Cavendish Bakery App — Privacy Policy
Last updated: 24 August 2026
1. Who we are
Cavendish Bakery ("we", "us") operates the Cavendish Bakery App, a mobile and web application for our staff, customers and partners to manage orders, production, scheduling and related bakery operations. Our contact details are available on our website.
2. What data we collect
Account & login data — email address, name, and role. Staff sign in via a PIN or email/password; we do not store passwords in plain text.
Employee data — name, contact details, date of birth, National Insurance number, employment terms, working schedule, clocking records, holiday requests, and documents you sign (e.g. contracts, self-certification forms).
Customer & order data — name, email, phone, delivery address, and order details including payment status for online and in-shop orders.
Device data — an anonymous device identifier and hardware fingerprint used to authorise shared bakery devices (tablets/kiosks). We do not track your personal location.
Usage data — analytics events such as screen views and button taps, used to improve the app.
Optional uploads — photos or files you choose to upload (e.g. product images, supplier invoices, signatures).
3. Why we use it
To manage employment, payroll preparation, scheduling and attendance; to process and fulfil customer orders; to maintain food safety, COSHH and SFBB records as required by law; to run digital signage; and to operate and improve the bakery.
4. Legal basis (UK GDPR)
We process staff data under our employment relationship and legal obligations (e.g. HMRC, health & safety). We process customer order data under contract performance. We process analytics under our legitimate interest in improving the app.
5. Who we share it with
We use trusted service providers to host the app and send transactional emails. Sales and payments may be processed via our point-of-sale provider (Goodtill) and payment processor (Stripe). We share data only where necessary to operate the service and never sell your data.
6. How long we keep it
Employee records are kept for the duration of employment plus the period required by law (e.g. payroll and tax records). Order and food-safety records are retained per regulatory requirements.
7. Your rights
You can request access to, correction of, or deletion of your personal data by contacting us. Staff can view much of their own data directly in the app.
8. Security
Data is stored securely with access restricted by role. Sensitive fields are protected and administrative actions are logged.
9. Children
The app is not directed at children and we do not knowingly collect data from them.
10. Changes
We may update this policy; material changes will be communicated via the app or our website.
11. Contact
For privacy questions, contact us via the details on our website.
---
That's a solid starting point — review it with whoever handles your GDPR/HR before submitting, since you know your exact data practices best.
I can't see your App Scan results directly (they're in the Publish → Mobile app tab in your editor), but if you paste what it flagged I can help you fix each item. Otherwise, the most common scan flags for an app like this are: missing/placeholder privacy URL, login-only apps being rejected for not enough native function, and "Sign in with Apple" if you offer any third-party/social login.

