Privacy Policy

At Cotta, we respect your privacy. This policy outlines how we collect, use, and protect your personal information when you visit our website, our app, or use our services.

VERSION 3.1, LAST UPDATED 3 AUG 2026

1. Information and Scope

Cotta Digital Services Limited ("Cotta," "we," "us," or "our") is committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, store, and share your information when you use our mobile application (the "App"), our website (cottavita.com), and our marketplace services (collectively, the "Services").

Cotta operates a marketplace connecting Customers with Partners (merchants). We primarily fulfil deliveries using our own employed drivers and vehicles, supported by Nash, a third-party logistics management platform used to assign drivers, plan routes, and track deliveries. On occasion, where our own delivery capacity is unavailable, we may use Stuart, a third-party delivery network, to complete a delivery. In all cases, your personal data is shared only to the extent necessary to fulfil your order

Company Information

  • Legal Entity: Cotta Digital Services Limited

  • Company Number: 16714780 (Registered in England & Wales)

  • Registered Office: 3rd Floor, 15 Half Moon Street, London, United Kingdom, W1J 7DZ

  • Data Controller: Cotta Digital Services Limited acts as the Data Controller for all Customer and Partner data collected through the App.

Age Restriction: Our Services are not directed at individuals under the age of 18. By using the App or our Services, you confirm that you are aged 18 or over. If we become aware that personal data has been collected from a person under 18, we will delete that data promptly.

2. Information We Collect

We Collect We adhere to the principle of Data Minimisation, collecting only the data necessary to provide the core functionality of our marketplace and delivery services.

2.1 Information You Provide Directly

  • Identity Data: First name, last name, and username.

  • Contact Data: Delivery address, billing address, email address, and telephone number. Note: We require a valid mobile phone number to send you delivery updates and to facilitate coordination between our delivery team and you.

  • Financial Data: Partial payment card details (e.g., last 4 digits). Full payment credentials are processed directly by our PCI-DSS compliant payment processor, Stripe, and are not stored on Cotta’s servers.

  • Profile Data: Your username, password, order history, feedback, and survey responses.

  • Browse Filters: Dietary and allergen filters (e.g. "Gluten-Free," "Vegan," "Halal") are available as search filters to help you find relevant products. These selections are not stored against your account or profile and are not retained once your session ends.

2.2 Information We Collect Automatically

When you interact with our App, we utilise device permissions and third-party Software Development Kits (SDKs) to collect:

  • Location Data: With your explicit consent, we collect your precise geolocation only while you are using the App (Foreground Permission). This data is used to:

    1. Verify that your delivery address is within our serviceable area.

    2. Display relevant Partners available in your vicinity.

    3. Enable efficient route optimisation for our drivers. (You may revoke location access at any time via your device settings. If you do so, you must manually enter your delivery address.)

  • Technical & Usage Data: Internet Protocol (IP) address, device model, operating system version, time zone, and app interaction logs (e.g., screen views, crash reports). With your consent, we use Google Analytics for Firebase and PostHog to collect this data to maintain App stability and performance and to understand how the App is used so we can improve it.

  • Device Identifiers: We collect the iOS Identifier for Vendor (IDFV), an Apple-assigned identifier used for analytics purposes and to route push notifications via OneSignal. The IDFV is specific to our app on your device and cannot be used to track you across third-party applications.

  • Advertising Identifiers: On iOS, the App uses Apple's App Tracking Transparency framework and asks your permission before accessing your device's advertising identifier (IDFA). On Android, the App may access your Google Advertising ID, which you can reset or delete, and opt out of ad personalisation, at any time in your device settings. Where you permit it, we use the advertising identifier to measure the performance of our marketing and to improve the App. If you do not grant permission, or you reset or delete the identifier, we do not use it.

  • Product Analytics (PostHog): We use PostHog, a product-analytics service hosted in the EU (eu.i.posthog.com; the US region is not used), to understand how the App is used so we can improve it. With your consent, we collect screen views and in-app interactions (for example “basket item added” or “checkout started”), app version, operating system, device model, language, a truncated/anonymised IP address, and a device or user identifier. 

  • How We Identify You for Analytics: Before you sign in, your analytics events use a randomly generated device identifier. When you sign in, this is linked to your account so we can understand your usage across sessions and devices. It does not by itself reveal your name or email, but it is pseudonymous personal data under UK GDPR because we can connect it to your account.

  • Data Excluded from Analytics: We maintain a blocklist of property names that are excluded from collection. We do not send your name, email address, postal address, phone number, payment card details, passwords or authentication tokens to PostHog, and sensitive screens such as Checkout and Add a Payment Card are excluded from capture entirely.

  • Analytics Consent Record: We record the fact and timing of your analytics consent decision, including if you decline, as part of our compliance obligations.

  • Cookies and Website Tracking: When you visit our website at cottavita.com, we may use cookies and similar tracking technologies. This is governed separately by our Cookie Policy, which explains the categories of cookies used, their purposes, and how to manage your preferences. The App itself uses SDKs and local device storage rather than browser cookies; the relevant disclosures for app-specific tracking are set out in this Privacy Policy.

2.3 Information Generated Through Order Fulfilment

When an order is placed and fulfilled, we generate and process:

  • Logistics & Tracking Data: Timestamps of order acceptance, pickup, and delivery; driver route data managed via Nash's logistics platform; and proof of delivery (which may include a photograph of the package at your location if you are unavailable to receive it personally).

3. How We Use It & Legal Basis

We process your personal data only where we have a lawful basis to do so under the UK GDPR.

Purpose / Activity

Type of Data

Lawful Basis for Processing

Account Registration

Identity, Contact

Performance of a Contract: Necessary to create your user profile and grant access to the marketplace.

Order Processing & Delivery

Identity, Contact, Financial, Location

Performance of a Contract: We require your location and contact details to fulfil your order and coordinate delivery.

Service Notifications

Contact (Phone/Email)

Performance of a Contract: Sending order confirmations and delivery updates via Twilio or similar providers.

Route Optimisation

Location, Address

Legitimate Interest: To enable efficient driver routing and minimise delivery times, processed via Nash's logistics platform.

Driver Safety & Fraud Prevention

Identity, Transaction, Usage

Legitimate Interest: To protect our delivery and operations staff from abusive behaviour and to detect fraudulent payment activity.

App Improvement & Analytics

Technical, Usage

Legitimate Interest: To analyse user behaviour (via Firebase) to improve App features and fix crashes.

Product Analytics & App Improvement

Technical, Usage

Consent (Article 6(1)(a)): With your consent, we analyse usage via Google Analytics for Firebase and PostHog to improve App features and fix crashes. Where you have an account, we may link your PostHog analytics identifier to your account record in HubSpot to understand how product usage relates to the support and communications you receive. Where you have consented to marketing communications, this linkage may also be used for marketing analysis.

Marketing Communications

Identity, Contact

Consent: We will only send you promotional offers if you have opted in. You may withdraw consent at any time.

Browse Filter Use

Filter selections (transient)

Legitimate Interest: We process dietary and allergen filter selections in real time solely to return relevant search results. These selections are not stored, retained, or linked to your profile. Because the data is not retained, no special category processing occurs under Article 9 UK GDPR.

Product analytics consent. Product analytics runs on your consent. No analytics events are sent before you grant consent on first launch, and none are sent if you decline. You can change your mind at any time in Account → Analytics Settings. Switching analytics off stops further events being sent and shuts down the PostHog SDK in the current session. For users with an account, your preference is saved to your account and maintained across devices and reinstalls. Events already collected remain stored for up to 2 months before automatic deletion; if you would like earlier deletion, contact hello@cottavita.com. Withdrawing consent does not affect the lawfulness of processing that took place before you withdrew it. 

4. Who We Share It With

We do not sell your personal data. Because Cotta primarily delivers using its own employed drivers, third-party data sharing is limited. However, we do work with the following categories of external recipients:

4.1 Internal Access

Certain Cotta employees and contractors, including operations and customer service staff, may access your personal data strictly for the purpose of managing your orders and resolving service queries. All staff are bound by confidentiality obligations.

4.2 External Service Providers (Data Processors)

We engage trusted third-party service providers to support our technical operations. These providers process data on our behalf and are subject to contractual data protection obligations:

  • Marketplace Partners (Merchants): We share your Order Details (items ordered) with the relevant Partner to prepare your goods. We do not share your full delivery address with Partners unless strictly necessary for specific fulfilment types.

  • Payment Processors: Stripe processes your payments and acts as an independent controller for the financial transaction data it collects.

  • Logistics Management: Nash provides the platform through which we assign drivers, plan routes, and track deliveries. Nash receives your delivery address and order reference to operate this service on our behalf.

  • Emergency Delivery Fulfilment: Stuart, a third-party delivery network, may occasionally be used where our own delivery capacity is unavailable. In these cases, Stuart receives your name, delivery address, and order reference solely to complete that delivery.

  • Authentication: Auth0 manages secure user login and session management. Auth0 processes your email address and authentication credentials on our behalf.

  • Product Analytics: PostHog provides our product-analytics platform and processes app usage events on our behalf to help us improve the App. PostHog is hosted in the EU (eu.i.posthog.com); the US region is not used. PostHog acts as a data processor on our behalf.

  • CRM and Marketing: HubSpot receives your name, email address, telephone number, marketing consent status and dates, and order data to power our customer relationship management system and, where you have opted in, to send you marketing communications. HubSpot acts as a data processor on our behalf.

  • Cloud Infrastructure: Google Firebase and Microsoft Azure host our databases and application backend.

  • Communication Services: Twilio sends SMS delivery updates. OneSignal sends push notifications.

  • Consent Management: OneTrust operates our cookie consent mechanism on cottavita.com, recording and storing user consent preferences on our behalf. OneTrust processes a unique consent identifier and timestamp when you interact with our cookie banner.

Data Processing Addendums. We have Data Processing Addendums in place with PostHog and HubSpot. You can read their privacy notices at posthog.com/privacy and legal.hubspot.com/privacy-policy.

5. Account Deletion and Data Retention

5.1 Your Right to Delete

You have the right to delete your account at any time. We provide a mechanism to initiate account deletion directly within the App:

  1. Go to Account.

  2. Select Account Settings.

  3. Tap Delete Account.

Effect of Deletion: Upon confirmation, your login credentials will be immediately deactivated. Your personal profile data (name, email, saved addresses) will be permanently erased or anonymised within 30 days of your request.

5.2 Retention of Transaction Records

Please note that even if you delete your account, Cotta is legally required to retain certain data:

  • Financial Records: We retain records of financial transactions (transaction ID, amount, date) for a period of 6 years to comply with HMRC tax and accounting regulations in the UK.

  • Fraud & Safety Data: We may retain hashed device identifiers associated with fraudulent activity or safety incidents to prevent banned users from re-registering, protecting our platform and internal staff.

5.3 Retention of Analytics Data

  • Product Analytics Data: Events captured by PostHog are retained for 2 months and then automatically deleted.

  • Existing Users: Analytics data collected from existing app users before 23 June 2026 under our previous lawful basis is retained until automatic deletion at the 2-month rolling limit.

6. International Transfers

Our primary operations are in the United Kingdom. However, our technical infrastructure (e.g., Stripe, Firebase, Twilio) utilises servers located in the United States.

The UK-US Data Bridge: When we transfer your personal data to our service providers in the United States, we rely on the UK Extension to the EU-US Data Privacy Framework (DPF). Our major vendors, including Stripe, Google, Twilio, Auth0, HubSpot, OneSignal, and OneTrust, are certified participants in the DPF, ensuring they provide a level of data protection adequate under UK law. Nash, our logistics management platform, processes and stores your data via its UK entity, so no international transfer occurs. For any other transfers not covered by the DPF, we rely on the International Data Transfer Agreement (IDTA) approved by the UK Information Commissioner's Office (ICO), which contractually requires equivalent data protection standards.

Product analytics (PostHog): Product analytics data is processed on servers in the European Union (eu.i.posthog.com); we do not use PostHog’s US region. Transfers from the United Kingdom to the EEA are permitted by the UK’s adequacy regulations for EEA countries. We have a Data Processing Addendum in place with PostHog covering these transfers.

7. Your Legal Rights

Under the UK GDPR, you have the right to:

  • Request access to your personal data (Subject Access Request).

  • Request correction of inaccurate data.

  • Request erasure of your data (as detailed in Section 5).

  • Object to processing based on legitimate interests.

  • Request restriction of processing.

  • Data Portability (receive a copy of your data).

You may also request deletion of the analytics events linked to your account, and you can withdraw your analytics consent at any time in AccountAnalytics Settings.

To exercise these rights, please contact us at hello@cottavita.com. We may request specific information to confirm your identity before processing your request.

  1. Additional Rights for Users in Specific Territories

If you are located in one of the territories below, you have additional rights under local law, on top of the rights in Section 7. Find your territory by scrolling through them.

8.1 Canada & Quebec

If you're in Canada, you can access and correct your personal information, and withdraw consent to its collection, use, or disclosure at any time under PIPEDA. If you're in Quebec, you also have the right to request destruction or anonymisation of your data, receive it in a portable format, and object to fully automated decisions. Contact hello@cottavita.com, or the Office of the Privacy Commissioner of Canada.

8.2 Japan

Under Japan's Act on the Protection of Personal Information, you can request disclosure, correction, or deletion of your information, and details of how it's shared with providers outside Japan (principally the UK and US). Contact hello@cottavita.com, noting “Japan — Personal Information Enquiry.”

8.3 South Korea

Under South Korea's Personal Information Protection Act (PIPA), we're required to disclose the following about transfers of your personal information outside South Korea:

Recipient category

Location

Items transferred

Platform hosting and infrastructure (Azure/Microsoft)

United Kingdom; United States

Account data, order data, usage data

Payment processing (Stripe)

United States

Payment reference data (last 4 card digits, transaction IDs)

CRM and marketing (HubSpot)

United States

Account data, marketing preferences, order history

Product analytics (PostHog)

EEA

Anonymised usage data

SMS and notifications (Twilio, OneSignal)

United States

Phone number, device identifier

Authentication (Auth0)

United States

Email address, encrypted authentication credentials

Purpose: hosting, payment processing, customer relationship management, product analytics, transactional communications, and authentication. Retention: for the periods described in Section 5. Safeguards: data processing agreements with each recipient, including confidentiality obligations, encryption requirements, and access controls.

By creating an account and using the Platform, you consent to this transfer. You may withdraw this consent at any time by contacting hello@cottavita.com — but withdrawal is likely to prevent us from providing the Platform's services, as core infrastructure is located outside South Korea; we'll explain the impact before processing your request.

Under PIPA you also have the right to: request disclosure of the personal information we hold; request correction; withdraw consent; request suspension of processing or deletion where permitted by law; and request details of overseas transfers. Contact hello@cottavita.com.

8.4 Other territories

If you're located in one of the territories below, you have the following rights under local law. Unless noted, contact hello@cottavita.com to exercise them.

United Arab Emirates. Access, rectification, erasure, objection, restriction, and portability under the PDPL. Your personal data is transferred to and processed in the United Kingdom under contractual safeguards. Complaints also to the UAE Data Office.

Qatar. Access, correction, and objection under Law No. 13 of 2016. Your personal data is transferred to and processed in the United Kingdom under contractual safeguards.

Bahrain. Access, correction, deletion, and objection under the 2018 PDPL. Your personal data is transferred to and processed in the United Kingdom under contractual safeguards. Complaints also to Bahrain's Personal Data Protection Authority.

Oman. No comprehensive data protection law currently applies; we handle your data to the same standard as the rest of this policy.

Australia. We currently fall within the Privacy Act's small business exemption, but follow the Australian Privacy Principles as good practice regardless.

New Zealand. Access and correction under the Privacy Act 2020. Escalate to the NZ Privacy Commissioner if unsatisfied.

Singapore. Access, correction, consent withdrawal, and portability under the PDPA. Your personal data is transferred to and processed in the United Kingdom and by the service providers described in Section 6, under contractual arrangements ensuring a comparable standard of protection. Complaints also to the PDPC.

Hong Kong SAR. Access and correction under the PDPO. Complaints also to the Privacy Commissioner for Personal Data.

Malaysia. Access, correction, and consent withdrawal under the PDPA. We don't sell your data for third-party marketing. Your personal data may be transferred outside Malaysia, including to the United Kingdom, under contractual safeguards.

Thailand. Information, access, portability, objection, deletion, and restriction under the PDPA. As there is no formal adequacy determination between Thailand and the United Kingdom, we rely on your consent to this cross-border transfer, which you may withdraw at any time — this may affect the availability of the Platform's services. Complaints also to Thailand's Personal Data Protection Committee.

Taiwan. Inquiry, a copy of your data, correction, cessation of processing, and deletion under the PDPA. Your personal data is transferred to and processed in the United Kingdom under appropriate contractual safeguards.

8.5 European Union (EU)

Representative

We value your privacy and your rights as a data subject and have therefore appointed Prighter Group with its local partners as our privacy representative and your point of contact for the following regions:

European Union (EU)

Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact us via our representative, Prighter, or make use of your data subject rights, please visit the following website: https://app.prighter.com/portal/11083530479

Our representative holds a copy of our Records of Processing Activities relevant to EU data subjects and is authorised to act as a contact point for EU supervisory authorities. Appointing a representative does not limit our own accountability as data controller; Cotta Digital Services Limited remains responsible for the lawfulness and transparency of our processing.

Transfer of your data to the United Kingdom

When you use the Platform, your personal data is transferred to and processed in the United Kingdom. The European Commission has adopted an adequacy decision under Article 45 GDPR recognising the United Kingdom as providing an adequate level of data protection. Transfers from the EU to the United Kingdom therefore do not require additional safeguards such as standard contractual clauses. The adequacy decision is subject to periodic review by the Commission; if it is revoked, expires, or is significantly modified, we will implement an appropriate alternative transfer mechanism and update this policy accordingly.

Your rights as a user in the EU

If you are located in the EU, you have all the rights described in Section 7, which mirror the substantive data subject rights under the GDPR. You also have the right to lodge a complaint with the supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement — or to contact Prighter directly via the portal link above. A full list of EU supervisory authorities is available at edpb.europa.eu.

9. Contact Us

Cotta Digital Services Limited

Email: hello@cottavita.com

Registered Office: 3rd Floor, 15 Half Moon Street, London, United Kingdom, W1J 7DZ

Complaints: You have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues.

EU users may also contact our EU representative, Prighter, at https://app.prighter.com/portal/11083530479, or their local data protection authority.


Do you have questions?

Reach out to our team and start a discussion.

COTTA logo