Legal
Privacy & cookie policy
What personal information Travel Cashier Ltd collects when you use our website, reserve or purchase foreign currency, use our Click & Collect service, or use our in-store currency exchange services.
- Effective date
- 1 July 2025
- Last reviewed
- 1 July 2025
- Version
- 1.6
This policy explains why we use your information, the legal bases we rely on, how long we keep it, who we may share it with, how we use cookies, and your rights.
1. Who we are
Travel Cashier Ltd (“we”, “us” or “our”) operates foreign-currency exchange services, including our Click & Collect service and our in-store currency exchange services.
We are the data controller for the personal information described in this policy.
Travel Cashier Ltd is incorporated in England and Wales under company number 12477944. Our registered office is 57 Stroud Green Road, London, N4 3EG, United Kingdom.
Travel Cashier Ltd is supervised by HM Revenue & Customs for applicable anti-money-laundering requirements. Our MLR registration number is XMML00000152380.
If you have a question about this policy or want to exercise a data protection right, contact us by email at [email protected] or by telephone on +44 20 3417 8600.
2. What information we collect
The information we collect depends on how you interact with us and the nature of your transaction.
Order and transaction information
This may include:
- the currency and amount you reserve or purchase;
- the exchange rate applied;
- your selected store;
- your collection date;
- transaction references;
- payment and transaction information;
- information relating to foreign-currency buy-back transactions; and
- information about cancelled, declined or incomplete transactions where relevant.
Contact information
This may include your:
- name;
- email address;
- telephone number; and
- correspondence with us.
We use this information to administer reservations, communicate with you about transactions, respond to enquiries and complaints, and provide customer support.
Identity and compliance information
Depending on the transaction and our legal or compliance obligations, we may collect information including:
- date of birth;
- residential address;
- photographic identification details;
- information about the identification document presented;
- information about the purpose or nature of a transaction;
- information about source of funds;
- information needed to assess transaction risk;
- records of identity or verification checks; and
- information required to prevent or detect fraud, money laundering, terrorist financing or other financial crime.
We will only request information that is reasonably necessary for the relevant transaction, legal requirement or compliance purpose.
Website and technical information
When you use our website, we may collect technical information such as:
- IP address;
- browser and device information;
- pages viewed;
- information about how you use the website;
- cookie and similar technology information; and
- information about your cookie preferences.
Please see section 7 for further information about cookies.
Payment information
Where card payment is available, payments may be processed by our payment provider.
We do not intend to store full payment-card numbers. Depending on the payment arrangement, we may receive transaction references, payment status and limited card information such as the last four digits.
3. Why we use your information and our lawful bases
We use personal information for the following purposes:
To provide our services
We use your information to prepare, administer and complete your reservation or transaction and to provide Click & Collect and other services.
Lawful basis: performance of a contract with you, or taking steps at your request before entering into a contract.
To comply with legal and regulatory obligations
We use information to comply with applicable legal and regulatory requirements, including anti-money-laundering, counter-terrorist-financing, record-keeping, accounting and tax obligations.
Lawful basis: compliance with a legal obligation.
To prevent and detect financial crime
We use information to carry out customer due diligence, assess relevant risks, monitor transactions where required, and prevent or detect fraud, money laundering, terrorist financing and other financial crime.
Lawful basis: compliance with legal obligations and, where appropriate, our legitimate interests in protecting our business, customers and the financial system.
To communicate with you and deal with enquiries and complaints
We use your information to respond to questions, provide customer support and investigate complaints.
Lawful basis: performance of a contract, compliance with legal obligations, or our legitimate interests in administering and improving our services, depending on the circumstances.
To maintain and improve our services
We may use information to maintain website security, troubleshoot problems, understand how our services are used and improve our services.
Lawful basis: our legitimate interests in operating, securing and improving our business, subject to applicable data protection requirements.
Marketing
Where we send marketing communications by electronic means, we will do so in accordance with applicable electronic-marketing and data-protection requirements.
Where consent is required, we rely on your consent and you can withdraw it at any time.
4. Identity checks and financial crime
As an HMRC-supervised money service business, we may be required to identify and verify customers, keep records, assess transaction risks and monitor transactions for financial-crime risks.
We may therefore request information such as identification documents, proof of address, information about the purpose or nature of a transaction, and information about the source of funds, depending on the circumstances.
Where we are legally required to make a report to a relevant authority, applicable law may restrict what we can tell you about the report or the reasons for certain compliance decisions.
We will only use information obtained for compliance purposes in accordance with applicable law and our legal and regulatory obligations.
5. Who we share information with
We do not sell your personal information and do not share it with other organisations for their own direct-marketing purposes.
We may share personal information where necessary for the purposes described in this policy, including with:
- payment providers that process or reconcile payments;
- money-transfer providers where you use a separate money-transfer service;
- IT, hosting, security and technology suppliers that provide services to us;
- professional advisers, accountants and auditors;
- HM Revenue & Customs and other regulatory or supervisory authorities;
- the National Crime Agency, police and other law-enforcement authorities where disclosure is required or permitted by law; and
- other suppliers or service providers where necessary to provide our services or comply with our legal obligations.
Where a supplier processes personal information on our behalf, we will require appropriate contractual and security arrangements.
6. How long we keep your information
We retain personal information only for as long as necessary for the purposes for which it was collected, including to meet legal, regulatory, accounting and reporting obligations.
Anti-money-laundering and transaction records
Where the Money Laundering Regulations require us to retain customer due-diligence or transaction records, we generally retain them for the applicable statutory period.
Depending on the circumstances, this may be five years from the date a business relationship ends or five years from the date a transaction is completed.
Some records may need to be retained for longer where another legal or regulatory obligation applies.
Accounting and tax records
Certain accounting, tax and financial records may need to be retained for longer periods where required by applicable law.
Enquiries and correspondence
We retain enquiries and correspondence for as long as reasonably necessary to deal with the enquiry, maintain an appropriate record of our communications and meet any applicable legal or regulatory obligations.
We periodically review these records and securely delete or anonymise information that is no longer required.
Marketing records
Where you have consented to marketing, we retain records of your consent and withdrawal for as long as reasonably necessary to demonstrate compliance with applicable marketing and data-protection requirements.
7. Cookies
Our website uses cookies and similar technologies.
Cookies are small files or similar technologies that can store information on your device or allow us to recognise your browser.
We use different categories of cookies depending on their purpose.
Strictly necessary cookies
These cookies are required for the website or a service you have requested to function properly, for example to maintain security or support essential website functionality.
Where a cookie is strictly necessary, it may be used without consent where permitted by law.
Functional cookies
Functional cookies support optional features and preferences, such as remembering choices made during your visit.
These cookies will only be used where the applicable consent requirements have been satisfied.
Analytical cookies
Analytical cookies help us understand how visitors use our website, such as which pages are visited and where users experience problems.
We will only use non-essential analytical cookies where you have given the required consent.
Marketing cookies
Marketing cookies may be used to measure advertising activity, understand interactions with advertising and personalise marketing.
We will only use marketing cookies or similar technologies where the required consent has been obtained.
Managing your cookie choices
You can change your cookie preferences at any time through the cookie settings available on our website.
You can also block or delete cookies through your browser settings. Blocking some cookies may affect how the website functions.
8. How we protect your information
We take appropriate technical and organisational measures to protect personal information against unauthorised access, loss, misuse, alteration or disclosure.
Information transmitted through our website is protected using encryption in transit where appropriate.
Access to customer information is restricted to people who need it for their role and are subject to appropriate confidentiality and security requirements.
Where identification documents are inspected in store, we will handle and record the relevant information in accordance with our legal and compliance obligations and our internal procedures.
9. Transfers outside the UK
We aim to keep personal information in the UK or, where appropriate, in countries that provide an adequate level of data protection.
Where personal information is transferred outside the UK and the transfer is not covered by an applicable adequacy arrangement, we will use an appropriate lawful transfer mechanism and safeguards as required by applicable data-protection law.
Information about relevant safeguards may be requested by contacting us at [email protected].
10. Your rights
Depending on the circumstances and subject to applicable legal exemptions, you may have the right to:
- request access to the personal information we hold about you;
- request correction of inaccurate or incomplete information;
- request erasure of your personal information;
- request restriction of processing;
- object to certain processing;
- request portability of information where the right applies; and
- withdraw consent where we rely on consent.
Your rights are not absolute. For example, we may be required by law to retain certain information and may therefore be unable to comply fully with a request for deletion.
You also have the right to object to processing based on our legitimate interests where the applicable legal conditions are met.
To exercise a right, contact [email protected]. Please include “Data request” in the subject line where possible and provide enough information for us to identify you and understand your request.
We will normally respond within the applicable statutory time limit, which is generally one month from receiving a valid request. Where permitted by law, this period may be extended for complex or multiple requests.
Complaints
If you are unhappy with how we have handled your personal information, please contact us first so that we can investigate your concern.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s data-protection supervisory authority. The ICO website is available at ico.org.uk.
11. Automated decision-making and profiling
We do not currently intend to make decisions about customers based solely on automated processing, including profiling, where those decisions have legal or similarly significant effects on you.
Where this changes, we will update this policy and provide any information required by applicable data-protection law.
12. Changes to this policy
We may update this Privacy & Cookie Policy from time to time to reflect changes to our services, technology, legal requirements or data-processing practices.
The latest version will be published on our website.
Where a change materially affects how we use personal information, we will provide appropriate information before the new processing begins where required by law.
Company information
- Registered name
- Travel Cashier Ltd
- Company number
- 12477944
- Registered office
- 57 Stroud Green Road, London, N4 3EG, United Kingdom
- HMRC MLR registration
- XMML00000152380
- Customer service
- +44 20 3417 8600
- [email protected]
Version 1.6 · Effective 1 July 2025 · Last reviewed 1 July 2025