top of page

Privacy Policy

Introduction

This Privacy Policy describes the processing of your personal information by Caravella Fine Food and applies to you, our customers and visitors ('you', 'your'), whenever you use one of our websites (www.caravellafinefood.shop) (the 'Website'), purchase our products or services online or attend one of our events.

We appreciate that there is a lot of information in this Privacy Policy, so we have set it out in sections to help you navigate it more easily and so that you can quickly find relevant information to answer any specific questions you may have. However, if you have any questions which are not answered in this Privacy Policy, please contact us using the details set out in the ‘How to Contact Us’ section at the end of this Privacy Policy.

It is important that you read this Privacy Policy, together with any other notice which we may provide you on specific occasions when we are collecting or processing your personal information, so that you are fully aware of how and why we are using your information, and the legal rights that you have. Where you are sharing your data with us as part of online purchases or bookings, this Privacy Policy should also be read alongside our Terms of Use, which explain how you may use our Website, and our Cookie Policy, which explains the cookies that can be set (subject to your consent) and used by the Website to collect your personal information.

Any changes to this Privacy Policy in the future will be posted on this page, so please check back frequently to see any updates or changes. Where appropriate, we will also notify you of any changes by email, and we will also post a notice on the Website landing page.

What types of personal information do we collect and why?

Under applicable Italian and EU data protection laws we are required to explain what information we collect from you and how and why we use it. This is summarised as follows:

  • Personal Details: including your first name, last name, email address, residential address, telephone number, marital status, title, gender, and date of birth.
     

  • Image Data: including CCTV footage when you visit our stores to ensure that our customers and staff are protected, photographs or video footage when we use film or photography at one of our events, footage from body-worn security cameras (or 'bodycams') where we use these at any of our private events, and details of any user-generated content (e.g., photos that you tag us in on your social media).

Please note: Wherever we capture film or photography at one of our events, we will provide you with a separate information notice to explain your image rights.

  • Transactional Data: including information about any goods and services that you purchase either in-store or online, or events you book to attend, restaurant reservations, details of amount spent, payment card information, bank details and billing information, and details of deliveries and/or returns.
     

  • Technical Device Data: including your IP address, login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system, and other technology on the devices you use to access our guest Wi-Fi or our Websites, including details of the pages you visited on our Websites.
     

  • Profile Data: including information about your interests, your preferences, feedback, and survey responses, and how you redeem any offers and promotions made available to you, how you interact with our Websites and our understanding of your interests and shopping habits, this can come from information you have given to us or which is inferred or derived from our analysis of all the information we hold about you and includes our predictions about your interests. This information allows us to personalise our offers and services for you.
     

  • Communications Data: including your correspondence with us, any feedback that you provide us with and details of your contact and marketing preferences.
     

  • Usage Data: including information such as how and when you use our Websites, details of your search history on our Websites, Website performance statistics, traffic data, and other Website usage data.
     

  • Location Data: including information about your country of residence and GPS data.
     

  • Third Party Data: including personal information about you which we have received from other parties such as our social media and media providers, public registers and any of our third-party service providers and partners.
     

  • Aggregated data: we may also collect, use and share aggregated data or anonymised data for statistics and/or analysis purposes. Aggregated data may be derived from your personal information but is not considered personal information as it does not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific feature on our Websites.

Please note: If we combine or connect aggregated data with your personal information so that it can directly or indirectly identify you, we treat the combined data as personal information which will only be used in accordance with this Privacy Policy.

Sensitive Personal Information

We may also collect and use the following sensitive or special categories of personal information about you:

  • Health Data: including any information about disabilities, accessibility requirements or any food allergies that you provide to us and which we need to accommodate for when you attend any of our events or restaurants, as well as information which relates to particular purchases, and which could infer (or from which we could derive) your health data (e.g., where you buy our diabetic food products); and
     

  • Religious Data: including any information about specific religious dietary requirements you may have that you provide to us and which we need to accommodate for when you attend any of our events or restaurants (e.g., where you require a kosher or halal meal).

How and when do we collect your personal information?

We collect the majority of the personal information that we process about you directly from you, including when you provide this information to us by:

  • Registering on the Website for an online account or otherwise contact us to obtain information relating to us or our products and/or services;
     

  • Placing orders on our Website, in store or by telephone;
     

  • Updating the 'Your Online Account', 'Your Address Book' or 'Your Order Details' section of the Website; and
     

  • Communicating with us by phone, e-mail or otherwise, or when you complete a questionnaire or competition entry form;
     

  • Subscribing to our newsletter, emails or other marketing communications;
     

  • Purchasing goods and services, and other interactions we may have with you in-store;
     

  • Engaging with us on social media, including tagging us in any of your images and entering any of our prize draws;
     

  • Registering for or purchasing tickets to attend one of our events;
     

  • Contacting us by any means (including via email, telephone, Web message, social media, WhatsApp, Apple Business Chat, ChatBot, Trustpilot, Eventbrite and/or SevenRooms) with queries or complaints;

  • Purchasing, registering and/or using one of our E-Gift cards.

We may also collect technical and personal information through the use of cookies when you access and interact with our Website(s) or guest Wi-Fi or which may be contained within emails or direct messages we send to you. For further information on how we use cookies, please see the "Cookies" section below as well as our separate Cookie Policy.

Data relating to Minors

Please note: If you are under 16 years of age, you are not permitted to subscribe to our services or use and/or submit your personal information on our Website(s).

Where we obtain a parent or guardian’s consent, we will collect and process personal information of children under the age of 16 solely for the purpose of managing that child's attendance at seasonal events.
 

We do not knowingly collect personal information about children under the age of 16 for any other purpose, and we will promptly delete such information if we are informed that we hold it.

Information from other sources

We may receive personal information about you from various third parties that we engage with in order to assist us with providing products and/or services to you, including:

  • Our carriers: we may collect delivery and address information from our carriers who deliver products to you;
     

  • Our marketing agents: we may collect marketing information from marketing companies who send customer communications and direct marketing materials on our behalf;
     

  • Our security providers: we may collect security footage and other security information from our third-party security providers;
     

  • Our data analytics providers: we may collect data analytics information from companies that provide us with data analytics services;
     

  • Credit Bureaus: we may collect information on your account, payment and credit history, including information from credit bureaus and service providers we use to process payments; and
     

  • Our other third-party providers: we may collect and share information with other third-party providers who provide support and services to us, or in relation to whom we are engaged, including social media providers, media providers, search engines and data analytics or advertising intermediaries who may collect data direct from their own cookies and websites.

Please note: If you provide us with personal information about another person (e.g., when you enter gift recipient delivery details on our Website), you must ensure that before you provide us with their personal information, you have their agreement to do so and that they are aware of the ways in which we use personal information as set out in this Privacy Policy.

Legal basis for processing personal information

By law, whenever we process your personal information, we are required to have a ‘legal basis’ for doing so. The legal bases we use to process your personal information will generally be one or more of the following:

  • Contractual necessity: where it is necessary to enable us to comply with our contractual obligations to supply you with the products and/or services you want;
     

  • Legitimate interests: where it is necessary for our legitimate business interests in administering our relationship with you and running our business effectively. Where 'legitimate interests' is our legal basis for processing your data, we will take into account any potential impact on your rights, freedoms, and interests;
     

  • Legal compliance: where it is necessary for us to process your personal information to enable us to comply with a legal or regulatory obligation; and/or
     

  • Consent: where we have asked for and gained your consent to use your information for particular purposes, for example, to send you marketing communications, or information related to your child (only for the purposes of attending seasonal events). We will also rely on your explicit consent wherever we need to process your sensitive personal information (such as Health Data or Religious Data).

Withdrawing consent

Where consent is our legal basis for processing your personal information, you can withdraw your consent at any time, and we will then stop any future processing for that purpose. If you wish to withdraw your consent, then please contact us using the details set out in the ‘How to Contact Us’ section at the end of this Privacy Policy.
 

Please note: If you choose not to share your personal information with us, or refuse certain contact permissions, we may be unable to provide some of the products and services you've asked for. For example, if you fail to provide us with your full address, it would not be possible for us to fulfil your delivery, or if you failed to provide us with your payment card details then we will not be able to process your payment.

Our purposes for using your personal information

There are many ways we will need to use your personal information in the context of your relationship with us. We have set out the main purposes in the tables below and we have indicated the main applicable legal bases of processing. In some cases, more than one legal basis may apply to our use of your personal information and there may be other specific uses which are linked to or covered by the purposes set out below.
 

If you would like further information on the specific legal bases which we rely on in relation to any of the processing purposes we have set out below, please contact us using the details set out in the ‘How to Contact Us’ section below.

Shopping and Retail Purposes

Purpose for Processing - Legal basis

  • To register and maintain your customer account on our Websites - Contract Necessity

  • To fulfil your orders (including order delivery and processing payments) - Contract Necessity

  • To send you emails about outstanding E-Gift card balances - Legitimate Interests: To keep you up to date with your balances

  • To send you email reminders when you shop on our Websites and then abandon your online shopping bag before completing your checkout - Consent or Legitimate Interests: Where you are an existing customer, we rely on our legitimate interests to increase our customer engagement

  • To send you service messages about your order or updates regarding delivery of your order - Legitimate Interests: To contact you whenever we need to and provide you with relevant service information

  • To enrich our picture of who you are and what you like, and to inform our business decisions. For this purpose, we will combine data captured from across our business, including from third parties and publicly available information.Consent where data is captured by way of cookies or you have positively opted in to sharing data for marketing purposes; and/or Legitimate Interests: In relation to data we otherwise capture across our business and from third parties which we use to tailor your experience as one of our customers

  • To improve the products we offer in-store and on our WebsitesConsent where data is captured by way of cookies or you have positively opted in to sharing data for marketing purposes; and/or Legitimate Interests: In relation to data we otherwise capture across our business and use to ensure our products are of the highest quality for our customers

  • To personalise your customer experience on our Websites. For this purpose, we use Cookies and similar technologies. For more information about how we use Cookies, please see our Cookie Policy.Consent where data is captured by way of cookies which require you to positively opted in; and/or Legitimate Interests: In relation to data we otherwise capture across our business and use to tailor your customer experience

Events, Hospitality and Personalised Service Purposes

Purpose for Processing - Legal Basis

  • To allow you to register to attend one of our events - Legitimate Interests: To manage your registration or booking

  • To send you email reminders about any upcoming events or bookings - Legitimate Interests: To provide you with relevant service information about your registration or booking

  • To respond to any enquiries and/or complaints at any of our events - Legitimate Interests: To manage our relationship with you and ensure that we are able to support you with any queries or complaints

  • To monitor your attendance at any of our events so that we can enrich our picture of who you are and what you like. For this purpose, we will combine data captured from across our business, including from third parties and publicly available information. Consent where data is captured by way of cookies or you have positively opted in to sharing data for marketing purposes; and/or Legitimate Interests: In relation to data we otherwise capture across our business and use to help us build your customer profile and manage our relationship with you

  • To improve the hospitality and events services we offer - Legitimate Interests: To ensure our services are of the highest quality for our customers

  • To accommodate any dietary preferences (including food allergies and religious requirements) and any other accessibility requirements you may have when attending one of our events or restaurants. For this purpose, we will (where applicable) process certain sensitive personal information about you, including Health Data and/or Religious DataConsent (wherever we process your Health Data or Religious Data). Legitimate Interests: To ensure that we are able to accommodate any specific health-related or religious requirements our customers may have prior to attending one of our events or restaurants

  • To provide our personal shopper and/or concierge services - Consent where you have expressly asked us to provide service, Contract Necessity where the processing relates to any purchase you have made; and/or Legitimate Interests: Where we process your data to tailor your experience and provide a bespoke personal shopper and/or concierge service

Marketing (including Social Media) Purposes

Purpose for Processing - Legal Basis

  • To send you marketing emails about our products, services and any ongoing or upcoming promotional offers or events that we think may be of interest to you - Consent where data is captured by way of cookies or you have positively opted in to sharing data for marketing purposes; and/or Legitimate Interests: Where you are an existing customer, we also rely on our legitimate interests to increase our customer engagement

  • To send you any postal marketing materials about our products, services and any ongoing or upcoming promotional offers or events that we think may be of interest to you - Legitimate Interests: To increase our customer engagement and boost our target audiences

  • To improve our marketing communications and enrich our picture of who you are and what your preferences are. For this purpose, we use Cookies and similar technologies for data analytics purposes. For more information about how we use Cookies, please see our Cookie Policy.Consent where we collect Technical Device Data via cookies, we do this on the basis of your consent, or in the case of Essential Cookies, on the basis of our legitimate interests in order to operate the site and ensure its security. Legitimate Interests: To offer you the most tailored and bespoke customer experience

  • To select and serve relevant adverts to you and/or to serve relevant ads to our target audiences which may also include you. For this purpose, your personal information is anonymised beforehand and may be aggregated. Consent where data is captured by way of cookies or you have positively opted in to sharing data for marketing purposes; and/or Legitimate Interests: Otherwise where we process your data to serve adverts which do not require express consent (e.g. adverts displayed on websites or in a general feed on social media) to offer you the most tailored and bespoke customer experience

 

  • To enable our third-party marketing partners to send marketing communications on our behalf - Consent where data is captured by way of cookies or you have positively opted in to sharing data for marketing purposes; and/or Legitimate Interests: Otherwise, where we process your data to ensure that our products and services are appropriate and delivered in a timely fashion

  • To allow you to update and manage your contact and marketing preferences - Consent where data is captured by way of cookies or you have positively opted in to sharing data for marketing purposes; and/or Legitimate Interests: Otherwise where we process your data to ensure that you have control over your own contact and marketing preferences

  • To optimise our social media operations and target specific customer engagement. For this purpose, we use Meta (Facebook and Instagram), TikTok and Pinterest in relation to targeted and 'Lookalike' audiences, and programmatic behavioural advertising to help us build a customer profile - Consent where data is captured by way of cookies or you have positively opted in to sharing data for marketing purposes; and/or Legitimate Interests: Otherwise where we process your data to allow us to create a more tailored and bespoke customer experience

 

  • To allow you to enter any of our prize draws or competitions - Consent where data is captured by way of cookies or you have positively opted in to sharing data for marketing purposes; and/or Legitimate Interests: Otherwise where we process your data to manage the prize draw or competition and for our internal business purposes

 

  • To seed organic social media content, to buy relevant ad space, to provide social media customer service support (e.g., answering DMs and comments) and for community management purposes (e.g., answering comments and posting comments across our relevant special media content) - Legitimate Interests: To build and develop our brand

 

  • To carry out data matching and analytics in respect of data obtained from third-parties (such as our third-party advertisers). For this purpose, your personal information will be anonymised - Consent where data is captured by way of cookies or you have positively opted in to sharing data for marketing purposes; and/or Legitimate Interests: Otherwise where we process data to build and develop our targeted advertising campaigns

  • To carry out data matching and analytics of the success of our marketing campaigns - Consent where data is captured by way of cookies or you have positively opted in to sharing data for marketing purposes; and/or Legitimate Interests: Otherwise where we process data to build and develop our brand and marketing campaigns across all channels

  • To interact with and monitor any user-generated content. To the extent that you tag F&M products, services or sites in your user-generated content, we will obtain your consentConsent where data is captured by way of cookies or you have positively opted in to sharing data for marketing purposes; and/or Legitimate Interests: Otherwise where we process data to build and develop our brand and engagement with our customers

General Purposes

Purpose for Processing - Legal Basis

To respond to any enquiries and/or complaints, whether in-store or online - Legitimate Interests: To manage our relationship with you and ensure that we are able to support you with any queries or complaints

 

To update our records and maintain any online account you may have with us - Legitimate Interests: To ensure that we have accurate and up to date information.

To administer and protect our business and this site, including to prevent or detect fraud or abuses of our Websites and safeguarding your personal and financial dataLegal Compliance where the activity is to ensure we meet our legal obligations and prevent or detect fraud. Contract Necessity where we process data to ensure appropriate steps are taken to meet the terms in our contract with you, including payment of taxes or otherwise Legitimate Interests: Otherwise to protect our business and customers

To comply with our financial record keeping obligations - Legal Compliance as applicable where we have a legal duty to meet; or Legitimate Interests: where we otherwise process data to ensure that we are compliant with our legal obligations

To protect our customers, premises, assets and partners from crime. For this purpose, we use CCTV and other security measures (such as security guards and bodycams) at our events and on our premises. Wherever we use CCTV for this purpose, we will provide appropriate signage to inform you that this is the case. Legal Compliance as applicable where we have a legal duty to meet; or Legitimate Interests: Where we otherwise process data to ensure the security of our premises, our staff and our customers

To develop, test, maintain and improve our systems and Websites - Legitimate Interests: To ensure that our systems and Websites are secure and reliable

 

To comply with our legal obligations (where applicable) to share personal information with law enforcement and/or government bodiesLegal Compliance as applicable where we have a legal duty to meet

 

To enable our third-party service providers to carry out technical, logistical, or other functions on our behalfLegitimate Interests: To ensure that our products and services are appropriate and (where applicable) delivered in a timely fashion

 

To anonymise and aggregate your personal information for our own data analytics purposesLegitimate Interests: To allow us to make improvements to our products and services

 

To provide you with access to our [membership/loyalty/reward] schemeLegitimate Interests: To develop our relationship with our members and customers

Legitimate Interests

Where required under applicable data protection laws, we have determined, acting reasonably and considering the circumstances, that we are able to rely on legitimate interests as the lawful basis on which to process your personal information in certain circumstances (as set out in the tables above).
 

We have reached this decision by carrying out a balancing exercise to make sure our legitimate interest is not overridden by your privacy rights as an individual, and we consider that it is reasonable for us to process your information for the purposes of our legitimate interests as:
 

  • We process your personal information only so far as is necessary for such purpose; and
     

  • It can be reasonably expected for us to process your personal information in this way.

bottom of page