This sort of insecure, easily accessible customer data is exactly what you don't want to happen, both from a moral point of view and to stay on the right side of the ICO, who are in charge of enforcing the General Data Protection Regulations (GDPR) in the UK. You can see their detailed guidance here, and a useful checklist specifically for small businesses here.