Updated November 2025
Contents
Privacy Policy. 1
Introduction. 1
Legal Framework. 1
Personal Information that we collect 1
Personal Information that we receive from other sources. 2
What we do with your Personal Information. 3
How we share your Personal Information. 3
User rights and data deletion. 5
Exercising Your Rights. 6
Data Security and Retention. 7
Transferring Personal Information outside of the EEA. 7
Complaints. 8
Scope and Changes to this Policy. 8
Our contact information and opting out 8
The Caffe Nero Group operates across the United Kingdom, Europe, Turkey, the Americas,
Africa and the Middle East. For the purposes of this policy, any reference to “Caffè Nero”
should be interpreted as a reference to The Nero Group Ltd and its subsidiaries and
operating entities collectively. The Nero Group Ltd acts as the Data Controller, or in certain
circumstances a Joint Data Controller, for the personal data processed within the Group
and by the entities that sit within it.
The Caffè Nero Group, includes the following trading names and subsidiary entities:
Caffè Nero, Green Caffè Nero, Favor Bakery, Harris & Hoole, FCB, Coffee#1, 200 Degrees,
Aroma, Neal Street Technologies, and Nero Coffee Roasting.
This Privacy Policy applies to The Nero Group Ltd, the parent company, and its subsidiaries. It governs how Caffè Nero Group collects, uses, and protects the personal data you provide when using our website (the “Site”), as well as any other personal information we may obtain about you (“Personal Information”). In this Policy, “we”, “us” and “our”, refer to The Nero Group Ltd, registered in the UK with registered office 9-15 Neal Street WC2H 9PW. Our company registration number is 06002065.
WE ARE REGISTERED AS A DATA CONTROLLER WITH THE UNITED KINGDOM INFORMATION COMMISSIONER’S OFFICE UNDER REGISTRATION NUMBER ZB128061. WE TREAT YOUR INFORMATION VERY CAREFULLY AND WE HAVE WRITTEN THIS DOCUMENT TO HELP YOU UNDERSTAND WHAT INFORMATION WE COLLECT, WHO HAS ACCESS TO IT AND FOR WHAT PURPOSES. IF YOU ARE IN THE PROCESS OF CREATING AN ACCOUNT WITH OR HAVE ALREADY DONE SO, YOU SHOULD READ THIS DOCUMENT IN CONNECTION WITH OUR AGREEMENT WITH YOU. THIS DOCUMENT IS NOT PART OF THE AGREEMENT AND IS NOT BINDING ON YOU (IT IS FOR INFORMATION ONLY).
Caffè Nero Group Ltd is committed to protecting the security and privacy of third parties (including its customers and all visitors to the Site. We comply with applicable data protection laws including the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR) 2003 (as amended) all similar or related legislation relating to the processing of Personal Information and/or privacy applicable in any jurisdiction and will take reasonable steps to ensure that your Personal Information is secure, and monitored with regard to access, both internally and externally.
We use cookies and similar technologies to enhance your experience and analyse site usage; you can manage your preferences or withdraw consent via our Cookie Policy
The law on data protection sets out a number of different reasons for which a company may collect and process your personal data, including:
In some limited circumstances, we may also need to collect and process special category personal data about you. We will only do so on the basis of your explicit consent or where there is specific legal basis for doing so.
When you engage with us—whether by email, telephone, visiting our premises, or making enquiries through our website—you may provide personal information such as your name, contact details, should you consider making a purchase, additional personal data such as payment details may be collected. Furthermore, when you use our website, we may automatically collect technical information including your IP address, browser type, and other usage data.
The personal data which we may collect depends upon the means by which you choose to engage with us and the information that you choose to provide. This may include the following:
Loyalty Programme Data
The Caffe Nero App is powered by Neals Street Technologies, through participation in our loyalty programme, we collect data including purchase history, rewards balances, and user preferences, and subject to the Neal Street Tech Privacy policy.
We may obtain personal information about you from third parties who have collected it with your consent. This can include data shared for purposes such as fraud prevention. Additionally, our employees may provide us with emergency contact details and information about their dependents or other individuals relevant to employee benefits arrangements. In all such cases, the third party is responsible for ensuring that you have provided the necessary consents for your personal information to be shared and used as described.
We may also receive information about you through your use of other websites or services operated by us. Furthermore, we collaborate with a variety of third-party partners—including business partners, subcontractors (in areas such as technical support, payment processing, and delivery), advertising networks, analytics providers, search information providers, customer insight companies, credit reference agencies, recruitment agencies, and job boards—and may receive personal data from these entities.
Where you apply for a job vacancy with us, we may conduct verification checks, including contacting referees, to confirm the accuracy of the information you have provided
We collect and process personal data for various legitimate purposes, including but not limited to:
We may share your personal data within the Nero Group to facilitate smooth operations, manage loyalty programmes, conduct marketing, and perform analysis. Trusted third-party processors—such as those handling payments and app functionalities—may access your data only under strict confidentiality and privacy obligations.
In certain circumstances, we may disclose your personal information to carefully selected third parties. This will only occur with your consent or where we have a lawful basis to do so. If you have previously granted permission but later change your mind, you may opt out by contacting us as outlined below.
By submitting your personal data, you acknowledge that these third parties may receive and process your information. We require all third parties to handle your data securely and in accordance with this Privacy Policy, and we take reasonable steps to enforce these standards.
Circumstances Requiring Disclosure
We may be required to disclose your personal data to comply with legal obligations, conduct internal investigations, enforce our Terms and Conditions or protect the rights, property, or safety of Caffè Nero group companies, our customers, employees, or other personnel. This may include sharing information with other organizations for fraud prevention, legal and insurance claims and credit risk management.
Purpose of Data Sharing
To enhance your customer experience, we combine data from various sources to offer personalized updates, offers, promotions, and, for loyalty members, relevant rewards. Additionally, we may use your personal data to:
Sharing with Group Companies and Third Parties
We may share your data with any member of our corporate group, as defined under UK law (section 1159 of the Companies Act 2006).
In specific situations, your data may be disclosed to third parties such as:
These third parties are provided only with the information necessary to perform their services and are contractually obligated to use your data solely for those purposes.
We are committed to respecting your privacy and ensuring that you have control over your personal data. Under applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR), you have certain rights regarding the personal information we hold about you. These rights include:
You have the right to request access to the personal data we hold about you. This allows you to obtain a copy of your data and information about how it is being processed.
If any personal data we hold about you is inaccurate, incomplete, or outdated, you have the right to request correction or updating of your data.
You may request the deletion or removal of your personal data where:
Please note that in some cases, we may be required to retain certain personal data to comply with legal obligations or for legitimate business purposes, such as fraud prevention or to enforce contractual terms.
You have the right to request that we limit how we use your personal data in certain circumstances, for example, if you contest the accuracy of the data or object to its processing.
Where applicable, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to request that we transfer this data to another controller.
You may object to our processing of your personal data on grounds relating to your particular situation, including where we process your data for direct marketing purposes. If you object, we will no longer process your data unless we can demonstrate compelling legitimate grounds for the processing.
You have the right not to be subject to decisions based solely on automated processing, including profiling, which significantly affect you. We may use “knock-out” questions and limited automated decision-making as part of our recruitment processes. These questions are designed to quickly determine whether certain minimum criteria are met (for example, legal eligibility or required qualifications). Responses to knock-out questions may result in an automated decision that disqualifies an applicant without further human review. We process this information solely for the purpose of evaluating eligibility, in accordance with applicable data protection laws
Exercising Your Rights
To exercise any of your rights or make any requests regarding your personal data, please contact us at:
We will respond to your request in accordance with applicable data protection laws, usually within one month. In some cases, we may require additional information to verify your identity before processing your request.
Data Processors and Joint Controllers
When we engage third-party service providers (data processors) to process your personal data on our behalf—such as payment processors, IT support, marketing agencies, and analytics providers—we require them to handle your information in accordance with this Privacy Policy and applicable data protection laws.
These data processors process your personal data solely for the purposes defined by us and under strict contractual obligations, including:
When your personal data is no longer necessary for the purposes for which it was shared with third-party processors, or upon termination of the contract with those processors, we require them to securely delete, anonymize, or return your personal data to us, in accordance with our data retention policies and applicable laws.
We take reasonable steps to verify that our data processors comply with this deletion requirements to prevent any unauthorized retention or use of your personal information beyond the agreed scope.
If you exercise your right to erasure (data deletion), we will instruct our data processors to delete your personal data as soon as reasonably practicable, except where retention is required by law or for legitimate business purposes as permitted by applicable regulations.
Where applicable, we will inform you of which joint controller holds responsibility for your data deletion request and provide relevant contact details if you wish to pursue your request with the other controllers directly.
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including to meet any legal, accounting, or reporting requirements.
When your data is no longer needed, we will securely delete or anonymize it in accordance with our data retention policies and industry best practices.
Below you can see the most common processing, legal basis and retention periods for personal data within the Caffe Nero Group.
| Data Type | Legal Basis | Retention Period |
| When you contact CS | Legal Obligation
Legitimate interest |
Up to 6 Years
Up to 3 Years |
| CCTV Recordings | Legitimate interest | 2 – 6 Weeks |
| Transactional Data | Legal Obligation | Up to 6 Years |
| Online Shop Purchases | Legal Obligation | Up to 6 years |
| Customer data for Direct Marketing | Consent | Consent withdrawn or account inactive |
| Customer database for Customer Insight | Legitimate interest | 28 days from when the purposes for which it was collected ends |
| When you Sign in to the Wi-Fi | Legitimate interest | 28 days from when the purposes for which it was collected ends |
Please be aware that deleting your personal data may affect our ability to provide certain products or services to you, or to comply with legal obligations.
If you unsubscribe from marketing, we maintain a record of the request indefinitely to ensure we do not contact you again.
If you request deletion of your data, we retain a record of the deletion request so we can demonstrate compliance to guidelines set under GDPR.
The Personal Information you provide to us is primarily stored and processed on our servers located within the European Economic Area (EEA).
However, to deliver our services effectively, it may sometimes be necessary to transfer your Personal Information outside the UK and, where relevant, the EEA to our staff, third-party service providers, suppliers, or group companies. This includes individuals involved in support services and other business operations who may be based outside the EEA.
We are committed to ensuring your Personal Information is handled securely and in compliance with applicable Data Protection Legislation when processed or accessed from locations outside the EEA. Accordingly, such transfers will only occur under one or more of the following conditions:
Should you have any queries or complaints in relation to how we use your Personal Information, please contact using the details set out as described below. Should you wish to take any complaints or queries further, you have the right to contact the Information Commissioner’s Office regarding such issues.
Our Site may, from time to time, contain links to and from third party websites. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these websites or their related policies. Please check these policies before you submit any Personal Information via these websites.
This Privacy Notice is directed at our guests, customers, job applicants, and any external individuals with whom we engage. In relation to personal data our current and former employees are covered by separate internal documentation and operational practices, including individual employee contracts and company rules, policies, processes and procedures.
Caffè Nero may amend this Policy at any time without notice. By continuing to use the Website and making use of our services you agree to the updated Policy. If you do not agree to any changes that we make, you should not use or access (or continue to use or access) the Site and/or our services. Any changes to this Policy will be posted on the Site.
You can opt out of receiving various communications from us by contacting us through our contact us page
Caffè Nero Group Ltd complies with GDPR and other relevant privacy laws. Users can exercise their rights, submit requests, or lodge concerns by contacting Caffè Nero Group Ltd through the following channels:
Email: enquiries@caffenero.com
Phone: +44 (0)20 7520 5150
Web: Contact Us Form (https://www.caffenero.com/uk/help/contact-us/)
For unresolved complaints, users have the right to contact the Information Commissioner’s Office (ICO): ICO Contact Details: Information Commissioner’s Office Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF Helpline: 0303 123 1113 Website: www.ico.org.uk
If you have any questions please feel free to contact us by email at Alternatively, you may call our team on +44 (0)20 7520 5150 , Monday to Friday: 9am to 5pm