Legal
Privacy notice
This notice explains how Seymour handles personal data for the public website, customer ordering journey and staff ordering tools.
Last updated: 22 July 2026
Who this notice covers
Seymour supports independent takeaway businesses that take direct online orders. It handles customer order data, staff account data, security records and operational messages needed to run that service.
Each takeaway is expected to act as controller for its own customer and order data. Seymour acts as processor for normal service delivery and as controller for its own billing, security, support and administration data.
Personal data handled
- Customer names, email addresses, phone numbers, delivery addresses and order notes submitted during checkout.
- Order contents, fulfilment choices, payment state, Stripe identifiers and customer order status activity.
- Staff names, email addresses, roles, authentication events, security activity and support-access audit events.
- Technical data such as IP-adjacent request records, session identifiers, browser storage and server logs needed for security and reliability.
Why data is used
- To create and fulfil direct customer orders.
- To let staff accept, decline, update and reconcile orders.
- To authorise card payments and capture payment after staff acceptance.
- To send service emails, order updates and account verification messages.
- To protect accounts, investigate abuse, keep audit records and meet legal or tax obligations.
Sharing and suppliers
Customer order data is shared with the takeaway business responsible for fulfilling the order. Payment card details are handled by Stripe. Seymour stores payment state and Stripe references, not raw card details.
Seymour may also use hosting, database, email delivery, monitoring and support suppliers where they are needed to operate the service.
Retention
Order snapshots are kept for operational, tax and dispute evidence. Customer contact details can be redacted when direct identification is no longer needed under the configured retention policy.
Security and audit records are kept for as long as they are needed to protect the platform, investigate incidents and evidence support access.
Your choices and rights
You can ask for access, correction, deletion, restriction, portability or objection where those rights apply. Marketing email consent can be changed from the customer account tools when marketing preferences are available.
Contact orders@food.crayonsandco.de to raise a privacy request. If the request relates to a specific takeaway order, Seymour may need to refer it to the takeaway business as controller.