Jan's Pantry ("we", "us", "our") operates the website janspantry.co.uk. We are committed to protecting your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This policy explains what data we collect, why we collect it, how long we keep it, and your rights.
1. Data Controller
The data controller responsible for your personal data is Jan's Pantry, contactable at hello@janspantry.co.uk.
2. What Data We Collect
a) Newsletter & Voucher Reveal Subscriptions
When you subscribe to our newsletter or reveal a gated voucher code, we collect:
- Your email address
- Your IP address at the time of subscription
- The date and time you subscribed
Legal basis: Consent (Article 6(1)(a) UK GDPR). You actively provide your email and submit the form. You can withdraw consent at any time by unsubscribing.
b) Voucher Reveal Logs
When you reveal a voucher code, we log:
- A hashed (anonymised) version of your email address
- A hashed (anonymised) version of your IP address
- The deal slug and timestamp
These hashes cannot be reversed to identify you. They are used solely for rate limiting and abuse prevention.
Legal basis: Legitimate interest (Article 6(1)(f) UK GDPR) — preventing abuse of the voucher system.
c) Contact Form
When you submit our contact form, we collect your name, email address, and message content. This data is used solely to respond to your enquiry.
Legal basis: Legitimate interest (Article 6(1)(f) UK GDPR) — responding to your enquiry.
d) Server Logs
Our web server automatically records IP addresses, request URLs, browser user-agent strings, and timestamps for security monitoring purposes.
Legal basis: Legitimate interest (Article 6(1)(f) UK GDPR) — protecting the website against malicious activity.
3. How We Use Your Data
- To send you our weekly deals newsletter (only if you have subscribed)
- To email you a voucher code when you request one
- To respond to enquiries submitted via our contact form
- To prevent abuse — rate limiting and security monitoring
- To improve the website based on aggregate, anonymised usage patterns
We do not sell, rent, or share your personal data with third parties for marketing purposes.
4. Third Parties & Affiliate Links
Our deal pages may contain links to retailer websites. Some of these may be affiliate links, meaning we may earn a small commission if you make a purchase — at no extra cost to you.
When you click an external link, you leave our site and are subject to that retailer's own privacy policy. We are not responsible for the privacy practices of third-party websites.
We do not share your personal data (email, name, IP address) with any retailer or affiliate partner.
5. Cookies
We use minimal cookies:
| Cookie / Storage | Purpose | Duration |
|---|---|---|
tm_gdpr_consent |
Stores your cookie consent preference (accepted / declined) | Persistent (localStorage) |
PHPSESSID |
Standard PHP session cookie — remembers revealed voucher codes during your visit | Session (deleted when you close your browser) |
jp_revealed_* |
Remembers which voucher codes you have already revealed (sessionStorage) | Session (deleted when you close your browser tab) |
We do not use Google Analytics, Facebook Pixel, or any third-party tracking or advertising cookies.
6. Data Retention
| Data | Retention Period |
|---|---|
| Newsletter subscriber data | Until you unsubscribe, or until you request deletion |
| Voucher reveal logs (hashed) | 12 months |
| Contact form submissions | 12 months |
| Server security logs | 30 days |
You may request deletion of your data at any time (see section 7).
7. Your Rights Under UK GDPR
You have the following rights regarding your personal data:
- Right of access — request a copy of the data we hold about you
- Right to rectification — ask us to correct inaccurate data
- Right to erasure — ask us to delete your data ("right to be forgotten")
- Right to restrict processing — ask us to limit how we use your data
- Right to data portability — receive your data in a structured, machine-readable format
- Right to object — object to processing based on legitimate interest
- Right to withdraw consent — unsubscribe from our newsletter at any time
To exercise any of these rights, email us at hello@janspantry.co.uk. We will respond within 30 days.
8. Unsubscribing from Our Newsletter
Every email we send contains an unsubscribe link at the bottom. You can also unsubscribe at any time by visiting https://janspantry.co.uk/unsubscribe or emailing hello@janspantry.co.uk.
When you unsubscribe, we mark your record as inactive. We retain your email address in an inactive state to ensure we do not accidentally re-subscribe you. You may request full deletion at any time.
9. Children's Privacy
Our website is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
10. Security
We take reasonable technical and organisational measures to protect your data, including:
- HTTPS encryption on all pages
- Hashing of IP addresses and email addresses in logs
- Rate limiting to prevent brute-force and abuse
- HMAC-based CSRF protection on forms
- Regular security monitoring
11. Complaints
If you are unhappy with how we have handled your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Helpline: 0303 123 1113
12. Changes to This Policy
We may update this policy from time to time. The "last updated" date at the top of this page will always reflect the most recent version. We encourage you to review this page periodically.
13. Contact Us
For any privacy-related queries, or to exercise your data rights, please contact:
Jan's Pantry
Email: hello@janspantry.co.uk