HospoPilot is a kitchen management SaaS platform operated by HospoPilot Ltd ("HospoPilot", "we", "us"). This policy explains what data we collect, how we use it, and how long we keep it. We are committed to complying with the UK GDPR and the Data Protection Act 2018.
For privacy queries contact us at support@hospopilot.co.uk.
We retain different types of data for different periods based on legal and operational needs:
| Data type | Retention period | Reason |
|---|---|---|
| Temperature & cleaning logs | 24 months | EHO audit trail requirement |
| Delivery records | 24 months | Food safety traceability |
| Incident reports | 36 months | Potential legal claims window |
| Photos (invoices, incidents) | 24 months | Auto-deleted after 24 months to manage storage |
| Staff training records | 36 months | Compliance and due diligence |
| Recipe & allergen data | Account lifetime + 12 months | Business continuity |
| Account & billing data | 7 years after account closure | UK tax and financial record requirements |
Records older than their retention period are permanently deleted from our systems. Text records are anonymised before deletion where required for aggregate analytics.
All data is stored in Supabase (EU region) with encryption at rest and in transit. Access is controlled via row-level security so each restaurant can only access its own data. We use Supabase Auth for authentication. Payment processing is handled entirely by Stripe — we never store card details.
Under UK GDPR you have the right to:
To exercise any of these rights, email us at support@hospopilot.co.uk.
HospoPilot uses strictly necessary session cookies for authentication. We do not use advertising or tracking cookies. No consent banner is required under PECR for strictly necessary cookies.
We may update this policy. Material changes will be notified by email or in-app notice. The latest version is always available at hospopilot.co.uk/privacy.