VD SON'S, BRIGHTON
Privacy Policy
Version 2026-09-05.1. Published 5 September 2026.
Pre-opening notice: online ordering is disabled. The store must confirm its legal identity, address, operating details and processor arrangements and obtain professional legal review before accepting orders. These proposed trading terms are not evidence that the shop is open for online sales.
Business identity and contact
VD Son's Indian Grocery Store, Brighton. Legal operator: HIT ENTERPRISE LONDON LIMITED. Business address: 84 Lewes Road, Brighton, BN2 3HZ.
Email: hello@vdsonsgrocery.co.uk. Telephone: awaiting confirmation.
VD Son's is a trading name of HIT ENTERPRISE LONDON LIMITED.
Registered in England and Wales. Company number: 15374272.
Registered office: 120 Cavendish Place, Eastbourne, England, BN21 3TZ.
Information and purposes
This notice concerns the UK GDPR and Data Protection Act 2018. The controller named above decides how store information is used. We collect account name, email, a password hash and session identifiers; guest contact details; order lines, totals, payment status and references; delivery address and telephone; support correspondence; newsletter preferences; and limited sign-in and administrative activity records. Card numbers and security codes are entered with Stripe, not stored by this shop.
Lawful bases and choices
Account, order, payment, refund and delivery data are used to take steps you request and perform the purchase contract. Financial records and responses to lawful authorities may be kept to meet legal obligations. Proportionate fraud prevention, access control, service reliability and dispute handling rely on legitimate interests in protecting customers and operating the store; you may object to processing on this basis. Newsletter email uses separate consent, not a condition of shopping.
Contact, payment and address details needed to fulfil an order are required; without them we cannot complete delivery. Accounts, marketing signup, favourites and geolocation are optional. We do not deliberately request health information. Avoid sending unnecessary sensitive information in support messages. No solely automated decision-making with legal or similarly significant effects is implemented; postcode eligibility, stock and coupon rules are ordinary order checks.
Location and browser information
A postcode determines delivery eligibility and is retained with an order address only when you order. Precise browser location is requested only after you choose the location check and give browser permission. Coordinates are used for the delivery-distance calculation and are not written to the shop database. You can use a postcode instead. Network providers necessarily process IP addresses when delivering and protecting the service.
Recipients and international transfers
Website management and maintenance are provided by Agentic Mate. Cloudflare provides hosting, D1 storage, R2 images and security services. ChatGPT Sites is the deployment platform. Stripe processes card payment details and related fraud and transaction information when activated. The store's authorised delivery staff or confirmed courier receive only details needed for delivery. Authorised technical support may access records when necessary to maintain the service. Email forwarding and the selected outbound email provider process messages and recipient addresses. Independent providers may also act as controllers for their own legal or security purposes.
The client must confirm its legal controller, contracted email and courier providers, processing agreements, hosting access and transfer arrangements before online ordering opens. Providers may process information outside the UK. Where required, the controller must establish a valid adequacy basis or approved safeguards, such as the UK International Data Transfer Agreement or UK Addendum and appropriate assessments. Do not assume these arrangements are complete simply because this notice is published; ask the privacy contact for confirmed details and copies of applicable safeguards.
Retention
Sessions expire after seven days for customers or eight hours for administrators. Password reset links expire after 30 minutes. Expired sessions, reset records and rate-limit counters are removed by the retention process. Cancelled unpaid checkouts are removed after 30 days; unresolved payments remain until reconciled to avoid losing stock or payment records. Completed or cancelled order records and stock history are scheduled for deletion after six years, subject to confirmed legal retention needs. Application audit events are removed after 180 days.
Unconfirmed newsletter entries are removed after 30 days. Withdrawn newsletter evidence is kept for two years; a minimal hashed-email suppression entry remains to prevent unwanted future marketing. Active subscribers remain until withdrawal or a store review. Customer accounts remain while required for the requested account service; deletion requests remove the account after outstanding orders are resolved while necessary order records remain until their retention deadline. The store must run and review its retention controls and confirm provider-side log, backup, mailbox and payment retention separately.
Your rights
Depending on the applicable conditions, you may request access, correction, erasure, restriction, portability and object to processing. In particular, you can object to direct marketing at any time and withdraw consent without affecting earlier lawful processing. Use the no-login unsubscribe link in your subscription email. A suppression record is retained to honour that choice.
Signed-in customers can export their account and order data and request account deletion from My Account. Guests and anyone unable to sign in can contact the privacy email above. We may reasonably verify identity before releasing information or making changes. We aim to respond within one month; if a lawful extension is needed, we will explain it. Deletion is not absolute where information must be retained for legal obligations or claims.
Security and children
Passwords are stored as salted hashes. Access is limited through account ownership checks, administrator permissions and expiring sessions. Secure connections protect information in transit. These measures reduce risk but no website can guarantee absolute security. Do not share passwords or order-access links. The service is intended for adult purchasers, not directed at children; contact us if a child has supplied personal information so we can review it.
Complaints and updates
You may complain to the Information Commissioner's Office without first contacting us, although we welcome the opportunity to resolve concerns. Material changes will be explained here and, where appropriate, directly. Version 2026-09-05.1 is the initial pre-opening notice; client verification and professional legal review remain outstanding.