Privacy Policy

Last updated: May 2026

1. Our Commitment to Privacy

KitchenOS is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our kitchen management platform. We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Organisation name and subdomain
  • Administrator name and email address
  • Password (hashed and salted)
  • Billing information (processed by Stripe)

2.2 Usage Data

We automatically collect:

  • IP addresses and browser information
  • Device information (for mobile app)
  • Log data (timestamps, actions performed)
  • Session information

2.3 Kitchen Data

Data entered into the platform by your staff:

  • Stock items, quantities, and counts
  • Temperature readings
  • Compliance check records
  • Staff names and signatures
  • Supplier information
  • Recipe and allergen data

3. How We Use Your Information

  • To provide and maintain our services
  • To process payments and manage subscriptions
  • To send administrative emails (password resets, updates)
  • To respond to support requests
  • To improve our platform and user experience
  • To comply with legal obligations

4. Legal Basis for Processing

Under UK GDPR, we process personal data on the following bases:

  • Contract: Processing necessary to provide our service to you
  • Legitimate interests: Service improvement, fraud prevention, security
  • Legal obligation: Tax, accounting, and regulatory compliance
  • Consent: Where explicitly given (e.g., marketing emails)

5. Data Sharing and Third Parties

We do not sell your data. We only share data with:

  • Stripe: For payment processing (see Stripe Privacy Policy)
  • Vercel: For hosting our application
  • Neon: For database hosting
  • Law enforcement: When required by law or court order

6. Data Security

We implement appropriate technical and organisational measures:

  • SSL/TLS encryption for all data in transit
  • Encrypted database connections
  • Passwords hashed with bcrypt
  • Regular security audits and penetration testing
  • Access controls and audit logging

7. Data Retention

  • Account data: Retained while account is active
  • Kitchen records: 7 years (for food safety regulatory compliance)
  • Deleted accounts: Data removed within 30 days of deletion request
  • Backups: Retained for 30 days then purged

8. Your Rights

Under UK GDPR, you have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Erasure ("right to be forgotten")
  • Restrict processing
  • Data portability
  • Object to processing

To exercise these rights, email hello@bsmrox.com or use the data export feature in your admin panel.

9. Cookies

We use essential cookies for authentication and session management. We do not use tracking cookies for advertising. See our Cookie Policy for details.

10. International Transfers

Our infrastructure is hosted in the EU (Frankfurt) via Vercel and Neon. We do not transfer personal data outside the UK/European Economic Area except where adequate safeguards are in place.

11. Data Breach Notification

In the unlikely event of a personal data breach, we will notify affected users and the Information Commissioner's Office (ICO) within 72 hours where required by law.

12. Contact Us

For privacy-related questions or to exercise your rights:

13. Complaints

If you are unhappy with how we handle your data, you have the right to complain to the Information Commissioner's Office (ICO): ico.org.uk.