Privacy Policy
Last updated: 8 July 2026 — draft for legal review.
1. Definitions
Scoop — Scoop [registered company name TBD] Ltd, registered in England and Wales (company number [TBD], registered office [TBD]), operator of the platform. Platform — the website, management apps and order pages. Restaurant — a professional user with an account. Customer— a consumer ordering on a restaurant's order page. UK GDPR — the UK General Data Protection Regulation together with the Data Protection Act 2018. Stripe — the third-party payment processor. Courier network — a third-party delivery service connected by the restaurant (e.g. Uber Direct).
2. Who is responsible for your data
- Restaurants: Scoop is the data controller for account management, billing and support.
- Customers: the restaurant is the controller; Scoop acts as its processor under Article 28 UK GDPR to fulfil orders.
- Website visitors: Scoop is the controller for navigation data, contact forms and cookies.
3. Data we collect
- Restaurants: name, company details, business address, professional email, phone, hashed and salted password, login history, IP address, billing information (payments handled by Stripe), menu configuration, usage statistics, technical logs, support messages.
- Customers: first and last name, phone, email (where provided), delivery address, basket contents, payment status (card data is handled solely by Stripe), IP address, device type, technical logs.
- Visitors: pages visited, traffic source, session duration, device type, IP address, contact-form submissions.
- Special category data: none collected (Article 9 UK GDPR).
4. Where the data comes from
Directly from you when you create an account, submit a form, place an order, contact support or browse the platform; technical data is collected automatically through logs and cookies.
5. Purposes and legal bases
- Account creation and management — performance of a contract.
- Providing the platform and processing orders — performance of a contract (and the processor agreement with the restaurant).
- Billing and accounting — contract and legal obligation.
- Transactional notifications (order confirmations, status updates) — performance of a contract.
- Customer support — contract and legitimate interest.
- Security and fraud prevention — legitimate interest and legal obligation.
- Aggregate statistics and service improvement — legitimate interest.
- Marketing emails — legitimate interest for existing clients; consent for prospects.
- Non-essential cookies — consent.
- Responding to lawful requests from authorities — legal obligation.
6. Who can access the data
Authorised Scoop staff, the relevant restaurant (for its own customers' orders), vetted processors bound by UK GDPR-compliant agreements, and competent authorities where legally required. Our processors include: our cloud hosting provider, Stripe (payments and anti-fraud), connected courier networks, our domain registrar, and email, logging and support tools. Scoop never sells, rents or trades personal data for commercial purposes. A detailed processor list is available on request via the contact form.
7. International transfers
We prioritise processing in the UK and the European Economic Area. Where data is transferred elsewhere, we rely on UK adequacy regulations, the UK International Data Transfer Agreement or Addendum, or other safeguards permitted by UK GDPR. Details are available on request.
8. How long we keep data
- Active restaurant account — for the duration of the subscription.
- Closed account — 30 days, then deletion (subject to legal retention duties).
- Customer order data — 3 years.
- Technical and security logs — 12 months maximum.
- Accounting records and invoices — 6 years (Companies Act 2006 / HMRC rules).
- Contact-form submissions — 3 years from last contact.
- Non-essential cookies — 12 months maximum.
- Prospect data — 3 years from last active contact.
9. How we protect data
HTTPS/TLS encryption in transit, cryptographic password hashing with salt, strict access controls, logging of sensitive actions, regular encrypted backups, separation of environments, regular security updates, and fully externalised payment processing with Stripe (PCI-DSS Level 1). Restaurants are responsible for keeping their own credentials safe.
10. Your rights
Under UK GDPR you have the right of access, rectification, erasure, restriction of processing, objection, data portability, and withdrawal of consent at any time. Submit requests via the contact form; we respond within one month (extendable by two months for complex requests) and may need to verify your identity. Requests about a specific order should go to the restaurant concerned (as controller) — we forward them as a courtesy where we can. You can complain to the Information Commissioner's Office (ICO): ico.org.uk, or Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
11. Cookies
Strictly necessary cookies need no consent. Audience measurement and any personalisation/marketing cookies are used only with your consent, requested by a banner on first visit and manageable at any time in settings or your browser. Non-essential cookies live at most 12 months before consent is requested again.
12. Automated decisions
We make no decisions producing legal or similarly significant effects based solely on automated processing (Article 22 UK GDPR). Automated fraud and anomaly detection runs without automated individual decisions.
13. Children
The platform is not intended for children under 13. We do not knowingly collect their data; anything discovered is deleted promptly. Please report concerns via the contact form.
14. Data breaches
We notify the ICO within 72 hours of becoming aware of a notifiable breach (Article 33 UK GDPR) and affected individuals where the risk is high (Article 34). Where we act as a restaurant's processor, we notify the restaurant without undue delay so it can meet its own obligations.
15. Changes to this policy
We may update this policy to reflect legal or technical changes. Substantial changes are communicated to restaurants by email with reasonable notice.
16. Contact
For any privacy question or to exercise your rights: the contact form on the website, or by post to Scoop [registered company name TBD] Ltd, [TBD registered office address]. Company legal information is available on written request.