HospoPilot

Privacy & Data Retention Policy

Last updated: June 2026

1. Who we are

HospoPilot is a kitchen management SaaS platform operated by HospoPilot Ltd ("HospoPilot", "we", "us"). This policy explains what data we collect, how we use it, and how long we keep it. We are committed to complying with the UK GDPR and the Data Protection Act 2018.

For privacy queries contact us at support@hospopilot.co.uk.

2. Data we collect

  • Account data: name, email address, role, restaurant name when you sign up.
  • Operational records: temperature logs, cleaning logs, delivery records, incident reports, daily checks — entered by your team while using HospoPilot.
  • Photos: invoice photos attached to delivery records; photos attached to incident reports. Stored in Supabase Storage.
  • Training records: staff quiz attempts and allergen module completions, including staff names and scores.
  • Recipe and allergen data: ingredients, recipes, allergen flags entered by your team.
  • Usage data: standard server logs (IP address, browser type, pages visited) for security and analytics purposes.

3. How we use your data

  • To provide, maintain, and improve the HospoPilot platform.
  • To generate compliance records and audit trails for your business.
  • To send transactional emails (account setup, password reset, staff quiz reminders).
  • To process subscription payments via Stripe.
  • We do not sell your data to third parties or use it for advertising.

4. Data retention

We retain different types of data for different periods based on legal and operational needs:

Data typeRetention periodReason
Temperature & cleaning logs24 monthsEHO audit trail requirement
Delivery records24 monthsFood safety traceability
Incident reports36 monthsPotential legal claims window
Photos (invoices, incidents)24 monthsAuto-deleted after 24 months to manage storage
Staff training records36 monthsCompliance and due diligence
Recipe & allergen dataAccount lifetime + 12 monthsBusiness continuity
Account & billing data7 years after account closureUK tax and financial record requirements

Records older than their retention period are permanently deleted from our systems. Text records are anonymised before deletion where required for aggregate analytics.

5. Data security

All data is stored in Supabase (EU region) with encryption at rest and in transit. Access is controlled via row-level security so each restaurant can only access its own data. We use Supabase Auth for authentication. Payment processing is handled entirely by Stripe — we never store card details.

6. Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your data (subject to our legal retention obligations above).
  • Object to processing or request restriction of processing.
  • Data portability — receive your data in a machine-readable format.
  • Lodge a complaint with the ICO (ico.org.uk).

To exercise any of these rights, email us at support@hospopilot.co.uk.

7. Third-party processors

  • Supabase — database and file storage (EU)
  • Vercel — hosting and CDN
  • Stripe — payment processing
  • Anthropic — AI features (ingredient categorisation, allergen suggestions). Data sent to Anthropic is not used to train their models under our enterprise agreement.
  • Resend — transactional email

8. Cookies

HospoPilot uses strictly necessary session cookies for authentication. We do not use advertising or tracking cookies. No consent banner is required under PECR for strictly necessary cookies.

9. Changes to this policy

We may update this policy. Material changes will be notified by email or in-app notice. The latest version is always available at hospopilot.co.uk/privacy.