ALPORTHOSPITALITY SOLUTIONS
Privacy & data protection

Privacy Policy

Effective date: 10 September 2026. This notice explains how Alport Hospitality Solutions handles personal data when operating our website, hospitality-management platform, customer accounts, billing, support and connected services.

People | Process | Profit

We only use personal data where we have a proper purpose and lawful basis. We design the platform to keep venue data separated by organisation and site, restrict access by user role, and use specialist service providers where needed to operate the service.

1. Who we are

Controller for our own business data: Alport Hospitality Solutions.

Contact address: to be added before public commercial launch.

Privacy contact: a dedicated privacy email address will be published before public commercial launch.

For information that a customer venue uploads about its own staff, guests, suppliers or other individuals, the customer will normally be the data controller and we will normally act as its data processor, processing that information on the customer's documented instructions and under the applicable customer agreement or data-processing agreement.

2. What this policy covers

This policy covers the Alport Hospitality Solutions website and platform, including account creation, login and access management, sites and venues, sales, stock, suppliers, purchasing, menu and recipe costing, staff records, rota and shifts, payroll-management records, finance and EBITDA tools, supplier invoices and payment instructions, budgets, audit logs, EHO and food-safety compliance records, subscription and licence management, company administration, support, and integrations that a customer chooses to connect.

3. Personal data we may process

CategoryExamplesWhy it may be used
Account and identity dataName, work email, username/login details, password hash, role, permissions, account status, organisation and site association.Create and secure accounts, authenticate users, control access and administer licences.
Business and venue dataBusiness name/type, venue name and address, site details, contact information and operational settings.Set up and operate customer organisations and sites.
Employee and workforce dataEmployee name, work email, department, job title, pay type/rate, holiday allowance, shift/rota data, payroll totals, deductions and employer-cost data.Provide staff, rota, labour planning and payroll-management features for customer venues.
Health or special-category dataWhere a customer records fit-to-work, sickness, allergy, medical or other health-related information in compliance workflows.Only where the customer chooses and has its own lawful basis and applicable Article 9 condition. Access should be restricted to authorised roles.
Food-safety and compliance dataStaff sign-off names, opening/closing checks, temperature records, corrective actions, training/compliance records, verification and review history.Provide audit trails and support a venue's food-safety management processes.
Finance and commercial dataSales, expenses, budgets, supplier invoice details, payment instructions, references, subscription amounts and transaction status.Provide reporting, finance, purchasing, subscription and management functions.
Supplier/contact dataSupplier contact names, business emails, phone numbers, payment terms, invoices and order details.Manage supplier relationships, purchasing and ordering workflows.
Guest/booking dataBooking names, contact details, reservation times, party size and related reservation information where a booking integration is enabled.Forecast demand, staffing, stock and operational requirements. We only process what the connected service/customer makes available.
Technical and security dataIP address, device/browser information, timestamps, session identifiers, request logs, security events and audit-log entries.Secure, troubleshoot, monitor and protect the service.
Billing dataBilling email/address, tax/VAT information, Stripe customer, subscription, checkout and invoice identifiers, payment status and payment history.Create and administer subscriptions, invoices and payment status. Card details are handled by Stripe and are not stored by Alport Hospitality Solutions.
Support and communicationsMessages, support requests, feedback, attachments and records of account-related communications.Provide support, respond to requests and improve the service.
Forecast/context dataVenue location, weather data, public/local events and operational forecasts.Help venues forecast demand. Weather/public-event data is generally not personal data unless combined with identifiable information.

4. Where we get personal data

We may receive data directly from users and customer administrators; from other users within the same customer organisation; from connected EPOS, booking, supplier, payment or hospitality systems that the customer authorises; from Stripe for subscription billing; from service providers that help us operate the platform; and from public sources used for contextual data such as weather or local events.

5. Our purposes and lawful bases

PurposeTypical UK GDPR lawful basis
Provide accounts, subscriptions and the contracted platform.Contract; and legitimate interests where the contract is with the user's employer/business rather than the individual.
Billing, invoicing, tax/accounting and financial administration.Contract; legal obligation; legitimate interests.
Security, fraud prevention, logging, service reliability and abuse prevention.Legitimate interests; legal obligation where applicable.
Customer support, product administration and service communications.Contract and/or legitimate interests.
Product analytics and service improvement using operational data.Legitimate interests, with aggregation or de-identification where appropriate. Non-essential tracking cookies will only be used with required consent.
Direct marketing.Consent where required by law, or legitimate interests where permitted. Individuals can opt out at any time.
Customer-controlled workforce, booking and compliance data.The customer determines its lawful basis as controller. We process the data under the customer's documented instructions as processor.

If special-category data such as health information is processed, the customer/controller must identify both an Article 6 lawful basis and a valid Article 9 condition. We do not use special-category data for advertising.

6. Automated forecasting and decision support

The platform may use sales, bookings, stock, rota, weather, event and historical operating data to create forecasts, alerts or recommendations. These features are intended as management decision-support. Unless we tell you otherwise, Alport Hospitality Solutions does not make solely automated decisions about individuals that produce legal or similarly significant effects. Customers remain responsible for employment, staffing, disciplinary, pay, health-and-safety and other consequential decisions.

7. Who we share information with

We may share personal data with vetted service providers acting on our behalf, including hosting/database infrastructure, payment processing, email/communications, error monitoring, security, support and professional advisers. Current production services may include Render for application/database hosting and Stripe for subscription payment processing. Where a customer enables an integration, we may also exchange the minimum necessary data with the chosen EPOS, booking, supplier, banking/payment or other integration provider.

We may also disclose information where required by law, court order, regulator or competent authority; to protect the rights, safety and security of users or the service; or in connection with a merger, acquisition, financing or sale of all or part of the business, subject to appropriate confidentiality and data-protection safeguards.

8. Stripe and payment information

Subscription checkout is provided by Stripe. Stripe may collect card or bank details, billing address, tax information and fraud-prevention data under its own privacy terms. Alport Hospitality Solutions receives transaction and subscription information needed to administer the account, but our application does not store full payment-card details.

9. Cookies and similar technologies

The platform uses a session cookie that is necessary for secure login and maintaining an authenticated session. Necessary cookies do not require optional analytics/advertising consent. If we introduce analytics, advertising or other non-essential cookies, we will provide clear information and obtain consent where required before setting them. Users can also manage cookies through their browser, although blocking necessary cookies may prevent sign-in or core functionality.

10. International transfers

Some service providers may process data outside the UK. Where UK personal data is transferred internationally, the controller will use a lawful transfer mechanism as required, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, or another permitted safeguard. Further information on safeguards can be requested using the privacy contact above.

11. How long we keep information

We keep personal data only for as long as it is reasonably needed for the purpose for which it was collected, to provide the service, meet customer instructions, resolve disputes, protect legal rights and satisfy legal/accounting obligations. Retention may vary by data type and customer configuration.

DataGeneral retention approach
Active account and operational dataFor the life of the customer account/contract, subject to the customer's deletion and retention instructions.
Closed customer-account dataNormally deleted or anonymised after an appropriate offboarding/export period, except where a longer period is required for legal claims, security, accounting or statutory obligations. The precise production retention schedule should be stated in the customer contract/DPA.
Subscription, invoice and accounting recordsRetained for the period required by applicable tax/accounting law and legitimate record-keeping needs.
Security and application logsKept for a limited period proportionate to security, troubleshooting and abuse-prevention needs.
Support recordsFor as long as required to resolve the matter and maintain an appropriate service history.
BackupsMay remain for a limited backup-rotation period after deletion from the live service, after which they are overwritten or expire.

12. Security

We use technical and organisational measures designed to protect personal data, including encrypted HTTPS transport, password hashing, role-based access controls, authenticated sessions, organisation/site data separation, database access restrictions, audit logging, restricted company-admin access, secure environment-variable storage for secrets, and controlled access by authorised personnel. No internet service can guarantee absolute security, so customers should also use strong unique passwords, limit user access and promptly remove accounts that are no longer required.

13. Customer responsibilities

Customer organisations are responsible for ensuring that personal data they enter or connect to the platform is collected lawfully, is relevant and accurate, is only visible to appropriate users, and is supported by their own staff/customer privacy information where they act as controller. Customers should not place highly sensitive personal data into free-text fields unless the feature is intended for it and they have a proper legal basis.

14. Your data-protection rights

Depending on the circumstances and lawful basis, individuals may have rights to be informed, access their personal data, correct inaccurate data, request erasure, restrict processing, receive/transfer certain data, object to processing, withdraw consent where consent is relied upon, and obtain safeguards in relation to qualifying automated decisions.

Your right to object

If we process your personal data on the basis of legitimate interests, you have the right to object. You also have an absolute right to object to the use of your personal data for direct marketing.

If the information is held by us only on behalf of one of our customer venues, we may need to refer your request to that customer as the relevant controller. We will assist the controller as required by our contractual and legal obligations.

15. Children

The Alport Hospitality Solutions business platform is intended for authorised business users and is not directed at children. A hospitality customer may employ young workers or hold booking information involving children; in those cases the customer remains responsible for the lawful basis, transparency and safeguards for that processing, and we process the information on the customer's instructions.

16. Data breaches

We maintain processes to investigate suspected personal-data breaches. Where we act as processor, we will notify the relevant customer/controller without undue delay after becoming aware of a personal-data breach affecting that customer's data, in accordance with the contract/DPA. Where we are controller, we will assess whether notification to the ICO and affected individuals is required.

17. Complaints

Please contact us first so we can try to resolve any concern. Individuals also have the right to complain to the UK's data-protection regulator, the Information Commissioner's Office (ICO). Current ICO contact information is available at ico.org.uk.

18. Changes to this policy

We may update this policy when the platform, our suppliers, integrations, law or business structure changes. We will publish the revised version here and change the effective date. Where a change materially affects how we use personal data, we will provide additional notice where appropriate.

19. Contact

Before public launch: set PRIVACY_EMAIL, PRIVACY_LEGAL_NAME, PRIVACY_ADDRESS and, when applicable, PRIVACY_ICO_NUMBER in Render so the published notice contains the final legal contact information.
Help & cookies