Cococure Privacy Policy

Effective Date: 10/08/2026

At Cococure, we are dedicated to protecting and respecting your privacy. This policy outlines how we handle and secure your personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Please read this policy carefully to understand our practices regarding your data.


1. Who We Are

Cococure operates restaurants and nightclub venues (including Haus in Stratford, Cité in Aldgate and TWNTY7) and the website cococure.com. This privacy policy applies to our venues, our website and all interactions involving personal data collected by Cococure.


2. What Data We Collect and How We Collect It

Personal Data Collected at Entry

To ensure safety and compliance, we may collect specific personal information at entry:

  • Identification Data: Collected via ID scanning to verify age and identity upon entry. This data includes name, date of birth, age, gender, photo, and other relevant information visible on the ID.
  • Photographs: Taken as part of our ID verification process to help with guest identification.

CCTV Footage

Our premises are equipped with CCTV cameras for security and safety purposes, covering both public and restricted areas.

Bookings, Tickets and Payments

When you buy a ticket, join a guest list, book a table or make any other purchase, we collect the details needed to fulfil it: your name, email address, phone number, date of birth (where required for age-restricted entry), party details, what you bought, and payment records. Card payments are processed by Stripe — we never see or store your full card number. If you choose to save a card with us (for example to guarantee a guest-list entry or to pay with one tap), the card is stored by Stripe and we hold only a secure reference to it.

Website, Cookies and Similar Technologies

Our website uses cookies and similar technologies to remember your basket, keep the site secure, measure how visitors find and use the site (including which marketing channel or partner link brought you here), and — with your consent — support advertising measurement. You can manage advertising cookies through our consent banner.

When You Contact Us

If you message us on WhatsApp, by SMS, email or through our website forms, we keep a record of the conversation — including when you contacted us and what it was about — so we can help you faster next time.


3. How We Use Your Data

We collect and process your personal data to:

  • Verify identity and age for entry compliance.
  • Maintain a safe and secure environment within the venue.
  • Address any security incidents effectively.
  • Fulfil your bookings, tickets, table reservations and orders, and provide customer service.
  • Build a single customer record. We combine the information described above — your bookings and purchases, payments, visits to our venues (including door entry records), loyalty activity, and your messages to us — into one customer profile. We use this profile to recognise returning guests, calculate loyalty tiers and rewards, apply any credit you hold, personalise offers, and understand our business (for example, how many guests are new versus returning).
  • Send you marketing about Cococure events, offers and promotions, where we have your consent or a legitimate business interest. Every message includes a way to opt out, and we maintain a suppression list so opt-outs stick.
  • Measure and improve our marketing. With your consent where required, we share limited data (such as a hashed version of your email address, or the fact that a purchase happened) with advertising platforms including Meta (Facebook/Instagram), Google, TikTok and Snapchat, so we can measure our advertising and reach audiences similar to our guests. Hashing means the platform cannot read your email unless it already holds the same one.
  • Comply with legal and regulatory obligations, especially those relating to venue licensing, safety and accounting.
  • Provide the VIVA Scheme with customer details when customers have been involved in violent behaviour.

Legal Bases

We rely on: contract (fulfilling your bookings and purchases), legitimate interests (venue safety, fraud prevention, building our customer records, loyalty, and first-party marketing to existing customers), consent (advertising cookies and marketing where consent is required), and legal obligation (licensing, safety and accounting requirements).


4. Third-Party Data Processing

PatronScan

Cococure uses PatronScan to manage ID scanning and entry verification. PatronScan collects and processes data on our behalf as follows:

  • Data Verification: PatronScan checks ID data against its database of incidents reported across other venues, helping us ensure a safe environment for all guests.
  • Data Retention: For guests with no reportable incidents, data collected by PatronScan is stored securely for a maximum of 31 days before automatic deletion. If a guest is associated with a reportable incident, PatronScan may retain the data for up to 5 years to ensure compliance with security and safety standards.
  • Our own visit record: Separately from PatronScan’s systems, Cococure keeps a record of your visit — the venue, date and time of entry, and the name, date of birth, age and gender from your scanned ID, plus contact details where you have provided them — as part of your customer record with us. ID photographs are not kept in our customer records.

Please refer to PatronScan’s privacy policy for additional information on their data management practices.

VIVA Scheme

VIVA Scheme uses personal data to pursue and prosecute perpetrators of violent behaviour using CCTV and PatronScan data.

CCTV Data

Our CCTV system collects video footage solely for security purposes. This data is retained for a minimum of 31 days and up to a maximum of 60 days. After this period, footage is automatically deleted unless required for ongoing investigations or regulatory compliance.

Payments — Stripe

All card payments (online, at the door, and card machines at our venues) are processed by Stripe, Inc. Stripe holds your card details; we hold records of what was paid, when, and for what. Stripe may also process data for fraud prevention. See Stripe’s privacy policy for details.

Messaging Providers

We send booking confirmations, service messages and (where permitted) marketing via WhatsApp (through the WhatsApp Business Platform and our provider WATI), SMS (Twilio) and email. These providers process your contact details and message content on our behalf.

Advertising and Analytics Platforms

With your consent where required, we share limited event data (for example, that a purchase or booking happened, its value, and a hashed email address) with Meta, Google, TikTok and Snapchat for advertising measurement and audience building, and we use Google Analytics to understand website usage. We also record which marketing channel, partner or promoter link led to a booking. Where a booking is attributed to one of our event partners or promoters, they can see the booking and its value; they only see your personal contact details when they made the booking on your behalf — not when you booked yourself through their link.

Other Service Providers

We use carefully selected providers to run our website and systems, including hosting and content-delivery (Cloudflare), our point-of-sale provider (Toast) for food and drink orders at your table, and email delivery services. Each processes data only on our instructions.


5. Data Security

We implement appropriate security measures to protect your data from unauthorized access, disclosure, alteration, or destruction. This includes secure storage, restricted access to personal data, and the use of encryption where applicable. Our data partners, including PatronScan and Stripe, are also required to uphold stringent security protocols.


6. Data Retention Periods

Cococure retains personal data only for as long as is necessary for the purposes outlined in this policy:

  • ID and Photograph Data (PatronScan systems): Retained by PatronScan for up to 31 days for guests with no incidents, and up to 5 years if associated with a reportable incident.
  • Our customer records (bookings, purchases, visit history including door-entry records, loyalty activity and message history): retained while you remain a customer and for a reasonable period afterwards, unless you ask us to delete them (see your rights below).
  • Payment and transaction records: retained for up to 7 years to meet accounting and tax obligations.
  • CCTV Footage: Stored for a minimum of 31 days and a maximum of 60 days, after which it is deleted unless required for specific investigations.
  • Marketing opt-outs: kept indefinitely on our suppression list so that we never message you again after you opt out.

7. Your Data Protection Rights

Under the UK GDPR, you have the right to:

  • Access Your Data: Request a copy of the data we hold on you — including your customer record.
  • Rectify Your Data: Request corrections if you believe any personal data we hold is inaccurate.
  • Erase Your Data: Ask us to delete your customer record. We will do so unless we must keep specific records for legal reasons (for example transaction records for tax, or incident records for safety).
  • Restrict or Object to Processing: Limit or object to the processing of your data under certain conditions — including objecting to profiling for marketing purposes at any time.
  • Withdraw Consent: Where processing is based on consent (such as advertising cookies or marketing messages), withdraw it at any time.
  • Data Portability: Request the transfer of your data to another organization.
  • Complain to the ICO: If you feel your rights have been violated, you may contact the Information Commissioner’s Office (ICO), the UK’s data protection authority.

8. How to Contact Us

For questions about this privacy policy or to exercise your rights under the UK GDPR, please contact us at:

Email: [email protected]
Address: 8 Minories EC3N 1BJ
Phone: 0203 983 3790


9. Updates to This Policy

We may update this privacy policy periodically to reflect changes in our practices, legal requirements, or for other operational reasons. Any updates will be posted on our website, and significant changes will be communicated through our standard communication channels.


By visiting Cococure and engaging with our services, you acknowledge the terms outlined in this privacy policy. We thank you for choosing Cococure and for trusting us with your data.

Chat with us