BakeSafe Privacy Policy

Contact: bakesafehelp@gmail.com · Version v1.7

Controller and contact: BakeSafe is provided by bakesafeuk. Contact us at bakesafehelp@gmail.com about privacy or data requests. This notice explains how BakeSafe handles personal data under UK data protection law.

Roles (controller and processor): For your BakeSafe account data (for example your sign-in email, display name, Firebase account ID, subscription status, business name/address, settings, and the food-safety records you create for your own business), BakeSafe is the controller. Where you enter personal data about your customers into BakeSafe, you are the controller of that customer data and BakeSafe is the processor. We store and process that customer data only to provide the BakeSafe service to you, on your instructions by you using the app. We do not use your customers’ details for our own marketing, and we do not sell them.

Account data: When you sign in with Google or Microsoft (including Outlook), that provider handles the sign-in process and BakeSafe receives your email address, display name if provided, and account identifiers needed to create and secure your BakeSafe account. We use this to sign you in, keep your records separate, and sync your account across your phone, tablet and laptop.

Records you enter: BakeSafe stores the compliance information you add, including temperature logs, daily diary entries, 4-weekly reviews, allergen and ingredient records, label details, supplier details, stock records, availability, customer orders, invoices, business name/address and settings.

Customer data we may process as your processor: If you add it to an order or related feature, this can include customer name, phone number, email address, delivery address, order details, notes, deposit or payment notes you enter, invoice details, order confirmation link identifiers, and your customer’s response on a confirmation page (for example confirm or something’s not right). If you attach an inspiration photo to an order, that image is also stored for that order.

Order confirmation links: BakeSafe provides one-time order confirmation links and pages as part of the service so your customer can view order details and respond. You choose whether, when and how to send that link (for example using Share on your device). BakeSafe does not email, text or otherwise message your customers for you. Your customer can open the same link more than once to view the order before they respond. Once they submit a response (confirm or report something’s not right), that link stops working and they cannot reopen it to see the order again. You can create a new confirmation link from BakeSafe if you need to send another one.

Your responsibilities as controller of customer data: You must only enter customer details you are allowed to use, keep them accurate where needed, and give your customers any privacy information the law requires for your business. You decide what customer information to collect and how you contact them.

Photos and label scanning: If you use photo or bulk photo scanning, the images are sent securely to BakeSafe's cloud scanning service, supported by Google cloud processing services, to read ingredient and allergen information. BakeSafe stores the extracted text you choose to keep, not the original photo as a permanent account record.

Support chat: When you use BakeSafe’s in-app chat, we use Crisp (crisp.chat) as our processor to run that messaging. Chat can include the messages you send, screenshots or other images you attach, and your BakeSafe sign-in email and display name so we can match the conversation to your account. Crisp may also process technical data needed for the chat session, such as IP address, browser or device information, and necessary chat session cookies (names starting with crisp-client/). Crisp hosts messaging data in the European Union. Crisp’s own privacy information is at crisp.chat/en/privacy.

Chat retention: After we have finished helping you, we delete the chat from our Crisp inbox unless we need to keep it for a legitimate reason. We may keep a chat (including any images) where needed for a refund or billing dispute, a complaint or claim, fraud or abuse investigation, security, legal compliance, or another similar legitimate purpose. Crisp keeps conversation history available to BakeSafe until we delete it; Crisp also keeps certain system logs (for example connection logs) for up to one year under its own rules. If you ask us to delete your personal data, we will remove related chat content we control unless we need to keep it for one of the reasons above.

Notifications: If you turn on notifications, BakeSafe stores a device push token and your reminder settings so Firebase Cloud Messaging can send order, stock expiry and FSA alert notifications to you (the baker). You can turn reminders off in BakeSafe and can also block notifications in your device settings.

Payments and subscriptions: If you subscribe, payment is handled by Stripe. Stripe processes payment and billing information such as your name, email address, billing address, payment method details, payment status, invoices and fraud checks. BakeSafe stores Stripe customer/subscription IDs and subscription status so we can manage access. BakeSafe does not store full card details. Stripe processing for your subscription is about your billing with BakeSafe, not messaging your customers.

FSA alerts: BakeSafe checks the public Food Standards Agency food alerts feed and compares relevant alert wording with your saved stock/allergen records so it can show matching alerts.

Cookies and local app storage: BakeSafe uses necessary cookies and browser/PWA storage such as localStorage, sessionStorage, IndexedDB, cache storage and a service worker so the app can sign you in, keep records synced, protect backend requests, remember essential preferences, recover from cached app issues, and work as an installed PWA. These essential Firebase/Google and BakeSafe storage technologies are needed for the service to function. BakeSafe does not use advertising or analytics tracking cookies.

Optional chat cookies: Crisp support chat is optional. BakeSafe asks for chat cookie consent before loading Crisp chat. If you do not allow chat cookies, BakeSafe still works, but Crisp chat will not open on that browser or device. Crisp chat cookies use names starting with crisp-client/ and can last for the session or up to 6 months by default, renewed when Crisp chat loads. See the full Cookie Policy.

Why we use data: We use your account and records data to provide the BakeSafe service, save and export your records, sync across devices, send reminders you enable, keep the app secure and reliable, help with support requests you send through chat, and help you maintain food safety records. Where we act as processor of your customers’ data, we process it only to host and sync your orders, show confirmation pages, support invoices/exports you generate, and related order features — not for BakeSafe’s own marketing to those customers. The lawful bases for BakeSafe as controller of your account data are contract, legitimate interests, and consent or device permission for notifications.

Who processes it: BakeSafe uses Google Firebase Authentication, Firestore, Cloud Functions and Cloud Messaging for sign-in, storage, processing and notifications; Microsoft for Microsoft/Outlook sign-in when you choose that option; Stripe for payment and subscription processing; and Crisp for in-app support chat. BakeSafe's cloud scanning service, supported by Google cloud processing services, processes label photos when you choose to scan them. Your browser, operating system and device notification services may process app and notification data needed to deliver the PWA. We do not sell your data. We may update this list of sub-processors from time to time as the service changes.

When we may share data: We may share relevant information if needed to prevent or investigate scams, fraud, abuse or security issues, to protect BakeSafe or other users, to comply with the law, or to respond to a valid request from a court, regulator, law enforcement or other public authority.

Where it is stored: Account and records data is stored and processed using Google services. Support chat data is processed by Crisp in the European Union. Some of our providers may process data outside the UK, including in the EU/EEA or further afield. Where personal data is transferred outside the UK, we rely on lawful transfer safeguards such as the UK’s adequacy arrangements (including for the EU/EEA) or standard contractual clauses. Microsoft and Stripe may also process relevant data under their own transfer arrangements when you use their services through BakeSafe.

Retention: Daily task records are deleted after 6 months. Customer orders (including customer contact details on those orders) are kept until you delete them (subject to the in-app order limit). Stock control is active stock only. Consent records are kept for legal purposes. Push tokens are kept while notifications are enabled or usable. After a customer responds on a confirmation link, that link mapping is removed; the response status remains on the order until you delete the order. Support chats are deleted from our Crisp inbox when no longer needed, unless kept for a legitimate reason as described under Chat retention. Deletions are permanent, so export records you need to keep.

Security: We use access controls and industry-standard protections provided by our hosting and authentication providers, including encrypted connections, to help protect data in BakeSafe. No method of transmission or storage is completely secure.

Your rights: You can ask to access, correct, delete, restrict or receive a copy of your personal data, and you can object to some processing. You can withdraw notification permission at any time. Contact bakesafehelp@gmail.com to exercise these rights. You can also complain to the Information Commissioner's Office at ico.org.uk. If one of your customers asks about their data, that request is primarily for you as controller; you can correct or delete their details in BakeSafe by editing or deleting the relevant order, and we will help where we act as processor.

Beta notice: BakeSafe is in testing and supports record-keeping, but you remain responsible for meeting your own food safety and business obligations. Do not rely on BakeSafe as your only compliance record.