Privacy Policy
Last updated: 29 June 2026
This policy explains how AllerSafe ("we", "us") collects, uses, and protects personal data when you use our website and service at allersafe.org. We are the data controller for the personal data described below. If you have any questions, contact us at support@allersafe.org.
1. What we collect
- Account data: your email address, used to sign you in with one-time codes.
- Business data you enter: venue names and addresses, ingredients, dishes, and allergen information. This is mainly business information, but a venue address may identify a sole trader.
- Billing data: if you subscribe, your payment is processed by Stripe. We do not see or store your card details — we only store a Stripe customer reference and your subscription status.
- Technical data: a strictly-necessary session cookie to keep you logged in, plus standard server logs (e.g. IP address, request times) used for security and reliability.
2. How we use it
- To provide and operate the service (authentication, storing your menus, generating labels, matrices and QR menus).
- To take payment and manage your subscription.
- To send you essential service emails (login codes, billing notices) and to respond to support requests.
- To keep the service secure, prevent abuse, and meet our legal obligations.
3. Our legal bases (UK GDPR)
- Contract: to provide the service you have signed up for.
- Legitimate interests: to secure, maintain and improve the service.
- Legal obligation: where we must keep records (e.g. for tax).
4. Who we share it with (sub-processors)
We use trusted providers to run AllerSafe. They process data only on our instructions:
- Supabase — database and storage.
- Vercel — application hosting.
- Stripe — payment processing.
- Resend — sending transactional emails.
Some of these providers may process data outside the UK/EEA. Where they do, appropriate safeguards (such as UK/EU standard contractual clauses) are in place. We do not sell your personal data.
5. How long we keep it
We keep your account and business data for as long as your account is active. If you close your account, we delete or anonymise your personal data within a reasonable period, except where we must keep certain records (for example, billing records for tax purposes). Login codes expire after 15 minutes.
6. Your rights
Under UK GDPR you have the right to access, correct, delete, restrict, or object to our use of your personal data, and the right to data portability. To exercise any of these, email support@allersafe.org. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).
7. Cookies
We only use a single strictly-necessary cookie to keep you signed in. We do not use advertising or tracking cookies, so no cookie banner is required. If this changes, we will update this policy and ask for your consent where needed.
8. Security
We protect your data with encryption in transit, access controls, and reputable infrastructure providers. No system is perfectly secure, but we take reasonable steps to safeguard your information and will notify you and the ICO of any breach where legally required.
9. Changes to this policy
We may update this policy from time to time. We will post the new version here and update the date above. Continued use of the service after a change means you accept the updated policy.
10. Contact
AllerSafe — support@allersafe.org