Privacy Policy & Terms of Service 2026

Last updated: 5 May 2026

This privacy policy explains how Kitchen Kit (kitchen-kit.co.uk) collects, uses, stores and protects your personal data when you visit the site, sign up for the newsletter, contact us, or click an affiliate link. It is written to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Plain English version: we collect very little. We don’t sell anything. We use what we do collect only to run the site and respond to you. You can ask us to delete it at any time.

1. Who we are

Kitchen Kit is operated by Ben (the editor and sole operator), trading as Kitchen Kit. The website is kitchen-kit.co.uk. For any data-protection questions, contact hello@kitchen-kit.co.uk. Kitchen Kit is the data controller for the personal data we hold.

2. What personal data we collect

Information you give us

  • Newsletter sign-up: your email address, and optionally your first name.
  • Contact form: your name, email address, subject, and message.
  • Comments (if enabled): your name, email address, comment content, and IP address (collected automatically by the comment system for spam prevention).

Information collected automatically

  • Standard server logs: IP address, browser type and version, operating system, referring URL, timestamps, and pages viewed. Used for security and basic site analytics.
  • Google Analytics 4 / Microsoft Clarity (or equivalent): anonymised usage data including pages viewed, time on page, device type, and approximate location (city level). Used to improve the site.
  • Cookies: see Section 7 below.

Information from third parties

  • Amazon Associates: we receive aggregate, anonymised reports about clicks and conversions on our affiliate links. We do not receive any individual purchase or personal data from Amazon.

3. How we use your personal data and the lawful basis

  • To send you the newsletter, only after you have explicitly opted in. Lawful basis: your consent (UK GDPR Art. 6(1)(a)).
  • To respond to messages you send via the contact form or by email. Lawful basis: legitimate interest in providing customer support (UK GDPR Art. 6(1)(f)).
  • To run, secure and improve the website (analytics, server logs, anti-spam). Lawful basis: legitimate interest in operating a working, secure website (UK GDPR Art. 6(1)(f)).
  • To track affiliate-link clicks for revenue reporting. Lawful basis: legitimate interest in operating an ad-supported business model. No personally identifying information is collected via affiliate tracking.
  • To comply with legal obligations (e.g. tax records, requests from law enforcement). Lawful basis: legal obligation (UK GDPR Art. 6(1)(c)).

4. Who we share your data with

Kitchen Kit does not sell, rent, or trade your personal data. We share it only with the third-party service providers required to operate the site, and only the minimum data they need:

  • Email service provider (ConvertKit / Beehiiv / Kit, or equivalent) — to send the newsletter. Stores: your email and any name you provided.
  • Hosting provider (Cloudways / Kinsta / SiteGround, or equivalent) — to host the website. Stores: server logs (IP, requests).
  • Google (Google Analytics, Google Search Console) — for site analytics and Search Console performance data. Stores: anonymised usage data, cookie identifiers.
  • Microsoft (Clarity, if used) — for session-recording-based UX analytics. Stores: anonymised session data.
  • Cloudflare (or equivalent CDN) — for site performance and DDoS protection. Stores: IP addresses, request metadata.
  • Amazon (Associates Programme) — when you click an affiliate link, Amazon’s cookies are set on your device. Amazon’s privacy policy then applies. Kitchen Kit does not receive personal data from Amazon.

All third parties named above are bound by their own GDPR-compliant privacy terms. Where they’re outside the UK/EEA, transfers are protected by Standard Contractual Clauses or equivalent safeguards.

5. How long we keep your data

  • Newsletter subscribers: until you unsubscribe (one-click link in every email). After unsubscribing, your email is retained for 30 days then permanently deleted.
  • Contact form / email correspondence: 24 months after the last interaction, then deleted unless still needed for an ongoing matter.
  • Server logs: 90 days, then automatically deleted.
  • Google Analytics data: retained per Google’s default retention (currently 14 months).
  • Tax / financial records: 6 years, as required by HMRC.

6. Your rights under UK GDPR

You have the following rights regarding your personal data. To exercise any of them, email hello@kitchen-kit.co.uk.

  • Right of access — request a copy of the personal data we hold about you.
  • Right to rectification — request correction of inaccurate or incomplete data.
  • Right to erasure (‘right to be forgotten’) — request deletion of your data, subject to legal obligations.
  • Right to restrict processing — request that we stop processing your data while a query is resolved.
  • Right to data portability — receive a machine-readable copy of data you provided to us.
  • Right to object — object to processing based on legitimate interest, including direct marketing.
  • Right to withdraw consent — at any time, including unsubscribing from the newsletter.
  • Right to lodge a complaint — with the UK Information Commissioner’s Office (ICO) at ico.org.uk if you’re unhappy with how we handle your data.

We will respond to all requests within 30 days. There is no charge for reasonable requests.

7. Cookies

Kitchen Kit uses cookies and similar technologies. A cookie banner is shown on your first visit, allowing you to accept or reject non-essential cookies.

Strictly necessary cookies (always on)

  • Session cookies needed for the site to function (e.g. remembering your cookie-banner choice, security tokens).

Analytics cookies (only with consent)

  • Google Analytics 4 — measures site usage. IP anonymisation enabled.
  • Microsoft Clarity (if used) — heatmap and session recording, with personally identifying inputs masked.

Affiliate / advertising cookies

  • Amazon Associates — set by Amazon when you click a ‘Buy on Amazon UK’ link. Used to attribute any subsequent purchase to Kitchen Kit. We do not see your purchase data.

You can manage cookies via your browser settings or via the cookie banner’s ‘Cookie Settings’ link in the site footer.

8. Data security

We use HTTPS site-wide, regular software updates, strong passwords, two-factor authentication on all administrative accounts, and a reputable hosting provider with built-in security. No system is 100% secure, but we take reasonable steps to protect your data. In the unlikely event of a personal-data breach affecting you, we will notify you and the ICO within 72 hours where required by law.

9. Children’s privacy

Kitchen Kit is not directed at children under 16 and we do not knowingly collect personal data from children. If you believe a child has provided us with their data, please email hello@kitchen-kit.co.uk and we will delete it.

10. International data transfers

Some of our service providers (e.g. Google, Amazon) are based outside the UK. Where personal data is transferred internationally, we rely on the UK Government’s adequacy regulations, Standard Contractual Clauses, or equivalent safeguards as required by UK GDPR.

11. Changes to this policy

We may update this policy from time to time to reflect changes to the site, services, or legal requirements. The ‘Last updated’ date at the top will change accordingly. Material changes (e.g. new categories of data collection) will be communicated via the newsletter where you have opted in.

12. How to contact us

For any privacy questions or to exercise your data rights, email hello@kitchen-kit.co.uk. We aim to respond within 5 working days.

If you remain unhappy with how we have handled your data, you can complain to the Information Commissioner’s Office (ICO) at ico.org.uk or by phone on 0303 123 1113.