Last Updated: 22 June 2026
This Privacy Policy applies to all personal data collected and processed by London Fox Ltd (trading as Cacao Route Chocolates) via safe internal database storage mechanisms, our website infrastructure, client account ecosystems, and transaction modules. Please read it carefully.
Who We Are
This Privacy Policy is provided by London Fox Ltd, a company registered in England and Wales, trading as Cacao Route Chocolates. Our registered address is 30 High Street, Walton-on-Thames, Surrey, KT12 1BZ.
London Fox Ltd is the data controller for the personal information we collect about you. This means we determine the purposes and means by which your personal data is processed. As data controller, we are responsible for ensuring your data is handled lawfully, fairly, and transparently in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
If you have any questions about how we handle your personal data, please contact us at info@cacaoroute.co.uk.
Summary: London Fox Ltd (Cacao Route) is the data controller for your personal information. We are committed to protecting your privacy and complying fully with UK data protection law.
What Data We Collect
We collect and securely store different categories of personal data in our centralised internal databases depending on how you interact with our forms, account options, and transaction modules. Below is a detailed mapping of the datasets we process.
Identity & Contact Data
- First name and last name
- Email address
- Phone number
- Postal address (for delivery, correspondence, and billing records)
- Company name, registration numbers, and operational details (for wholesale inquiries and trade account applications)
- Instagram or social media handle (where voluntarily provided)
Account & Profile Data
- Unique customer credentials (encrypted usernames and security passwords)
- Profile preferences, saved delivery routes, and custom interface configurations
- Trade account application details and validation logs
- Administrative event activity logs (for tracking authorized team interventions and site integrity checks via our admin panel)
Transaction & Order Data
- Granular details of custom orders, wholesale supply inquiries, and specialized menu requirements
- Order quantities, product selection history, fulfillment timelines, and logistical confirmations
- Payment processing tokens, gateway logs, and settlement status (full credit/debit numbers are routed straight to our secure tokenized payment gateway partner)
- Invoice records and financial ledger balances matching trade account profiles
Communication Data
- Messages and payloads submitted through contact forms, trade applications, or wholesale inquiry modules
- Systemic email communications (such as automated trade approval notifications, dispatch confirmations, and billing receipts)
- Direct email threads with our helpdesk team
- Newsletter preference configurations
Technical & Usage Data
- IP address, browser version matrix, and dynamic session tokens
- Interactive clickstreams, behavioral timings, and journey points across our site infrastructure
- Referring parameters or query links utilized to arrive at our domain
- Device metadata profiles and operating system footprints
- Associated cookie tokens (see Section 10)
Special Categories of Data
We may process health-related dietary parameters or ingredient sensitivities (e.g., specific nut allergen constraints or lifestyle preferences) explicitly submitted by you when customizing order files. This metadata is classified as sensitive personal data under UK GDPR and is stored exclusively to execute your product preparation parameters safely.
How We Collect Your Data
Your personal details enter our computing workflows using several ingestion channels:
Directly from You
- When you submit general contact forms, wholesale supply inquiries, or trade account registration structures
- When you configure a secure client profile or access our portal environment using account credentials
- When you commit transaction details or order parameters through our point-of-sale or digital systems
- When you sign up for periodic newsletters or opt-in messaging lists
- When you interact with our promotional sweeps or seasonal event pipelines
- When you coordinate with our team directly via email channels, digital channels, or in-store counters
Automatically Through Site Interactions
- When navigating our domain, dynamic session cookies and telemetry trackers index your browser footprint (see Section 10)
- Server infrastructure logs document entry vectors, validation checkpoints, and system response parameters
From Trusted Infrastructure Partners
- Our PCI-compliant payment gateway provider transfers tokenized confirmation files, transaction identifiers, and processing status updates
- Analytics engines feed back aggregate, non-identifiable usage statistics regarding traffic behavior and layout utility
How We Use Your Data
Data stored in our core database environments is processed strictly to manage core operational actions, communication trees, and legal validations.
| Operational Purpose | Underlying Data Utilized |
|---|---|
| Fulfilling orders, wholesale requests, and specialized menus | Identity, contact, transaction profiles, dynamic dietary metrics |
| Validating, provisioning, and maintaining wholesale trade account applications | Identity, organizational parameters, transactional data, application records |
| Managing secure customer profiles, login modules, and identity checks | Identity credentials, access logs, account configurations |
| Processing secure transactions via our encrypted payment gateway | Transaction indexes, billing parameters, gateway tokens |
| Routing dynamic notifications (trade approvals, order confirmations, payment receipts) | Identity, contact parameters, transaction profiles, communication flags |
| Managing platform integrity, security, and updates via the corporate admin panel | Technical identifiers, identity profiles, dynamic administrative audit trails |
| Addressing contact submissions, feedback, and customer assistance responses | Identity markers, contact variables, communication payloads |
| Issuing promotional updates and newsletter campaigns (subject to clear opt-in consent) | Identity markers, electronic communication targets, preference logs |
| Executing legal, corporate, tax, and regulatory compliance protocols | Identity details, complete purchase footprints, billing logs |
We do not sell your personal data. All collected information resides safely on secure database systems. We do not distribute your records to third parties for independent commercial marketing actions, nor do we run automated automated decision-making engines or profile vectors with legal impacts.
Legal Basis for Processing
Under UK GDPR framework parameters, we operate under defined lawful bases to log and handle your data parameters within our server databases:
Contractual Necessity
Processing is required to honor contract commitments or evaluate onboarding parameters initiated by you. This includes setting up your wholesale portal profile, executing bulk supply requests, processing payments through our gateway, or verifying incoming trade applications.
Legitimate Interests
Processing supports core business management operations that do not conflict with your baseline privacy freedoms. This applies to utilizing an administrator panel to secure the site, logging technical operational trends, protecting data streams from fraudulent exploits, and coordinating customer service inquiries.
Explicit Consent
Processing occurs because you provided a specific, unambiguous directive—most notably when clicking newsletter opt-in elements or acknowledging optional tracking scripts. You hold an absolute right to cancel this consent instantly via built-in opt-out handles or direct email contact.
Legal Mandates
Processing is required to comply with binding statutes, such as retaining historical sales ledgers, transaction records, and invoice configurations to fulfill HMRC audit rules across the United Kingdom.
Who We Share Your Data With
We restrict data exposure to specific framework components necessary to keep our workflows active. We execute strict data processing protocols with the following entities:
Service Providers & Core Integrated Systems
- Payment Gateway Infrastructure Partner (Stripe Inc.) — Manages all tokenized credit/debit card checks directly. Our databases never hold raw card details; information passes via secure, encrypted routing directly to the payment gateway.
- Database & Hosting Providers — Secure server infrastructure that acts as the primary repository for customer accounts, form records, and purchase details.
- Transactional Email Ingestion Engines — Automatically transmits service updates, including account validations, order summaries, and payment alerts.
- Logistical Fulfillment Teams — Coordinates distribution actions by mapping delivery paths and routing consignments to your preferred destination.
- Google Analytics Infrastructure — Evaluates anonymized behavioral data to improve layout components and minimize navigation friction.
Regulatory Disclosures
We may share operational information with HMRC, judicial offices, or government inspectors when compelled by statutory legal processes or to protect corporate safety assets.
Corporate Transitions
If London Fox Ltd participates in an asset transfer, merger, or restructuring process, database assets containing user records may transition to the succeeding management group under strict privacy preservation terms. You will receive an alert before any such ownership change occurs.
Contractual Mandates: All processing vendors working with us are strictly prohibited from using your data for alternative purposes. They must process information solely according to our directives and match UK data protection standards.
International Data Transfers
Select infrastructure elements—including payment processing modules and telemetry clusters—are managed by global tech vendors and may store records outside the United Kingdom. Whenever data travels beyond UK borders, we guarantee compliant safeguards:
- The recipient territory holds an active adequacy decision issued by the relevant UK authorities.
- Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum are executed within our vendor contracts.
- Approved data protection frameworks and technical encryption layers are implemented at every stage.
To request details regarding active cross-border data transfer tools, contact us at info@cacaoroute.co.uk.
How Long We Keep Your Data
Records are retained within our database clusters only for the timeframe necessary to satisfy operational requests, resolve complaints, or meet statutory financial laws. Our data retention policy follows these periods:
| Database Record Type | Retention Duration | Governing Legal/Operational Directive |
|---|---|---|
| Transaction ledgers, payment tokens, and invoice files | 7 Years | HMRC Corporate Tax Compliance Mandate |
| Wholesale trade accounts and profile credentials | 7 Years post account closure | Contractual tracking and liability preservation |
| Contact form entries and wholesale inquiry payloads | 3 Years from submission | Operational history and quality control auditing |
| Administrative panel logs and configuration records | 2 Years | Platform security auditing and access verification |
| Newsletter contact subscriptions | Active until opt-out received | Consent-driven communication model |
| Telemetry analytics strings and behavioral paths | 26 Months | Standard framework analysis constraints |
| Cookie authorization configurations | 12 Months | Consent framework tracking standards |
Once retention thresholds expire, records are permanently dropped from database storage or stripped of identifying metrics using secure data erasure techniques.
Your Rights
Under the UK GDPR framework, you hold strong legal protections concerning how your data is handled. To request an adjustment or exercise any of these options, contact our team at info@cacaoroute.co.uk. We resolve verified requests within 30 days without charge.
Right of Access
You can request an export of all information linked to your identity stored in our databases, alongside details on how that data is used.
Right to Rectification
You can update incomplete contact entries, address variations, or profile options stored across our active database systems.
Right to Erasure
You can request the permanent removal of your account, form details, and interaction logs from our databases, provided there are no overriding legal retention requirements.
Right to Restrict Processing
You can pause active data processing workflows—such as during identity validation disputes—while keeping the underlying data stored in an un-editable state.
Right to Data Portability
You can request a clean, machine-readable format of your personal profile details to transfer your records to alternative software platforms.
Right to Object
You can object to data processing handled under legitimate interest arguments or halt automated marketing workflows instantly.
Right to Withdraw Consent
You can revoke previously granted processing approvals at any time. This action will not retroactively invalidate processing that occurred prior to the withdrawal.
Right to Complain
You have the right to lodge a formal grievance with the Information Commissioner's Office (ICO) at ico.org.uk if you believe our data processing breaches your legal rights.
To invoke your rights, submit an email with the subject "UK GDPR Data Request". For security purposes, we may ask you to verify your identity before processing any database lookups or changes.
Cookies
Our web infrastructure uses browser-based cookie cookies to support secure portal sessions, retain basket items, capture layout choices, and inform marketing optimizations.
Types of Cookies We Use
| Cookie Category | Functional Scope Within Systems | Requires Explicit Opt-In |
|---|---|---|
| Strictly Necessary | Maintains secure user sessions, manages credentials, secures online order steps, and processes data forms safely. | No |
| Analytics Tracking | Feeds telemetry data to Google Analytics to evaluate site navigation trends and identify code bugs. | Yes |
| Functional Preferences | Remembers user layout preferences, language configurations, and previous cookie choices. | Yes |
| Marketing Optimization | Measures promotional campaign performance across integrated advertising networks like Meta (Instagram/Facebook). | Yes |
Managing Preferences
A consent prompt appears on your initial visit, allowing you to accept or block tracking configurations. You can adjust these settings at any time via your browser controls. For a deeper breakdown of cookie structures, view our dedicated Cookie Policy.
Children's Privacy
Our platform solutions and product lines are intended for adults. We do not knowingly compile records from individuals under the age of 13. If a parent identifies that an underage individual has submitted contact forms or created an account profile within our database, notify us at info@cacaoroute.co.uk to initiate immediate, secure deletion sequences.
How We Protect Your Data
We maintain strict technical frameworks and organizational security measures to protect the integrity of our customer data and internal storage clusters against unauthorized access, loss, or alteration:
- SSL/TLS cryptographic tunnels secure all data moving between your client browser and our database endpoints.
- Advanced hashing algorithms encrypt all customer passwords, ensuring credentials cannot be read in plaintext.
- Database environments use advanced firewalls, isolated cloud storage blocks, and strict authorization layers.
- Payment transactions pass exclusively through tokenized API links to our PCI-DSS Level 1 gateway provider.
- Internal admin panel access is restricted using multi-factor verification and granular role permissions.
- Our technical teams run regular software updates and security scans to address newly discovered web exploits.
While we use strong industry practices, no data system is completely impenetrable. If you suspect an account compromise or credential exposure, alert our security team immediately at info@cacaoroute.co.uk. In the event of a significant data breach affecting your privacy rights, we will notify you and the Information Commissioner's Office within 72 hours, in line with statutory UK GDPR guidelines.
Third-Party Links
Our web layouts display external hyperlinks pointing to related partners or social networks (e.g., Instagram, Facebook, and TikTok). Following these links moves your session outside our controlled infrastructure, meaning this privacy policy no longer governs your data collection. Review the privacy documentation of any third-party asset you visit.
Changes to This Policy
We update this policy document periodically to reflect adjustments to our database setups, legal rules, or platform code changes. Material updates will be noted via the revision timestamp at the header of this page.
If an update significantly alters how we handle user data or core privacy options, we will notify account holders directly via automated email notices or clear warnings on our homepage. Continued interaction with our services signifies your acknowledgement of the updated privacy policy terms.
Contact Us
For questions regarding our privacy rules, database security setups, or to request changes to your stored customer records, contact our compliance team. We address verified incoming requests within 5 operational business days.
Data Controller: London Fox Ltd (trading as Cacao Route Chocolates)
Address: 30 High Street, Walton-on-Thames, Surrey, KT12 1BZ
Direct Contact Email: info@cacaoroute.co.uk
Incorporation Area: England and Wales
If our processing responses fail to address your concerns or you suspect a regulatory breach, you can escalate your claim directly to the national monitoring authority:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Web Link: ico.org.uk
Help Desk Line: 0303 123 1113