Platform Privacy Policy
This policy explains how BakeCheck handles personal data in connection with the member platform — the admin dashboard used by bakeries and their staff. It covers both the account data we control and the Shopper data we process on your behalf.
This is the privacy policy for Members (bakery businesses using the platform). Members of the public ordering from a bakery's storefront should read that shop's own consumer privacy notice, linked in the storefront footer.
This policy is written to reflect the UK GDPR and the Data Protection Act 2018.
1. Who is the controller
BakeCheck is operated by [LEGAL REVIEW: insert operating legal entity name, company number, registered office, and — if appointed — Data Protection Officer / UK representative contact].
- For your account and platform-management data (see §2), BakeCheck is the controller.
- For your Shoppers' personal data (names, contact details, and orders placed through your storefront), you (the Member) are the controller and BakeCheck is your processor — see §4.
2. Account data we collect and why
When you use the member platform we process:
- Account identity — your email address, your name, and a securely hashed password. We never store your password in plain text.
- Workspace content — the ingredients, recipes, products, and label records you create, including the audit trail of label actions (which records the acting user's email against each generate, approve, or export event).
- Authentication data — a secure, HTTP-only session cookie, and one-time invite and password-reset tokens (stored only as hashes).
We use this data to provide the Platform, authenticate you, maintain the label audit trail that food-labelling good practice requires, and communicate with you about the service.
We do not use analytics, advertising, or third-party tracking, and we do not log your IP address or device fingerprint for tracking purposes. The only cookies we set are those strictly necessary to keep you signed in.
3. Lawful bases
We rely on:
- Performance of a contract — to provide the Platform under the Membership Terms.
- Legitimate interests — to secure the Platform, prevent misuse, maintain audit records, and support you. [LEGAL REVIEW — confirm legitimate-interests assessment.]
- Legal obligation — where we must retain or disclose data to comply with the law.
4. Shopper data: our role as your processor
When your Shoppers place orders, the Platform processes their personal data — typically name, email, phone number, delivery/collection address, and order history — on your instructions and only to provide the Platform to you. In respect of this data:
- You are the controller and BakeCheck is the processor.
- We process Shopper data only to operate your storefront, take and manage orders, and send the transactional emails you enable (order confirmations, acceptance, and collection reminders).
- We use the following categories of sub-processors: our hosting provider and the email/SMTP provider used to send platform and order emails. [LEGAL REVIEW — list named sub-processors and their locations.]
- We apply appropriate technical and organisational security measures, including tenant isolation, encryption of stored SMTP credentials, and hashed passwords and tokens.
- On termination we make your data available for export and then delete it (see §7).
- We do not use Shopper data for our own purposes and will not process it outside your documented instructions.
[LEGAL REVIEW — this section functions as a data-processing agreement (DPA) and should be reviewed, and may need to be issued as a separate signed DPA, before paid memberships launch.]
5. Email
Platform emails (such as user invitations) are sent using the platform's configured SMTP service. Order-related emails to your Shoppers are sent using the SMTP settings you configure for your own Workspace. Stored SMTP credentials are encrypted at rest.
6. International transfers
[LEGAL REVIEW — confirm whether any hosting or email sub-processor transfers data outside the UK/EEA and, if so, the safeguards relied upon (e.g. UK IDTA / adequacy).]
7. Retention
We retain account and Workspace data for as long as your membership is active and for a reasonable period afterwards to allow export, then delete or anonymise it. One-time invite and reset tokens expire automatically. [LEGAL REVIEW — define specific retention periods, including for order records held on your behalf.]
8. Your rights
Under UK data protection law you have rights to access, rectify, erase, restrict, and port your personal data, and to object to certain processing. To exercise these rights in respect of your account data, contact us using the details below. Where the request concerns Shopper data, the Shopper should contact the relevant bakery (the controller), and we will assist that bakery as its processor. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
9. Cookies
We use only strictly necessary cookies for authentication. We do not set analytics, advertising, or tracking cookies, so no cookie consent banner is required for non-essential cookies. [LEGAL REVIEW — revisit if analytics is ever added.]
10. Changes and contact
We may update this policy; the current version and effective date are shown at the top of this page. Questions or requests can be sent to [LEGAL REVIEW: insert contact / DPO email].