Legal
NextTill Privacy Policy
How we use personal information when you visit, trial, buy or use NextTill.
Last updated: 2 September 2026
Cherry Tree Garden Centre Limited, company number 16760931, registered at Cherry Tree Garden Centre, 8 Wragby Road, Sudbrooke, Lincoln, United Kingdom, LN2 2QU, operates NextTill. In this policy, NextTill, we, us and our refer to that company.
This notice explains how we handle personal information when we act as a controller. It also explains the different position where a business customer uses NextTill to process information about its own customers, staff or other people, in which case that business will normally be the controller and NextTill will normally act as its processor.
1. Data-protection law
We process personal information in accordance with applicable UK data-protection and privacy law, including the UK GDPR, the Data Protection Act 2018, the Data (Use and Access) Act 2025 and the Privacy and Electronic Communications Regulations 2003 where they apply.
2. Information we collect
Depending on how you use NextTill, we may collect:
- Account and contact information — name, business name, email address, telephone number, trading address and account role;
- Authentication and security information — password hashes, staff or account identifiers, login/session information, security events and access records;
- Business and onboarding information — business type, locations, till numbers, current EPOS provider, payment provider, product counts, preferred go-live date, hardware and setup/import notes;
- Subscription and billing information — plan, subscription status, invoices, payment status and billing records. We do not need or intend to store full card numbers, CVV security codes or PINs in NextTill;
- Support and communications — messages, support requests, diagnostic information, complaints, feedback and records of our response;
- Technical and usage information — IP address, browser/device information, terminal identifiers, app version, timestamps, error information, synchronisation status and security/diagnostic logs;
- Marketing preferences — whether you asked to receive NextTill marketing and information needed to record an opt-out or withdrawal;
- Integration configuration — information needed to connect services you choose to enable, such as payment, marketing or marketplace providers; and
- Website/session information — essential cookies, session identifiers and local storage necessary for login, security and application operation.
3. Customer-controlled business data
A live NextTill customer may use the Service to store or process information relating to its own customers, loyalty members, staff, suppliers and transactions. Examples can include names, contact details, purchase history, receipts, customer/member identifiers, staff identifiers and roles.
For that information, the NextTill customer normally decides why and how the information is used and is therefore the controller. NextTill normally processes it on the customer's documented instructions as a processor. Our processor obligations are set out in the Data Processing Schedule within the Terms of Service.
If you are an individual whose information has been entered into NextTill by one of our business customers, you should normally contact that business first to exercise your rights. We will assist the business where required.
4. Where information comes from
We obtain information directly from you when you complete forms, create or use an account, contact us or configure the Service. We may also receive information from authorised colleagues within your business, from integrations you choose to connect, from your device/browser and from technical logs generated when the Service is used.
5. Why we use personal information and our lawful bases
We may use personal information for the following purposes:
- To create and perform the contract — including account setup, tenant provisioning, access, support, subscriptions and supplying the Service. Our lawful basis is normally that processing is necessary for a contract or to take steps at your request before entering into one.
- To secure and operate NextTill — including authentication, fraud prevention, monitoring, diagnostics, backups, incident investigation and service improvement. Our lawful basis is normally our legitimate interests in operating a secure, reliable business service, balanced against individual rights.
- To meet legal obligations — including tax/accounting records, data-protection duties, lawful requests and regulatory obligations.
- To communicate about the Service — including important operational, legal, security and billing messages. These are service communications rather than optional marketing.
- To send optional marketing — where consent is required we rely on consent; in situations where UK law permits business-to-business marketing without consent, we may rely on legitimate interests, but we will identify ourselves and provide a way to opt out.
- To establish, exercise or defend legal claims — where necessary for our legitimate interests and legal rights.
Where we rely on legitimate interests, we consider whether the processing is necessary and whether your interests, rights or freedoms override ours.
6. Who we share information with
We may share personal information only where reasonably necessary with:
- hosting, infrastructure, backup, email, communications, security and support providers acting for us;
- payment, marketing, accounting, marketplace or other integration providers where you choose to connect them;
- professional advisers such as accountants, insurers and lawyers under appropriate confidentiality duties;
- law-enforcement bodies, regulators, courts, tax authorities or other public bodies where disclosure is required or permitted by law; and
- a buyer, investor or successor in connection with a genuine sale, restructuring or transfer of the NextTill business, subject to appropriate confidentiality and data-protection safeguards.
We do not sell personal information to advertisers.
7. Sub-processors
Where we act as a processor for a NextTill customer, we may use sub-processors needed to operate the Service. The customer's general authorisation and the safeguards applying to those sub-processors are set out in the Data Processing Schedule in our Terms of Service.
8. International transfers
Some service providers or connected integrations may process information outside the United Kingdom. Where UK data-protection law requires a safeguard for a transfer, we will use an appropriate lawful mechanism, which may include adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses or another permitted safeguard.
9. How long we keep information
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, security and dispute-resolution requirements.
- Account, contractual, subscription and material support records may be retained for the duration of the relationship and normally for up to six years afterwards where needed for legal or accounting purposes.
- Marketing information is kept while marketing remains appropriate; if you opt out, we may retain the minimum information needed to honour that opt-out.
- Security and technical logs are retained for periods appropriate to security, diagnostics and fraud prevention and are reviewed so they are not kept unnecessarily.
- Customer-controlled tenant data is retained in accordance with our contract and the customer's instructions. Following termination it may be deleted or anonymised after a reasonable export/recovery period, subject to legal obligations and normal backup cycles.
- Data-protection complaint and rights-request records may be retained where necessary to demonstrate that we handled the matter properly and complied with our legal obligations.
10. Security
We use technical and organisational measures designed to protect personal information against unauthorised access, accidental loss, alteration or disclosure. Depending on the relevant part of the Service, these may include HTTPS transport, password hashing, access controls, tenant/database separation, protected server storage, backup/recovery processes, logging and restrictions on administrative access.
No internet-connected service can promise absolute security. If we become aware of a personal-data breach, we will assess it and make notifications to customers, affected individuals or the Information Commissioner where UK law requires us to do so. Where we act as a processor, we will notify the relevant customer/controller without undue delay.
11. Your rights
Depending on the circumstances, UK data-protection law may give you rights to:
- ask for access to your personal information;
- ask us to correct inaccurate or incomplete information;
- ask for deletion of information in certain circumstances;
- ask us to restrict processing in certain circumstances;
- object to processing based on legitimate interests or to direct marketing;
- receive certain information in a portable format where the portability right applies; and
- withdraw consent at any time where our processing relies on consent, without affecting processing that was lawful before withdrawal.
These rights are not absolute and may depend on why we hold the information and other legal requirements.
12. Automated decision-making
We do not currently use personal information for solely automated decisions made by NextTill that produce legal effects or similarly significant effects on individuals. If that changes, we will provide the information and safeguards required by law.
13. Marketing
Optional marketing at signup is separate from accepting the Terms or Privacy Policy. Where we ask for consent to send marketing by email, the box is optional and is not pre-ticked. You can withdraw or opt out at any time using the method in the message or by contacting us.
14. Cookies and local storage
NextTill may use cookies, sessions, local browser storage and similar technologies that are necessary for authentication, security, preferences, offline operation and core Service functionality. If we introduce non-essential advertising or analytics technologies that require consent under UK law, we will provide the required information and consent controls before using them.
15. Data-protection complaints
If you believe we have handled your personal information incorrectly, you have the right to complain to us. We provide an electronic complaints process at Data protection complaint.
We will acknowledge a data-protection complaint within 30 days and investigate and communicate the outcome without undue delay, keeping you appropriately informed if the investigation takes time.
You also have the right to complain to the UK Information Commissioner's Office (ICO). You can find information about making a complaint at ico.org.uk. We would appreciate the opportunity to address your concern first, but you are not required to give up any statutory right to approach the ICO.
16. Contact and identity
The controller for NextTill's own account, website and business-administration processing is:
Cherry Tree Garden Centre Limited
Company number 16760931
Cherry Tree Garden Centre, 8 Wragby Road, Sudbrooke, Lincoln, United Kingdom, LN2 2QU
Trading as NextTill
For privacy rights or complaints, please use our privacy and data-protection complaint form so the request is recorded and routed correctly.
17. Changes to this policy
We may update this policy to reflect changes in law, the Service, our providers or how we process information. We will update the date at the top and, where a change is material, provide additional notice where appropriate.