Privacy Policy

Who we are

We are Cask & Vine, an online retailer based in Edinburgh. Our website address is: https://caskandvine.co.uk.

 

What personal data we collect and why we collect it

Orders & Accounts

When you place an order or create an account, we collect the information needed to process and deliver your purchase. This includes your name, billing and shipping address, email address, phone number, and IP address. We also store your order history for customer service, fraud prevention and accounting purposes.

Legal basis: Contract (processing your order) and Legitimate Interest (fraud prevention).

Payments (Stripe)

We use Stripe to process payments. We do not receive or store your full card details. Stripe may collect your billing information, card details, IP address and device data for fraud prevention. You can read their privacy policy here: https://stripe.com/gb/privacy.

Legal basis: Contract and Legitimate Interest.

Comments

When visitors leave comments, we collect the data shown in the comments form, the visitor’s IP address and browser user agent string to help spam detection.

An anonymised string created from your email address (a hash) may be sent to the Gravatar service. Gravatar’s Privacy Policy is available at https://automattic.com/privacy/. After your comment is approved, your profile picture may be visible to the public next to your comment.

Media

If you upload images, avoid uploading photos with embedded location data (EXIF GPS). Other visitors can download these images and extract location information.

Cookies

WooCommerce, WordPress and our security/analytics tools use cookies necessary for the website to function. These include cookies that store your cart, login status, age verification response and display settings.

Examples include:

  • woocommerce_cart_hash – remembers your cart contents
  • woocommerce_items_in_cart – tracks cart updates
  • wp_woocommerce_session_* – stores a unique session ID
  • Age verification cookie (Easy Age Verify) – remembers that you confirmed your age
  • Login cookies – remember your account between visits if selected

Embedded content from other websites

Articles on this site may include embedded content such as videos, images or articles. Embedded content behaves exactly as if you visited the other website and may collect data, use cookies or track your interaction.

Analytics (Google Analytics)

We use Google Analytics to understand how visitors use our website. This may collect anonymised IP addresses, device information, pages visited and interaction patterns. You can view Google’s Privacy Policy here: https://policies.google.com/privacy.

Legal basis: Consent.

Security (Wordfence)

We use Wordfence to protect the site from malicious traffic. Wordfence may collect IP addresses, attempted logins and device data to block suspicious activity. This information is used solely for security and is not used for marketing.

Legal basis: Legitimate Interest (security and fraud prevention).

Age Verification (Easy Age Verify)

We use Easy Age Verify to ensure visitors meet the legal age requirement to view or purchase age-restricted products. The plugin sets a simple cookie to remember that you confirmed your age. It does not collect or store personal data and does not send information to third parties.

Who we share your data with

We only share data when necessary to operate our business:

  • Stripe – payment processing
  • Wordfence – site security
  • Google Analytics – website statistics
  • Our website hosting provider – site operation and backups

If you request a password reset, your IP address will be included in the reset email for security.

How long we retain your data

Comments and their metadata are stored indefinitely so we can recognise and approve follow-up comments automatically.

Order data is kept for up to 6 years for accounting and legal purposes.

Security logs collected by Wordfence are retained for approximately 30 days.

Registered users can see, edit or delete their personal information at any time (except usernames). Administrators can also see and edit this information.

What rights you have over your data

You can request an exported file of the personal data we hold about you, including any data provided to us. You may also request that we erase your personal data, except for information we are required to keep for administrative, legal or security reasons.

Where your data is sent

Visitor comments may be checked through an automated spam detection service. Order and payment data may be processed by Stripe or our hosting provider. Analytics data may be processed by Google.

Contact information

If you have any questions about this privacy policy or wish to exercise your data rights, please contact us at:

Cask & Vine
244 Canongate, Edinburgh EH8 8AB
Email: orders@caskandvine.co.uk

 

Get a Private Booking

BOOK A TABLE NOW!

Book A Tasting