Last updated: June 2025
Privacy Policy
This Privacy Policy explains how AllerLink (“we”, “us”, “our”) collects, uses, and protects your personal data when you use our services. We are committed to protecting your privacy and processing your personal data in compliance with the General Data Protection Regulation (GDPR) and applicable UK and EU data protection law.
1. Who we are
AllerLink is the data controller for personal data processed through this service. Our registered address and Data Protection Officer contact details will be provided before launch following legal registration.
2. What data we collect
Tenant and Chef users
- Name and email address (account registration)
- Business and restaurant details (name, address, country)
- Billing information (handled exclusively by Stripe — we never store card data)
- Menu content, allergen declarations, and sign-off records
- Activity log entries (login events with UTC timestamps)
Consumer (diner) users
- Name and email address (account registration)
- Allergen and dietary profiles — GDPR Article 9 special category health data
- Device locale and regulatory zone
Consumer allergen profile data is encrypted at the field level before being stored in our database, using application-level encryption. Selection lists (items chosen during a restaurant visit) are stored on your device only and never transmitted to our servers.
3. Why we collect your data
- To operate the AllerLink platform and provide our services
- To maintain a legally required allergen audit trail (signed-off menu snapshots)
- To process subscription payments via Stripe
- To send transactional notifications (service alerts, payment events)
- To comply with applicable food safety and data protection law
We process GDPR Article 9 health data (allergen profiles) only with your explicit consent, recorded before any health data is stored. You may withdraw consent at any time by deleting your account.
4. How long we keep your data
- Signed-off menu snapshots and allergen audit records: retained for the applicable Retention Window per jurisdiction (durations to be confirmed by legal counsel before launch)
- Consumer personal data: deleted within 30 days of a confirmed erasure request (GDPR Article 17)
- Cancelled Tenant accounts: audit data retained for the Retention Window; PII deleted on request
5. Your rights
Under GDPR, you have the right to:
- Access your personal data (Article 15)
- Rectify inaccurate data (Article 16)
- Erasure of your personal data, subject to legal retention requirements (Article 17)
- Data portability in a machine-readable format (Article 20)
- Object to processing (Article 21)
Consumer users can exercise erasure (Article 17) and portability (Article 20) rights directly from account settings in the AllerLink app. For other requests, contact us at the address provided before launch.
6. Third-party processors
- Render (EU Frankfurt): database and server hosting — Render DPA executed before EU/UK data accepted
- Cloudflare R2 (EU storage): photo storage — Cloudflare DPA executed before EU/UK data accepted
- Stripe: payment processing — Stripe never receives health data
- Firebase (Google): push notifications — no health data transmitted
- SendGrid (Twilio): transactional email — no health data transmitted
7. Contact
For data protection queries, please contact us at the address to be provided at launch. You also have the right to lodge a complaint with your local data protection supervisory authority (e.g., the ICO in the UK or your national authority in the EU).