Back to Kona

Legal

Privacy
Policy

Last updated: April 2025

1. Who we are

Kona Coffee ("Kona", "we", "us") is operated by Kona Media. We are the data controller for the personal data described in this policy. Contact us at george@kona-coffee.co.uk for any privacy-related questions.

2. What data we collect

We collect the following personal data:

  • When you purchase: name, email address, delivery address, and payment details (processed directly by Stripe — we never see your full card number).
  • When you join the waitlist: name, email address, preferred drop, and brewing method.
  • When you visit our site: IP address, browser type, pages visited, and time on site via analytics (see section 5).

3. How we use your data

We use your personal data to:

  • Process and fulfil your order.
  • Send you order confirmation and shipping updates.
  • Notify waitlist members when a new drop goes live (with your consent).
  • Improve our website and understand how people use it.
  • Comply with legal obligations.

We will never sell your data to third parties. We will never send you marketing emails without your explicit consent.

4. Legal basis for processing

Under UK GDPR, we process your data on the following bases:

  • Contract: processing your order and delivering your box.
  • Legitimate interest: basic website analytics to improve the site.
  • Consent: sending waitlist and marketing emails. You can withdraw consent at any time by clicking unsubscribe or emailing us.

5. Third-party services

We use the following third-party services that may process your data:

  • Stripe — payment processing. See Stripe's privacy policy.
  • Google Fonts — font delivery. See Google's privacy policy.
  • [Your email platform, e.g. Mailchimp / Loops / Resend] — waitlist and transactional emails.
  • [Your analytics tool, e.g. Plausible / Fathom / Google Analytics] — website analytics.

6. Data retention

We retain your personal data only as long as necessary:

  • Order data is kept for 7 years to comply with HMRC requirements.
  • Waitlist data is deleted 12 months after the relevant drop, or immediately upon unsubscribe.
  • Analytics data is retained in aggregate and contains no personally identifiable information.

7. Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Delete your data ("right to be forgotten"), subject to legal obligations.
  • Restrict or object to processing.
  • Data portability — receive your data in a machine-readable format.
  • Withdraw consent at any time where processing is based on consent.

To exercise any of these rights, contact us at george@kona-coffee.co.uk. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).

8. Security

We take reasonable technical measures to protect your data, including HTTPS encryption and limiting access to personal data to those who need it. No method of transmission over the internet is 100% secure, but we take our obligations seriously.

9. Children

Our site is not directed at children under 13. We do not knowingly collect personal data from children.

10. Changes to this policy

We may update this policy when our practices change. The current version is always on this page. For significant changes we will notify customers by email.

11. Contact

Privacy questions or requests: george@kona-coffee.co.uk

Kona Coffee © 2026 Kona Coffee · Made with care
Terms Privacy Cookies