The Crown Inn · Pishill
How we look after
your information
What we hold about you, why we hold it, how long we keep it, and what you can ask us to do with it. Written in plain English rather than legal shorthand.
About this notice
This notice explains what we do with information about people. It covers everyone we deal with:
- visitors to thecrownpishill.com
- guests who eat and drink with us in the pub or the Thatch Barn
- couples and families planning a wedding or private event, and their guests
- businesses booking the Garden Studio or the Barn for meetings and corporate events
- suppliers, contractors and people who apply to work with us
Our own team members receive a separate, fuller privacy notice covering employment.
We have written this in plain English rather than legal shorthand. If anything is unclear, ask us — we would rather explain it than have you guess.
Who we are
The Crown Inn, Pishill is operated by John Bloomer, trading as The Crown Pishill, of Stonor Road, Pishill, Henley-on-Thames, Oxfordshire RG9 6HH. We are the “data controller” for the information described here, which means we decide why and how it is used. We are registered with the Information Commissioner’s Office as a data controller.
How to reach us about your information
Email hello@thecrownpishill.com, write to us at the address above, or call 01491 913787. We are not required to appoint a Data Protection Officer and have not done so; responsibility for data protection sits with the owner.
The short version
If you read nothing else, this is the shape of it.
| What we hold | Why |
|---|---|
| Your name and contact details | To take your booking and talk to you about it |
| Table reservations | To hold your table and manage the restaurant |
| Card and payment records | To take payment and keep the accounts HMRC requires |
| Event files — guest numbers, timings, menus, suppliers | To plan and run your event |
| Dietary and access requirements | To feed you safely and get you into the building comfortably |
| An identity check record for private hirers | Because our hirers take on personal responsibility for a 15th-century listed building |
| CCTV footage | For the safety of our guests and our team, and to prevent crime |
| Wifi sign-in details | To provide guest wifi and keep it secure |
We do not sell your information to anyone, and we never will. We do not use it to make automated decisions about you. We do not share it with other businesses for their own marketing.
When you use our website
What we collect. If you fill in an enquiry form we collect what you put in it — usually your name, email address, telephone number, and the details of what you are asking about. Our website is hosted by 123 Reg, whose servers record standard technical information about every visit: IP address, browser type, the pages you looked at and when.
Cookies
We keep this deliberately simple. Our site sets only a small number of cookies that are strictly necessary for it to work — page loading, security, and remembering any preference you have set. Cookies of that kind do not require your consent.
We do not currently use analytics, advertising or third-party tracking cookies. If we decide to add website analytics, we will update this notice and tell you clearly before we do, and anything used for advertising would be set only with your consent.
You can block or delete cookies in your browser settings at any time, though parts of the site may then stop working properly.
Booking a table
Our reservation links take you to OpenTable. When you book through OpenTable you are giving your information to OpenTable as well as to us — they operate their own privacy policy and use diner data for their own purposes, including their own account and marketing services. Please read their notice before you book. We receive the reservation details, and we use them only to hold your table and look after you when you arrive.
Lawful basis
For enquiry forms and reservations, we process your information because it is necessary to take steps at your request before entering into a contract, and then to perform it. For site security we rely on our legitimate interests in running a secure website.
When you eat and drink with us
Reservations. Your name, contact details, party size, date and time, and any notes you give us — a birthday, a high chair, a dog, a preferred table.
Payments. Card payments are handled by CBE Pay, which is integrated with our till system, also provided by CBE. We never see or store your full card number; we hold a transaction record showing the amount, the date, the last four digits and the authorisation reference. We keep those records for six years because tax law requires it.
Allergies and dietary requirements. If you tell us about an allergy, an intolerance, or a dietary requirement, we record it against your booking so the kitchen and the floor team can act on it. Information about an allergy is information about your health, which the law treats as a special category needing extra protection — section nine explains how we handle it. We would always rather you told us and we recorded it than the alternative.
Guest wifi. Our guest wifi is provided through BT and asks you to sign in. We record the details you provide, the device identifier, the time you connected and the volume of data used. We do this to provide the service, to keep the network secure, and to comply with any lawful request about misuse of it. We do not use wifi sign-in details for marketing. We keep wifi connection logs for 12 months.
Feedback and reviews. If you leave feedback with us directly, we use it to put things right and to improve. If you post a public review, that is between you and the platform.
Lawful basis
Performing our contract with you for reservations and payments; our legal obligations for tax records; our legitimate interests in running the pub safely and securely; and your explicit consent for allergy and dietary information.
CCTV
CCTV operates in and around the buildings, the car park and the approaches. It is there to protect our guests, our team and the building, to prevent and detect crime, and to help us meet the conditions of our premises licence. Signs are displayed at the points covered.
- No camera is installed in any area where people would reasonably expect privacy. There is no CCTV in toilets, changing areas or accommodation, and none in the bridal preparation areas.
- Our cameras do not record sound. Sound can be heard by a member of our team viewing a camera live, but no audio is stored or retained. We take the view that recording our guests’ conversations would be intrusive and unnecessary.
- Footage is retained for 31 days and then overwritten automatically, unless it has been retained for a specific incident, in which case we keep it until that matter is concluded.
- Access to footage is restricted to the owner and senior management, and every access is logged.
- We will disclose footage to the police, to our insurers, or to a licensing or enforcement authority where there is a proper basis for doing so. We will not put footage on social media.
Your rights over footage
You can ask for a copy of footage of yourself. Please tell us the date, the approximate time and where you were, and give us a description or a photograph so we can find you — and please ask promptly, because footage is overwritten. We may need to obscure other people who appear in the same frames.
Lawful basis
Our legitimate interests in the safety of people on the premises, the security of a listed building, and the prevention of crime. Where footage is used in connection with a criminal matter, we rely on the substantial public interest basis for the prevention and detection of unlawful acts.
Weddings, private events and celebrations
This section covers everything from a first enquiry through to the security deposit being returned.
6.1 Enquiries and viewings
Your name, contact details, the date you are interested in, your likely numbers and budget, and what you have told us about the event. If you visit, we make a note of the conversation. If you do not go ahead, we keep the enquiry for 24 months and then delete it — unless you have asked to hear from us about future dates.
6.2 Confirming who you are
Before we confirm a private hire, we check the identity and home address of the person named as hirer. This is explained in full at clause 2.7 of our terms of hire. In summary:
- We ask to see one photographic identity document and one document showing your home address.
- We record only that the check was made, what type of document we saw, and the date. We do not routinely take or keep copies of your documents.
- If in a particular case we do need to retain a copy, we will tell you why before you provide it, hold it encrypted with restricted access, and delete it on the schedule at section eleven.
- We keep the record of the check for 24 months after the event.
We do this because the hirer takes on personal responsibility for the conduct of guests and for damage to a Grade II listed thatched building, and we need to be able to identify and contact them afterwards if a liability arises. Our lawful basis is legitimate interests, not consent — consent would not be meaningful when the alternative is that we decline the booking, and we would rather be straight with you about that. We have carried out and documented a legitimate interests assessment, and you can ask to see it.
You can object to this processing at any time. If you do, we will explain honestly what it means for your booking rather than simply refusing.
And if you cannot provide documents from the lists in our terms, please tell us. We will discuss alternatives — a letter from a solicitor or accountant, a pension or benefits letter, or simply posting your booking confirmation to the address you have given and asking you to acknowledge it. We will not decline a booking on that basis alone.
6.3 Payments
We ask for payment by bank transfer, or debit or credit card, from an account in the hirer’s own name. We hold the payment records, the account name shown to us, and the transaction references — not your account number or full card number. We keep financial records for six years.
6.4 Planning your event
As your event takes shape we build a file: timings, guest numbers, seating plans, menus, the running order, your supplier list and their contacts, and your access and dietary requirements. We hold this because we cannot run the event without it.
Information about your guests. Guest lists, seating plans, dietary requirements and access needs are information about other people that you give to us. We rely on you to tell your guests that their details have been passed to us and that this notice explains what we do with them — clause 16.3 of our terms puts that obligation on you. A line in your invitation or on your RSVP card is usually all it takes.
We use guest information only to run your event. We delete guest lists 3 months after the event unless there is a reason to keep them, such as an outstanding matter or an insurance question.
6.5 Dietary, allergy and access requirements
These often reveal something about a person’s health, and sometimes about their religion or beliefs. Section nine explains the extra protection that applies. In short: we collect them because they are the only way to feed people safely and get everyone comfortably into a 15th-century building, we share them only with the kitchen and the team working your event, and we delete them with the rest of the event file.
6.6 Suppliers you bring
We collect contact details, insurance certificates, PAT certificates, risk assessments and food hygiene ratings from your caterers, musicians, florists, stylists and hire companies. We hold these to satisfy ourselves that the people working on our site are properly insured and competent, and because our own insurers and the fire safety regime expect us to. We keep supplier documents for 6 years after the event, in line with the period during which a claim could be brought.
6.7 Photography and film
- Our photography. We photograph and film the venue for our own marketing. We will not photograph a private event without your agreement. Where you agree, we do not identify individuals by name, and we will remove any image at your written request. This is dealt with at clause 16.1 of our terms.
- Your photographer. A photographer or videographer you engage works for you, not for us. They are responsible for their own use of the images and for their own privacy obligations.
- Guests’ phones. We cannot control what guests photograph. If that matters to you, say so in your invitations — an unplugged ceremony works far better when people arrive expecting it.
6.8 Security, conduct and incidents
Where an incident occurs — damage, an injury, a guest removed, a false fire alarm, a noise complaint — we record what happened, when, who was involved and what we did. We keep an incident log for every event where SIA door supervisors are used. This protects us if our premises licence is ever reviewed, and it protects you if there is a dispute about a deduction from the security deposit.
Incident records are kept for 6 years. They may be shared with the police, our insurers, South Oxfordshire District Council’s licensing team, or the fire and rescue service where there is a proper basis for it.
Lawful basis
Performing our contract with you; our legal obligations under licensing, fire safety and health and safety law; and our legitimate interests in protecting the building, our team, our guests and our licence.
Corporate meetings and events
Most of section six applies equally to corporate bookings. Three things are different.
We deal mainly with business contact information. The name, job title, work email and work telephone number of the person organising the event, and the company’s billing details. We rely on our legitimate interests in providing services to businesses, which is the ordinary basis for business-to-business dealings.
Delegate lists. If you send us a list of attendees — for badges, place cards, catering or access — we treat it the same way as a wedding guest list. We use it only to run your event and delete it 3 months afterwards. As the organiser, you are responsible for telling your delegates that their details have been shared with us.
Marketing to businesses. We may send information about our venue to a business contact at a corporate email address without asking first, because the law permits it for business-to-business email. We will always tell you how to stop, and we will stop immediately when you ask. If you would prefer not to hear from us at all, one line by email is enough. We will not do this to an individual’s personal email address without their consent.
Confidentiality. Where your event involves commercially sensitive material — a board meeting, an offsite, a strategy day — we will sign a confidentiality agreement if you would like one. Our team is briefed not to discuss what happens in the room, and the Garden Studio is not overlooked.
Marketing and staying in touch
We are not currently sending marketing emails. This section sets out how we will do it when we start. We will update this notice, and name the email provider we use, before we send anything.
If you ask to hear from us, we will use your email address to send occasional news about the pub, the venue, our menus and events. You will be able to unsubscribe from every message we send.
If you have booked with us, we may send you similar information about our own venue and hospitality without asking again, because the law allows a business to contact its own customers about similar things. You will have been offered the chance to decline when we took your details, and you can opt out at any time in any message. We will not do this if you have told us not to.
We will not
- pass your details to another business for their marketing
- send you marketing by text or telephone without your agreement
- keep sending after you have unsubscribed
- make it difficult to unsubscribe
Our mailing list will be held with a specialist email provider, named here once we begin. We will review it every 24 months and remove people who have not opened anything in that time — a list of people who want to hear from you is worth more than a long one.
Lawful basis
Your consent, where you have subscribed. Our legitimate interests in marketing our own similar services to our own customers, within the rules for the “soft opt-in”, where you have booked with us. Consent can be withdrawn at any time; withdrawing it does not affect anything we did before you withdrew it.
Health, dietary and religious information
The law calls information about health, religion, race, sexual orientation, political opinions, trade union membership, genetics and biometrics special category data, and requires a second lawful basis on top of the ordinary one.
For us this almost always means one of three things: an allergy or intolerance, an access or mobility requirement, or a dietary requirement that reflects a religion or belief — halal, kosher, or observance of a fast.
Our second basis is your explicit consent. When you tell us, we take that as your explicit agreement that we may record it and use it to look after you. Where the information comes to us from an event organiser rather than from you directly, we rely on the organiser having your agreement, and we ask them to make that clear to you.
What we do with it
- record it against the booking, not in a general list
- share it only with the kitchen and the team working your event
- never use it for anything else, and never for marketing
- delete it with the rest of the booking or event file
You can withdraw your agreement at any time. Please bear in mind that if you do, we will not be able to cater safely for that requirement.
Who we share information with
We share information only where there is a reason to, and only as much as is needed.
| Who | What | Why |
|---|---|---|
| OpenTable | Table reservations | Runs our restaurant booking system, and operates as a controller in its own right for diner accounts |
| CBE | Transaction records and card payments | Our till and order system, and the integrated card payments service CBE Pay |
| BT | Wifi connection data | Provides our guest wifi |
| 123 Reg | Website data and enquiry forms | Hosts our website |
| Lawrence Grant | Financial records | Our accountants, who prepare our accounts and returns |
| Caterers and suppliers you engage | Only what they need — usually numbers, timings and dietary requirements | To do the job you have booked them for |
| SIA-licensed door supervisors | Event details and incident records | Where security is used at an event |
| Our insurers and brokers | Incident and claim information | To maintain cover and handle claims |
| Police, licensing authority, fire and rescue service, HMRC, local authority | Whatever is lawfully required | Where we are legally obliged, or where there is a proper basis such as investigating a crime |
| Professional advisers | As needed | Legal and professional advice |
Everyone who handles information on our behalf does so under a written contract that requires them to keep it secure and use it only for what we have asked. We do not sell personal information, and we do not share it with other businesses for their own marketing.
How long we keep things
| What | How long | Why |
|---|---|---|
| Website enquiry, no booking | 24 months | Long enough to follow up a date that did not work out |
| Table reservations | 24 months | To recognise returning guests and settle any query |
| Event enquiry, no booking | 24 months | Covers an enquirer returning for the following year’s date |
| Event contract and booking file | 6 years after the event | The limitation period for a contract claim |
| Identity check record | 24 months after the event | Matches clause 16.4 of our terms |
| Guest and delegate lists | 3 months after the event | No reason to keep them longer |
| Dietary, allergy and access information | Deleted with the event file | Special category data — kept no longer than needed |
| Financial and payment records | 6 years from the end of the accounting period | Required by tax law |
| Supplier insurance and certificates | 6 years after the event | The period in which a claim could be brought |
| Incident and accident records | 6 years | Claim limitation periods — or until the person reaches 21 where a child was involved |
| CCTV | 31 days | The shortest period that is practically useful |
| Wifi connection logs | 12 months | Network security |
| Mailing list | Until you unsubscribe | A consented list should not outlive the consent |
| Job applications, unsuccessful | 12 months | To answer a query about the decision, and to keep good candidates in mind |
Where we have kept something longer than the period above because it relates to an unresolved matter, we delete it once that matter concludes.
Information leaving the UK
Most of our information stays in the UK or the European Economic Area.
Our till and payments provider, CBE, is based in Ireland. Ireland is in the European Economic Area, which the UK recognises as offering an equivalent standard of protection, so no additional safeguard is needed for information held there.
One of the services we use — OpenTable — is provided by a company based in or with operations in the United States. Where information goes outside the UK and the EEA, we make sure it is protected to a standard the law recognises, using one of these:
- the UK Extension to the EU–US Data Privacy Framework, where the recipient is certified under it; or
- the International Data Transfer Agreement, or the UK Addendum to the standard contractual clauses, together with an assessment of the risks in the destination country.
You can ask us which applies to a particular service and we will tell you.
Keeping information safe
We take security seriously, in proportion to what we hold.
- Access is limited to the people who need it to do their job.
- Systems are password-protected, with multi-factor authentication on email, the booking system and the till.
- Devices are encrypted and kept up to date.
- Paper records — function sheets, run sheets, guest lists — are kept in a locked office and shredded when finished with, not put in the recycling.
- The team is briefed on handling guest information, and on not discussing guests or events outside work.
- CCTV footage is accessible only to the owner and senior management, and access is logged.
If something goes wrong and personal information is lost or exposed, we will assess it immediately, report it to the Information Commissioner’s Office within 72 hours where the law requires, and tell the people affected directly where there is a high risk to them.
Your rights
| Right | What it means |
|---|---|
| Access | Ask for a copy of what we hold and what we do with it |
| Rectification | Have anything inaccurate corrected, or anything incomplete completed |
| Erasure | Ask us to delete it, where we have no continuing reason to hold it |
| Restriction | Ask us to hold it but stop using it, while something is being resolved |
| Objection | Object to processing we do on the basis of legitimate interests — including our identity checks and our CCTV |
| Portability | Receive information you gave us in a machine-readable form, where processing is based on consent or contract and carried out automatically |
| Withdraw consent | Withdraw agreement you have given, at any time, without affecting what we did before |
| Direct marketing | Object to marketing at any time. This one is absolute — we must stop |
How to use them. Email hello@thecrownpishill.com or write to us at the address at the top. You do not need to use a particular form of words. We may need to confirm your identity before we act, particularly for a request to access CCTV.
How quickly. We respond within one month. If your request is complex or you have made several, we may extend by up to two further months, and we will tell you within the first month if we need to and why. There is no charge, unless a request is manifestly unfounded or excessive.
Some rights have limits. We cannot delete a booking record we are required to keep for tax, and we cannot give you CCTV footage of somebody else. Where we cannot do what you have asked, we will explain why rather than simply saying no.
Complaints
Please come to us first. Email hello@thecrownpishill.com, or write to us at the address at the top. You can raise a data protection complaint with us in any way you like — email, letter, in person, or in a message — and we will treat it as a complaint however it arrives.
Since 19 June 2026 we have a statutory duty to handle complaints about how we use personal information properly. We will:
- acknowledge your complaint within 30 days;
- investigate it in a way that is reasonable and proportionate to what you have raised;
- keep you informed while we do; and
- tell you the outcome without undue delay.
If you are not satisfied, you can complain to the Information Commissioner’s Office. Complaining to us does not take away that right, and you can go to the ICO at any point.
0303 123 1113 · ico.org.uk/make-a-complaint
You also have the right to bring a claim in the courts for compensation if you have suffered damage or distress.
Children
We are a family-friendly pub and children are welcome. We do not knowingly collect information about children through our website, and we do not market to children.
Where children attend an event, we hold only what the organiser gives us — usually a name for a place card and a dietary requirement — and we delete it with the rest of the event file. Our terms of hire require a named responsible adult for guests under 18, and the details we hold about that arrangement are part of the event file.
Where an incident involves a child, we keep the record until that person reaches 21, because that is when the period for bringing a claim expires.
Job applicants
If you apply to work with us, we use your application to assess you for the role and to contact you about it. We keep unsuccessful applications for 12 months, so that we can answer a question about the decision and so that we can come back to you if something else comes up. Tell us if you would rather we deleted yours sooner, and we will.
We check the right to work of everyone we employ, as the law requires. If you join us, you will receive a separate privacy notice covering employment.
Changes to this notice
We will update this notice when what we do changes. The version in force is always the one published at thecrownpishill.com/privacy, with its date at the top. Where a change materially affects how we use your information, we will tell you directly rather than relying on you to check.
| Version | Date | Change |
|---|---|---|
| 1.0 | 23 August 2026 | First published |
The Crown Inn, Pishill · Stonor Road, Pishill, Henley-on-Thames, Oxfordshire RG9 6HH · 01491 913787 · hello@thecrownpishill.com