Privacy Policy
Shere Khan Restaurant ("Shere Khan", "we", "us" or "our") is committed to protecting your privacy. This policy explains what personal data we collect when you visit our website, make a booking, or contact us, why we collect it, how we use it, who we share it with, and the rights you have over it under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
By using this website or making a booking with us, you acknowledge the practices described in this policy. If you do not agree with this policy, please do not use our website or provide us with your personal data.
1. Who We Are
The data controller responsible for your personal data is:
Shere Khan Restaurant
Company No. 13217114 (registered in England and Wales)
128 High Street, Ponders End, Enfield, London EN3 4ES
Telephone: 0203 946 8684
Email: [email protected]
We have not appointed a formal Data Protection Officer, as this is not a legal requirement for a business of our size and activities. For any data protection query, please use the contact details above or in Section 14.
2. Information We Collect
We collect personal data in the following ways:
Booking information
When you make a reservation through our online booking system (powered by DesignMyNight), we — and DesignMyNight, acting as our booking platform — collect your name, email address, phone number, party size, booking date and time, and any special requests or dietary/accessibility notes you choose to provide.
Contact form and enquiries
When you use our contact form, we collect your name, email address, phone number (if provided), the nature of your enquiry, and the message you send us.
Website usage and tracking data
When you browse our website, we automatically collect certain technical information, including your IP address (used only in hashed, non-reversible form for security rate-limiting — we do not store your raw IP address), browser and device type, pages visited, and how you arrived at our site (for example, from a Google search, a Google or Meta advertisement, a link from another site, or by typing our address directly). Where you consent, this includes advertising click identifiers (such as Google's gclid/wbraid or Meta's fbclid) and analytics identifiers issued by Google Analytics. This information helps us understand which marketing channels lead to genuine, confirmed bookings.
We only collect the categories of personal data described in this policy, and we do not knowingly collect any special category data (such as health, religious or biometric data) through this website, save where you voluntarily disclose it to us (for example, a dietary or accessibility requirement you choose to share in a booking note), which we use solely to accommodate your visit.
3. How We Use Your Information
We use your personal data for the following purposes, and on the following legal bases under UK GDPR:
- To process and confirm your booking — necessary for the performance of a contract with you (Article 6(1)(b)).
- To respond to enquiries sent via our contact form — necessary for our legitimate interests in providing customer service, and based on your consent where you tick the contact-consent box (Article 6(1)(a)/(f)).
- To understand which marketing channel led to a booking (for example, Google Ads, Meta Ads, organic search, or a direct visit) — based on your consent to analytics and marketing cookies (Article 6(1)(a)).
- To maintain and improve our website through aggregated, anonymised analysis of how it is used — necessary for our legitimate interests (Article 6(1)(f)).
- To keep our website and booking system secure, including rate-limiting and fraud prevention — necessary for our legitimate interests (Article 6(1)(f)).
- To comply with our legal obligations, such as keeping records for accounting and tax purposes — necessary for compliance with a legal obligation (Article 6(1)(c)).
We do not use your personal data for any automated decision-making or profiling that produces legal or similarly significant effects on you, and we do not use your data for any purpose incompatible with those set out above.
4. Cookies & Tracking Technologies
We use cookies and similar technologies to run our website, understand how it is used, and measure the effectiveness of our marketing. When you first visit our site, a cookie banner lets you accept or decline non-essential cookies before any analytics or marketing cookie is set. You can change your choice at any time by clearing your browser's cookies for this site and reloading the page, which will show the consent banner again.
Cookies on this site fall into three categories:
Analytics and marketing cookies are only set once you actively consent via our cookie banner. If you decline, only strictly necessary cookies are used, and we do not send advertising or analytics identifiers to Google or Meta.
5. Third-Party Services
We share limited personal data with the following third parties, solely to provide our services:
- DesignMyNight — our table reservation platform, which processes your booking details directly to manage availability and confirmations.
- Google (Analytics, Ads, Tag Manager) — processes website usage and, where you consent, advertising click data, to help us measure site performance and marketing effectiveness. See Google's own privacy policy at policies.google.com/privacy.
- Meta (Facebook/Instagram) — where you consent, processes limited advertising identifiers to help us measure the effectiveness of Meta advertising campaigns. See Meta's privacy policy at facebook.com/privacy/policy.
- Our website hosting provider, who stores our website files and database securely on our behalf.
Each of these providers acts either as an independent data controller of the data they process (Google and Meta, for their own advertising platforms) or as our data processor acting only on our instructions (our hosting provider). We do not sell your personal data to any third party, and we do not share it for purposes unrelated to running our restaurant and website.
6. Payment Information
We do not directly collect, process or store your full payment card details on this website. Where a booking requires a deposit or payment, this is collected securely by our booking platform (DesignMyNight) or a payment processor acting on our behalf, each of which operates in compliance with the Payment Card Industry Data Security Standard (PCI DSS). We never see, handle or store your full card number, expiry date or security code.
7. Data Retention
We keep personal data only for as long as necessary for the purposes described in this policy:
- Booking and enquiry records are generally kept for as long as needed to fulfil your booking or enquiry, and afterwards where we have a legitimate business or legal reason to retain them, such as accounting and tax record-keeping obligations under UK law (typically up to 6 years).
- Marketing and advertising identifiers (such as click IDs and analytics identifiers linked to a booking) are retained for a limited period in line with industry guidance from the Information Commissioner's Office, typically no longer than around 13 months, after which the underlying identifiers are removed while anonymised, aggregate channel information (for example, "Google Ads") may be kept for reporting purposes.
- Admin login and security logs are retained for a limited period for security and audit purposes.
Where you would like your personal data deleted sooner, see "Your Rights" (Section 10) below.
8. Data Security
We take appropriate technical and organisational measures to protect your personal data. Booking and tracking data is stored on a secured server, sensitive identifiers are encrypted at rest, our admin dashboard is protected by authentication, rate-limiting and audit logging, and all data is transmitted over encrypted (HTTPS) connections. Access to personal data is restricted to those who need it to carry out their role. While we take these steps seriously, no method of transmission or storage over the internet is completely secure, and we cannot guarantee absolute security.
9. Data Breach Notification
In the unlikely event of a personal data breach that poses a risk to your rights and freedoms, we will, where required by law, notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. Where a breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly, without undue delay, explaining what happened and what steps we and you can take in response.
10. Your Rights
Under UK GDPR, you have the following rights in relation to your personal data:
Right of Access
Ask us for a copy of the personal data we hold about you.
Right to Rectification
Ask us to correct inaccurate or incomplete personal data.
Right to Erasure
Ask us to delete your personal data, where there is no legal reason for us to keep it.
Right to Restrict Processing
Ask us to limit how we use your personal data in certain circumstances.
Right to Object
Object to our use of your data for marketing or analytics purposes at any time.
Right to Data Portability
Ask us to provide your data in a portable, machine-readable format.
Right to Withdraw Consent
Where we rely on your consent (such as marketing cookies), withdraw it at any time, without affecting processing already carried out.
Right to Complain
Lodge a complaint with the Information Commissioner's Office if you believe we have not handled your data properly.
To exercise any of these rights, please contact us using the details in Section 14 below. We will respond within one month, as required by law, and may ask you to verify your identity before actioning certain requests to protect your data from unauthorised access. You will not be discriminated against, charged a fee, or receive a different level of service for exercising any of these rights, except where permitted by law (for example, where a request is manifestly unfounded or excessive). You also have the right to lodge a complaint directly with the UK's independent regulator, the Information Commissioner's Office (ICO), at ico.org.uk or by calling 0303 123 1113. We would, however, appreciate the opportunity to address your concern directly first — please include your name and booking reference (if applicable) so we can respond as quickly as possible.
11. Children's Privacy
Our website and booking system are not directed at children, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will take steps to delete it promptly.
12. International Data Transfers
Some of our third-party service providers, such as Google and Meta, may process data on servers located outside the UK, including in the United States. Where this happens, those providers maintain appropriate legal safeguards recognised under UK GDPR, such as Standard Contractual Clauses or an equivalent adequacy mechanism, to protect your personal data to a standard consistent with UK law.
13. Changes to This Policy & Governing Law
We may update this privacy policy from time to time to reflect changes in our practices, or for legal, operational or regulatory reasons. Any change will be reflected by updating the "Last updated" date at the top of this page, and we encourage you to review this page periodically. Continued use of our website and services after a change is published constitutes your acceptance of the updated policy.
This policy is governed by, and is to be construed in accordance with, the laws of England and Wales. If any provision of this policy is found by a court or regulator to be unenforceable or invalid, that provision will be limited or removed to the minimum extent necessary, and the remaining provisions will continue in full force and effect.
14. Contact Us
If you have any questions about this privacy policy, or would like to exercise any of your data protection rights, please get in touch:
Shere Khan Restaurant
128 High Street, Ponders End, Enfield, London EN3 4ES
Telephone: 0203 946 8684
Email: [email protected]