ChefsRecords

Privacy Policy

ChefsRecords · Last updated: 10 October 2026

Who We Are

ChefsRecords is a food safety and staff management app for UK kitchens. We take your privacy seriously and are committed to protecting your personal data.

We have not appointed a Data Protection Officer, as we fall below the threshold that requires one. Data protection questions are handled directly by us using the contact form below.

Get in touch →

Your Role and Ours

ChefsRecords is a tool you use to keep records about other people - your staff and your suppliers. That makes this a two-part relationship, and UK GDPR treats each part differently.

  • For your own account data (your email address, subscription status and app settings), we are the "controller". We decide what is collected and why.
  • For the records you create about your staff and suppliers (names, incidents, meetings, absence reasons, right to work checks, certificates), you - or the business that employs you - are the controller. You decide what to record, why, and for how long. We are the "processor": we store and process that data on your instructions and never use it for our own purposes.

This matters in practice. Your staff have rights over the data you record about them, and those requests come to you, not to us. If a staff member asks what you hold about them, you can answer from the app and Settings > Export records. If such a request ever reaches us directly, we will point the person back to you and let you know it happened.

You are also responsible for telling your staff that you keep these records, and for having a lawful reason to keep them. Most employers cover this in a staff privacy notice or in the employment contract.

If your kitchen adds team members - other Managers, Supervisors and Staff who sign in themselves - the records they make belong to the kitchen too, with their names on them. The kitchen, as controller, decides how long to keep them.

What Data We Collect

We collect and store the following data when you use ChefsRecords:

  • Your account email address
  • Team members, if your kitchen has them: their names, job titles and roles (Manager, Supervisor or Staff), and for Supervisors and Staff a sign-in PIN, which is stored only as a one-way hash we cannot read back
  • Linked kitchen devices: a name for each device, whether it is shared or one person's phone, and a sign-in token, which we store only as a hash
  • Who recorded what: the name of the team member who took a reading, completed a checklist or logged an incident, stored with the record
  • Incident records (descriptions, categories, severity, status, photos)
  • Staff records (names, roles, and optional compliance tracking data)
  • Supplier records (name, category, contact details, account number, notes)
  • Staff activity records (lateness in minutes, absence in hours, overtime in hours)
  • Stock records (item names, quantities, storage locations, expiry dates)
  • Checklist records (your checklist templates and the completed history of each run)
  • Equipment records (the name, optional serial number, note and use of each probe your kitchen registers, and the name of the Manager who added it). A probe check on a checklist also stores the probe's name and serial number in the reading. This is information about your equipment, not about a person - please do not put personal details in the notes
  • Temperature records (cooking, cooling, hot holding, reheating and delivery temperatures - the readings taken, the item or delivery they relate to, timestamps, and any note or delivery-note reference you add)
  • Training and certificate records (certificate type, dates, expiry) - Pro plan only
  • Right to work records (document type, date checked, expiry) - Pro plan only
  • 1-to-1 meeting records (date, notes, topics discussed, optional digital signature)
  • Return to work interview records (absence dates, reason, fitness confirmation, employee signature) - Pro plan only

We do not collect any data beyond what is needed to run the app.

Why We Process It, and Our Lawful Basis

UK GDPR requires a lawful basis for each purpose. For the data where we are the controller, ours are:

  • Running your account and providing the app - performance of a contract, Art. 6(1)(b). Without your email address and subscription status we cannot give you access.
  • Taking payment - performance of a contract, Art. 6(1)(b). Payments are handled by Apple or Google through RevenueCat.
  • Keeping the service secure and working - legitimate interests, Art. 6(1)(f). This covers crash reporting and preventing abuse. We keep it proportionate by stripping personal identifiers before any crash report leaves your device.
  • Meeting our own legal obligations - legal obligation, Art. 6(1)(c). For example, retaining billing records for the period tax law requires.

For the staff and supplier records you create, the lawful basis is yours to decide as the controller. In an employment context this is usually legitimate interests, or compliance with a legal obligation such as food safety and right to work law. We process that data only on your instructions.

Sensitive Data (Article 9)

Some of what the app can record is "special category" data under Article 9 of UK GDPR, which carries stricter rules:

  • Sickness absence reasons recorded during a Return to Work interview may reveal information about a person's health.
  • Right to Work documents may reveal nationality or immigration status.

Where the app captures this, it shows a notice at the point of entry so whoever is recording it knows what they are handling.

As the controller of that data, you are responsible for having a valid Article 9 condition before you record it. In an employment context this is usually Art. 9(2)(b) - obligations in employment law, supported by an appropriate policy document - or the explicit consent of the staff member. If you are unsure, take HR or legal advice before recording health information about your team.

We handle this data only as your processor. We do not analyse it, profile it, or use it for any purpose of our own.

How We Use Your Data

Your data is used solely to provide the features of the ChefsRecords app. We do not sell, share, or use your data for advertising or marketing purposes. Your kitchen's records are accessible only to the people in your kitchen when they are signed in, and each of them only according to their role (Manager, Supervisor or Staff).

Data Storage

All app data is stored securely using Supabase, a cloud database provider. Our database is hosted in the United Kingdom (London - AWS eu-west-2) and does not leave the UK in normal operation. Data is encrypted in transit (HTTPS/TLS) and at rest. Access is protected by Row Level Security - only people in your kitchen can read or change its data, and each role only what it is allowed to.

Incident photos and 1-to-1 meeting signatures are stored in a private storage bucket. They are accessed via short-lived signed URLs (1-hour expiry) generated at the moment you view them, so a URL accidentally shared cannot be reused indefinitely.

Exporting your records

A Manager can export the kitchen's records from Settings as a spreadsheet file (.xlsx) holding the kitchen's temperature records, checklists, incidents, suppliers and stock. The file is created on the Manager's own device and is not encrypted, so anyone who has it can open it - you are responsible for keeping it safe and deleting it when it is no longer needed.

Staff files (right-to-work records, certificates, meetings and attendance) and incidents about a member of staff are included only if the Manager chooses to include them. Photos and signatures are not included; they remain in our cloud storage and are only viewable when signed in to your account. Copies left in the app's own folder on the device are deleted automatically after 30 days.

Payments & Subscriptions

Subscription payments are handled by Apple (App Store) or Google (Google Play) through RevenueCat. We never see or store your payment card details. RevenueCat receives your account's user ID, your App Store or Google Play purchase records and basic device details its software sends. It tells us your subscription status (Trial, Standard or Pro) and the purchase events behind it, such as the product, the store and renewal or expiry dates, so the right plan is unlocked.

Data Retention

We retain personal data only for as long as we need it to provide the service, in line with UK GDPR Art. 5(1)(e) (the storage-limitation principle).

  • Auto-deleted after 6 years: closed incident records, staff 1-to-1 meeting records, staff activity records (lateness, absence, overtime), training and certificate records, and right-to-work records are deleted automatically 6 years after their creation date by a nightly server job. Open incidents (those not yet marked Closed) are kept indefinitely as unfinished business.
  • Why 6 years, and what it is not: this is our default housekeeping period, not a legal retention requirement. UK food hygiene law (Reg. 852/2004, Art. 5) requires records to be kept for an appropriate period and sets no fixed number. Some records carry their own rules that differ from our default - in particular right-to-work checks, which the Home Office expects to be kept for the duration of employment plus at least 2 years, and accident records under RIDDOR, which must be kept for at least 3 years. Where your own obligations require a different period, export and retain those records yourself.
  • Kept while your account is active: staff profiles, suppliers, stock items, checklists and their completed run history, temperature records, and your workplace settings are retained for as long as your kitchen's account is active. They are not on the automatic 6-year timer - they are removed when the kitchen is deleted or when you ask us to delete them (see Account deletion below).
  • Audit log: every change to a record is logged in an internal audit trail for accountability under Art. 5(2). The audit log is retained for 24 months and then auto-purged daily. Free-text content (notes, descriptions, reasons) is replaced with [REDACTED] before storage so the original wording does not persist beyond the live record.
  • Crash, error and performance data: Sentry (EU/Frankfurt) retains crash and error reports, and the performance timings from a sample of sessions, for 90 days. Personal identifiers (email, IP address, query strings, RC user IDs) are stripped before transmission.
  • Account deletion: deleting your account (Settings > My profile > Delete Account) removes your sign-in or PIN, your settings and your place on the team list, straight away. If your kitchen carries on, the records you made stay with it, with your name on them, as does anything the kitchen keeps about you such as training or right to work records. They are the kitchen's compliance records, and the kitchen, as controller, decides how long to keep them. If you are the kitchen's billing Manager and nobody else is left, the kitchen and all its records are removed, and its photos and signatures within 30 days. The 6-year retention rule does not apply. Deleting your account does not cancel a subscription - cancel it in your Apple ID or Google Play settings.
  • Storage objects (incident photos, signatures): a weekly server job removes any storage file no longer referenced by a database record (orphans), so deleted records do not leave files behind.
  • Exported records: when a Manager exports records from Settings, the spreadsheet goes wherever they choose to save it (iCloud, email, Files). It is not encrypted. We never see or store it, and any copy saved elsewhere is under your control. The copy left in the app's own folder on the device is deleted automatically after 30 days.

If Something Goes Wrong

If we become aware of a personal data breach affecting your data, we will tell you without undue delay, and in any event within 72 hours of becoming aware of it where the breach is likely to result in a risk to people's rights.

Because you are the controller of the staff and supplier records you create, you may then have your own duty to report the breach to the ICO under Art. 33, and in serious cases to the people affected under Art. 34. We will give you what you need to make that judgement: what happened, which data was involved, and what we have done about it.

Where a breach affects your own account data, we will report it to the ICO ourselves if the law requires it.

Your Rights (UK GDPR)

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your data
  • Restrict how we process your data while a concern is being resolved (Art. 18)
  • Export your data in a portable format (a Manager can use Export records in Settings - a spreadsheet, not encrypted)
  • Object to processing of your data
  • Ask for a person to review any decision about you that used the Incident Score. The score shown in the app and in PDF reports is calculated automatically from logged incidents and is guidance only - you can ask your manager to review it, give your view, and challenge it.

To exercise any of these rights, please contact us.

You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority, if you think we have handled your data badly. We would rather you came to us first so we can put it right, but you are not required to.

Complain to the ICO →

Third-Party Services

ChefsRecords uses the following third-party services:

  • Supabase - database and file storage (supabase.com), hosted in the UK (London)
  • RevenueCat - subscription management (revenuecat.com); receives your account's user ID, your App Store or Google Play purchase records and basic device details its software sends, so it can tell us your subscription status. Never your kitchen records.
  • Expo - app build and delivery platform (expo.dev)
  • Sentry - automated crash and error reporting (sentry.io), hosted in Germany. Receives crash and error reports (stack traces, device model, OS version and recent navigation breadcrumbs) when something goes wrong in the app, and performance timings (how long screens and requests take) from a sample of about 1 in 5 sessions. Personal data (names, incident details, photos, signatures, emails) is filtered out before transmission. Disabled in development builds. You can opt out of Sentry by contacting us.
  • Google (Google Forms) - our contact form. If you contact us through it, Google receives and stores whatever you write in your message. Please describe issues generally rather than pasting staff names or sensitive details into a support request.

Each of these services processes data under written terms that give it the same or equal protection to this policy. Each also has its own privacy policy.

Children's Privacy

ChefsRecords is not directed at children under the age of 13. We do not knowingly collect personal data from anyone under 13. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

Changes to This Policy

If we make material changes to this privacy policy, we will notify you within the app. Continued use of ChefsRecords after changes are posted constitutes your acceptance of the updated policy.

Contact

If you have any questions about this privacy policy or how we handle your data, please use our contact form.

Open contact form →