Nomad PassportNomads Cup website

Privacy notice

Version 1.3 · Last updated 10 August 2026

This notice explains how Nomad's Cup uses personal information when you use our website, order from a table, reserve a table, join our mailing list or use the Nomad Passport loyalty scheme.

Who is responsible for your information?

Nomad's Cup is the data controller for the personal information described in this notice.

129 Newbould Lane, Sheffield, S10 2PL
Email: mateusz@nomadscup.co.uk

What information we collect

Website visitors

Order at Table customers

Table reservation customers

Newsletter subscribers

Nomad Passport members

Why we use your information and our lawful basis

PurposeTypical informationLawful basis
Receive, manage and fulfil table reservations and waitlist requestsContact details, party size, date/time, preferences, assigned table/area, booking status and audit historyPerformance of our agreement with you to arrange the requested reservation and our legitimate interests in managing venue capacity accurately
Receive and fulfil Order at Table requestsTable, basket, order status, guest details or linked Passport, and payment statusPerformance of our agreement with you to provide the ordered food/drinks and our legitimate interests in operating the service accurately
Operate Nomad Passport, award stamps/rewards and provide secure account accessAccount, membership and loyalty activityPerformance of our agreement with you to provide the loyalty scheme
Verify the person presenting a live Passport and protect rewards/benefits from sharing or misusePassport photograph, live rotating QR verification and limited verification/audit recordsPerformance of the loyalty service and our legitimate interests in preventing misuse and protecting member benefits
Assign membership levels and provide level-specific benefitsReward-cycle milestones, current level, benefit eligibility and benefit-use historyPerformance of the loyalty scheme and our legitimate interests in operating member rewards consistently
Protect the website, staff portal and loyalty scheme from misuseSecurity logs, IP/device information, transaction/audit historyOur legitimate interests in security, fraud prevention and protecting the scheme
Send newsletters, offers and promotional updatesEmail, name and consent recordConsent. You can withdraw it at any time
Send essential Passport messages such as access links and reward notificationsEmail and Passport activityPerformance of the loyalty service and our legitimate interests in administering it
Respond to privacy requests and legal obligationsAccount data and request/audit recordsLegal obligation and, where relevant, legitimate interests

What is required and what is optional?

For Nomad Passport, your first name and email address are required so we can create and securely return you to your account. Your surname and phone number are optional. A clear, recent photograph of you is required to activate the live in-store Passport verification used for protected rewards and member benefits. If you do not add a photograph, the account can remain on record but the live QR and protected reward/benefit verification cannot be used. Marketing is always optional and is not required to use the loyalty scheme.

For online table reservations, we need a name, valid email address, party size and requested date/time. A phone number and seating notes are optional. Nomad Passport membership is not required to reserve a table. Staff-created walk-ins/bookings may be recorded without an email address where appropriate.

For the newsletter, an email address and an affirmative marketing choice are required. A first name is optional.

Marketing

We only send marketing emails where you have made an affirmative choice to receive them. Newsletter and Passport marketing preferences are recorded so we can demonstrate and respect that choice. Where you are a Passport member, opted-in marketing may be selected for an audience based on your membership level, whether you have a reward available or how recently you have used the loyalty scheme. This targeting never overrides an unsubscribe. Every marketing email includes an unsubscribe route, and Passport members can also change their preference from their Passport.

Withdrawing marketing consent does not stop essential account-access, security or reward messages that are necessary to operate Nomad Passport.

Table reservations

Online reservations use the shared Nomads Cup venue-capacity system to check available areas, tables and approved table combinations. Pending booking requests can temporarily hold suitable capacity while staff review them, helping to avoid overlapping reservations. Customers can use Nomad Passport or a secure guest management link to view, request changes to or cancel eligible bookings. Exact internal table allocations may be changed by staff before arrival.

Booking reminder emails may be sent before a confirmed reservation where reminders are enabled. These are service messages connected with the reservation rather than marketing. If deposits or online reservation payments are introduced later, this notice will be updated to identify the payment provider and relevant information sharing.

Order at Table and payments

The Order at Table service is operated within the Nomads Cup website. Orders and Reservations use the same live table-session layer so a seated booking, staff-recorded walk-in or submitted QR order can protect the physical table from overlapping allocation. Orders placed by different people at a seated booking may belong to the same visit while each person’s Nomad Passport identity, rewards and benefits remain separate. Completing an individual order does not itself mark the table vacant; staff clear the live table session when the party leaves. In the initial configuration, orders are sent to the internal Nomads Order Board and staff transfer them to the café till manually. Payment is collected using the existing till/card-reader process. If an online payment or direct POS connector is enabled in future, this notice will be updated to identify the relevant provider and the information shared with it.

Who we share information with

We do not sell your personal information to advertisers. We may use service providers that host or support the website/database, deliver email or provide other infrastructure needed to operate the service. Those providers only receive information needed for their role and are expected to handle it securely and in accordance with applicable data-protection requirements.

We may also disclose information where required by law, to establish or defend legal claims, or to protect the business, customers or service against suspected misuse.

Third-party website services

The public website uses or links to services such as Google Maps, Google-hosted fonts, Google review content and social-media pages. When these resources are loaded or you follow those links, the third-party provider may receive technical information such as your IP address and browser details under its own privacy terms. Nomad Passport account data is not provided to those services simply because you hold a Passport.

International transfers

Some technology providers may process technical or service data outside the UK. Where a transfer of personal information requires a UK GDPR safeguard, Nomads Cup will use an appropriate transfer mechanism or a provider covered by an applicable adequacy arrangement.

How long we keep information

Active Passport account information is kept while the account is in use. Replaced Passport photographs are removed, and the stored photograph is deleted when an approved account-deletion/anonymisation request is completed. Personal contact details are anonymised while non-identifying loyalty, membership-level and benefit-use ledger records may be retained where reasonably necessary for security, fraud prevention and audit integrity.

Newsletter subscription information is kept while you remain subscribed. After an unsubscribe, we may retain a limited suppression record so that we can continue to respect the request not to send marketing. Security and audit records are kept only for as long as reasonably necessary for security, troubleshooting, fraud prevention, legal or record-keeping purposes.

When you replace a Passport photograph, the previous image is removed. When an approved account-deletion/anonymisation request is completed, the stored Passport photograph is deleted and direct photo-verification fields are cleared. Table orders and table reservations linked to that Passport are detached from the account and customer-entered contact/free-text fields are removed where appropriate, while non-identifying order, booking, level, benefit and loyalty-ledger history may remain where needed to preserve transaction and audit integrity.

Your rights

Depending on the circumstances, UK data-protection law may give you rights to access your personal information, correct it, request erasure, restrict processing, object to certain processing and receive certain information in a portable format. Where processing is based on consent, you can withdraw that consent at any time without affecting earlier lawful processing.

Nomad Passport members can download a customer-facing copy of their main account, loyalty data and linked reservation history, change their marketing preference and request account deletion from the Passport. You can also contact us directly if you need a correction or a broader data-rights request.

Deletion and loyalty records

When a Passport deletion request is approved, direct contact details are anonymised and the account is archived. Non-identifying loyalty ledger records may remain where reasonably necessary to preserve transaction integrity, prevent abuse and maintain security/audit records.

Cookies, sessions and the installed Passport

We use essential cookies/session identifiers to secure forms, keep authenticated users signed in and protect Admin, Stamper and Passport access. These are used to provide and secure the requested service rather than for advertising.

If you add Nomad Passport to your Home Screen as a web app, a secure remembered session can be used so the installed Passport opens directly to your account. You can sign out to revoke that remembered customer access.

Automated processing and security monitoring

We do not use Nomad Passport to make solely automated decisions that have legal or similarly significant effects on customers. Membership levels are assigned automatically from completed reward-cycle milestones under the published scheme rules; administrators can review or override a level with an audit reason. The system can also apply automated security controls such as temporary login lockouts, reject expired live QR codes and flag unusual loyalty activity for administrator review.

How we protect information

We use measures including HTTPS, restricted administration access, hashed passwords/PINs, trusted-device controls for staff screens such as Passport Stamper and the Order Board, server-side rate limits, secure session tokens, CSRF protection, audit records, short-lived cryptographically signed live Passport QR codes, private customer-photo storage and restricted access to application/configuration files. No internet service can be guaranteed completely risk-free, so these measures are reviewed as the service develops.

Complaints

Please contact us first at mateusz@nomadscup.co.uk so we can try to resolve a concern. You also have the right to complain to the UK Information Commissioner’s Office. Information about making a data-protection complaint is available at ico.org.uk.

Changes to this notice

We may update this notice when the website, loyalty scheme or legal requirements change. The version and updated date shown at the top identify the notice currently in use.