Effective date: 10 September 2026. This notice explains how Alport Hospitality Solutions handles personal data when operating our website, hospitality-management platform, customer accounts, billing, support and connected services.
We only use personal data where we have a proper purpose and lawful basis. We design the platform to keep venue data separated by organisation and site, restrict access by user role, and use specialist service providers where needed to operate the service.
Controller for our own business data: Alport Hospitality Solutions.
Contact address: to be added before public commercial launch.
Privacy contact: a dedicated privacy email address will be published before public commercial launch.
For information that a customer venue uploads about its own staff, guests, suppliers or other individuals, the customer will normally be the data controller and we will normally act as its data processor, processing that information on the customer's documented instructions and under the applicable customer agreement or data-processing agreement.
This policy covers the Alport Hospitality Solutions website and platform, including account creation, login and access management, sites and venues, sales, stock, suppliers, purchasing, menu and recipe costing, staff records, rota and shifts, payroll-management records, finance and EBITDA tools, supplier invoices and payment instructions, budgets, audit logs, EHO and food-safety compliance records, subscription and licence management, company administration, support, and integrations that a customer chooses to connect.
| Category | Examples | Why it may be used |
|---|---|---|
| Account and identity data | Name, work email, username/login details, password hash, role, permissions, account status, organisation and site association. | Create and secure accounts, authenticate users, control access and administer licences. |
| Business and venue data | Business name/type, venue name and address, site details, contact information and operational settings. | Set up and operate customer organisations and sites. |
| Employee and workforce data | Employee name, work email, department, job title, pay type/rate, holiday allowance, shift/rota data, payroll totals, deductions and employer-cost data. | Provide staff, rota, labour planning and payroll-management features for customer venues. |
| Health or special-category data | Where a customer records fit-to-work, sickness, allergy, medical or other health-related information in compliance workflows. | Only where the customer chooses and has its own lawful basis and applicable Article 9 condition. Access should be restricted to authorised roles. |
| Food-safety and compliance data | Staff sign-off names, opening/closing checks, temperature records, corrective actions, training/compliance records, verification and review history. | Provide audit trails and support a venue's food-safety management processes. |
| Finance and commercial data | Sales, expenses, budgets, supplier invoice details, payment instructions, references, subscription amounts and transaction status. | Provide reporting, finance, purchasing, subscription and management functions. |
| Supplier/contact data | Supplier contact names, business emails, phone numbers, payment terms, invoices and order details. | Manage supplier relationships, purchasing and ordering workflows. |
| Guest/booking data | Booking names, contact details, reservation times, party size and related reservation information where a booking integration is enabled. | Forecast demand, staffing, stock and operational requirements. We only process what the connected service/customer makes available. |
| Technical and security data | IP address, device/browser information, timestamps, session identifiers, request logs, security events and audit-log entries. | Secure, troubleshoot, monitor and protect the service. |
| Billing data | Billing email/address, tax/VAT information, Stripe customer, subscription, checkout and invoice identifiers, payment status and payment history. | Create and administer subscriptions, invoices and payment status. Card details are handled by Stripe and are not stored by Alport Hospitality Solutions. |
| Support and communications | Messages, support requests, feedback, attachments and records of account-related communications. | Provide support, respond to requests and improve the service. |
| Forecast/context data | Venue location, weather data, public/local events and operational forecasts. | Help venues forecast demand. Weather/public-event data is generally not personal data unless combined with identifiable information. |
We may receive data directly from users and customer administrators; from other users within the same customer organisation; from connected EPOS, booking, supplier, payment or hospitality systems that the customer authorises; from Stripe for subscription billing; from service providers that help us operate the platform; and from public sources used for contextual data such as weather or local events.
| Purpose | Typical UK GDPR lawful basis |
|---|---|
| Provide accounts, subscriptions and the contracted platform. | Contract; and legitimate interests where the contract is with the user's employer/business rather than the individual. |
| Billing, invoicing, tax/accounting and financial administration. | Contract; legal obligation; legitimate interests. |
| Security, fraud prevention, logging, service reliability and abuse prevention. | Legitimate interests; legal obligation where applicable. |
| Customer support, product administration and service communications. | Contract and/or legitimate interests. |
| Product analytics and service improvement using operational data. | Legitimate interests, with aggregation or de-identification where appropriate. Non-essential tracking cookies will only be used with required consent. |
| Direct marketing. | Consent where required by law, or legitimate interests where permitted. Individuals can opt out at any time. |
| Customer-controlled workforce, booking and compliance data. | The customer determines its lawful basis as controller. We process the data under the customer's documented instructions as processor. |
If special-category data such as health information is processed, the customer/controller must identify both an Article 6 lawful basis and a valid Article 9 condition. We do not use special-category data for advertising.
The platform may use sales, bookings, stock, rota, weather, event and historical operating data to create forecasts, alerts or recommendations. These features are intended as management decision-support. Unless we tell you otherwise, Alport Hospitality Solutions does not make solely automated decisions about individuals that produce legal or similarly significant effects. Customers remain responsible for employment, staffing, disciplinary, pay, health-and-safety and other consequential decisions.
We may share personal data with vetted service providers acting on our behalf, including hosting/database infrastructure, payment processing, email/communications, error monitoring, security, support and professional advisers. Current production services may include Render for application/database hosting and Stripe for subscription payment processing. Where a customer enables an integration, we may also exchange the minimum necessary data with the chosen EPOS, booking, supplier, banking/payment or other integration provider.
We may also disclose information where required by law, court order, regulator or competent authority; to protect the rights, safety and security of users or the service; or in connection with a merger, acquisition, financing or sale of all or part of the business, subject to appropriate confidentiality and data-protection safeguards.
Subscription checkout is provided by Stripe. Stripe may collect card or bank details, billing address, tax information and fraud-prevention data under its own privacy terms. Alport Hospitality Solutions receives transaction and subscription information needed to administer the account, but our application does not store full payment-card details.
The platform uses a session cookie that is necessary for secure login and maintaining an authenticated session. Necessary cookies do not require optional analytics/advertising consent. If we introduce analytics, advertising or other non-essential cookies, we will provide clear information and obtain consent where required before setting them. Users can also manage cookies through their browser, although blocking necessary cookies may prevent sign-in or core functionality.
Some service providers may process data outside the UK. Where UK personal data is transferred internationally, the controller will use a lawful transfer mechanism as required, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, or another permitted safeguard. Further information on safeguards can be requested using the privacy contact above.
We keep personal data only for as long as it is reasonably needed for the purpose for which it was collected, to provide the service, meet customer instructions, resolve disputes, protect legal rights and satisfy legal/accounting obligations. Retention may vary by data type and customer configuration.
| Data | General retention approach |
|---|---|
| Active account and operational data | For the life of the customer account/contract, subject to the customer's deletion and retention instructions. |
| Closed customer-account data | Normally deleted or anonymised after an appropriate offboarding/export period, except where a longer period is required for legal claims, security, accounting or statutory obligations. The precise production retention schedule should be stated in the customer contract/DPA. |
| Subscription, invoice and accounting records | Retained for the period required by applicable tax/accounting law and legitimate record-keeping needs. |
| Security and application logs | Kept for a limited period proportionate to security, troubleshooting and abuse-prevention needs. |
| Support records | For as long as required to resolve the matter and maintain an appropriate service history. |
| Backups | May remain for a limited backup-rotation period after deletion from the live service, after which they are overwritten or expire. |
We use technical and organisational measures designed to protect personal data, including encrypted HTTPS transport, password hashing, role-based access controls, authenticated sessions, organisation/site data separation, database access restrictions, audit logging, restricted company-admin access, secure environment-variable storage for secrets, and controlled access by authorised personnel. No internet service can guarantee absolute security, so customers should also use strong unique passwords, limit user access and promptly remove accounts that are no longer required.
Customer organisations are responsible for ensuring that personal data they enter or connect to the platform is collected lawfully, is relevant and accurate, is only visible to appropriate users, and is supported by their own staff/customer privacy information where they act as controller. Customers should not place highly sensitive personal data into free-text fields unless the feature is intended for it and they have a proper legal basis.
Depending on the circumstances and lawful basis, individuals may have rights to be informed, access their personal data, correct inaccurate data, request erasure, restrict processing, receive/transfer certain data, object to processing, withdraw consent where consent is relied upon, and obtain safeguards in relation to qualifying automated decisions.
If we process your personal data on the basis of legitimate interests, you have the right to object. You also have an absolute right to object to the use of your personal data for direct marketing.
If the information is held by us only on behalf of one of our customer venues, we may need to refer your request to that customer as the relevant controller. We will assist the controller as required by our contractual and legal obligations.
The Alport Hospitality Solutions business platform is intended for authorised business users and is not directed at children. A hospitality customer may employ young workers or hold booking information involving children; in those cases the customer remains responsible for the lawful basis, transparency and safeguards for that processing, and we process the information on the customer's instructions.
We maintain processes to investigate suspected personal-data breaches. Where we act as processor, we will notify the relevant customer/controller without undue delay after becoming aware of a personal-data breach affecting that customer's data, in accordance with the contract/DPA. Where we are controller, we will assess whether notification to the ICO and affected individuals is required.
Please contact us first so we can try to resolve any concern. Individuals also have the right to complain to the UK's data-protection regulator, the Information Commissioner's Office (ICO). Current ICO contact information is available at ico.org.uk.
We may update this policy when the platform, our suppliers, integrations, law or business structure changes. We will publish the revised version here and change the effective date. Where a change materially affects how we use personal data, we will provide additional notice where appropriate.
PRIVACY_EMAIL, PRIVACY_LEGAL_NAME, PRIVACY_ADDRESS and, when applicable, PRIVACY_ICO_NUMBER in Render so the published notice contains the final legal contact information.