Privacy
Last updated 2 August 2026
The short version
We collect your email if you join the founding crew, and your name, address, email and order details if you buy something. We do not track you, we do not advertise to you off the back of it, and we do not pass your details to anyone who is not needed to get coffee to your door. There is no analytics on this site at all.
Who is responsible
The data controller is Chris Frost, trading as BlueLightCoffeeCo, in the United Kingdom. A postal address for the controller is published here before checkout opens; until then, email reaches a person and is the fastest route.
Questions, or to exercise any of the rights below, email hello@bluelightcoffee.co.
What we collect, and why
If you join the founding crew list
Your email address, and optionally which service you work in. We use it to tell you when we launch and nothing else. Our lawful basis is your consent, and you can withdraw it at any time by emailing us or using the unsubscribe link.
This is stored in a Supabase database. The form can only add to that list — it is not able to read it back — so an address you give us cannot be pulled out of the page by anyone else.
If you buy something
Your name, delivery address, email, order contents and the grind or size you chose. Our lawful basis is performance of the contract — we cannot send you coffee without knowing where you live.
We never see your card details. Payment happens on Stripe's own checkout pages, not on this site. Your card number does not pass through, or get stored by, anything we control.
Who else handles it
- Stripe — payments, and the order record behind them. Stripe is the controller of the payment data in its own right.
- Supabase — the founding-crew email list.
- GitHub Pages — serves this site. It logs IP addresses as part of doing so.
- The roaster and the carrier — get the name and address needed to pack and deliver your order, and nothing more.
Some of these process data outside the UK. Where they do, they rely on the UK Government's adequacy regulations or on standard contractual clauses with the UK addendum.
Cookies
This site sets none. There is no analytics, no advertising pixel and no tag manager on it — which is why you have not been asked to accept anything. Stripe sets its own cookies on its checkout pages, which are necessary for the payment to work and for fraud prevention; those are covered by Stripe's privacy policy.
How long we keep it
- Order records — six years after the end of the tax year they fall in, because HMRC requires it.
- Founding-crew emails — until you unsubscribe, or after two years with no contact from us.
Your rights
Under UK GDPR you can ask us for a copy of what we hold, ask us to correct it, ask us to delete it, object to how we use it, or ask for it in a portable format. Email us and we will do it within one month. We will not charge you and we will not make it difficult.
Order records we are legally required to keep are the one thing we cannot delete on request. Everything else, we can.
If we get it wrong you can complain to the Information Commissioner's Office at ico.org.uk, though we would rather you told us first so we can fix it.
Something here unclear, or something gone wrong with an order? Email hello@bluelightcoffee.co and a person will answer.