1. Who we are
KitchenOps is operated by Simpson Software. KitchenOps provides hospitality operations software for restaurants, cafés and other food-service businesses.
If you have a privacy question or want to exercise your data rights, contact us at hello@kitchenops.co.uk.
2. Information we collect
Depending on how you use KitchenOps, we may process:
- Account information, such as your name, email address and login details.
- Business information, including business name, sites and operational settings.
- Team information entered by authorised business users, such as staff names, roles and permissions.
- Operational records, including prep, handovers, waste, products, inventory, purchasing, receiving, stocktakes, recipes and related notes.
- Supplier information entered by customers, including supplier names, contacts and email addresses.
- Technical and security information needed to operate, protect and troubleshoot the service.
- Support communications when you contact us for help.
KitchenOps is not designed for customers to store unnecessary special-category personal data in ordinary operational fields.
3. How we use information
We use information to:
- Create and maintain KitchenOps accounts and workspaces.
- Provide the features and services requested by customers and their authorised users.
- Authenticate users and apply roles and permissions.
- Send operational emails, including supplier purchase orders and service-related messages.
- Provide support, investigate faults and maintain service reliability and security.
- Protect KitchenOps, our customers and users from misuse, fraud or unauthorised access.
- Meet legal, regulatory, accounting or compliance obligations where applicable.
4. Our lawful bases
Where UK data protection law applies, the lawful basis depends on the purpose and the relationship involved. We may rely on performance of a contract, legitimate interests, legal obligations, or consent where consent is specifically requested.
Our legitimate interests include operating and improving KitchenOps, providing customer support, maintaining security and preventing misuse, provided those interests are not overridden by your rights and freedoms.
5. Service providers and sharing
We do not sell personal data. We use trusted service providers where necessary to run KitchenOps. These may include:
- Supabase for application hosting, database, authentication and cloud services.
- Vercel for website and application delivery infrastructure.
- Resend and related email-delivery infrastructure for transactional email.
We may also disclose information where required by law, to protect legal rights or security, or as part of a legitimate business reorganisation. Service providers are only given information needed for the services they provide.
6. International processing
Some technology providers may process information outside the United Kingdom. Where UK data protection law requires safeguards for an international transfer, we use or rely on the safeguards made available by the relevant provider and applicable law.
7. Data retention
We keep personal data only for as long as it is reasonably needed for the purposes described in this policy, to provide the service, resolve disputes, maintain security, or meet legal and accounting obligations.
Retention periods can vary by type of information. When an account or workspace is deleted, information is deleted or anonymised within a reasonable period unless we need to retain particular records for a legal, security or legitimate business reason.
8. Account and data deletion
You can request deletion of your KitchenOps account and associated personal data using our account deletion page or by emailing hello@kitchenops.co.uk with the subject “KitchenOps account deletion request”. We may need to verify your identity and authority before deleting business or user records.
Where a business controls information about its own staff or users, we may refer an individual request to the relevant business administrator where appropriate.
9. Security
We use technical and organisational measures designed to protect information, including authenticated access, role-based permissions, secure hosting and encrypted network connections. No online service can guarantee absolute security, so we also encourage customers to protect passwords and limit account access to authorised users.
10. Your data protection rights
Depending on the circumstances and lawful basis, UK data protection law may give you rights including access, correction, deletion, restriction, objection and data portability. Where processing is based on consent, you may withdraw that consent at any time without affecting earlier lawful processing.
Your right to object: where we rely on legitimate interests, you may have the right to object to that processing. Contact us and we will consider your request in accordance with applicable law.
You also have the right to complain to the UK Information Commissioner’s Office if you are unhappy with how your personal data has been handled.
11. Children
KitchenOps is a business operations service and is not directed at children. Customers are responsible for ensuring that accounts are provided only to users who are appropriately authorised to use the service.
12. Changes to this policy
We may update this Privacy Policy when KitchenOps, our service providers or applicable requirements change. We will publish the current version on this page and update the effective date where appropriate.
CONTACTQuestions about your data?
Email hello@kitchenops.co.uk and we will help with privacy, access or deletion requests.