Skip to content

Pret x Shoreditch Nails

Shop Activation Privacy Notice

Last Updated : 9th May 2025

This notice provides an overview of how we collect, use, store, and share your information for the Pret x Shoreditch Nails Partnership. For further detailed information about how Pret manages personal data, please refer to our full Privacy Notice at https://www.pret.mom/en-GB/privacy-policy

Who we are

We are the Pret A Manger Group (that's who we mean by "Pret", "we, "us" or "our"). The Pret A Manger Group consists of affiliated companies of Pret A Manger (International) and Pret A Manger (Europe) Limited, registered in England and Wales with company numbers 14722221 and 01854213. Pret is the Data Controller, and our registered office is at 75b Verde, 10 Bressenden Place, London, England, SW1E 5DH.

Pret cares about your privacy and is committed to processing your personal information fairly and transparently and in accordance with all applicable data protection laws, including the Data Protection Act 2018 and the UK General Data Protection Regulation (together "Data Protection Law").

What type of information is collected from you?

We collect information that you provide to us when booking an appointment on the Pret x Shoreditch Nails Partnership Eventbrite page. This includes your name and email address. All other information including payment information will be handled by Eventbrite. In specific instances, we may need to collect additional data for the purposes explained to you at that time.

How is your information used and what is the legal basis for this use?

We process your information for the following purposes:

To fulfil a contract, or take steps linked to a contract:

  • to process and fulfil your booking;

  • to communicate with you about the event and provide customer service;

As required to conduct our business and pursue our legitimate interests:

  • to provide products and services you have requested

  • for customer services purposes to respond to any comments or complaints you send us;

  • for safety and security purposes using CCTV, panic alarms and body worn cameras in our shops, accident and incident reporting;

  • to enforce or apply our terms of service and any other agreement or protect the rights, property, or safety of Pret, customers, employees, contractors or others;

For purposes which are required by law or for the establishment, exercise or defence of legal claims:

  • responding to court orders, subpoenas or other legal processes with which Pret is required to comply;

  • for safety and public interest purposes;

  • for crime and fraud prevention, reporting, detection, investigation and related purposes.

Where we need to collect or process your personal data by law, or under the terms of a contract we have with you, and you fail to provide that data when requested, we may not be able to perform the agreement or provide you with certain goods and services.

With whom do we share your information?

Third Party Service Providers and Partners working on our behalf

In order to make the manicure service available, Pret has partnered with Shoreditch Nails to provide the service. Shoreditch Nails and their nail artists will receive your name and booking number in order to validate your reservation on arrival.

Pret works closely with our third-party suppliers and service providers to bring you high quality services and products. When you send us feedback or comment on any of our products or services, we may need to share such feedback/comment after the event.

Sharing to comply with legal obligations

We may use the information that you provide to us if we are under a duty to disclose or share your information in order to (a) comply with (and/or where we believe we are under a duty to comply with) any legal obligation; (b) enforce or apply our website terms of service and any other agreement; or (c) protect the rights, property, or safety of Pret, customers, employees, contractors or others. This includes exchanging information with other companies and other organisations for the purposes of fraud protection and prevention, or where we have to carry out an internal investigation.

Your Rights

You have the right to see the information we hold about you and to ask us to: (a) make changes to ensure that any information we hold about you is accurate and up to date; (b) erase or stop processing any information we hold about you where there is no longer a legal ground for us to hold it; or (c) in some cases, transfer any information we hold about you to a specified third party. In addition, you can object to the processing of your personal data in some circumstances (in particular, where we don’t have to process the data to meet a contractual or other legal requirement).

When you get in touch to exercise any of your rights, we will respond within one month of your request or verification of your identity (if applicable). Please note that if your request is more complicated, it may take a little longer to process and the response deadline can be extended by two months of your request where necessary. There is no charge for most requests, but if you ask us to provide a significant amount of data, we may ask you to pay a reasonable admin fee. Please contact us via the details set out at section 10 below.

These rights may be limited, for example if fulfilling your request would reveal personal data about another person, or if you ask us to delete information which we are required by law or have compelling legitimate interests to keep. We reserve the right to retain a record of your request in order to maintain appropriate records for our internal auditing.

How do we protect your information?

We use technical measures such as encryption and password protection to protect your data and the systems they are held in against unauthorised access, unlawful use, accidental loss, corruption or destruction. We also use operational measures to protect the data, for example by limiting the number of people who have access to the databases in which purchase information is held. We constantly keep our security measures under review and refer to industry security standards to keep up to date with current best practice.

How long do we retain your information?

Where we process registration data, we do this for as long as you are an active user of our sites and for 24 months after this. Where we process personal data in connection with performing a contract or payment, we keep the data for 6 years as required for financial record keeping.

Where we process personal data for marketing purposes or with your consent, we process the data until you ask us to stop and for a short period after this (to allow us to implement your requests).

Health and Safety records will be kept for the appropriate legal timeframe which in most cases will be a maximum of 3 years.

Young people

Appointments are only available to customers over 16 years of age.

Data Transfers

The information that we collect from you may be transferred to, and stored at, a destination outside the UK or the European Economic Area ("EEA"). It may also be processed by staff operating outside the UK or the EEA who work for us or for one of our suppliers, including staff engaged in the provision of support services. Where information is transferred outside the UK or the EEA, and where this is to a stakeholder or vendor in a country that is not subject to an adequacy decision by the UK or the EU Commission, data is adequately protected by EU Commission approved standard contractual clauses or alternative transfer mechanism.

Contact and Complaints

If you have any questions feel free to visit our contact page. This is also an ideal place to send us feedback and comments, you’ll always get a response from our lovely customer services team. Alternatively, you can contact us at Data Protection, Pret A Manger Europe Limited, 75b Verde, 10 Bressenden Place, London, England, SW1E 5DH.

Please note that you have the right to lodge a complaint with the supervisory authority which is responsible for the protection of personal data in the country where you live or work, or in which you think a breach of data protection laws might have taken place.