Privacy Policy
Last updated: 5 August 2026 · Effective from: 4 September 2026
If you check a menu without an Allergy ID card, we do not ask you for any personal information and we do not know who you are. We record what was checked and when — not who checked it: no account, no email address, and nothing in our records linking one visit to another. Your IP address is used only in the moment, to stop the same device flooding the service with requests; it is never stored — what we keep is a one-way salted hash of it, which cannot be turned back into your address. If you use an Allergy ID card, that check is linked to your card, which carries the name you put on it and may carry more — so those records are not anonymous. What each kind of record holds is set out under Why we process this data below.
Who we are
Allergy Spotter ("we", "us") is the operator of the allergyspotter.com service, based in the United Kingdom. We are the data controller for the information described in this policy. Contact: hello@allergyspotter.com.
What we collect
From restaurant guests (people using the allergen checker): the allergens they selected (including free-typed terms), the dish results they were shown, and a timestamp. If a guest chooses to confirm an order, they can also optionally type a table number, initials, or a name so staff can find them — entirely optional, and it's their choice what (if anything) to type. Guest pages use essential cookies only — no advertising or analytics cookies.
If a guest chooses to create an optional Allergy ID card (a free, guest-owned allergy profile usable at any restaurant on Allergy Spotter, not just one): the allergens/intolerances and the optional name or nickname they add to it, plus two access codes generated for them — a public one safe to show staff or put in a QR code (it only ever reveals what the guest has chosen to add to their card, nothing else), and a private one only they hold, needed to edit the card later. There's no account, password, or contact detail attached to a card — creating one is entirely optional and separate from using the allergen checker itself.
From restaurants (our customers): the minimum needed to run your account — your restaurant name and a password stored only as a salted cryptographic hash (we can never read it). Accounts are set up on your behalf using our own email address, not yours — your email isn't collected to register, since it isn't needed again once your account is set up. While staff are logged in, a temporary session cookie keeps them signed in and expires automatically.
From schools and care homes (our other kind of customer, alongside restaurants): the same minimal account details as above, plus — because a school or care home is keeping an actual allergy register rather than checking one-off guests — a genuinely different, more sensitive category of data. For each pupil or resident added to the register: their name, allergens/intolerances (including free-typed terms), and any emergency contact or auto-injector (AAI) details a parent, guardian, or next-of-kin chooses to provide. This is only ever added with that parent/guardian or next-of-kin's consent, captured via the paper or digital consent form built into the product. If an incident or near-miss is logged, or an Individual Healthcare Plan is created, those also contain that same register member's name and health information. None of this is shared with, or visible to, any restaurant on the platform — a school/care home's register is entirely separate from and invisible to the restaurant side.
Payments
Allergy Spotter is free for every restaurant's first 2 months, so we collect no payment or billing information during that period. If, following the review described in our Terms of Service, a restaurant's arrangement ever moves to a paid basis, payment details would only ever be collected directly in connection with that separate, explicitly agreed arrangement — never automatically. If a restaurant purchases an optional physical product from us (such as an NFC card), payment is arranged directly and no card details are stored in the Service.
Why we process this data
- To provide the service (performance of contract): your account details and menu data are needed for the product to function.
- Guest checks made without an Allergy ID card: when someone confirms what they were shown without using a card, the record holds the allergens they picked, the dishes, a table or ticket number if one was entered, and a timestamp. It holds nothing that identifies the guest — no name and no contact details. It can name the staff member who attended it or signed it off.
- Guest checks made with an Allergy ID card: when someone confirms using their Allergy ID card, the record is linked to that card and is not anonymous. The card carries their name, and may carry their date of birth, home address and emergency contact details. The record itself holds the allergens and any free-typed terms they declared, which is health information — special category data under UK GDPR.
- Consent (schools/care homes only): a register entry containing a named pupil or resident's allergy and health information is only ever added once a parent, guardian, or next-of-kin has given consent — via the paper consent form or the digital consent portal. That consent can be withdrawn at any time by asking the school/care home to remove the entry.
Where data is stored
Data is stored with Cloudflare (Workers and D1 database) in Cloudflare's Western Europe region. Cloudflare acts as our data processor.
How long we keep it
- Menu data — you can delete all of your menu data yourself at any time from your dashboard's Danger Zone.
- Your account and personal data — kept while your account is active. To have your entire account and all personal data (name, email, account details) permanently deleted, email hello@allergyspotter.com with your restaurant name. This isn't yet a self-service option, but every request is honoured — promptly, and in any case within 30 days.
- Guest-check logs — kept for 7 years to preserve the evidence record for as long as a genuine dispute could reasonably arise, then permanently deleted.
- Allergy ID cards — kept for as long as the card exists. Unlike guest-check logs, a guest holding the card's private edit link can update it themselves at any time with no need to contact us; email us with that link if you'd like a card permanently deleted instead.
- Register, incident, consent, and AAI records (schools/care homes) — deliberately not on an automatic time-based purge like guest-check logs, since these identify a named pupil or resident and unlike a guest check made without a card, a school/care home may have its own duty to retain safeguarding-related records for longer than any period we could reasonably guess at.
A school or care home can remove an individual register member themselves at any time from their own dashboard. That is worth stating precisely, because it does not erase everything about that person:
- Removed — their register entry itself: the live record of their allergens, notes, contacts and consent. It is deleted outright, and from that moment they no longer appear in any daily allergen check.
- Retained — the tamper-evident audit trail of what was recorded about them and when. That includes a final snapshot taken at the moment of removal, and the snapshot carries the same detail the live entry did: their allergens, any non-food allergies, notes, consent, contacts, medication details and care-plan record as they stood that day. Also retained: any daily allergen check they were part of, which records their name and the verdict they were given that day; and any incident or reaction logged involving them, which records their name directly.
Those two are kept deliberately, for two reasons. A tamper-evident record that a deletion can erase is not tamper-evident at all — erasing it would simply become the easiest way to change what it says. And a safeguarding record about a child needs to outlive that child leaving the setting, which is often exactly when someone needs to look at it. If you need all of it gone, including the audit trail, the whole account and everything in it can be permanently deleted on request, the same way as any other account.
- Login sessions — expire automatically.
Who we share data with
Nobody, in identifiable form. We do not sell or share restaurant, school/care-home, register, or guest data with third parties, except:
- Cloudflare, as our hosting and database provider;
- Aggregated, anonymised statistics (for example, "X allergy checks were performed across our network this month"), which we may use in our own marketing and share with partners. These never identify a restaurant by name without that restaurant's separate written agreement, and can never identify any guest, because they are aggregate counts rather than individual records.
Embedded video
Our home page carries two videos — one hosted by YouTube, one by Instagram. Neither plays on its own, and neither loads anything at all until you press play: what you see before then is a still image served by us, from our own servers. Nothing about your visit reaches Google or Meta unless you choose to watch.
If you do press play, that video is then loaded from YouTube or Instagram directly, and at that point they can see your IP address and may set cookies in your browser, in the same way as if you had opened the video on their own site. We use YouTube's no-cookie domain to limit that as far as the service allows. We are not sent anything back: we do not know who pressed play, and no video is embedded on any Allergy ID card, register, or consent page.
The mailing list
If you sign up for updates on our home page, we store your email address, which of the two audiences you picked (someone with allergies, or someone running a restaurant, school or care home), and the date you signed up. Nothing else — we do not ask for your name, and we do not record what your allergies are.
Lawful basis: consent. You give it by ticking the box on the form, which is never pre-ticked, and we only ever act on it after you confirm by clicking a link we email you. Until you click that link your address sits unused and is sent nothing further; if you never click it, the record is deleted within 7 days.
What we send: occasional updates about new features and restaurants that have joined — usually monthly, and never more often than that. We do not send anything else to this list, and we never sell or share it.
How to unsubscribe: every email has a one-click unsubscribe link that works immediately, with no login and no confirmation step. That removes you from our database and from our email provider at the same time. You can also email hello@allergyspotter.com and we will do it for you.
How long we keep it: until you unsubscribe. Unconfirmed signups are deleted after 7 days. We use Resend to send these emails, so confirmed addresses are stored with them as well as with us — unconfirmed ones never reach them at all.
Your rights
Under UK GDPR you can ask us to access, correct, delete, or restrict the personal data we hold about you. Contact hello@allergyspotter.com. You can also complain to the Information Commissioner's Office (ico.org.uk).
Guests: if you check a menu without an Allergy ID card, we don't ask for anything that identifies you — no account, no device ID. The one thing you can add is the optional table number, initials, or name you type in when confirming an order — entirely optional and up to you what, if anything, you type. If you use an Allergy ID card, the checks you make with it are linked to that card, so those are not anonymous. Because our records aren't searchable by guest identity, we have no way to look up or delete one individual guest's entry on request; if you're ever concerned about something you typed, the restaurant itself is best placed to help. If you've created an optional Allergy ID card, that one is different — you hold a private edit link that lets you view, change, or clear it yourself at any time (including any name you've added) with no need to contact us; email us with that link if you'd like the card permanently deleted instead of just edited.
Parents, guardians, and next-of-kin: your child's or relative's school or care home is the one holding the actual register data day to day, so requests to access, correct, or delete a register entry (and any incident or consent record tied to it) should go to them first — most of that is already self-service through their dashboard or the consent portal link you were sent. If a school or care home can't resolve something for you directly, contact us at hello@allergyspotter.com and we'll help.
Changes
We'll update this policy when the service changes and show the "last updated" date above. Material changes will be notified to you.