Privacy Policy

Last updated: 13 July 2026

This policy explains how SafeTap (“we”, “us”) collects and uses personal data when you use our website and mobile app. We are the data controller for the account information you provide, and a data processor for the records your business creates. We comply with the UK GDPR and the Data Protection Act 2018.

What we collect

  • Account data: your name, email, business name and password (stored hashed).
  • Staff data: staff names and 4-digit PINs (stored hashed). PINs are never stored in plain text.
  • Records: the checks, temperatures, notes and photos your team logs. Photos may show people and are treated as personal data.
  • Technical data: device tokens for push notifications, and basic logs needed to run the service.
  • Bluetooth: the app can connect to a Bluetooth probe thermometer to read temperatures. Bluetooth is used only for this, on your device — we do not collect location data and we do not track nearby devices.

How we use it

  • To provide the app: storing your daily records and showing them back to you.
  • To send reminders and alerts you have enabled.
  • To take payment via our payment provider, Paddle, acting as merchant of record.
  • To keep the service secure and meet our legal obligations.

Legal basis

We process account and record data to perform our contract with you. Marketing emails are sent only with your consent, which you can withdraw at any time.

Where your data lives

All SafeTap data is hosted in the United Kingdom (AWS London, eu-west-2) and MongoDB Atlas London. Photos and exports are stored in a private store and are only accessible through short-lived, authenticated links.

Retention

Records are retained for around 24 months by default to support food-safety due diligence, after which they are automatically deleted. You can request earlier deletion of your data.

Deleting your account

You can delete your account at any time from inside the app: More → Account → Delete account. Deleting an owner account cancels the subscription immediately and removes sign-in access for the whole team. Food-safety records are kept for the business’s legal audit trail (they may need to be shown to an Environmental Health Officer) and are then deleted under the retention period above. To have personal details removed sooner, email hello@safetap.co.uk.

Sharing

We do not sell your data. We share data only with the processors that run the service (e.g. AWS for hosting, Paddle for payments, Firebase for push notifications), under appropriate agreements.

Cookies

We only set analytics cookies with your consent, as UK PECR requires. On your first visit a banner asks whether we may use Google Analytics to understand how visitors find and use the site (for example, which pages are viewed and where visitors arrive from). If you reject — or simply ignore the banner — no analytics cookies are set at all. We use this information only in aggregate to improve the website, and we do not use advertising or cross-site tracking cookies. You can change your mind at any time via Cookie settings in the page footer; withdrawing consent also removes any analytics cookies already set.

Two things sit outside the banner because they are strictly necessary: your cookie choice itself (stored in your browser so we do not keep asking), and cookies set by Paddle, our payment provider, during checkout to process your payment securely and prevent fraud — these are only set on the checkout page itself.

Your rights

You have the right to access, correct, export or delete your personal data, and to object to or restrict certain processing. To exercise these rights, email hello@safetap.co.uk. You can also complain to the UK Information Commissioner’s Office (ICO).

Contact

Questions about this policy? Email hello@safetap.co.uk.