Send It Chef! by Rhodes logo

Privacy & data policy

How Send It Chef! handles personal data for venues, managers and kitchen staff.

Last updated 3 August 2026. This page is maintained by Send It Chef! — By Rhodes and is not an independent certification or audit.

Who is responsible for your data

Send It Chef! — By Rhodes (a sole trader business) is the data controller for account and usage data in the app. Registered address: 24 Queen Street, East Ardsley, Wakefield, WF3 2BE, United Kingdom.

Privacy enquiries can be sent securely through our contact form.

Each venue is the controller of the product, allergen and prep information its own team enters. We process that information on the venue's behalf as its service provider.

What we collect

  • Account data — name, initials, email address, role (manager or staff) and the venue you belong to. Created by your manager or by us when your venue is set up.
  • Kitchen data — products, categories, allergens and shelf life settings entered by your team.
  • Label usage records — the product name, number of labels, date/time, venue, the account that printed, and a random device identifier generated in your browser. We use this only to check licence usage and to detect one login being shared between venues.
  • On-device data — the chef name you type for labels, the device identifier and offline copies of your kitchen data are stored in your browser's local storage so the app works without internet.

We do not store the chef name typed on a label in our database — it is printed on the label and kept only on the device that printed it. We do not use advertising cookies or third-party analytics trackers, and we do not collect special category data.

Why we can use it (lawful basis)

  • Contract — to provide accounts, printing and support to your venue.
  • Legitimate interests — to keep the service secure, to check licence usage and to prevent account sharing.
  • Legal obligation — to keep basic business and billing records.

How long we keep it

  • Label usage records are deleted automatically after 12 months.
  • Account data is kept while your venue's subscription is active.
  • After a venue closes its account, remaining account and kitchen data is deleted within 30 days on request, or within 90 days automatically.
  • On-device data is cleared whenever you sign out and clear device data in Settings, or clear your browser storage.

Who else processes it

We use a small number of service providers to run the app: cloud hosting and database/ authentication infrastructure (provided through Lovable Cloud, built on Supabase, hosted in the EU/UK region), and email delivery for sign-in and account emails. They process data on our instructions only, under written terms including UK/EU transfer safeguards where relevant. We do not sell personal data.

Your rights

Under UK GDPR you can ask for a copy of your data, correction, deletion, restriction, or to object to processing based on legitimate interests, and to have your data provided in a portable format. Send your request through our contact form and we will respond within one month. Staff should also ask their venue manager, who can update or remove their account.

If you are unhappy with our response you can complain to the UK Information Commissioner's Office (ico.org.uk).

Security and shared responsibility

Data is encrypted in transit, access is restricted per venue by database-level access rules, and only signed-in accounts can read your venue's data. You are responsible for keeping passwords private, not sharing logins between venues, and for the accuracy of prep and use-by information printed on labels.

Please report a suspected security issue through our contact form.