Privacy Policy
Last Updated: June 17, 2026
Welcome to the Great British Market (“we,” “our,” or “us”). We are committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our consumer voting engine, or apply to join our trader roster.
Please read this policy carefully. By using our website or submitting your data to us, you acknowledge the collection and use of information in accordance with this policy.
1. Important Information and Who We Are
Data Controller
Great British Market is the data controller and is responsible for your personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Contact Details
If you have any questions about this privacy policy or our data protection practices, please contact us at:
Email: hello@british-markets.co.uk
Address:
Great British Markets
4th Floor, Silverstream House
45 Fitzroy Street, Fitzrovia
London
W1T 6EB GB
2. The Data We Collect About You
We may collect, use, store, and transfer different kinds of personal data about you, which we have grouped together as follows:
For Consumers / Residents:
Identity & Contact Data: First name, last name, and email address.
Geographic Data: Postcode (used via our localized "Launch Voting" landing page to generate regional demand insights).
Marketing & Communications Data: Your preferences in receiving updates about upcoming market launches.
For Prospective and Approved Vendors (Traders):
Business Contact Data: Company name, trading street address, postcode, first name, last name, email address, and mobile phone number.
Brand & Aesthetic Data: Vendor category, core supply ethos, brand biography, website URL, and social media/Instagram handles.
Operational & Technical Data: Setup type, primary cooking fuel source (e.g., LPG), power requirements, and Food Hygiene Ratings.
Compliance & Legal Data: Vehicle profiles, Vehicle Registration Numbers (VRN), registered Local Authority details, Public Liability Insurance (PLI) policy numbers, PLI expiry dates, and uploaded copies of regulatory certificates (PLI, Food Hygiene, PAT Electrical Testing, and Gas Safety certificates).
Financial & Transaction Data: Tokenized payment credentials linked to our payment processors (GoCardless/Stripe Connect) for flat-rate tariff collections and rolling monthly subscriptions.
3. How Your Personal Data Is Collected
We collect data from and about you through:
Direct Interactions: You fill out our online inquiry forms, consumer voting widgets, or multi-step vendor registration funnels (Form 1 and Form 2) natively embedded on our website.
Automated Technologies: As you interact with our website, our Customer Relationship Management (CRM) platform tracking tools may automatically collect technical data about your equipment, browsing actions, and patterns.
Third Parties / Social Media Outreach: Our administrative team may initiate contact with premium brands via Instagram and collect publicly available business data or email addresses provided by you during early outreach.
4. How We Use Your Personal Data
We will only use your personal data when the law allows us to. Most commonly, we use your data in the following circumstances:
Purpose / ActivityType of DataLawful Basis for Processing
For Consumers: Processing localized launch votes to build "Proof of Demand" packages for local councils and landlords.
Identity, Contact, Geographic
Consent (freely given when voting) or Legitimate Interests (to validate local market viability).
For Vendors: Initial vetting, aesthetic evaluation, and communication sequence management via Form 1.
Identity, Contact, Brand & Aesthetic
Legitimate Interests (to curate a premium, non-competing 50-stall marketplace).
For Vendors: Compliance vetting, legal handshakes, regulatory document validation, and pitch allocation via Form 2.
Identity, Contact, Operational, Compliance, Legal
Performance of a Contract or taking steps prior to entering into a trading agreement.
For Vendors: Processing flat-rate tariffs, rolling monthly subscriptions, and concession splits.
Identity, Contact, Financial, Transaction
Performance of a Contract.
5. How Your Data is Stood, Processed, and Shared
To maintain a secure and integrated operational engine, we utilize centralized third-party technology architecture. Your data is strictly managed across the following environments:
HubSpot CRM: Serves as our single source of truth for communications, inbound lead tracking, marketing sequences, and hosted legal documents. All website form submissions route natively straight into HubSpot.
Airtable: Actively used as our internal operational workspace to map layout zones, schedule trading rosters, and structure active vendor categories. Approved data is pushed from HubSpot to Airtable at specific operational milestones.
Merchant Processors: Your payment transactions and tokenized subscription setups are processed securely via GoCardless and Stripe Connect; we do not store raw credit card or bank details on our servers.
International Data Transfers
We utilize a global/local staffing framework. Early lead administration, CRM data entry, data verification, and compliance loops are securely handled by our offshore administrative data-pod based in Manila, Philippines.
To ensure your data receives an identical level of protection as it does within the UK, we enforce strict Standard Contractual Clauses (SCCs) and data processing agreements with our offshore personnel, ensuring full compliance with UK GDPR mandates.
6. Data Retention
We will only retain your personal data for as long as reasonably necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements.
Consumer Voting Data: Retained long enough to compile local authority dossiers and manage regional launch notifications.
Vendor Compliance Documentation: Kept active for the duration of your presence on our master roster and updated annually to verify active Public Liability Insurance and safety logs.
7. Your Legal Rights
Under UK data protection laws, you have rights in relation to your personal data, including the right to:
Request access to your personal data.
Request correction of inaccurate personal data.
Request erasure of your personal data (the "Right to be Forgotten").
Object to processing or request restriction of processing your personal data.
Withdraw consent at any time where we are relying on consent to process your data.
If you wish to exercise any of these rights, please email us at our designated compliance address listed in Section 1.
You also have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK regulator for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO, so please contact us first.