Privacy Policy
Privacy Policy
Last updated: 15 May 2026
Black Fire Foods ("we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you visit our website or purchase from us. It is issued in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as they apply in Northern Ireland.
1. Who We Are (Data Controller)
For the purposes of data protection law, the data controller is:
- Black Fire Foods
- Address: 19 Ardmore Park, Belfast, BT10 0JJ, Northern Ireland
- Company number: NI675933 (registered in Northern Ireland)
- Email: tim@blackfirefood.com
If you have any questions about this Policy or how we handle your data, contact us at the details above.
2. What Personal Data We Collect
We may collect and process the following categories of personal data:
Information you give us directly:
- Name
- Delivery and billing address
- Email address
- Phone number
- Date of birth (where age verification is required)
- Order history and product preferences
- Account login details (if you create an account)
- Communications you send us (e.g. customer service enquiries)
- Marketing preferences
Information collected automatically:
- IP address and device information
- Browser type and version
- Pages visited, time spent, and referring website
- Cookie data (see Section 9)
Payment information:
- Card and payment details are collected and processed directly by Shopify, our ecommerce and payments platform. We do not store full card numbers on our servers.
3. How We Collect Your Data
We collect data:
- When you place an order or create an account
- When you contact us by email or via our contact form
- When you subscribe to our newsletter or marketing
- When you browse our website (via cookies and similar technologies)
- From third parties such as payment providers and couriers, where necessary to fulfil your order
4. Why We Use Your Data and the Legal Basis
Under the UK GDPR, we must have a lawful basis for processing your data. We rely on the following:
| Purpose | Legal Basis |
|---|---|
| To process and deliver your order | Performance of a contract |
| To take payment and handle refunds | Performance of a contract |
| To respond to your enquiries or complaints | Legitimate interests / contract |
| To send order confirmations and service messages | Performance of a contract |
| To send marketing emails (where you have opted in) | Consent |
| To improve our website and products | Legitimate interests |
| To prevent fraud and ensure security | Legitimate interests / legal obligation |
| To comply with tax, accounting, and food safety record-keeping laws | Legal obligation |
| Age verification for age-restricted products | Legal obligation |
You can withdraw consent for marketing at any time (see Section 8).
5. Who We Share Your Data With
We never sell your personal data. We share it only with trusted third parties who help us run our business, including:
- Shopify – our ecommerce platform, which hosts our website, processes your order, and handles payments securely on our behalf.
- Delivery couriers – to deliver your order. The courier used will depend on your delivery destination.
- Other service providers we use to operate our business – such as email service providers (for order confirmations and any marketing you have opted in to) and website analytics tools to help us improve our service.
- Professional advisers – such as accountants, auditors, and lawyers, where required.
- Government or regulatory bodies – where required by law (e.g. HMRC, the Food Standards Agency, the Information Commissioner's Office, courts, or police).
All processors are bound by written contracts requiring them to keep your data secure and use it only for the purposes we specify.
6. International Transfers
Some of our service providers may process data outside the UK. Where this happens, we ensure appropriate safeguards are in place, such as:
- The country has been deemed "adequate" by the UK Government; or
- We use UK International Data Transfer Agreements or the UK Addendum to the EU Standard Contractual Clauses.
You can request more information about these safeguards by contacting us.
7. How Long We Keep Your Data
We retain personal data only as long as necessary for the purposes set out in this Policy:
- Order and transaction records: 6 years after the end of the relevant tax year, to comply with HMRC requirements.
- Customer accounts: for as long as your account remains active. Inactive accounts may be deleted after 24 months of inactivity.
- Marketing preferences: until you unsubscribe or withdraw consent.
- Customer service correspondence: typically 2 years.
- Website analytics: typically 26 months.
After these periods, data is deleted or anonymised.
8. Your Rights
Under the UK GDPR you have the following rights:
- Right to be informed – about how we use your data (this Policy).
- Right of access – to request a copy of the data we hold about you.
- Right to rectification – to ask us to correct inaccurate or incomplete data.
- Right to erasure – to ask us to delete your data ("right to be forgotten"), in certain circumstances.
- Right to restrict processing – to limit how we use your data.
- Right to data portability – to receive your data in a portable format.
- Right to object – including to direct marketing and processing based on legitimate interests.
- Rights related to automated decision-making and profiling – we do not currently carry out automated decision-making that has legal effects on you.
- Right to withdraw consent – at any time, where processing is based on consent.
To exercise any of these rights, contact us at tim@blackfirefood.com. We will respond within one month. There is usually no charge.
9. Cookies
Our website uses cookies and similar technologies to make the site work, improve your experience, and analyse usage. Cookies fall into the following categories:
- Strictly necessary cookies – required for the website to function (e.g. shopping basket, checkout, login).
- Functional cookies – remember preferences such as language or region.
- Analytics cookies – help us understand how visitors use the site (e.g. Google Analytics).
- Marketing cookies – used to deliver relevant advertising and measure campaign effectiveness.
Non-essential cookies are only set with your consent, which you can give or withdraw via our cookie banner. You can also manage cookies through your browser settings.
For more details, please see our Cookie Policy [or include a fuller cookie table here].
10. Marketing
We will only send you marketing emails if you have opted in. Every marketing email contains an "unsubscribe" link. You can also update your preferences by contacting us.
11. Security
We take appropriate technical and organisational measures to protect your data, including:
- Encrypted connections (HTTPS/SSL) across our website
- Secure, access-controlled hosting environments
- Restricted staff access on a need-to-know basis
- Vetted third-party processors with their own security obligations
While we take security seriously, no system is completely secure. If you suspect a data breach, please contact us immediately.
12. Children's Privacy
Our website and products are not directed at children under 16. We do not knowingly collect personal data from children under 16 without parental consent. If you believe we may have collected data from a child, please contact us so we can delete it.
13. Complaints
If you are unhappy with how we have handled your data, please contact us first so we can try to resolve the issue.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's data protection regulator:
- Website: ico.org.uk
- Helpline: 0303 123 1113
- Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
14. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top will reflect the most recent changes. Significant changes will be communicated to you directly where appropriate.
15. Contact Us
If you have any questions, requests, or concerns about this Privacy Policy or your data:
Black Fire Foods 19 Ardmore Park, Belfast, BT10 0JJ, Northern Ireland Company number: NI675933 Email: tim@blackfirefood.com