This Privacy Policy explains what personal data Shaku Maku Catering Ltd ("we", "us") collects, why we collect it, how it is used, and your rights under the GDPR. We are the data controller for the personal data described below.
1. Contact
- Controller: Shaku Maku Catering Ltd, Ireland
- General enquiries: info@shakumaku.ie
- Data Protection enquiries: privacy@shakumaku.ie
- Supervisory authority: Irish Data Protection Commission, dataprotection.ie
2. What personal data we collect
| Category | Examples | Source |
|---|---|---|
| Identity & contact | Name, email, phone, billing/delivery address, company | You, at ordering or account registration |
| Order & transaction | Items ordered, event date, guest count, special requests, payment status, partial deposits, payment reference | You / automatically during checkout |
| Payment data | Card details are processed directly by Stripe or Revolut; we do not store card numbers. We store a tokenised reference to the payment only. | Stripe / Revolut |
| Account credentials | Hashed password, two-factor authentication secret (corporate accounts) | You, at registration |
| Usage & device | IP address, browser type, pages visited, timestamps, approximate geolocation derived from IP | Automatically via cookies & server logs |
| Communications | Emails, support tickets, phone-call notes | You, when you contact us |
| Security logs | Login attempts, failed logins, admin actions, deposit-terms acceptance records | Automatically, for fraud prevention & audit |
3. Why we process your data (purposes & legal bases)
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Processing and delivering your order; communicating about it | Contract — Art. 6(1)(b) |
| Processing payments; fraud prevention; chargeback handling | Contract & Legitimate interest — Art. 6(1)(b)&(f) |
| Keeping accounting records, issuing invoices/receipts | Legal obligation — Art. 6(1)(c) (Irish Revenue) |
| Maintaining your corporate portal account and authentication | Contract & Legitimate interest |
| Operating the website, analytics, and site security | Legitimate interest in running a safe & functional website |
| Marketing emails (where you have opted in) | Consent — Art. 6(1)(a); withdrawable at any time |
| Recording your acceptance of deposit terms (timestamp, IP, agreement version) | Legitimate interest in enforcing contractual agreements |
4. Who we share data with (processors & recipients)
We share the minimum personal data needed with trusted processors who act only on our written instructions and under data-processing agreements compliant with Art. 28 GDPR:
- Stripe, Inc. and Revolut Ltd — payment processing
- Our SMTP email provider — transactional emails (order confirmations, receipts, password resets)
- MongoDB Atlas / equivalent hosting provider — secure data storage within the EEA
- Google — where you use Google Calendar sync for events (controller-to-controller)
- Accountants and auditors — for statutory accounting obligations
- Regulatory & law-enforcement bodies — only where legally required
5. International transfers
Where a processor (e.g. Stripe) is based outside the European Economic Area, transfers are protected by the EU Commission's Standard Contractual Clauses and, where relevant, supplementary measures required under the Schrems II judgment.
6. Data retention
| Data | Retention period |
|---|---|
| Order records & invoices | 6 years after the order (Irish accounting / Revenue requirements) |
| Corporate account data | While your account is active + 2 years after last activity |
| Support enquiries | 2 years |
| Website visit logs | 24 months, then auto-purged |
| Failed login attempts | 48 hours (auto-purged by index TTL) |
| Deposit-terms acceptance record | 7 years for legal/audit purposes |
| Marketing consent | Until you withdraw consent, then deleted within 30 days |
7. Your rights
Under GDPR you have the rights summarised below. To exercise them, email privacy@shakumaku.ie. We respond within 30 days (up to 90 days for complex requests).
- Access a copy of the personal data we hold about you (Art. 15)
- Rectification of inaccurate data (Art. 16)
- Erasure ("right to be forgotten") where no overriding legal basis applies (Art. 17)
- Restriction of processing in defined circumstances (Art. 18)
- Portability — receive your data in a structured machine-readable format (Art. 20)
- Object to processing based on legitimate interests or direct marketing (Art. 21)
- Withdraw consent at any time where processing is based on consent (Art. 7(3))
- Lodge a complaint with the Data Protection Commission (dataprotection.ie)
For a full walkthrough of how to exercise each right, see our GDPR & Your Data Rights page.
8. Security
We apply industry-standard measures: TLS encryption in transit, hashed passwords (bcrypt), JWT-based session tokens with refresh-token rotation, brute-force rate-limiting, role-based access controls, and audit logs for all admin actions. Despite this, no system is perfectly secure. Promptly notify us of any suspected compromise.
9. Cookies
We use a limited set of cookies. See our Cookie Policy for details and manage your preferences there.
10. Children
Our services are not directed at children. We do not knowingly collect personal data from anyone under 16.
11. Changes to this policy
Material changes will be highlighted on the Website for at least 30 days. The "Last updated" date at the top shows the current version.