Ghochen Partners · Legal
Privacy Policy
Last updated June 2026
This Privacy Policy describes how Ghochen Limited collects, uses, and discloses personal data when you use Ghochen Partners. It is written to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This is a draft prepared for review by a UK-qualified solicitor and is not yet binding. The ICO registration number must be inserted before personal data is processed at scale.
1. Who we are
Ghochen Limited is the controller of your personal data. Our registered office is in Kingston upon Hull, United Kingdom. You can contact us at privacy@ghochen.com.
We are registered with the Information Commissioner’s Office (ICO) under registration number [to be obtained before launch].
2. What data we collect
Data you provide directly:
- Identity data: name, date of birth, passport or driving licence (for identity verification via Stripe Identity).
- Contact data: phone number, email address, business address.
- Business data: trading name, legal entity name, Companies House number, UTR, VAT number.
- Financial data: bank account details (collected and held by Stripe, not by Ghochen).
- Compliance data: FSA hygiene rating, insurance details, food safety certificates.
- Content data: product names, descriptions, images.
- Communication data: messages you send through the Platform to customers or Ghochen support.
Data collected automatically:
- Device data: device type, operating system, app version, crash logs.
- Usage data: features used, screens visited, session duration, error events.
- Location data: approximate location derived from IP address and business address.
Data from third parties:
- From Stripe: identity verification results, payment processing data.
- From the Food Standards Agency: your business’s current hygiene rating.
- From Companies House (if applicable): public company registration data.
3. Legal bases
We process your personal data on the following legal bases under UK GDPR Article 6:
- Contract: to provide the Platform and fulfil our obligations under our Partner Terms.
- Legal obligation: to comply with tax law, anti-money-laundering law, food safety law, and cooperate with competent authorities.
- Legitimate interests: to improve the Platform, prevent fraud, and ensure security. We balance these against your rights.
- Consent: for optional features such as marketing communications. Consent can be withdrawn at any time.
4. How we use your data
- To provide the partner services: accepting orders, processing payments, facilitating customer communication.
- To verify your identity and business credentials.
- To process payments and payouts through Stripe.
- To comply with legal obligations, including tax reporting and food safety cooperation.
- To detect and prevent fraud, abuse, and security threats.
- To improve the Platform through analytics and research on usage patterns.
- To provide customer support and communications about your account.
- To send you marketing communications where you have consented.
6. International transfers
Most personal data is stored in the UK or the European Economic Area. Some service providers may process data in the United States under appropriate safeguards, including UK International Data Transfer Agreements and Standard Contractual Clauses.
7. Retention
- Active partner account data: for the duration of your account plus 7 years thereafter, for tax and legal compliance.
- Order and financial records: 7 years from the transaction date.
- WhatsApp message bodies: 13 months, then purged.
- Marketing preferences: until you withdraw consent.
- Support messages: 2 years from the end of the conversation.
8. Your rights
Under UK GDPR you have rights to access your data, correct inaccurate data, erasure (in limited circumstances), restrict processing, data portability, object to processing, and withdraw consent. You can exercise these rights by emailing privacy@ghochen.com.
You have the right to complain to the Information Commissioner’s Office at ico.org.uk.
9. Security
We use technical and organisational measures including encryption in transit and at rest, row-level security on databases, regular security reviews, and staff training. No system is perfectly secure; we will notify you and the ICO of material breaches as required.
10. Changes
We will update this Policy from time to time. Material changes will be notified to you at least 30 days in advance.