Privacy Policy
Last updated: 27 August 2026
This Privacy Policy explains how Jennings Brewery Limited collects, uses and looks after your personal information when you visit www.jenningsbrewery.co.uk , buy from us, join our membership, book a brewery tour, or get in touch.
We are the data controller for the information described here. That means we decide why and how it is used, and we are responsible for looking after it.
Where another company handles something for us - taking a card payment, delivering a parcel, running the tour calendar - we say so below and name them.
Please read this policy carefully. If anything in it is unclear, contact us using the details in the Contact section at the end and we will explain it.
Who We Are and How to Contact Us
We are Jennings Brewery Limited, a company registered in England and Wales under company number 12853898. Our registered office is at Brewery Lane, Cockermouth, Cumbria CA13 9NE.
You can contact us about anything in this policy by email at info@jenningsbrewery.co.uk , by phone on 01900 397459 , or by post at the address above.
Changes to This Privacy Policy
We may update this policy from time to time - for example if we change how the website works, start using a new supplier, or need to reflect a change in the law. When we do, we will post the revised policy on this page and update the "Last updated" date shown at the top.
If a change materially affects how we use your information, we will take additional steps to tell you, such as an email or a notice on the website.
The Information We Collect
What we collect depends on what you do. Most people who visit the website simply read it, and we collect nothing that identifies them beyond the technical information described under Cookies and Similar Technologies below.
When you place an order. We ask for your name, email address and phone number on every order, and your delivery address when the order is being posted. We ask for a phone number on collection orders too, so we can reach you if there is a problem. We also hold what you ordered, the amount paid, and the delivery or collection arrangements.
Payment card details. We never see or store your card number. Card payments on this website are taken by Square through their own secure payment form, and your card details go straight to Square. We receive only confirmation that the payment succeeded, along with the card type and last few digits shown on your receipt.
Gift cards. If you buy or use a gift card, we hold its number, its balance and the transactions against it. If you buy one as a gift and ask us to send it to someone else, we hold the recipient's details for that purpose.
When you join or renew a membership. In addition to the order information above, we hold which membership tier you hold, when it started and when it ends, which member benefits you have used or are still owed, how many free tour tickets you have left, and whether you have asked for your membership to renew automatically. If you have asked for automatic renewal, Square securely stores your card for that purpose; we do not see the card details.
When you buy from us in person. If you buy or renew a membership at the till, or give us your details in the shop, that information reaches the same customer record as your website orders, because our till and our website share one system.
When you book a brewery tour. Public tours are booked and paid for through Bookeo, our booking system, which collects the details it needs to hold your booking. If you are a member redeeming a free tour, you enter the email address your membership is registered under so we can check how many free tickets you have left, and we pass the details needed to make the booking to Bookeo.
When you contact us. If you email, phone or write to us, we keep the correspondence and whatever you choose to include in it, so we can answer you and keep a record of what was agreed.
Our mailing list. If you are on our mailing list, we hold your email address, your name where you have given it, and a record of how you came to be on it and when. You can take yourself off it at any time using the unsubscribe link in any email we send.
Automatically, when you use the website. We collect technical information such as your IP address, the type of device and browser you are using, and the pages you visit and when. This is described under Cookies and Similar Technologies below.
What we do not collect. This website has no customer accounts, so there is no username or password for you to manage or for us to look after. We do not run loyalty points, product reviews or a referral scheme. We do not buy information about you from data brokers, and we do not build advertising profiles.
Brewery Tour Health Declarations
If you book or join a guided brewery tour, we ask everyone on the tour to complete a short health declaration when they arrive. This is because the tour route passes through an area where we produce food and drink. The declaration asks you to confirm that you have not had sickness, vomiting, diarrhoea or any contagious gastrointestinal illness in the previous 48 hours, that you have not been in close contact in that time with anyone who has, and that you will tell staff and stop if you feel unwell before or during the tour.
The information in a health declaration concerns your health, which data protection law treats as "special category data" and gives extra protection. We use it only to decide whether you can safely join the tour, to protect the safety of our food and drink and of our other visitors and staff, and to keep the food-safety records that good hygiene practice requires. We do not use it for any other purpose, and we never use it for marketing.
We ask because the law requires it of us. As a food business we must not let anyone carrying an illness that could be passed on through food enter a food-handling area in any capacity, and the tour route goes through one. Our lawful basis for using this information is therefore our legal obligation (Article 6(1)(c) UK GDPR), under the food-hygiene rules that apply to us.
Because the information concerns your health, we also need a second and stricter condition, and for that we rely on your explicit consent (Article 9(2)(a) UK GDPR). You give it by signing the declaration, having been told on the form why we collect it. You can decline. If you do, you cannot join the tour that day, but we will move your booking to another date or refund you in full, so declining costs you nothing.
We keep your signed declaration for 30 days after your visit and then securely destroy it. Thirty days covers the period in which an illness connected with a visit would come to light. After that we keep only a record of the tour itself: the date, how many people were on it, and confirmation that everyone completed a declaration and that nobody declared a relevant illness. That record names nobody and holds no health information about you, and we keep it for one year as part of our food-safety records.
You have rights over this information, including the right to ask for a copy, to withdraw your consent, and to ask us to delete it. If you withdraw your consent we will destroy your signed declaration; it does not affect a tour you have already been on. After 30 days there is nothing left to withdraw, because the declaration has already been destroyed. The "Your Rights" section below explains these rights and how to use them. If you have any concerns about how we handle your health declaration, please contact us using the details in the "Contact" section.
How We Use Your Information, and Our Legal Basis
Data protection law requires us to have a "lawful basis" for each thing we do with your information. Ours are set out below, and they apply to everyone, wherever you live.
To sell you something and get it to you. Processing your order, taking payment, arranging delivery or collection, sending order confirmations and telling you when a collection order is ready, and handling returns, refunds and any complaint about an order. Our lawful basis is performance of a contract with you (Article 6(1)(b) UK GDPR).
To run your membership. Recording your tier and expiry date, applying member pricing and free delivery, granting and tracking member benefits and free tour tickets, sending your welcome and renewal emails, telling you before your membership ends, and - only if you have asked for it - renewing it automatically. Our lawful basis is performance of a contract with you (Article 6(1)(b)).
To handle tour bookings. Holding and managing your booking, and letting members redeem free tickets. Our lawful basis is performance of a contract with you (Article 6(1)(b)).
To meet our legal obligations. Keeping accounting and VAT records, meeting our duties as a licensed alcohol retailer including age verification, and keeping food-safety records. Our lawful basis is compliance with a legal obligation (Article 6(1)(c)).
To keep the website and our business secure. Detecting and preventing fraud, misuse and attacks on the website, and keeping server logs. Our lawful basis is our legitimate interests (Article 6(1)(f)) in protecting our business and our customers. We have weighed this against your rights and consider it to be processing you would reasonably expect.
To answer you and to improve what we do. Responding to enquiries and complaints, and understanding how the website is used so we can make it better. Our lawful basis is our legitimate interests (Article 6(1)(f)) in being responsive and in running the business well. Where this involves analytics cookies we also ask for your consent, as described under Cookies and Similar Technologies below.
To send you news and offers. If you have bought from us, we may send you occasional email about our beers, events and other things we make. UK marketing rules allow us to do this for our own customers, provided we offer you a way out every time - so every one of those emails carries an unsubscribe link, and if you use it we will not send you another. Our lawful basis is our legitimate interests (Article 6(1)(f)) in telling our own customers what we are up to.
If you join our mailing list without buying anything, we send you the same email on the basis of your consent (Article 6(1)(a)) instead, and you can withdraw that at any time by the same unsubscribe link or by contacting us.
Either way, we do not pass your details to anyone else to market to you, and we send nothing by text message or post.
Health declarations for brewery tours. See the Brewery Tour Health Declarations section above, which explains both the lawful basis and the additional condition that applies because health information needs extra protection.
We do not sell your personal information, and we never have. We do not share it with anyone for their own marketing, and we do not use it for targeted advertising.
Cookies and Similar Technologies
A cookie is a small file that a website stores on your device. Some are essential for the site to work; others are optional and need your permission first. We also use your browser's local storage, which works in a similar way. This section covers both.
Essential storage, which does not need your consent. These are needed for the website to work, and are set whether or not you accept analytics:
jennings_cart - remembers what is in your basket as you move between pages. Kept in your browser until you complete your order or clear it.
jennings-age-verified - remembers that you have confirmed you are over 18, so you are not asked on every page. Kept in your browser until you clear it.
jennings_consent - remembers the cookie choice you made, so we do not ask again. Kept in your browser, and records the date you chose. If we ever change what we collect, we will ask you again.
taproomFloatDismissed - remembers that you closed the taproom notice. Cleared when you close your browser.
Square, who take our payments, may also set cookies on the checkout page in order to process your payment securely and to detect fraud. These are essential to taking payment.
Analytics, which we use only if you agree. We use Google Analytics 4 to understand how many people visit the website and which pages they find useful. It is switched off until you accept it on the banner shown when you first visit, and until then it sets no cookies. If you accept, it sets:
_ga - tells one visitor apart from another. Expires two years after your most recent visit.
_ga_G-GKSJTK9WK4 - keeps track of a single visit. Expires two years after your most recent visit.
Google Analytics tells us things like how many people came to the site, roughly what part of the world they were in, and which pages they looked at. We have configured it not to share your information with Google for advertising, and we do not use it to identify you personally or to advertise to you.
Changing your mind. You can change or withdraw your choice at any time using the "Cookie settings" link in the footer at the bottom of any page. Withdrawing your consent stops Google Analytics and deletes the cookies it set. You can also delete cookies through your browser's own settings, though blocking the essential storage above will stop parts of the website working, including the basket.
We use no advertising cookies, no social media tracking pixels, and no analytics tool other than the one named above. The Facebook and Instagram links in our footer are ordinary links and do not track you on our site.
Fonts. Our pages load typefaces from Google Fonts, which means your device's IP address is sent to Google in order to fetch them. No cookie is set for this.
Who We Share Your Information With
We share your information only with companies that provide services to us, and only as far as they need it to do that job. They act on our instructions, are bound by contract to keep it secure, and may not use it for their own purposes. They are:
Square - takes card payments, and holds our order, customer, gift card and membership records. Square is also our till, so a website order and a purchase made in the brewery shop sit in the same record.
Mailchimp, including Mailchimp Transactional - sends our emails: order confirmations and membership emails, and marketing emails to people who have asked for them.
Bookeo - runs the brewery tour calendar and takes payment for publicly booked tours.
ShipStation - produces the delivery label for an order being posted, and passes your name and delivery address to the courier carrying your parcel.
Railway - hosts the website and stores its server logs.
Cloudflare - provides our domain name service and protects the site from attack.
Google - provides Google Analytics, if you have accepted analytics cookies, and serves the typefaces the site uses.
Sanity - stores the website's own content, such as product descriptions and pages. It holds very little personal information.
We will also disclose your information where the law requires it, or to establish, exercise or defend legal claims - for example to our accountants, insurers or professional advisers, to HMRC or a licensing authority, or in response to a valid request from a law enforcement or regulatory body. If our business were sold or reorganised, customer records would transfer with it, and we would tell you first.
We do not sell your personal information, and we do not share it with anyone for their own marketing purposes.
| What we share | Who we share it with |
|---|---|
|
|
Sending Your Information Outside the UK
Some of the companies above are based outside the United Kingdom, or store information outside it. Google, Mailchimp, Railway, Cloudflare and ShipStation are United States companies, and Bookeo is based in Australia.
When your information goes outside the UK, we make sure it is protected to the standard UK law requires. We rely on one of the following: a decision by the UK government that the destination country protects information adequately, which includes United States companies certified under the UK Extension to the EU-US Data Privacy Framework; or the UK's International Data Transfer Agreement, or the UK Addendum to the European Commission's Standard Contractual Clauses, which are contracts putting equivalent protections in place.
If you would like more detail about the safeguard used for a particular transfer, contact us using the details in the Contact section and we will tell you.
How Long We Keep Your Information
We keep your information only for as long as we need it, and then delete it or make it anonymous. How long that is depends on why we hold it:
Order and payment records - six years after the end of the financial year the order falls in, because we are required to keep records of our sales for tax purposes.
Membership records - for as long as your membership runs, and then six years, because a membership is a purchase and forms part of the same accounting records.
Gift card records - until the card is spent or expires, and then six years as part of our accounting records.
Tour booking records - one year after the tour, except the payment record, which is kept with our accounting records for six years.
Brewery tour health declarations - 30 days after your visit, and then we destroy the signed form. We keep a record of the tour itself for one year, but it names nobody and holds no health information. The Brewery Tour Health Declarations section above explains this in full.
Marketing contacts - until you unsubscribe or ask us to stop. We also review the list from time to time and remove people who have not opened or clicked an email in a long while.
Enquiries and correspondence - two years after the matter is closed, unless it relates to an order or a complaint we need to keep for longer.
Website server logs - about 30 days, unless a log is needed for a security investigation.
Google Analytics data - 14 months, after which Google deletes it automatically.
Where we no longer need your information for the purpose we collected it, but must still keep a record for legal or accounting reasons, we keep only the minimum required and stop using it for anything else.
How We Keep Your Information Safe
The website is served over an encrypted connection, and card details are handled entirely by Square and never reach our own systems. Access to customer records is limited to the people who need it to do their jobs, and each of them has their own account. We choose our suppliers partly on their security, and they are contractually required to protect the information we pass them.
No system can be completely secure, and no method of sending information over the internet is guaranteed safe. Please do not send us card details, or anything else sensitive, by email.
If you think something has gone wrong with your information, tell us straight away using the details in the Contact section and we will investigate. Where the law requires it we will report a personal data breach to the Information Commissioner's Office, and where it is likely to put you at high risk we will tell you directly.
Your Rights
Data protection law gives you rights over your personal information. They are not all absolute - some apply only in particular circumstances - but we will always explain our decision if we cannot do what you ask.
The right to be informed. To be told how we use your information, which is what this policy is for.
The right of access. To ask for a copy of the personal information we hold about you.
The right to rectification. To have inaccurate information corrected, or incomplete information completed.
The right to erasure. To ask us to delete information we hold about you. This does not extend to records we are legally required to keep, such as the accounting record of an order you placed.
The right to restrict processing. To ask us to stop using your information while a dispute about it is resolved.
The right to data portability. To receive the information you gave us in a portable format, or to have us send it to another organisation, where that is technically possible.
The right to object. To object to our using your information where we rely on legitimate interests. You can object to direct marketing at any time, and we will always stop.
The right to withdraw consent. Where we rely on your consent - for joining our mailing list, for analytics cookies, and for tour health declarations - you can withdraw it at any time. Withdrawing consent does not affect anything we did lawfully before you withdrew it.
To exercise any of these rights, contact us using the details in the Contact section below. To stop our emails, the quickest route is the unsubscribe link in any of them, which works whether we are emailing you as a customer or because you joined the list; for analytics cookies, use the "Cookie settings" link in the footer.
We will respond within one month. If your request is complex, or you have made several, we may extend that by up to two further months, and we will tell you if we do. There is normally no charge. We may need to confirm who you are before we act, so that we do not give your information to someone else. We will never treat you differently for exercising your rights.
Children
The website sells alcohol and is not intended for children. You must be 18 or over to buy from us, and we ask you to confirm your age before you shop. We do not knowingly collect information about anyone under 18 through the website.
Children can join a brewery tour when accompanied by an adult, subject to the conditions in our tour terms. Where a health declaration is completed for someone aged under 18, we ask a parent or guardian to sign it. We hold that declaration on the same basis, and for the same short period, as any other.
If you believe a child has given us their information, contact us and we will delete it.
Other Websites We Link To
Our website links to other websites, including our social media pages and our tour booking system. This policy does not cover them.
When you follow a link to another website, we suggest you read its own privacy policy. We are not responsible for how those sites handle your information.
Complaints
If you are unhappy with how we have handled your personal information, please tell us first, using the details in the Contact section, so that we have the chance to put it right.
You also have the right to complain to the Information Commissioner's Office, the UK's data protection regulator, at any time. You can complain online at https://ico.org.uk/make-a-complaint or by phone on 0303 123 1113. Complaining to us first does not affect that right.
Contact
If you have any questions about this policy, want to exercise any of your rights, or would like this policy in another format, please contact us:
By email: info@jenningsbrewery.co.uk
By phone: 01900 397459
By post: Jennings Brewery Limited, Brewery Lane, Cockermouth, Cumbria CA13 9NE
Jennings Brewery Limited is the data controller for the personal information described in this policy.