Privacy Policy

1) Who we are (the “Controller”)
Ain’t Nothin But Limited (company no. 03408088) (“we”, “us”).
Registered office: 869 High Road, London, N12 8QA, United Kingdom.
Trading address (venue): 20 Kingly Street, London, W1B 5PZ.
Contact: hello@aintnothinbut.co.uk | +44 (0)20 7287 0514.
2) What this notice covers
How we collect, use and protect personal data when you use our website (aintnothinbut.co.uk), join our mailing list, contact us, visit the venue, or purchase merchandise via our online store.
3) The data we collect
- Contact & communications: name, email, phone (if provided), and your messages.
- Marketing preferences: your opt-in/out choices (email/SMS where used).
- E-commerce (if you buy from us): name, email, billing and delivery address, phone (for delivery), order contents, order history, delivery preferences, returns history; payment data is processed by our payment provider(s)—we do not store full card numbers. We receive limited details such as transaction IDs and the last 4 digits for reconciliation and fraud prevention.
- Operational: courier tracking numbers and delivery confirmations.
- Venue security (on-site): CCTV footage for safety and security.
4) Lawful bases (UK GDPR)
- Contract: to take payment, fulfil, deliver and handle returns/refunds for your order.
- Consent: marketing emails/SMS and non-essential cookies/analytics.
- Legitimate interests: secure/functional site, fraud prevention, responding to queries, venue security (balanced against your rights).
- Legal obligation: tax/accounting and regulatory compliance.
5) How we use data
- Operate and improve our website and online store.
- Process orders, take payment, arrange delivery/collection, and manage returns/refunds.
- Provide support, respond to queries and handle complaints.
- Send marketing you’ve opted into; you can unsubscribe any time.
- Prevent fraud/abuse and protect our legal rights.
6) Sharing & processors
We use providers for hosting, payments (e.g., a PCI-DSS compliant processor), email, and fulfilment/couriers. They act on our instructions under data-processing terms. We also link to third-party platforms (e.g., calendar/social); their use is governed by their own privacy notices.
7) International transfers
Where partners are outside the UK/EEA, we rely on adequacy decisions or Standard Contractual Clauses plus supplementary safeguards, as applicable.
8) Cookies
- Strictly necessary cookies (e.g., cart, checkout, security).
- Analytics/performance cookies (only with your consent).
- Manage preferences via our banner (where shown) and your browser settings.
9) Retention
- Orders & finance records: normally 6 years from the end of the financial year they relate to (or longer if legally required).
- Marketing data: until you unsubscribe or after 24 months of inactivity.
- Support queries: typically 12 months.
- CCTV: typically 30 days unless needed longer for an incident.
10) Your rights
You can request access, rectification, erasure, restriction, objection, and portability, and withdraw consent at any time (this doesn’t affect prior processing). You can complain to the ICO.
11) Children
Our site/marketing are not aimed at children under 16.
12) Updates
We may update this notice and will post the latest version here with a new effective date.
Contact: Ain’t Nothin But Limited, 869 High Road, London, N12 8QA | hello@aintnothinbut.co.uk.
