Privacy Notice

Simply Catering internal web app

Last updated: June 2026

Who this notice is for

This privacy notice explains how Simply Catering uses personal information in the Simply Catering internal web app. The app is used by authorised staff, managers and administrators for internal catering operations.

It is written for people who have an app login, people whose details are recorded in the app, and staff who may be named in operational records.

What personal data the app stores

The app may store user account details such as name, email address, site, role, active status and password login information. Passwords are stored in protected form, not as plain text.

The app stores site and supplier information needed to run the catering operation, including site names, supplier names, contact details where provided, product lists and ordering settings.

Orders may include the site, supplier, order reference, delivery date, products, quantities, notes, status, and the user activity connected with creating, updating or sending the order.

Food safety records may include daily checks, temperature checks, cleaning records, probe checks, hot holding, cooling, cooking, reheating, deliveries, corrective actions, training records, safe method reviews, food safety issues and EHO record information.

Daily takings records may include date, site, cash totals, card totals, notes, the user who entered or updated the record, and related reporting information.

Square daily totals imported into the app may include daily sales totals and reconciliation information. Square does not store customer card numbers in our app, and the app is not intended to hold customer card numbers.

Invoices may include supplier details, invoice numbers, dates, totals, VAT, uploaded files, extracted invoice lines, product or ingredient matches, review notes and processing status.

Recipes, ingredients, allergens and nutrition records may include product names, ingredient details, supplier item details, pack sizes, costs, recipe methods, allergen information, nutrition information and related change history.

The app may also store audit and system activity, such as when records were created, changed, imported, processed, reviewed or submitted, and which user account was involved.

Why we use this data

We use this data to run supplier ordering, site operations, food safety checks, daily takings, invoice processing, Square takings reconciliation, recipe and ingredient management, allergen and nutrition records, reports and internal administration.

We also use it to manage user access, keep the app secure, maintain audit trails, investigate errors or misuse, support staff and managers, and meet legal, finance, employment, contract and food safety record keeping duties.

Our lawful basis

Under UK GDPR, we usually use this information because it is necessary for legitimate interests in running and protecting the catering business, managing staff and contractors, keeping operational records, and maintaining food safety and financial controls.

Some records are used because we need them to meet legal obligations, including food safety, tax, accounting, employment and health and safety duties. Where a specific legal basis is required, Simply Catering will handle the record in line with UK data protection law.

Who can access it

Access is limited to authorised users who need the information for their work. This may include site staff, managers, administrators and support providers who help operate or maintain the app.

Access levels may depend on role, site and business need. Administrators may be able to see more information so they can manage users, sites, suppliers, reports, imports and system settings.

Who it may be shared with

We do not sell personal information. We may share information where needed with internal managers, site teams, administrators, IT and support providers, professional advisers, insurers, auditors, regulators or public authorities.

Information may also be shared with suppliers or service providers where needed to place orders, resolve invoice queries, support food safety processes, maintain the app, process imported data or comply with the law.

If Square daily totals are used, Square remains a separate service provider for payment and sales information. This app stores daily totals and reconciliation information only where imported or entered; it does not store customer card numbers.

Retention

We keep information for as long as it is needed for operational, legal, audit, food safety, finance, employment, contract and reporting purposes.

Retention periods may vary by record type. For example, food safety, invoice, takings and audit records may need to be kept longer than routine working notes. When information is no longer needed, it should be deleted, anonymised or archived in line with internal procedures.

Security

The app is intended for authorised users only. Users should keep login details private, use the app only for work purposes, and only access records they need for their role.

Simply Catering uses appropriate technical and organisational measures to protect the information held in the app. No system can be guaranteed completely secure, so suspected unauthorised access, incorrect data or data loss should be reported promptly.

Your rights

You may have rights under UK data protection law, including the right to ask for access to your personal information, correction of inaccurate information, deletion, restriction, objection, or a copy of your information.

Some rights may be limited where records must be kept for legal, regulatory, employment, finance, or food safety reasons.

Contact

Contact your site manager or system administrator for privacy questions or to request help with your data.

Complaints

You can raise a privacy concern with Simply Catering first so we can try to put it right.

You also have the right to complain to the Information Commissioner's Office, the UK data protection regulator. The ICO website is ico.org.uk and its helpline is 0303 123 1113.