Privacy Policy
Last updated: 8 July 2026
This policy was written by reading the SpiceUp system's actual code — every statement below describes something the software really does, not template language. It covers two things: this website, and the SpiceUp point-of-sale product.
Part 1 — This website
This website is deliberately built to collect almost nothing:
- No cookies. The site sets no cookies of any kind — which is why there is no cookie banner.
- No analytics or trackers. There is no Google Analytics, no advertising pixel, no fingerprinting.
- No third-party requests. Fonts and images are served from this site itself. Your visit is not disclosed to Google, any CDN, or anyone else by this page.
- The contact form is the one way this site collects anything, and only when you choose to send it. What you enter (name, and optionally business name, address, email, phone, and your message) is stored securely in our own database and emailed to us so we can reply. It is used only to respond to your enquiry — never added to a mailing list, never shared, never used for marketing. Ask us to delete it at any time.
- Hosting: the site is hosted by Render (render.com), whose servers keep standard technical access logs (IP address, time, page requested) for security and operations.
Part 2 — The SpiceUp product
When a restaurant runs SpiceUp, the system handles personal data for three groups of people. Here is exactly what, and why.
2.1 Customers ordering online
| What we collect | Why | Legal basis (UK GDPR) |
|---|---|---|
| Name and phone number | To prepare your order and contact you about it | Contract — fulfilling your order |
| Delivery address and postcode | To deliver your food and calculate the delivery charge | Contract |
| Email address (optional) | To send your order confirmation receipt | Contract |
| Order contents and notes | To cook what you asked for | Contract |
| Account details, if you register (email, password) | To let you sign in; passwords are stored only as one-way cryptographic hashes — we cannot read them | Contract |
| Consent records (what you agreed to, when, from what device) | To prove we asked for your permission properly | Legal obligation |
| Marketing preferences | Only if you separately tick the marketing box — it is never bundled with ordering | Consent — withdraw any time |
2.2 Customers ordering by phone
- Calls may be answered by an AI ordering assistant. Callers are told at the start of the call that it may be recorded.
- We process the caller's phone number, the conversation (to understand the order), and the resulting order details.
- Call recordings are automatically deleted after 60 days; this happens by a scheduled job in the system, not by manual housekeeping.
- The conversation is processed by Google's AI service (Gemini) to understand speech; see "Who else touches the data" below.
2.3 Payments
- Card payments are processed by Stripe. Your card number goes directly to Stripe and never touches SpiceUp's servers.
- SpiceUp stores only: the amount, the payment method type, and Stripe's reference numbers — enough for receipts, refunds, and accounting.
2.4 Restaurant staff
- Staff accounts hold: name, username, role, and optionally an email — plus PINs and passwords stored only as one-way hashes.
- Order records note which staff member took an order (accountability for the business).
2.5 Cookies in the product
The ordering site and staff screens use strictly necessary cookies only: a session cookie that keeps you signed in (protected so scripts cannot read it) and a security token that blocks forged requests. There are no advertising, analytics, or tracking cookies anywhere in the product.
2.6 How long we keep things
| Data | Kept for | Then |
|---|---|---|
| Phone call recordings | 60 days | Deleted automatically |
| Payment processing logs | 90 days (180 for failed payments being investigated) | Deleted automatically |
| Orders and receipts | Up to 6 years | Kept for UK tax and accounting law, then deleted |
| Customer accounts | Until you ask us to delete them | Erased on request (see your rights) |
2.7 Who else touches the data (our processors)
| Service | What it does for us |
|---|---|
| Render | Hosts the application servers |
| MongoDB Atlas | Hosts the database (encrypted at rest) |
| Stripe | Processes card payments |
| Twilio | Connects phone calls and sends order text messages |
| Google (Gemini) | Understands speech during AI phone orders |
| Upstash | Short-lived caching to keep menus fast (no long-term personal data) |
| Cloudinary | Hosts menu photos (food images — not personal data) |
Some of these providers process data outside the UK. Where they do, transfers rely on the safeguards in their standard data processing agreements (UK adequacy decisions, the UK International Data Transfer Addendum, or Standard Contractual Clauses).
2.8 Your rights
Under UK GDPR you can ask us to:
- Show you your data (access/export) — SpiceUp has a built-in export function for exactly this;
- Correct it if it's wrong;
- Delete it — SpiceUp has a built-in erasure function that removes your records including call-recording audio, except what tax law requires us to keep;
- Stop marketing — withdraw consent any time; marketing consent is stored separately from your order data;
- Object or restrict processing in certain cases;
- Receive your data in a portable format.
Email jahangirbaigm@gmail.com and we will respond within one month. You can also complain to the UK regulator, the Information Commissioner's Office, at ico.org.uk.
2.9 How we protect it
- All connections are encrypted in transit (TLS); the database is encrypted at rest.
- Every staff member has their own login and role; admin access requires two-factor authentication.
- Sign-in attempts are rate-limited with automatic lockouts against guessing attacks.
- The system was independently security-audited before launch and the critical findings were fixed and verified.
- Nightly backups and around-the-clock uptime monitoring are in place.
2.10 Children
SpiceUp's services are not directed at children under 16, and we do not knowingly collect their data.
2.11 Changes to this policy
When the product changes what it does with data, this policy changes with it — that is a standing rule of how SpiceUp is built. The date at the top always reflects the latest revision. The highlighted [placeholders] will be replaced when the company registration completes; the practices described are in force now.