Last reviewed: Pending first legal review
CaterCloud (“we”, “us”) provides catering business management software. This placeholder policy explains, at a high level, how we handle personal information. Final controller/operator details and contact points will be confirmed by legal.
We collect account details, business data you enter, usage/log data, and data from integrations you connect. The precise categories and purposes will be itemised in the lawyer-approved version.
We use information to provide and secure the service, process payments, send transactional messages you trigger, and improve the product using aggregated, anonymised data. We do not sell personal information.
We share data with vetted sub-processors (hosting, database, payments, email, SMS, AI inference, error monitoring) strictly to run the service. A definitive sub-processor list will be maintained alongside the final policy.
Data is encrypted in transit and at rest, isolated per tenant, and retained only as long as needed for the service and to meet legal/tax obligations. Concrete retention periods will be set in the final version.
Depending on where you are, you may have rights to access, correct, delete, export, or object to processing of your personal information. See the jurisdiction note below for how these apply to your region.
We use essential, preference and (with consent) analytics cookies. See the Cookie Policy for detail and to manage your choices.
We will notify you of material changes to this policy. For any privacy question or request, contact info@catercloud.io. Final notice periods and contacts pending legal review.
Your rights and how we handle your information depend on where you access CaterCloud. The notes below outline the regime for each market we serve. All wording is placeholder pending legal review.
TEMPLATE: If you access CaterCloud from Australia or New Zealand, we handle your personal information in line with the applicable Privacy Act and privacy principles. You may raise a concern with us first, and escalate to the relevant privacy regulator if unresolved. [Final wording pending legal review.]
Oversight: the Office of the Australian Information Commissioner (OAIC) / the NZ Privacy Commissioner.
TEMPLATE: If you access CaterCloud from the UK, Ireland or the EEA, you have rights under the GDPR including access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with your local supervisory authority. We describe our lawful bases and transfer safeguards here. [Final wording pending legal review.]
Oversight: your local data protection authority (e.g. the ICO in the UK, the DPC in Ireland).
TEMPLATE: If you are a California resident, you have rights under the CCPA/CPRA including the right to know, delete, correct, and opt out of "sale" or "sharing" of personal information. We do not sell personal information. [Final wording pending legal review.]
Oversight: the California Privacy Protection Agency (CPPA).
TEMPLATE: If you access CaterCloud from Canada, we handle personal information consistent with PIPEDA and applicable provincial privacy laws. You may request access or correction, and complain to the OPC if unresolved. [Final wording pending legal review.]
Oversight: the Office of the Privacy Commissioner of Canada (OPC).
TEMPLATE: If you access CaterCloud from South Africa, we process personal information in line with POPIA. You may exercise your data-subject rights and lodge a complaint with the Information Regulator. [Final wording pending legal review.]
Oversight: the Information Regulator (South Africa).