Privacy Policy

Last updated: March 2026

Storekit Ltd. (“Storekit”, “we”, “our”, or “us”) provides cloud-based ordering and operational software for hospitality businesses. We are committed to protecting personal data and maintaining transparency in how information is processed across our website and platform.

This Privacy Policy explains how we collect, use, and safeguard personal data when you interact with Storekit, whether as a website visitor, business contact, or end user of services provided by our customers.

Storekit Ltd. is committed to protecting personal data in accordance with applicable data protection laws, including the UK GDPR, the Data Protection Act 2018, and where applicable, the EU GDPR.

1. Who We Are

Storekit Ltd. is a provider of cloud-based ordering and operational software for hospitality businesses.

For the purposes of this policy:
+ we act as a data controller for website visitors and business contacts
+ we act as a data processor when processing end-customer data on behalf of venues

Contact:
[email protected]

2. Scope of This Policy

This policy applies to:
+ visitors to our website
+ individuals who contact us or request demos
+ business customers and prospects

This policy does not cover how venues use Storekit to process their customers’ data. In those cases, the venue is the data controller.

3. Personal Data We Collect

3.1 Information you provide
When you contact us, request a demo, or otherwise engage with us:
+ name
+ email address
+ company or venue details
+ job title (if provided)
+ any information included in communications

3.2 Automatically collected data
When you visit our website:
+ IP address
+ browser type and device information
+ pages visited and interactions
+ timestamps and referral URLs

This information is collected using cookies and analytics tools.

3.3 Platform-related data (contextual)
When individuals interact with Storekit-powered ordering systems, we may process:
+ name and contact details
+ order and transaction data
+ delivery or fulfilment details

In this context, Storekit processes data on behalf of the venue (controller).

4. How We Use Personal Data

We use personal data to:
+ respond to enquiries and demo requests
+ provide and improve our website and services
+ manage customer relationships
+ communicate with prospective customers
+ monitor usage and performance
ensure security and prevent misuse

We do not sell personal data or use it for behavioural profiling or advertising resale.

5. Legal Basis for Processing

We rely on the following legal bases:
+ Legitimate interests — operating and improving our services
+ Contractual necessity — where engaging with customers
+ Legal obligation — compliance requirements
+ Consent — where required (e.g. cookies or marketing communications)

6. How We Share Personal Data

We do not sell personal data.

We may share data with:
+ service providers supporting hosting, analytics, and operations
+ integration partners required for service delivery
+ professional advisers
+ regulatory authorities where required by law

All data sharing is subject to appropriate contractual safeguards.

7. Sub-processors and Service Providers

Storekit relies on a limited number of third-party providers to deliver its services, including:
+ cloud hosting providers
+ monitoring and observability tools
+ authentication and infrastructure services
+ payment providers (who process payments directly)

Where these providers process personal data, they are bound by contractual data protection obligations.

8. International Data Transfers

Where personal data is transferred outside the UK or EEA, we ensure appropriate safeguards are in place, including:
+ Standard Contractual Clauses (2021)
+ UK International Data Transfer Addendum
+ adequacy decisions

9. Data Retention

We retain personal data only as long as necessary to:
+ respond to enquiries
+ maintain business relationships
+ comply with legal and regulatory obligations
+ support operational integrity

Data may be anonymised or deleted when no longer required.

10. Security

We implement appropriate technical and organisational measures to protect personal data, including:
+ encryption in transit and at rest
+ role-based access controls
+ multi-factor authentication
+ secure infrastructure and monitoring systems
+ incident response procedures

11. Your Rights

Under UK GDPR, you have the right to:
+ access your personal data
+ request correction
+ request deletion
+ restrict processing
+ object to processing
+ request data portability

To exercise these rights, contact:
[email protected]

12. Cookies and Tracking Technologies

We use cookies and similar technologies to:
+ ensure website functionality
+ analyse traffic and usage patterns
+ improve performance

You can control cookies via your browser settings.
Where applicable, a cookie banner provides additional controls.

13. Third-Party Links

Our website may contain links to third-party websites.
We are not responsible for their privacy practices.

14. Changes to This Policy

We may update this Privacy Policy from time to time.
Updates will be published on this page.

15. Contact

If you have any questions about this Privacy Policy or how we handle personal data, please contact:

[email protected]

Create your free storekit account today