Privacy Policy

Last updated: 6 October 2026

1. Who we are

PassTheCheck (“we”, “us”) runs the PassTheCheck food safety record-keeping service. Contact: hello@passthecheck.co.uk.

2. Two kinds of data, two different roles

Your account (the business owner’s and team members’ sign-in details, the business’s details and billing). We decide how this is used, so we are the controller.

Your business’s records (everything the business enters: temperature and cleaning records, staff names and initials, training, fitness-to-work declarations, complaints and so on). The business decides what goes in and why, so the business is the controller and we are its processor: we only store and handle these records to run the service for that business, under the data processing terms in our Terms of Service.

If you work for a business that uses PassTheCheck and want to see, correct or remove information about you, ask your employer first. We will help them answer you.

3. What data we hold

Account data

  • Email address and password (stored hashed), or, if you sign in with Google, the name, email address and account ID Google shares with your permission. We never see your Google password.
  • Business name, address, contact details, settings and team members’ names and roles
  • Subscription status and billing dates. Card payments are handled by Stripe; we never see or store card details.

Business records

  • Food safety records, menu and allergen information, cleaning and COSHH records, uploaded documents
  • Staff names, initials and roles, and training records with certificate details
  • Fitness-to-work declarations, including notes about illness and return to work. This is health information, a special category of personal data. It is collected because food hygiene law requires food handlers who are ill to be excluded. The app asks businesses to record only what is needed (fit or not fit, what was done, when they can return) and not diagnoses or medical details.
  • Customer complaints, which may include a customer’s name or contact details if the business adds them

Technical data

  • Sign-in times and session data, and the browser and app version shown with any problem you report
  • If you report a problem with a screenshot, that screenshot

4. How we use account data, and our legal basis

  • Running the service, your subscription and service emails (trial and billing messages, reminders, overdue-check emails and the monthly records report): contract
  • Keeping the service secure, fixing problems you report and improving it using anonymised, aggregated information: legitimate interests
  • Keeping financial records and responding to lawful requests: legal obligation

We never sell data, and we do not send marketing without your explicit consent.

5. Emails that contain records

The monthly records report attaches a PDF of the previous month’s records, which can include staff names and fitness-to-work entries. It goes to the owner’s email address and, if the owner adds one, one more address they choose. Owners can switch it off in Settings. Overdue-check emails list what is overdue and may also go to managers when the owner hasn’t opened the app for a few days.

6. Who else handles data (sub-processors)

We use these companies to run the service, each under a data processing agreement:

  • Supabase: database, file storage and sign-in. Data is stored in Ireland (EU).
  • Vercel: hosts the app. Our server code runs in Dublin (EU); Vercel is a US company.
  • Resend: sends our emails (US company).
  • Stripe: takes subscription payments.
  • Google: sign-in, only if you choose Sign in with Google.
  • Your browser’s push service (for example Apple or Google), only if you turn on reminders, to deliver notifications such as “Morning fridge check due”. They contain no records.

Where any of these handle data outside the UK, they do so under safeguards the UK recognises, such as the UK Extension to the EU–US Data Privacy Framework or the ICO’s International Data Transfer Addendum, as set out in their data processing terms.

We will tell business owners before adding or replacing a company on this list. We do not share data with your local council, the FSA or any other authority unless the law requires it.

7. Who can see a business’s records

  • The business owner and the team members they invite.
  • Anyone the owner gives an inspector access link to, until it expires. The owner chooses who to share it with.
  • The PassTheCheck owner, and anyone given support access, can view a business’s records through our admin tools. We only do this to provide support, fix problems or keep the service secure, and access is limited to named people.

8. Data stored on your device

So that PassTheCheck opens quickly and keeps working if the signal drops, some information is kept on the phone, tablet or computer you use it on:

  • a copy of the screens and records you have recently viewed
  • records you have saved while offline that have not been sent yet
  • preferences, such as the initials you last used

Records saved while offline are held only on that device until it reconnects and sends them to our servers. Until then they are not backed up, cannot be seen on your other devices or through an inspector link, and will be lost if the device is lost, reset or its browser data is cleared. Offline saving is a backup for when you have no signal, not a way of working; open the app with a connection as soon as you can so your records are sent.

When you sign out, the stored copy of your records is removed from the device. Records that have not been sent yet are kept on the device so they are not lost, and are sent the next time you sign in with a connection. Anyone who can use an unlocked device you are signed in on may be able to see this information, so we recommend using a screen lock.

9. How long we keep data

  • While your account is open, records are kept so you can show them to an inspector. You can delete individual records you no longer need.
  • If you cancel your subscription, your records stay so you can come back or download them. Delete your account to remove them.
  • When you delete your account, your business’s records, documents and sign-in are deleted straight away. Copies in our database provider’s backups are overwritten within 7 days. This cannot be undone, so download everything first (Settings → Download everything).
  • Billing records are kept as long as tax law requires.

10. Your rights

Under UK GDPR you can ask to see, correct, delete, restrict or object to the use of your personal data, and to have it in a machine-readable form (Settings → Download everything gives you all your business’s records). Email hello@passthecheck.co.uk; we will reply within one month. For business records, the business (as controller) decides, and we help it respond.

If you are unhappy with how we handle your data, you can complain to the Information Commissioner’s Office (ICO).

11. Cookies

PassTheCheck uses only the cookies needed to keep you signed in, plus the on-device storage described in section 8. We do not use advertising, analytics or tracking cookies.

12. Security and data breaches

Connections are encrypted (HTTPS), passwords are hashed, and each business can only reach its own records, enforced by the database itself. Uploaded documents are private and only opened through short-lived links.

If a breach affects personal data, we will tell affected business owners without undue delay, and the ICO within 72 hours where the law requires it.

13. Changes to this policy

We will email business owners about any important change before it takes effect.