Only Farmers

Privacy Policy

Last updated: 14 August 2026

How Only Farmers collects, uses, shares, and protects personal data.

Operated by:

Only Farmers Limited

Registered in England & Wales | Company No. 17058134

Registered address: 27 Mortimer Street, London, W1T 3BL

Registered with the Information Commissioner’s Office (ICO) — data protection registration reference ZC152228.

privacy@onlyfarmers.co.uk

1. Introduction

Only Farmers Limited (“Only Farmers”, “we”, “us”, “our”) is the data controller for personal data collected through the Only Farmers platform (“Platform”), including our website at onlyfarmers.co.uk and our mobile application.

We are committed to protecting your privacy and processing your personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Data (Use and Access) Act 2025, and the Privacy and Electronic Communications Regulations 2003 (PECR).

This Privacy Policy explains what personal data we collect, why we collect it, how we use it, who we share it with, how long we keep it, and what rights you have. It applies to all users of the Platform, whether you are a Farmer, Guest, or Visitor.

This Privacy Policy should be read alongside our Terms & Conditions, Cookie Policy, and all other legal documents available at onlyfarmers.co.uk/legal.

2. Data Controller & Contact Details

The data controller for the purposes of applicable data protection law is:

Only Farmers Limited

Company No. 17058134

27 Mortimer Street, London, W1T 3BL

Only Farmers Limited is registered with the Information Commissioner’s Office (ICO) as a data controller. Data protection registration reference: ZC152228.

For privacy enquiries, data subject rights requests, or complaints:

Data Protection Contact: privacy@onlyfarmers.co.uk

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk or by calling 0303 123 1113.

3. Personal Data We Collect

The personal data we collect depends on how you interact with the Platform and whether you are a Farmer, Guest, or Visitor.

3.1 Data You Provide Directly

Account registration (Farmers and Guests): full name, email address, telephone number, postal address, date of birth, password (encrypted), and profile photograph (optional).

Farmer-specific data: farm or business name, business address, bank account details (for payouts), company registration number (if applicable), public liability insurance certificate, Gas Safety Certificate, food hygiene rating, alcohol licence details, animal exhibition licence details, and any other regulatory documentation required by our Terms & Conditions.

Booking data: dates, number of guests, special requirements (dietary, accessibility, medical ), and any messages exchanged between Farmers and Guests through the Platform messaging system.

Payment data: payment card details are collected and processed by Stripe, Inc. and are not stored by Only Farmers. We receive a tokenised reference, the last four digits of your card, the card type, and the billing address.

Reviews and content: any text, photographs, or other content you submit to the Platform, including reviews of experiences, reviews of products, Listing descriptions, and messages.

Jobs board data: if you create a Work Profile, we collect your stated skills, experience, qualifications, availability, preferred location, and any other information you include. If you post a Job Posting, we collect the role description, location, pay rate, and requirements you provide. Messages between Farmers and applicants sent through the Platform are also collected.

Marketplace and product data: if you list or purchase products, we collect product descriptions, photographs, prices, delivery addresses, dispatch and tracking information, and purchase history. For Only Farmers Shop purchases, we collect the same data and process it as the retailer.

Delivery addresses: where you purchase a physical product for delivery, we collect your delivery name and address. This data is shared with the Seller (or with our delivery partner for Only Farmers Shop products) to fulfil the order.

Correspondence: any communications you send to us by email, through the Platform, or by other means.

Identity and age verification: where age verification or identity checks are required, we may collect government-issued identification documents, biometric data (facial age estimation), or Open Banking verification data. This data is processed solely for the purpose of verification and is deleted promptly once verification is complete.

3.2 Special Category Data

Some of the personal data we collect may constitute ‘special category data’ under Article 9 of the UK GDPR, which requires an additional legal basis for processing. This includes:

We do not process special category data for any purpose other than those described above. We do not process data concerning racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, or sexual orientation.

3.3 Data We Collect Automatically

Device and technical data: IP address, browser type and version, operating system, device type, unique device identifiers, screen resolution, and language settings.

Usage data: pages visited, features used, search queries, click patterns, session duration, referring URL, and interactions with Listings.

Location data: approximate location derived from your IP address. We do not collect precise GPS location data unless you explicitly grant permission through your device settings, which you may withdraw at any time.

Cookie data: information collected through cookies and similar technologies as described in our Cookie Policy, available at onlyfarmers.co.uk/legal.

3.4 Data We Receive from Third Parties

Stripe: transaction status (successful, failed, refunded), payout initiation and completion status, chargeback and dispute details (including dispute reason codes), fraud risk scores, and payment method metadata (card brand, country of issue, expiry status). Stripe does not share your full card number with us.

Social login providers: if you register or log in using a third-party service (such as Apple or Google), we receive the following categories of data from that provider, as permitted by your settings with them: full name, email address, profile photograph (if available), and a unique account identifier. We do not receive your password from the social login provider.

Publicly available data: we may collect publicly available information about Farmers’ businesses (such as Food Hygiene Ratings from the Food Standards Agency, Companies House registration data, or local authority licensing records) to verify Listing accuracy and regulatory compliance.

Age verification providers: where a third-party age verification provider is used, we receive a pass/fail verification result and, where applicable, an estimated age range. We do not receive the underlying identity document or biometric data held by the provider.

3.5 Is Providing Your Data Mandatory?

Providing certain personal data is a contractual requirement in order to use the Platform. Specifically:

Providing age verification data is a statutory requirement where verification is mandated by the Online Safety Act 2023. If you do not complete age verification when required, you will not be able to access the relevant features of the Platform.

Providing special requirements (dietary, accessibility, medical) is entirely voluntary. If you choose not to provide this information, we will not be able to communicate your needs to the Farmer, and the Farmer may not be able to accommodate them.

All other data described in Section 3.3 (automatic collection) is collected as part of the normal operation of the Platform and does not require a specific action from you.

4. How and Why We Use Your Data

We process your personal data for the purposes set out below. For each purpose, we have identified the legal basis we rely on under the UK GDPR.

Purpose Data Used Legal Basis
Creating and managing your account Name, email, password, phone, date of birth Contract performance (Art. 6(1)(b))
Processing Bookings and payments Booking details, payment token, contact details Contract performance (Art. 6(1)(b))
Paying out Farmers Bank account details, Booking records, payout amounts Contract performance (Art. 6(1)(b))
Verifying Farmer compliance (insurance, licences, safety certificates) Insurance certificates, Gas Safety Certificates, food hygiene ratings, alcohol and animal licences Legitimate interests (Art. 6(1)(f)) — ensuring Guest safety and maintaining trust in the Platform
Age verification and identity checks ID documents, biometric data, Open Banking data Legal obligation (Art. 6(1)(c)) — Online Safety Act 2023; explicit consent (Art. 9(2)(a)) for biometric data
Communicating with you about your account, Bookings, and support queries Name, email, phone, message content Contract performance (Art. 6(1)(b))
Publishing reviews and Farmer responses Name, review text, photographs Legitimate interests (Art. 6(1)(f)) — enabling informed Guest decisions and maintaining an honest marketplace
Sharing Guest details with Farmers to fulfil a Booking Name, contact details, special requirements Contract performance (Art. 6(1)(b)); explicit consent (Art. 9(2)(a)) for any health or dietary data
Fraud prevention, chargebacks, and platform security Payment data, IP address, device data, account activity Legitimate interests (Art. 6(1)(f)) — protecting Only Farmers, Farmers, and Guests from financial loss and fraudulent activity
Content moderation and safety (including OSA compliance) User content, reports, account data Legal obligation (Art. 6(1)(c)) — Online Safety Act 2023
Improving the Platform, analytics, and product development Usage data, device data, aggregated Booking data Legitimate interests (Art. 6(1)(f)) — understanding how the Platform is used to fix issues, improve features, and develop new services
Sending marketing communications (email, push notifications) Name, email, preferences, Booking history Consent (Art. 6(1)(a)); or PECR soft opt-in for existing customers where marketing relates to similar services
Displaying personalised Listing recommendations (profiling) Location, search history, Booking history, preferences Legitimate interests (Art. 6(1)(f)) — showing relevant content to improve user experience (see Section 4.1; you may opt out)
Complying with tax reporting obligations (including DAC7/OECD) Farmer name, address, tax identification, income received through Platform Legal obligation (Art. 6(1)(c)) — HMRC reporting
Responding to legal requests, court orders, and regulatory enquiries Any relevant personal data Legal obligation (Art. 6(1)(c))
Handling Damage Reports and disputes Booking details, photographs, correspondence, payment data Legitimate interests (Art. 6(1)(f)) — resolving disputes fairly and recovering losses for Farmers
Displaying Job Postings and matching Farmers with applicants Job Posting details, Work Profile data, messages, location Contract performance (Art. 6(1)(b))
Processing product purchases and delivery Product details, delivery address, payment token, dispatch and tracking data Contract performance (Art. 6(1)(b))
Operating the Only Farmers Shop (direct retail) Purchase details, delivery address, payment data, returns data Contract performance (Art. 6(1)(b)) — Only Farmers is the retailer
Facilitating product returns and refunds Order details, return reason, delivery tracking, refund amount Legal obligation (Art. 6(1)(c)) — Consumer Rights Act 2015 and Consumer Contracts Regulations 2013

Where we rely on legitimate interests, we have conducted a balancing test to ensure that our interests do not override your fundamental rights and freedoms. You may request a copy of our legitimate interests assessments by contacting privacy@onlyfarmers.co.uk.

4.1 Profiling

We use profiling (as defined in Article 4(4) of the UK GDPR) in a limited way to personalise your experience on the Platform. Specifically, we analyse your location data, search history, Booking history, and stated preferences to display Listing recommendations that are likely to be relevant to you (for example, showing “Coming Up Near You” results on the home screen).

This profiling does not produce legal effects or similarly significantly affect you. It is used solely to improve the relevance of content displayed to you. You can opt out of personalised recommendations at any time by adjusting your preferences in your account settings. If you opt out, you will still see Listings, but they will not be tailored to your browsing or Booking history.

We do not use profiling to make automated decisions about your ability to book, your pricing, or your access to any feature of the Platform.

5. Who We Share Your Data With

We share your personal data only where necessary and only with the following categories of recipients:

Farmers and Guests. When a Booking is confirmed, we share the Guest’s name, contact details, and any special requirements with the relevant Farmer so that the Booking can be fulfilled. Similarly, we share the Farmer’s contact details and Listing address with the Guest. Farmers are independent data controllers for any personal data they receive about Guests and must process it in accordance with Section 4.9 of our Terms & Conditions.

Stripe, Inc. Our payment processor. Stripe processes payment card data, bank account details, and transaction information on our behalf and as an independent data controller for its own fraud prevention and regulatory compliance purposes. Stripe’s privacy policy is available at stripe.com/privacy. Stripe is certified under the EU-US Data Privacy Framework.

Clerk, Inc. Our authentication provider. Clerk processes your email address, your name, and your sign-in credentials, including the identity details supplied by Apple or Google where you choose to sign in with those services, in order to create your account, verify that it belongs to you, and keep your sessions secure.

Stream.io, Inc. Our chat infrastructure provider. Stream processes and stores the content of messages you send through the Platform, together with any attachments, your display name, and your profile photo, so that conversations can be delivered and remain available to you and the person you are messaging.

Functional Software, Inc. (Sentry). Our error monitoring provider. When the app or the Platform encounters a fault, Sentry receives technical diagnostic data including your device type, app version, and the screen you were on, together with an account identifier. For a sample of sessions in which an error occurs, this includes a visual recording of the app screen in which all text and images are masked before the recording leaves your device.

Mapbox, Inc. Our mapping provider. When a map is displayed, Mapbox receives your IP address and the map area being viewed in order to serve the map imagery.

Hosting and infrastructure providers. We use cloud infrastructure providers (such as Amazon Web Services or Google Cloud Platform) to host the Platform and store data. These providers act as data processors under written data processing agreements and process data within the UK or EEA where possible.

Analytics providers. We use PostHog to understand how the Platform is used. Where possible, data is anonymised or pseudonymised before processing. Details of the cookies and tracking technologies used are set out in our Cookie Policy.

Communication providers. We use third-party email and push notification providers to send transactional and marketing communications on our behalf. Push notifications to the mobile app are delivered by OneSignal, Inc., which receives your device push token, your device type, and an account identifier in order to deliver the notifications you have chosen to receive.

Age verification providers. Where age verification is required, we may share limited personal data with a third-party age verification provider. Data is processed solely for the purpose of verification and is not retained by the provider beyond what is necessary to complete the check.

Professional advisors. We may share personal data with our legal, accounting, and insurance advisors where reasonably necessary for the provision of professional services to Only Farmers.

Law enforcement and regulators. We may disclose personal data to law enforcement agencies, courts, regulators (including Ofcom, the ICO, the FCA, HMRC, the Equality and Human Rights Commission, and the Food Standards Agency), or other public authorities where we are required or permitted to do so by law, or where disclosure is necessary to protect the rights, property, or safety of Only Farmers, our users, or the public. Content involving CSAM will be reported to the Internet Watch Foundation and the National Crime Agency without delay.

Collections agencies. Where amounts are owed to Only Farmers or to a Farmer and cannot be recovered through the Platform, we may share limited personal data with a third-party collections agency as set out in our Terms & Conditions.

Business transfers. In the event of a merger, acquisition, or sale of substantially all of Only Farmers’ assets, your personal data may be transferred to the acquiring entity. We will notify you of any such transfer and any change in data controller.

Sellers (marketplace). When you purchase a product from a third-party Seller through the Platform, we share your name and delivery address with the Seller so that the order can be fulfilled. The Seller is an independent data controller for any personal data they receive and must process it in accordance with applicable data protection law.

Delivery and logistics providers. For Only Farmers Shop orders and, where applicable, marketplace orders, we may share your name, delivery address, and order details with third-party delivery and logistics providers for the purpose of fulfilling your order. These providers act as data processors under written data processing agreements.

We do not sell your personal data to any third party. We do not share your personal data with advertisers for their own marketing purposes.

6. International Transfers

Your personal data is primarily stored and processed within the United Kingdom. However, some of our service providers are based in the United States or other countries outside the UK. These include Stripe (payments), Clerk (authentication), Stream (chat), OneSignal (push notifications), Mapbox (maps), and PostHog (analytics).

Where we transfer personal data outside the United Kingdom, we ensure that appropriate safeguards are in place in accordance with Chapter V of the UK GDPR. These safeguards include:

You may request a copy of the safeguards we rely on for any specific international transfer by contacting privacy@onlyfarmers.co.uk.

7. How Long We Keep Your Data

We retain personal data only for as long as is necessary for the purpose for which it was collected, or as required by law. The retention periods below are our standard maximum periods; where data is no longer necessary before the stated period expires, we will delete or anonymise it earlier. We may retain data beyond the stated period where there is an ongoing legal dispute, regulatory investigation, unresolved complaint, or other lawful reason to do so.

Data Category Retention Period Reason
Account data (active accounts) Duration of account Contract performance
Account data (after closure) 6 years from closure Limitation Act 1980; tax and legal obligations
Booking and transaction records Retained indefinitely. If you delete your account, the booking record is kept but your name, email address, telephone number and any requests you made are removed from it Tax, accounting, and legal obligations; the Farmer needs the record of what was booked and paid
Payment card tokens Until card is removed or account closed Contract performance (Damage Reports, refunds)
Farmer compliance documents (insurance, licences, safety certs) Duration of Listing plus 6 years Regulatory compliance and legal claims
Messages between Farmers and Guests Retained indefinitely. If you delete your account, your messages remain in the conversation but are no longer attributed to you Dispute resolution and platform safety; the other person in the conversation keeps their own record of it
Reviews Retained indefinitely. If you delete your account, the review stays published but is no longer attributed to you or linked to your profile Platform transparency; removing reviews on account closure would misrepresent a Farmer's rating history
Community posts and comments Retained indefinitely. When you delete your account, posts and comments you made in the community are kept but are no longer attributed to you. They appear as “Deleted Account” and are not linked to your profile or contact details We do this so that conversations other members took part in remain intact
Identity and age verification data Deleted within 30 days of verification Data minimisation
Special category data (dietary, health, accessibility requirements) 12 months from Booking date, or until any related dispute is resolved Data minimisation; retained shorter than general Booking records as not needed for tax or accounting
Marketing consent records Duration of consent plus 2 years Demonstrating consent (accountability)
Server logs and security data 12 months Security monitoring and incident response
Analytics data (anonymised/aggregated) Indefinite Not personal data once anonymised
Correspondence (support queries, complaints) 3 years from resolution Service improvement and legal claims
HMRC/DAC7 tax reporting data 7 years from end of tax year HMRC requirements
Work Profiles and job application data Duration of account plus 1 year, or 6 months after the applicant’s last activity if no account Service provision; data minimisation
Job Postings Duration of Listing plus 6 months Service provision; dispute resolution
Product purchase and delivery records 6 years from purchase date Tax, accounting, legal obligations, and Consumer Rights Act claims (6-year limitation)
Delivery addresses Duration of account or 6 years from last purchase, whichever is shorter Contract performance; data minimisation
Product reviews Duration of Product Listing plus 1 year Platform transparency
Content moderation and OSA reports 3 years from action taken Regulatory compliance (OSA 2023)
Data relating to under-18 users (accounts terminated) Deleted immediately upon identification T&Cs age restriction (18+) and data minimisation

8. Your Rights

Under the UK GDPR and the Data (Use and Access) Act 2025, you have the following rights in relation to your personal data:

To exercise any of these rights, contact us at privacy@onlyfarmers.co.uk. We will respond to your request within one month. In complex cases or where we receive a high volume of requests, we may extend this by a further two months, in which case we will notify you within the first month.

We will not charge a fee for responding to a rights request unless the request is manifestly unfounded or excessive. We may ask you to verify your identity before processing your request.

9. Children’s Data

The Platform is restricted to users aged 18 and over for all account-related activity, including registration, making Bookings, purchasing products, listing as a Farmer, and using the jobs board. Users under the age of 18 may only browse public Listings on the Platform; they may not create an account, make a Booking, or otherwise transact through the Platform.

We may use age verification (which may include date of birth checks, ID document checks, biometric facial age estimation, or Open Banking verification) to confirm that account holders are aged 18 or over. Where we are unable to verify that a user is 18 or over, we will not permit account registration or transactional use of the Platform.

We do not knowingly allow any person under the age of 18 to register an account, make a Booking, or otherwise transact through the Platform. If we become aware that a user under 18 has created an account or transacted on the Platform in breach of our Terms & Conditions, we will terminate the account without notice and delete the associated personal data, save where we are required to retain it for legal or regulatory purposes.

Where users under the age of 18 browse the Platform as Visitors (without an account), we still process limited personal data about them (such as device, technical, usage, approximate location and cookie data described in Section 3.3). We process this data in accordance with the ICO’s Children’s Code (Age Appropriate Design Code) and apply the following safeguards to all browsing users where we cannot confirm that they are 18 or over: default privacy settings are set to the highest level; precise location data is not collected; personalised recommendations based on profiling are not applied by default; marketing communications are not served; and we do not use nudge techniques or design features that encourage users to weaken their privacy settings. Non-essential cookies and similar tracking technologies are only set with consent, as described in Section 10 and our Cookie Policy.

10. Cookies and Tracking Technologies

We use cookies and similar technologies (such as local storage, pixels, and SDKs in our mobile app) to operate the Platform, remember your preferences, understand how you use the Platform, and serve relevant content.

Full details of the cookies we use, their purposes, and how to manage your cookie preferences are set out in our Cookie Policy, available at onlyfarmers.co.uk/legal.

In summary, we use the following categories of cookies:

You can manage your cookie preferences at any time through the cookie settings on our website or through your browser settings. Withdrawing consent for non-essential cookies will not affect the core functionality of the Platform.

11. Security

We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, loss, destruction, or alteration. These measures include:

No system is completely secure. In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you and the ICO in accordance with Article 33 and Article 34 of the UK GDPR.

12. Marketing Communications

We will only send you marketing communications (including promotional emails, push notifications, and newsletters) where you have given your consent or where we are permitted to do so under the PECR soft opt-in (i.e., where you are an existing customer and the marketing relates to similar services to those you have previously used).

You can opt out of marketing communications at any time by: clicking the “unsubscribe” link in any marketing email; adjusting your notification preferences in your account settings; or contacting us at privacy@onlyfarmers.co.uk.

Opting out of marketing will not affect transactional communications (such as Booking confirmations, payout notifications, safety alerts, or account-related messages), which we will continue to send as necessary.

13. Third-Party Links and Services

The Platform may contain links to third-party websites or services (for example, Stripe’s payment pages, social media platforms, or external map providers). We are not responsible for the privacy practices of those third parties. We encourage you to read the privacy policies of any third-party services you interact with.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, in applicable law, or for other operational reasons. Where we make material changes, we will notify registered users by email and by prominent notice on the Platform at least 14 days before the changes take effect.

The “Last updated” date at the top of this Policy indicates when it was most recently revised. We encourage you to review this Policy periodically.

15. Contact Us

For any questions, concerns, or requests relating to this Privacy Policy or your personal data:

Only Farmers Limited

Company No. 17058134

27 Mortimer Street, London, W1T 3BL

Privacy & data protection: privacy@onlyfarmers.co.uk

General enquiries: hello@onlyfarmers.co.uk

Legal documents: onlyfarmers.co.uk/legal

Information Commissioner’s Office: ico.org.uk | 0303 123 1113

© 2026 Only Farmers Limited. All rights reserved. Registered in England & Wales.