Last updated 8 September 2026
What we collect, why we use it, who else sees it, how long we keep it, and the rights you have over it under UK GDPR. Written to be read, not to be survived.
This summary is a courtesy, not the document. Where the two differ, the numbered sections below govern.
GetScran is a platform for independent UK food and grocery shops — their till, their ordering website, their app, their kitchen screens and their delivery run. It is operated by Aliao Group Limited, a company registered in the United Kingdom, company number [to confirm], registered office [to confirm].
We are registered with the Information Commissioner's Office under registration number [to confirm].
This notice covers:
Each shop also publishes its own privacy notice on its ordering site, naming its own company. Where the two cover the same thing, the shop’s notice governs what the shop does and this one governs what we do.
The law separates the organisation that decides why and how personal data is used (the controller) from one that handles it on the controller’s behalf (the processor). Both roles apply here, and which one we are depends on the data. This is the most important thing on the page, so it is stated plainly:
Anything on this page — including a request to see, correct or delete your data — goes to privacy@getscran.com. For anything about an order, support@getscran.com reaches a real person, and the shop you ordered from can usually sort it fastest.
Unhappy with how we handled it? You can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you came to us first, but you never have to.
The rest of the set
Shop owners are also covered by a separate merchant agreement, which includes the data-processing terms we sign with every shop. Ask us for a copy.
Aliao Group Limited, a company registered in the United Kingdom, company number [to confirm], registered office [to confirm].
Different people meet GetScran in different places and give up very different amounts of information. This is the honest list.
If you order online or in an app with an account. Your name, mobile number and/or email; your delivery addresses (including the map pin you drop); what you ordered, when, from which shop, for how much, and any note you left for the kitchen; your loyalty balance and card number; your marketing choices; your reviews; the device you use, so we can send you order updates.
If you tell us about allergies. Your saved allergen and dietary preferences are health data — the law treats it as a special category and so do we. You give it voluntarily to keep yourself safe, we use it for nothing else, and you can clear it at any time from your account.
If you order age-restricted items. Your year of birth — not your full date of birth. That is the minimum that answers the question, so it is all we ask for. If a driver checks ID at the door, we record the fact that ID was checked, never the document.
If you order at a kiosk or over the counter. Normally nothing — there is no account and no sign-in. If staff park your basket while you wait, they may note the name you gave and any allergy you mentioned, so the kitchen gets it right.
If you order through WhatsApp. Your WhatsApp number, the branch you picked and where you are up to in the conversation. The messages themselves travel through WhatsApp (Meta) and are subject to their terms as well as ours.
If you order through Just Eat, Uber Eats or Deliveroo. Those apps are the controller for your account with them. What reaches the shop through us is the order: the name, contact details and address they pass on, and the items.
If you phone the shop. See sections 7 and 8 — caller recognition and, where the shop uses it, an AI phone assistant.
If you drive for a shop. Your name, phone, vehicle details, your shifts, your GPS position while you are on shift, the drops you completed, cash you collected and any issues you raised. See section 9.
If you work in a shop. Your name, role, login, your clock-in and clock-out PIN (stored only as a one-way hash — nobody, including us, can read it back), your shifts, cash-ups, tips allocated to you, and a record of actions like voids and refunds. Your employer is the controller for this; we hold it for them.
If you run a shop. Your business details — company name and number, VAT number, registered address, contacts, bank and payment-provider identifiers, plan, invoices and payouts.
If you just visit a website. A count that a page or a product was viewed, and the technical basics any web server sees. See our cookie notice for exactly what is stored on your device.
We do not use CCTV, we do not profile you for advertising, and we do not buy personal data from anybody.
UK GDPR makes us name a lawful basis for every use. Here they are, in the same words the law uses.
| What we do | Why | Lawful basis |
|---|---|---|
| Take, price, cook and deliver your order | You asked us to | Performance of a contract |
| Your account, sign-in codes and order history | So you do not retype everything and can find past orders | Performance of a contract |
| Allergen preferences | So we can warn you before you order something unsafe | Your explicit consent (special-category data) |
| Loyalty points and rewards | You joined the scheme | Performance of a contract |
| Age checks on alcohol, tobacco, vapes and lottery | Licensing law requires it | Legal obligation |
| Keeping order, payment, VAT and commission records | HMRC requires six years of accounting records | Legal obligation |
| Marketing texts, emails, push and WhatsApp messages | To tell you about offers from a shop you have used | Your consent, per channel |
| Recognising your number when you ring the shop | So the counter can greet you and pull up your usual address | Legitimate interests |
| Fraud prevention, rate limits, security and audit logs | To keep accounts and shop takings safe | Legitimate interests, and our security duty |
| Counting page and product views | To see which menu items people look at | Legitimate interests |
| Driver location while on shift, and delivery records | Live tracking, ETAs, proof of delivery, allocating the next drop | Legitimate interests of the shop |
| AI insights built from a shop’s own daily figures | To help a shop staff and prep for the day ahead | Legitimate interests |
Where we rely on legitimate interests we have weighed our interest against yours, and you can object at any time (section 15). Where we rely on consent you can withdraw it at any time, and withdrawing it never affects anything done before you did.
Loyalty is per shop, or per group of shops. If you join a franchise’s scheme — a chain with several branches under one brand — your customer record and your points are deliberately shared across every branch of that group, because that is the point of it: earn at one branch, spend at another.
What that means in practice, said out loud:
If you delete your account, any remaining points are forfeited — they are a reward, not money, and we cannot pay them out.
Under the Privacy and Electronic Communications Regulations we only send marketing texts, emails, push notifications or WhatsApp messages where you have agreed to that channel. Consent is recorded per channel and is off by default — an account starts with every marketing channel switched off until you turn one on.
Order updates are not marketing. “Your order is being cooked”, “the driver is on the way”, a receipt, or a code to sign in — those are part of the service you asked for and they keep coming while you have an open order.
One thing we want to be straight about. After you have ordered, a shop may ask you to leave a review, by text or email. Today that ask is not gated on your marketing consent, and it should be. We are changing it so that a review request follows the same opt-out you set for everything else. Until then, replying STOP or telling the shop stops it, and we would rather tell you than let you find out.
Many shops have a desk phone wired into their till. When it rings, the phone tells the till the caller’s number, and the till looks that number up in that shop’s own customer book so the person answering can say “Hi Sarah — same address?” instead of taking it all down again.
Precisely what happens, and nothing more:
We rely on legitimate interests for this: recognising an existing customer who has chosen to ring a shop they already use is what any good counter does from memory, and it is what you would expect. Tell the shop, or email us, if you would rather it did not.
Some shops let an AI assistant answer the phone when nobody can get to it — it takes the order, answers questions about the menu, and hands over to a person when it is out of its depth. If a shop uses it, you are told at the start of the call that you are speaking to an automated assistant.
The assistant is provided by ElevenLabs and the phone number by Twilio; both are listed in section 11.
What a driver sees about you. For a drop they are carrying: your name, address, phone number and any delivery note. That is how the food reaches your door.
And when they stop seeing it. Those four things are visible to a driver for the trading day of the delivery only. When the day rolls over they are gone from the driver’s app — and gone from what our servers will send it, so it is not a matter of the app being polite about hiding them. A shift’s worth of doorsteps does not sit in somebody’s personal phone forever. What a driver keeps is the non-personal record they need to check they were paid correctly: the shop, the time, the order code, the amount.
Driver location. While a driver is on shift the app reports their position, so the shop can see the run and you can see the map. Raw position pings are deleted after 7 days. The position where a delivery was completed is kept for 13 months as the delivery record — and a deletion request from you outranks that.
If you share your exact location to help a driver find you, that position is yours and is deleted with the rest of the delivery’s location data.
Third-party couriers. Where a shop uses Stuart, Uber Direct or Deliveroo’s courier network instead of its own driver, your name, address, phone and delivery note are passed to that network so it can make the drop.
Drivers’ own data. We keep a score for each driver used only to break a tie when allocating the next run and to set how many drops they can hold at once. It is written into our system, in as many words, that it is not a performance record, not evidence in a disciplinary, and that nothing may make pay depend on it — any consequence beyond allocation is a human decision with a written reason. A cash tip handed to a driver at the door is the driver’s own and is never shown to the shop.
We use AI in a handful of places. All of them assist a person; none decides anything about you.
We make no solely automated decision that produces a legal effect for you, or anything similarly significant. No AI refuses your order, sets your price, closes your account, decides a refund, or scores you as a customer. Where a score does exist — for drivers — its only permitted effect is allocating the next run, and anything beyond that is a human decision with a written reason. If you ever think an automated step got something wrong, email us and a person will look at it.
Our servers and database are in the UK and the EU. Some of the suppliers above are based in the United States, so a limited amount of data reaches them — for example a phone number to send a text, or the words of a phone call to produce a transcript.
Where that happens we rely on the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with each supplier’s own technical protections. You can ask us for a copy of the safeguards for any particular supplier.
We do not keep things “just in case”. Every table in our database is on a list that either gives it a deletion window or records, in writing, why it is kept — and the build fails if somebody adds a new one and does not decide. These are the windows that matter to you:
| What | How long | Why |
|---|---|---|
| Order, payment, VAT and commission records | 6 years | HMRC requires it. Your name and contact details are removed if you ask us to erase you — the money record stays, the identity does not |
| Your account, addresses, loyalty | Until you delete it, or ask us to | It is yours |
| AI phone call transcripts | 180 days | Long enough to settle a dispute about an order |
| Caller recognition records | 24 hours | Only useful while the phone is ringing |
| Raw driver GPS pings | 7 days | Cleared nightly |
| Delivered position (proof of delivery) | 13 months | Delivery disputes |
| Gift card recipient details | 30 days after the card is sent | They never signed up with us |
| Page and product view counts | 90 days raw, then daily totals only | Anonymous product interest |
| Security and audit logs | 12 months | Proving who did what, including any deletion you ask for |
| Sign-in codes, magic links, sessions | Until they expire | Dead the moment they expire |
| Tips allocation records | 3 years | Employment (Allocation of Tips) Act 2024 |
Under UK GDPR you can:
All of these are free, and we answer within one calendar month.
In your account, immediately:Account → Marketing & privacy. You can download your data, change every marketing choice, and delete your account from that screen without asking anybody.
By email: privacy@getscran.com, from the address or number on your account where you can. If we cannot tell it is you we will ask one question to check — we are not going to hand your order history to somebody who typed your name.
Through the shop: where a shop is the controller you can go to the shop or come to us. Either way it gets dealt with; we will not bounce you between us.
For a franchise group — a chain with several branches — a request about the shared record is actioned by head office, for the whole group at once.
You must be 16 or over to hold a GetScran account. The service is not designed or marketed for children, and we do not knowingly collect data from a child. If you believe a child has an account, tell us and we will delete it.
Ordering at a counter or a kiosk creates no account and asks for nothing about you. Age-restricted items are refused to anyone who cannot prove they are 25 or over — see our terms.
If something does go wrong and it is likely to be a risk to you, we will tell the ICO within 72 hours and tell you without undue delay.
Come to us first — privacy@getscran.com — and we will try to put it right.
You can complain to the Information Commissioner's Office at any time, and you never have to come to us first: ico.org.uk, or 0303 123 1113. Where a shop is the controller, the complaint can be made about the shop, about us, or about both.
When this notice changes we update the “Last updated” date at the top. If a change materially affects how your data is used, we will tell you — by email or in the app — rather than quietly editing the page and hoping you look.