Privacy Policy
Last updated: 18 May 2026
This Privacy Policy explains how Rawlings Commercial Limited, trading as Love My Cakes (“we”, “us”, “our”), collects, uses, stores and protects your personal information when you visit the website www.lovemycakes.co.uk, contact us, or place an order for our bespoke cakes and desserts.
We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Data (Use and Access) Act 2025, and the Privacy and Electronic Communications Regulations 2003 (PECR).
1. Who we are (Data Controller)
For the purposes of UK data protection law, the data controller is:
-
Company name: Rawlings Commercial Limited
-
Trading as: Love My Cakes
-
Company number: 02254330 (registered in England and Wales)
-
Registered office: 12 Bridge Road, Rudgwick, Horsham, West Sussex, RH12 3HD, United Kingdom
-
ICO registration number: ZC150295
-
Website: www.lovemycakes.co.uk
For any questions regarding this Privacy Policy or your personal data, please contact our designated contact for data protection matters:
-
Contact person: Maria Kovalikova
-
Email: maria@lovemycakes.co.uk
-
Phone: +44 7493 395714
2. What personal data we collect
Depending on how you interact with us, we may collect the following categories of personal data:
2.1 Information you provide directly
-
Contact and order details – your name, email address, telephone number, and delivery or collection address (where applicable);
-
Order information – the type of cake or dessert you have requested, design preferences, flavour choices, occasion details, requested date and time, and any personalised text (e.g. names or messages to be written on the cake);
-
Dietary information – any allergies, intolerances or dietary requirements you choose to share so that we can produce a safe product for you. This may include health-related information, which is treated as a special category of personal data and used solely for the purpose of fulfilling your order;
-
Correspondence – the content of any messages you send us by email, WhatsApp, the website contact form, or social media direct message;
-
Payment confirmation – proof of bank transfer or other payment evidence you send us. We do not store card numbers; payments are handled directly between you and your bank.
2.2 Information collected automatically when you visit the website
Our website is built using the Wix platform. When you visit the site, Wix automatically collects limited technical information on our behalf, including:
-
IP address and approximate location;
-
Browser type, operating system and device information;
-
Pages visited, time spent on the site, and referring website;
-
Cookies and similar storage technologies (see Section 8).
2.3 Information from social media
If you contact us via Instagram (@lovemycakes_sussex) or Facebook, we will receive whatever profile information and messages you choose to share through those platforms.
Children: Love My Cakes is not directed at children. We do not knowingly collect personal data from anyone under 16. If a cake is being ordered for a child, we only need the contact details of the adult placing the order.
3. Why we use your personal data and the lawful basis for doing so
Under UK GDPR we must have a valid lawful basis for every use of your personal data. The table below explains what we do with your data and why.
Purpose
Lawful basis
Responding to your enquiries and quoting for a bespoke order
Steps taken at your request prior to entering into a contract (Art. 6(1)(b) UK GDPR)
Producing your order, agreeing a delivery or collection time, and delivering or handing over the product
Performance of a contract (Art. 6(1)(b))
Recording and processing payment
Performance of a contract (Art. 6(1)(b))
Recording allergens and dietary requirements
Your explicit consent and/or substantial public interest in food safety (Art. 9(2)(a)/(g)); also legal obligation under food safety law
Keeping records of orders, invoices and correspondence for tax and accounting purposes
Legal obligation (Art. 6(1)(c)) – HMRC and Companies House record-keeping
Showing photographs of finished cakes on the website or social media
Legitimate interest in promoting our business (Art. 6(1)(f)); consent (Art. 6(1)(a)) where a customer is identifiable
Operating and securing the website, preventing fraud
Legitimate interests (Art. 6(1)(f))
Non-essential cookies and analytics
Your consent (PECR; Art. 6(1)(a))
4. Bespoke orders, deliveries and cancellations
All cakes and desserts produced by Love My Cakes are made to order to your specifications. Because they are bespoke perishable goods, made or clearly personalised to your requirements, the statutory right to cancel under the Consumer Contracts (Information, Cancellation and Additional Charges) Regulations 2013 does not apply once production has commenced (regulation 28(1)(b) and (c)). The delivery or collection date and time are agreed individually between you and us at the time of ordering.
This does not affect your statutory rights under the Consumer Rights Act 2015 if the product supplied is not of satisfactory quality, not as described, or not fit for purpose. Please contact us as soon as possible if you believe there is a problem with your order.
Full ordering, deposit and cancellation conditions are set out on the How to Order page of the website and any written quote you receive.
5. Who we share your personal data with
We do not sell your personal data. We only share it with the following categories of recipients where strictly necessary:
-
Website host – Wix.com Ltd. processes data submitted through the website on our behalf as a processor. See Wix’s privacy notice at wix.com/about/privacy.
-
Email provider – the service hosting our @lovemycakes.co.uk email inbox, used to send and receive correspondence with you.
-
Messaging platforms – if you contact us via WhatsApp (Meta), Instagram (Meta) or Facebook (Meta), your messages are processed by those platforms in accordance with their own privacy policies.
-
Payment – your bank and ours process bank-transfer payments. We do not receive or store your full card or account details.
-
HMRC, Companies House and our accountant – where required for tax, statutory accounts and record-keeping purposes.
-
Couriers or delivery helpers – only where a third party is used to deliver an order, and only the minimum information needed (name, delivery address, phone number).
-
Professional advisers and authorities – e.g. legal advisers, insurers, the police, or regulators where we are legally obliged to disclose information or to protect our legal rights.
6. International transfers
Some of the providers we use (such as Wix and Meta platforms) may store or process personal data outside the United Kingdom, including in the European Economic Area and the United States. Where data is transferred outside the UK, it is protected by one of the safeguards permitted by UK GDPR, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or the UK Extension to the EU–US Data Privacy Framework.
7. How long we keep your personal data
We only keep personal data for as long as is necessary for the purpose for which it was collected, and to meet our legal obligations:
-
Order enquiries that do not result in an order – up to 12 months from last contact;
-
Completed orders and related correspondence – at least 6 years after the end of the tax year in which the order took place, in line with HMRC and Companies Act requirements;
-
Allergen and dietary information – kept with the order record for the same period, so we can demonstrate compliance with food safety law;
-
Website analytics and cookie data – as set out in Section 8 below;
-
Photographs of finished cakes – retained indefinitely for portfolio purposes unless you ask us to remove an image in which you, your name or your message can be identified.
8. Cookies and similar technologies
Our website uses cookies and similar storage technologies. Cookies are small files placed on your device that help the site work, remember your preferences, and measure how it is used.
-
Strictly necessary cookies are set automatically – they are required for the site to function and for basic security. No consent is required for these under PECR.
-
Functional, analytics and marketing cookies (including any Wix analytics, Google Analytics, Meta Pixel or similar) are only set with your consent, which you provide through the cookie banner on first visit.
You can change or withdraw your cookie consent at any time by clearing cookies in your browser and revisiting the site, or by using the cookie settings link if displayed.
9. Marketing
We do not currently run a marketing newsletter or send promotional emails. If this changes in the future, we will only send marketing messages to you with your prior opt-in consent, in line with PECR, and every message will include an easy way to unsubscribe.
10. Your rights under UK GDPR
You have the following rights in relation to your personal data. To exercise any of them, please email maria@lovemycakes.co.uk. We will normally respond within one month and we will not charge a fee unless your request is manifestly unfounded or excessive.
-
Right to be informed – this Privacy Policy.
-
Right of access – to obtain a copy of the personal data we hold about you.
-
Right to rectification – to have inaccurate or incomplete data corrected.
-
Right to erasure (“right to be forgotten”) – to have your data deleted where there is no good reason for us to keep it (subject to legal record-keeping obligations).
-
Right to restrict processing – to limit how we use your data in certain situations.
-
Right to data portability – to receive a copy of the data you have provided in a structured, machine-readable format.
-
Right to object – to object to processing based on legitimate interests, and to direct marketing at any time.
-
Right to withdraw consent – where we rely on your consent, you can withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
-
Rights in relation to automated decision-making – we do not make decisions about you using fully automated means.
11. How to complain
If you are not happy with how we have handled your personal data, please contact us first so we have the chance to put things right.
You also have the right to lodge a complaint with the UK supervisory authority:
-
Information Commissioner’s Office (ICO)
-
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
-
Helpline: 0303 123 1113
-
Website: ico.org.uk
12. Security
We take appropriate technical and organisational measures to protect your personal data against accidental loss, unauthorised access, alteration or disclosure. These include strong passwords on email and Wix accounts, two-factor authentication where available, keeping devices up to date, and limiting access to order records to authorised personnel only.
No method of transmission over the internet is 100% secure, so we cannot guarantee absolute security of data sent via email or web forms.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in the law or in how we run the business. The “Last updated” date at the top of the page shows when the current version came into force. If we make a significant change, we will draw it to your attention by a notice on the website.
14. Contact
If you have any questions about this Privacy Policy, or you would like to exercise any of your rights, please contact:
Maria Kovalikova
Rawlings Commercial Limited (trading as Love My Cakes)
12 Bridge Road, Rudgwick, Horsham, West Sussex, RH12 3HD
Email: maria@lovemycakes.co.uk
Phone: +44 7493 395714
