support@pastureapp.co.uk, or write to LRC Innovation Ltd, 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ. Our data protection contact is the Directors.
If you are unhappy with how we handle your data you can complain to the Information Commissioner’s Office (ICO) at ico.org.uk, though we would welcome the chance to address your concern first.
13. Changes to this policy
We may update this policy from time to time. The “last updated” date above shows when it last changed, and we will notify you of material changes where required.