1. Scope and controller
This policy applies to the Streetly promotional website, web marketplace and mobile apps, including customer, vendor, administrator and delivery accounts; local shopping and multi-vendor orders; custom delivery; Library of Things transport; support; product requests; and partnership enquiries. Streetly is operated by eStreet Services Ltd, company number 11631701, registered at Studio 1, 305A Goldhawk Road, London, W12 8EU, United Kingdom. For the processing described here, eStreet Services Ltd is normally the controller under the UK General Data Protection Regulation, the Data Protection Act 2018 as amended, including by the Data (Use and Access) Act 2025, and the Privacy and Electronic Communications Regulations 2003 (“PECR”).
Independent vendors are normally separate controllers for the information they need to accept, prepare and fulfil an order, answer product questions, manage returns and meet their own legal duties. Library of Things venues and other booking providers are also separate controllers for their bookings and lending services. Their privacy information may apply alongside this policy.
2. Information we collect
Account, identity and contact information
- name, email address, mobile number where provided, user identifier, profile image, account type, access level and preferences;
- authentication, verification, session and short-lived website-to-app sign-in handoff information. Firebase Authentication handles server-side authentication. Where remembered sign-in is used, the mobile app may keep the email and password entered for sign-in in operating-system-protected secure storage on that device; these credentials are not written to the Firestore user profile or available to Streetly staff through that profile;
- records of terms and privacy notices presented or accepted, timestamps, communication permissions, opt-outs and suppression status;
- saved addresses, postcode, recipient details, delivery instructions and approximate or precise location if you choose to provide it or use a location-dependent feature;
- saved favourites, in-app alerts, device and push-notification tokens and the communications associated with your account.
Shopping, delivery and payment information
- searches, viewed products, vendors and collections, favourites, baskets, orders, selected vendors, substitutions, quantities, discounts, prices, delivery or collection choices, status, refunds and related messages;
- pickup and destination names, telephone numbers, addresses, access instructions, delivery notes, requested time windows, route and stop status, start or completion coordinates, handover or collection codes and QR or barcode information;
- delivery evidence, such as a proof photo and driver note, where needed to document a collection, delivery, return or dispute;
- Library of Things booking or security code, borrowed-item and return information that you supply for the transport service;
- limited payment information such as amount, status, card type, payment and payout references. Stripe handles complete card, bank, identity-verification and payout details; Streetly does not store your complete card number.
Content, support and business information
- support requests, complaints, product requests, the contact email and marketing choice supplied with a product request, reviews, ratings, survey responses, photos or files you submit and other communications;
- for a product request, the requested product or service, example link, notes, email where supplied, whether that email matches a Streetly account and whether email updates were requested;
- partnership enquiries, including contact name, business name, email, postcode, business type, message, submission identifier and privacy acknowledgement;
- vendor information, including business identity, contacts, locations, catalogue, stock, fulfilment data, licences, insurance, tax identification, reportable sales or consideration and payout status;
- records needed to investigate fraud, safety incidents, product recalls, disputes or breaches of our terms.
Technical and usage information
- IP address, browser, device and app identifiers, app version, operating system, language, timestamps, referral source, pages or screens visited, buttons and features used, diagnostics, performance and security logs;
- Firebase Analytics events generated in the app, which may include a pseudonymous Firebase user identifier, event or screen name and interaction information linked to the signed-in account;
- camera, photo-library, barcode-scanner and location information only when you use a feature that needs it and, where required, after the device asks for permission;
- information kept locally on the device, such as remembered sign-in information, active basket references, recent or trending searches and temporary address details;
- cookie, advertising or similar identifiers where enabled. Optional website analytics and advertising technology is not activated until you give the consent required by law.
3. Where information comes from
We receive information directly from you; from your device and use of Streetly; from vendors, authorised administrators, delivery personnel and Library of Things venues involved in your order or booking; from Stripe, Firebase, Klaviyo, Google Maps and Places, app stores, address or location providers and communications providers; and from people who contact us about an order or business. We may match an email supplied with a product request against Firebase Authentication to associate the request with an existing account. For vendor checks, fraud prevention, digital-platform reporting or legal compliance, we may also receive information from Companies House, HM Revenue & Customs, regulators, sanctions or fraud-prevention sources and other public records.
Information marked as required on a form is needed to provide the requested account, order or service or to meet a legal requirement. If you do not provide it, we may be unable to create the account, complete the order, deliver safely or respond properly. Optional fields can be left blank unless the service explains otherwise.
4. How and why we use information
| Purpose | Typical information | Lawful basis |
|---|---|---|
| Create, verify and manage accounts; provide the app and web platform | Account, contact, authentication, device and preference data | Contract; legitimate interests in operating a usable and secure service |
| Process, fulfil, deliver, collect, cancel and refund orders | Contact, address, location, order, transaction and communications data | Contract; legal obligation; legitimate interests in fulfilment and support |
| Calculate local availability, delivery fees and routes; confirm pickup, delivery or return | Address, approximate or precise location, recipient, route, scan, status and delivery-evidence data | Contract; legitimate interests in safe, accurate fulfilment; consent where device permission or storage law requires it |
| Process payments, refunds and vendor payouts | Transaction references, amount, status and vendor payment-account details | Contract; legal obligation; fraud-prevention interests |
| Provide support, handle complaints and resolve disputes | Account, order, evidence and communications data | Contract; legitimate interests; legal obligation; legal claims |
| Record a requested product or service and, where you opt into Streetly emails, tell you if that request becomes available | Product request, email address, account match and communication preference | Your request; legitimate interests in recording demand and improving local availability; consent for email updates and marketing |
| Receive and respond to partnership enquiries and notify authorised Master administrators | Enquiry, business and contact details | Steps requested before a potential contract; legitimate interests in managing prospective partnerships |
| Onboard and administer vendors and meet digital-platform reporting duties | Business identity, contact, tax, sales, transaction and payout data | Contract; legal obligation; legitimate interests in operating and protecting the marketplace |
| Protect customers and Streetly, verify vendors, prevent fraud, investigate misuse and manage product safety or recalls | Identity, vendor, device, security, order and transaction data | Legal obligation; legitimate interests in safety, trust and fraud prevention; legal claims |
| Send essential account, security, order, delivery and service messages | Name, contact details, order and account status | Contract; legal obligation; legitimate interests in operating and protecting the service |
| Provide favourites, alerts, saved addresses and other account preferences | Account, favourite, address, alert, device and preference data | Contract; legitimate interests in providing a useful service |
| Improve features, personalise ordinary service content, diagnose faults and understand app performance | Pseudonymous account identifier, events, screens, interactions, searches, orders, device, diagnostics, performance, feedback and aggregated data | Legitimate interests; consent where required for storage or access on a device |
| Send direct marketing and manage preferences | Name, email, mobile number, preferences, purchase and engagement data | Consent where relied on; otherwise legitimate interests in promoting our own services, always subject to PECR’s consent or soft-opt-in rules |
| Measure website use and advertising | Cookie, device, referral and interaction data | Consent for optional analytics or advertising technology |
| Meet accounting, tax, regulatory, corporate and legal duties | Transactions, contracts, identity and correspondence | Legal obligation; legal claims |
Where we rely on legitimate interests, we assess the benefit, necessity and impact on you. You may object in the circumstances described below. We may anonymise information so that it no longer identifies anyone and use that information for analysis, planning and reporting.
5. Service messages, marketing and preferences
We may send essential communications by email, SMS, push notification or in-app message, including email verification, password or security notices, order confirmations, substitutions, delivery updates, recalls and responses to you. These are not direct marketing, although you can manage available channels and contact details subject to what Streetly needs to provide the service.
We send marketing by email or SMS only when we have the consent required by PECR, or when the strict products-and-services soft-opt-in applies: we obtained the address directly while you bought or genuinely negotiated to buy from us, the message concerns our own similar products or services, and we offered a simple opt-out when collecting the details and in every message. Creating an account, accepting our terms, giving a mobile number or receiving a service message does not by itself amount to marketing consent. Email and SMS permissions are assessed separately.
A requested-product availability email is treated as marketing where it also promotes Streetly products or services. The website therefore explains that you must actively subscribe if you want those updates. Marketing is not a condition of creating an account, placing an order, submitting a product request or making a partnership enquiry.
You can stop direct marketing at any time by using the unsubscribe link in an email, replying STOP where offered in an SMS, changing available Streetly preferences or contacting us. We may keep a minimal suppression record so that we do not contact you again through that channel. Stopping marketing does not stop necessary account, safety, order or delivery messages.
6. Who receives information
We disclose only what is reasonably necessary to:
- authorised Streetly personnel, according to their role and access level. Partnership enquiry details are made available only to the team handling partnerships and are sent as individual Klaviyo event notifications to active administrators with Master-level privileges;
- the vendor or vendors involved in an order, return, product question or complaint;
- Streetly delivery teams, approved couriers, logistics providers and relevant Library of Things venues, including the recipient, location, route, handover and evidence information needed for fulfilment;
- Stripe for payments, refunds, fraud checks, identity checks and vendor payouts;
- Google Cloud and Firebase services, including Authentication, Firestore, Cloud Functions, Cloud Storage, Analytics, Performance Monitoring, Cloud Messaging and Remote Config, and BigQuery for hosting, databases, authentication, sign-in handoff protection, storage, push messaging, configuration, security, diagnostics, measurement, operational analysis and our controlled data flows;
- Klaviyo for permitted marketing, suppression and preference management, website subscriptions, product-request profiles and events, partnership-enquiry profiles and events, and related service or internal-administrator messages. Adding a non-subscribed enquiry profile does not itself subscribe that person to marketing;
- Google Maps and Places, address-search and location providers, app stores, analytics and advertising providers where relevant and, for optional website technology, only after the applicable consent;
- HM Revenue & Customs and, through lawful reporting arrangements where applicable, other tax authorities for digital-platform seller reporting;
- IT, security, fraud-prevention, accounting, legal, insurance and other professional providers acting under appropriate duties;
- courts, law enforcement, regulators, product-safety authorities or other bodies where disclosure is legally required or reasonably necessary to protect rights and safety;
- a genuine buyer, investor or successor as part of a corporate transaction, subject to confidentiality and data-protection safeguards.
We do not sell or rent personal information. Vendors may not use order information for unrelated marketing unless they independently meet all legal transparency and permission requirements.
7. International transfers
Some providers may process information outside the United Kingdom. Where a destination is not covered by UK adequacy regulations, we use a recognised safeguard where required, such as the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses or another lawful transfer mechanism, and carry out any required risk assessment. Contact us for further information about safeguards relevant to your information.
8. How long we keep information
We keep information only as long as needed for its purpose and for applicable legal, tax, accounting, safety, fraud-prevention and dispute requirements. Typical periods are:
- account profile, verification, favourites, alerts and saved-address information: while the account is active, then normally up to 24 months after closure unless earlier deletion is appropriate;
- information stored locally by the app: until it is cleared by the relevant app action, account deletion, operating-system controls or removal of the app; device backups and operating-system behaviour may affect when a local copy disappears;
- website-to-app handoff codes: valid for 15 minutes; a limited nonce record may be retained to prevent reuse and investigate abuse;
- orders, payments, refunds, invoices, route status, handover records and delivery evidence: normally six years after the relevant transaction or financial year;
- support, privacy complaints and customer disputes: normally three years after closure, or longer while a claim or regulatory matter remains active;
- vendor, partnership and commercial records: for the relationship and normally six years afterwards, or for the period required by digital-platform reporting rules;
- marketing contact and engagement data: until you unsubscribe, consent expires or we no longer need it, with a minimal suppression record retained to respect your choice;
- website partnership enquiries and product requests: normally up to two years, unless they become part of an account, commercial relationship, complaint or legal record with a different justified period;
- push tokens: while needed to send enabled notifications, until replaced, disabled or no longer associated with an active installation, subject to limited logs and backups;
- security, access, analytics, performance and diagnostic logs: usually 30 days to 14 months, unless a longer configured analytics period, an incident or a legal duty requires longer;
- the website cookie choice: six months.
Backup copies may remain for a limited recovery cycle before deletion. We may shorten or extend a period where the context, a legal hold, product-safety matter, fraud prevention, safeguarding or a dispute reasonably requires it.
9. Your rights
Depending on the circumstances, you may ask us to give you access to your information; correct it; erase it; restrict its use; provide certain information in a portable format; or stop processing based on legitimate interests. You can object to direct marketing at any time. You may withdraw consent without affecting processing already carried out lawfully.
Send a request using the details below. We may need proportionate information to verify identity. We normally respond within one month, although the law permits an extension for a complex request and permits us to limit or refuse a request in specific cases. If that happens, we will explain why and describe your complaint rights.
You can start account deletion from the app. This removes the authentication account and access associated with it, but it does not mean that every record disappears immediately: order, payment, refund, tax, fraud-prevention, safety, complaint and legal records may need to be retained or restricted for the periods described above. Contact us if you also want to exercise the right to erasure; we will assess the request and explain any information we must keep.
10. Cookies and similar technology
Cookies are small files stored on a browser or device. Similar technology includes pixels, tags, local or secure storage, mobile SDKs and scripts that can recognise a device, remember a choice or record an interaction. This section covers technology on the promotional website, web marketplace and mobile apps. Device permission prompts and just-in-time explanations may provide additional information when a particular feature is used.
Your choices
On a first visit, you can accept all optional technology, reject everything non-essential or choose categories individually. Analytics and marketing are off until you actively enable them. Continuing to browse is not consent. We store the choice for six months and may ask sooner if our use changes materially.
You can withdraw or change consent at any time through “Cookie settings” in the footer. A new setting applies from that point; it cannot undo processing already carried out lawfully.
Technology used on this website
| Technology | Category and purpose | Typical duration |
|---|---|---|
streetly_cookie_consent | Necessary. Records analytics and marketing choices so the site can respect them. | Six months |
| Cloud hosting, security and load balancing | Necessary. Google Cloud processes request, security and delivery information needed to serve and protect the site. Any exempt storage or access is limited to operational purposes. | Session or operational period |
_ga and _ga_* | Analytics, when enabled. Google Analytics 4 distinguishes browsers and measures visits, pages and interactions. | Typically up to two years |
_fbp, _fbc and Meta Pixel identifiers | Marketing, when enabled. Measures advertising results and may support audience creation or relevant advertising on Meta services. | Typically up to 90 days; Meta-controlled storage may vary |
The exact technology depends on configured integrations and the categories you enable. We periodically check the live site and update this table when providers, purposes or durations change.
Google Analytics 4. When analytics is enabled, Google may receive browser, device, approximate location, page and interaction information. Streetly uses Google Consent Mode with analytics and advertising storage denied by default and configures IP anonymisation where supported.
Meta Pixel. When marketing is enabled, Meta may receive browser, device, page, referral and interaction information and may associate it with information it already holds. We use it to understand campaign performance and, where configured, create or refine advertising audiences. The Meta Pixel does not load before marketing consent.
Technology used in the Streetly mobile app
| Technology | Purpose and information | Your control |
|---|---|---|
| Secure and local app storage | Remembers sign-in information where enabled, active basket references, recent or trending searches and temporary address details so the app can maintain the requested state. | Use relevant app controls, account deletion or device settings, or remove the app. Signing out may not clear every remembered local value. |
| Firebase Analytics and Performance Monitoring | Records app events, screens, interactions, a pseudonymous signed-in user identifier, device or app details and performance diagnostics to understand use and improve reliability. | Where consent is legally required for storage or access, we will request it. Device privacy controls may provide additional choices. |
| Firebase Cloud Messaging | Stores a device push token and device type to deliver enabled account, order, delivery and other permitted notifications. | Control notifications in Streetly or the device settings. |
| Firebase Remote Config | Retrieves operational app settings, such as mapping configuration and minimum-order thresholds. | Necessary to provide and configure relevant app functions. |
| Maps, Places and device location | Supports address search, local discovery, delivery pricing, route display and fulfilment. Precise location is used only for a feature that needs it and after the applicable device permission. | Deny or withdraw location permission in device settings; some nearby, address or delivery features may then be limited. |
| Camera, photo library and barcode or QR scanning | Supports product or catalogue images, delivery evidence and order or handover scanning when that feature is chosen. | Deny or withdraw camera or photo access in device settings; the related feature may then be unavailable. |
| Stripe mobile technology | Supports secure payment, authentication, fraud prevention and vendor onboarding or payout functions. | Needed when you choose the relevant payment or vendor function. |
We do not use microphone, biometric or background-location access merely because the app package contains a permission description. We will request such access only if a live feature genuinely needs it, after giving the information and choice required by law. You can review and change app permissions through your device settings.
11. Security, children and automated decisions
We use proportionate technical and organisational measures, including access controls, encryption in transit, managed cloud security, monitoring, backups and supplier controls. No service can be guaranteed completely secure. Protect your password and device and tell us promptly if you suspect misuse.
Streetly accounts are intended for people aged 18 or over and the marketplace is not directed at children. Age-restricted products may require additional age and identity checks. If you believe a child has provided information to us, contact us so we can investigate and take appropriate action.
We do not currently make decisions about customers solely by automated means that produce legal or similarly significant effects. We may use rules and risk signals to flag fraud, account-security or product-safety concerns for review. If we introduce significant solely automated decision-making, we will provide the information and safeguards required by law before it applies.
We may update this policy when Streetly, our providers or the law changes. We will bring material new uses of personal information to the attention of affected people before starting them where required. The date at the top identifies the current version.
12. Contact and complaints
For a privacy question, rights request or data-protection complaint, email hello@estreetservices.com or write to eStreet Services Ltd, Studio 1, 305A Goldhawk Road, London, W12 8EU, United Kingdom. Mark the message “Privacy” or “Data protection complaint” and explain what happened and the outcome you want.
We provide this email address as an electronic way to make a data-protection complaint. We will acknowledge a complaint within 30 days, take appropriate steps to investigate it, keep you informed where appropriate and communicate the outcome without undue delay. We may contact you for proportionate information needed to investigate.
You can also complain to the Information Commissioner’s Office. Visit ico.org.uk/make-a-complaint or telephone 0303 123 1113. We would appreciate the opportunity to address your concern first, but you do not have to contact us before approaching the ICO.