ChefsRecords · Last updated: 10 October 2026
ChefsRecords is a food safety and staff management app for UK kitchens. We take your privacy seriously and are committed to protecting your personal data.
We have not appointed a Data Protection Officer, as we fall below the threshold that requires one. Data protection questions are handled directly by us using the contact form below.
Get in touch →ChefsRecords is a tool you use to keep records about other people - your staff and your suppliers. That makes this a two-part relationship, and UK GDPR treats each part differently.
This matters in practice. Your staff have rights over the data you record about them, and those requests come to you, not to us. If a staff member asks what you hold about them, you can answer from the app and Settings > Export records. If such a request ever reaches us directly, we will point the person back to you and let you know it happened.
You are also responsible for telling your staff that you keep these records, and for having a lawful reason to keep them. Most employers cover this in a staff privacy notice or in the employment contract.
If your kitchen adds team members - other Managers, Supervisors and Staff who sign in themselves - the records they make belong to the kitchen too, with their names on them. The kitchen, as controller, decides how long to keep them.
We collect and store the following data when you use ChefsRecords:
We do not collect any data beyond what is needed to run the app.
UK GDPR requires a lawful basis for each purpose. For the data where we are the controller, ours are:
For the staff and supplier records you create, the lawful basis is yours to decide as the controller. In an employment context this is usually legitimate interests, or compliance with a legal obligation such as food safety and right to work law. We process that data only on your instructions.
Some of what the app can record is "special category" data under Article 9 of UK GDPR, which carries stricter rules:
Where the app captures this, it shows a notice at the point of entry so whoever is recording it knows what they are handling.
As the controller of that data, you are responsible for having a valid Article 9 condition before you record it. In an employment context this is usually Art. 9(2)(b) - obligations in employment law, supported by an appropriate policy document - or the explicit consent of the staff member. If you are unsure, take HR or legal advice before recording health information about your team.
We handle this data only as your processor. We do not analyse it, profile it, or use it for any purpose of our own.
Your data is used solely to provide the features of the ChefsRecords app. We do not sell, share, or use your data for advertising or marketing purposes. Your kitchen's records are accessible only to the people in your kitchen when they are signed in, and each of them only according to their role (Manager, Supervisor or Staff).
All app data is stored securely using Supabase, a cloud database provider. Our database is hosted in the United Kingdom (London - AWS eu-west-2) and does not leave the UK in normal operation. Data is encrypted in transit (HTTPS/TLS) and at rest. Access is protected by Row Level Security - only people in your kitchen can read or change its data, and each role only what it is allowed to.
Incident photos and 1-to-1 meeting signatures are stored in a private storage bucket. They are accessed via short-lived signed URLs (1-hour expiry) generated at the moment you view them, so a URL accidentally shared cannot be reused indefinitely.
A Manager can export the kitchen's records from Settings as a spreadsheet file (.xlsx) holding the kitchen's temperature records, checklists, incidents, suppliers and stock. The file is created on the Manager's own device and is not encrypted, so anyone who has it can open it - you are responsible for keeping it safe and deleting it when it is no longer needed.
Staff files (right-to-work records, certificates, meetings and attendance) and incidents about a member of staff are included only if the Manager chooses to include them. Photos and signatures are not included; they remain in our cloud storage and are only viewable when signed in to your account. Copies left in the app's own folder on the device are deleted automatically after 30 days.
Subscription payments are handled by Apple (App Store) or Google (Google Play) through RevenueCat. We never see or store your payment card details. RevenueCat receives your account's user ID, your App Store or Google Play purchase records and basic device details its software sends. It tells us your subscription status (Trial, Standard or Pro) and the purchase events behind it, such as the product, the store and renewal or expiry dates, so the right plan is unlocked.
We retain personal data only for as long as we need it to provide the service, in line with UK GDPR Art. 5(1)(e) (the storage-limitation principle).
If we become aware of a personal data breach affecting your data, we will tell you without undue delay, and in any event within 72 hours of becoming aware of it where the breach is likely to result in a risk to people's rights.
Because you are the controller of the staff and supplier records you create, you may then have your own duty to report the breach to the ICO under Art. 33, and in serious cases to the people affected under Art. 34. We will give you what you need to make that judgement: what happened, which data was involved, and what we have done about it.
Where a breach affects your own account data, we will report it to the ICO ourselves if the law requires it.
Under UK GDPR, you have the right to:
To exercise any of these rights, please contact us.
You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority, if you think we have handled your data badly. We would rather you came to us first so we can put it right, but you are not required to.
Complain to the ICO →ChefsRecords uses the following third-party services:
Each of these services processes data under written terms that give it the same or equal protection to this policy. Each also has its own privacy policy.
ChefsRecords is not directed at children under the age of 13. We do not knowingly collect personal data from anyone under 13. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
If we make material changes to this privacy policy, we will notify you within the app. Continued use of ChefsRecords after changes are posted constitutes your acceptance of the updated policy.
If you have any questions about this privacy policy or how we handle your data, please use our contact form.
Open contact form →