Hitch & Home — Privacy Notice
Effective from: [DATE — set when published] Version: 0.1 (working draft) Drafted by: Caversham Digital Status: Draft — solicitor review recommended before publication.
⚠️ This is an agency-prepared template aligned to UK GDPR and the Data Protection Act 2018. The content reflects standard small-business UK practice, but the legal entity name, registration number, retention periods, and any unusual data flows must be confirmed (and ideally reviewed by a solicitor) before this notice goes live on
hitchandhomeuk.com/privacy.
1. About this notice
This is the privacy notice for Hitch & Home, a mobile kitchen hire business based in Cardiff and operating across South Wales. We take your privacy seriously and want to explain — in plain English — what personal data we collect, why we collect it, and what we do with it.
If anything here is unclear or you’d like more detail, contact us on hire@hitchandhomeuk.com or 029 2252 3407 and we’ll explain.
2. Who we are
Hitch & Home is a trading name of [LEGAL ENTITY NAME], a company registered in [England and Wales / Wales] with company number [COMPANY NUMBER]. Our registered office is [REGISTERED ADDRESS].
We are the data controller for the personal data described in this notice. That means we decide what personal data is collected and how it’s used.
3. What data we collect
When you make an enquiry or booking
To respond to your enquiry, send you a quote, and (if you go ahead) deliver the trailer to your home, we collect:
- Your name
- Your phone number(s)
- Your email address
- The site address where you’d like the trailer (this may be the same as your billing address, or different)
- Your billing address, if different from the site address
- Details about your renovation — preferred dates, duration, number of people in the household, anything you tell us about the property
- Photos of your driveway / site, if you choose to send them so we can confirm suitability
- Any other information you choose to share in your enquiry
When you book
In addition to the above, we collect:
- Payment details — only for the duration of processing the booking deposit, balance, and security deposit (we don’t store full card details ourselves; we use a payment processor — see section 6)
- A copy of the signed Hire Agreement
- Your election on the Damage Waiver
On delivery and during the hire
- Photos of the trailer interior and exterior — taken on delivery, on collection, and during the hire if there’s a fault to record
- Photos of the site if relevant (only the area where the trailer is sited, not the rest of your home)
- Notes from any phone calls during the hire (e.g. fault reports, requested support visits)
- Records of any damage, cleaning charges, or deposit deductions, with the supporting reasoning
When you visit our website
- Standard analytics data if you visit
hitchandhomeuk.com— pages visited, approximate location (city level), device type, anonymised IP. See section 9 (Cookies) for more detail. - Anything you submit in our enquiry form — same fields as a phone enquiry
When you message us on social media
- Your social media handle and any message content you send via Instagram or Facebook DM. Note: the platforms themselves (Meta) collect their own data — see Meta’s privacy policy.
What we DON’T collect
We don’t collect:
- Bank account numbers (we accept payment by bank transfer or card, but the destination is our account, not yours)
- Date of birth, marital status, or any “special category” data (health, ethnicity, religion, etc.)
- Children’s data — we hire to adults; if a household includes children, we don’t record information about them
- Location data beyond the site address you’ve given us
4. Lawful bases — why we’re allowed to collect this data
UK GDPR requires us to have a lawful basis for processing your data. The bases we rely on:
| Activity | Lawful basis |
|---|---|
| Responding to your enquiry, sending a quote, taking a booking | Performance of a contract (or steps to enter a contract at your request) |
| Delivering the trailer, supporting you during hire, collecting at end | Performance of a contract |
| Taking and keeping condition photos | Legitimate interests — we have a legitimate interest in protecting our equipment and resolving disputes; this is balanced against your right to privacy of your home, and we never photograph beyond what’s necessary |
| Keeping records of bookings for accounting and HMRC purposes | Legal obligation |
| Sending you booking-related messages (delivery confirmations, reminders) | Performance of a contract |
| Sending you marketing emails or texts (only if you’ve opted in) | Consent |
| Posting your hire as a case study (only with your explicit permission) | Consent |
| Defending or pursuing legal claims | Legitimate interests |
You have the right to object to processing based on legitimate interests — see section 11.
5. How long we keep your data
We don’t keep data for longer than we need to.
| Data type | Retention period |
|---|---|
| Enquiry-only records (no booking placed) | 12 months from last contact |
| Booking records, Hire Agreement, payment records | 7 years from end of hire (HMRC requirement for accounting records) |
| Condition photos taken during a hire | 12 months from end of hire (or longer if there’s an open dispute, claim, or insurance matter) |
| Marketing-list contacts | Until you unsubscribe, then deleted within 30 days |
| Social media DMs | Per the platform’s retention; we don’t keep our own copies unless they relate to a booking |
| Website analytics (aggregated) | 26 months |
After these periods, we securely delete or anonymise the data.
6. Who we share your data with
We share your data only with the parties listed below, only when needed, and only the minimum required to do the job.
Service providers
- Payment processor —
[STRIPE / GOCARDLESS / SUMUP / NAME — TBC]— to process card and bank payments. They handle card details directly; we don’t see them. They act as our processor and are bound by their own UK GDPR-compliant terms. - Email and SMS provider — to send booking confirmations, delivery notifications, and (with your consent) marketing.
- Cloud storage provider —
[GOOGLE WORKSPACE / MICROSOFT 365 / NAME — TBC]— where we store booking records, photos, and accounting data. Data is encrypted at rest and in transit. UK / EU data centres preferred. - Accountant — for annual accounts and HMRC filings. They are bound by professional confidentiality and UK GDPR.
- Solicitor — only if a dispute arises. Bound by professional confidentiality and UK GDPR.
- Insurance provider — only if a claim is made (e.g. damage during hire, public liability incident).
Other parties (only when necessary)
- HMRC — if required by law (e.g. accounting records on inspection)
- Police or court — if required by law (e.g. valid court order)
- Howdens — only if you’ve voluntarily used a Howdens partnership discount code, in which case we may confirm to Howdens that you used the code (so the discount is honoured). We don’t share any other data with Howdens. (Note: this clause applies only if/when the Howdens partnership goes live with a discount mechanic.)
What we DON’T do
- We don’t sell your data. To anyone. Ever.
- We don’t share your data with advertisers or data brokers.
- We don’t share your data internationally outside the UK and EU, except where the cloud provider’s infrastructure makes routine transfers within their global network — in those cases, the provider has UK-adequacy or Standard Contractual Clauses in place.
- We don’t use your data to train AI or machine learning models.
7. International transfers
Most of your data stays in the UK. Where service providers (e.g. cloud storage, email) route data through other jurisdictions:
- We choose providers with UK-adequacy decisions (covering most of the EU and a few other countries the UK government has deemed safe) where possible.
- Where a transfer goes outside the adequacy list, we rely on Standard Contractual Clauses with the provider — the safeguard required by UK GDPR.
If you’d like the specifics of where each provider is based, contact us.
8. Security
We take reasonable measures to protect your data:
- Encrypted email (TLS) for booking and payment-related correspondence
- Encrypted cloud storage at rest and in transit
- Multi-factor authentication on our business accounts
- Limited access — only those who need to handle your data have access to it
- Regular review of access permissions
- Secure deletion at the end of retention periods
No system is perfect. If a data breach affects you, we’ll tell you within 72 hours of becoming aware of it (where the breach is likely to result in a risk to your rights and freedoms), and we’ll notify the Information Commissioner’s Office where required by law.
9. Cookies and website analytics
hitchandhomeuk.com uses a small set of cookies. We keep tracking minimal:
| Cookie | Purpose | Retention |
|---|---|---|
| Strictly necessary cookies | Site functions (e.g. remembering your form input if you navigate away) | Session only |
Analytics — [PLAUSIBLE / FATHOM / NONE — TBC] | Anonymous aggregate visit data so we can understand which pages people find useful | Anonymous; no individual tracking |
We don’t use:
- Google Analytics
- Facebook Pixel
- Advertising / retargeting cookies
- Third-party social-media trackers
When you first visit the website, you’ll see a brief cookie notice. You can reject non-essential cookies; nothing on the site stops working if you do.
To clear cookies, use your browser’s privacy settings.
10. Marketing
We only send you marketing if you’ve explicitly asked for it (ticked a box, signed up to a list, or replied “yes” to a question). We don’t add you to a marketing list just because you enquired.
If you’ve consented to marketing, we may contact you about:
- New trailer availability or service-area changes
- Seasonal promotions
- Useful renovation tips
- Customer case studies (with the customer’s permission)
Every marketing email includes a one-click unsubscribe. Once you unsubscribe, we’ll stop within 30 days and remove you from the list.
We don’t use your booking-history data to retarget you on Facebook, Instagram, or anywhere else.
11. Your rights
Under UK GDPR you have the following rights. To exercise any of them, contact hire@hitchandhomeuk.com and we’ll respond within one calendar month.
- Right of access — ask for a copy of the personal data we hold about you
- Right to rectification — ask us to correct inaccurate or incomplete data
- Right to erasure (“right to be forgotten”) — ask us to delete your data, subject to limits where we have a legal obligation to keep it (e.g. accounting records)
- Right to restrict processing — ask us to stop using your data while we sort something out
- Right to data portability — ask for your data in a machine-readable format so you can take it elsewhere
- Right to object — object to our use of your data based on legitimate interests, including for marketing
- Right to withdraw consent — for anything we’re doing on the basis of your consent
- Right not to be subject to automated decision-making — we don’t make any automated decisions about you, but you have this right anyway
We won’t charge you for exercising any of these rights, and we won’t make it difficult.
If we can’t agree, you have the right to complain to the Information Commissioner’s Office (ICO):
- Website:
ico.org.uk - Phone:
0303 123 1113 - Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
12. Children’s data
We don’t knowingly collect data from anyone under 18. Our service is sold to adult homeowners. If a child is part of a household receiving a hire, we don’t record information about them.
If you believe we’ve inadvertently collected data about a child, contact us and we’ll delete it.
13. Changes to this notice
If we make material changes to this notice, we’ll update the version number and the effective date at the top, and (where the changes affect you) we’ll let you know directly.
Material changes mean substantial differences in what data we collect, why, or who it’s shared with. Minor wording or contact-detail updates don’t count as material.
14. Contact
Questions, concerns, or to exercise any of your rights:
- Email:
hire@hitchandhomeuk.com - Phone:
029 2252 3407 - Post:
[REGISTERED OFFICE ADDRESS]
For unresolved complaints, the ICO is the supervisory authority — contact details in section 11.
Items to confirm before publication
- Legal entity name + registration number (in section 2)
- Registered office address (sections 2 and 14)
- Confirmed payment processor (section 6)
- Confirmed cloud storage provider (section 6)
- Confirmed email/SMS provider (section 6)
- Confirmed analytics tool — Plausible / Fathom / none (section 9)
- Effective date (top of document)
- Solicitor review — recommended before going live
- Final URL set (
hitchandhomeuk.com/privacy) - Linked from website footer, holding page, booking form, every customer-facing email