Parties
Between
- The Shop: the business named on the Orderhatch account, which is the controller of its customers' personal data.
- [Orderhatch trading entity], company number [company number], registered office [registered address] ("Orderhatch"), which is the processor.
This agreement forms part of the Orderhatch Terms of Service. It applies for as long as Orderhatch processes personal data for the Shop, including the 30 days after the Shop cancels. The Shop accepts it when it creates its account, and again whenever a new version is published.
1. What we process and why
| Purpose | Taking and managing click and collect orders on the Shop's behalf: showing the menu, taking order details, sending order confirmations and "ready" messages by email and text, showing orders on the Shop's order screen, alerting the Shop (and, if an order is not accepted, Orderhatch staff) so the order is not missed, handling refunds the Shop issues, and keeping order history for the Shop. |
|---|---|
| Data subjects | The Shop's customers. |
| Personal data | Name, email address, phone number, order contents, collection time, order status and refund history. A salted one-way hash of the customer's IP address, kept for 24 hours to stop fake orders holding collection slots. |
| Special category data | None is requested. Customers are not asked for health or allergy information. |
| Payment card data | Never received or stored by Orderhatch. Customers pay the Shop directly through the Shop's own Stripe account. Stripe is the Shop's own payment provider under the Shop's own agreement with Stripe. It is not a sub-processor of Orderhatch. |
| Duration | For the life of the Shop's subscription, then as set out in section 7. |
2. Our obligations as processor
Orderhatch will:
- Process the personal data only on the Shop's documented instructions. Using Orderhatch as designed, and the settings the Shop chooses, are those instructions. If the law requires us to do something else, we will tell the Shop first where the law allows.
- Make sure everyone with access to the data is bound by confidentiality.
- Keep appropriate technical and organisational security measures in place (section 5).
- Use sub-processors only as set out in section 4.
- Help the Shop respond to customers exercising their data rights (section 6).
- Help the Shop with security, breach notification, and any data protection impact assessment, taking into account the nature of the processing and the information available to us.
- Delete or return the data when the service ends (section 7).
- Make available the information needed to show we meet this agreement, and allow reasonable audits. Audits are limited to once a year with 30 days' notice, unless a breach has occurred or a regulator requires one.
- Tell the Shop immediately if we think an instruction breaks data protection law.
- Not use the Shop's customer data for our own purposes. We do not market to the Shop's customers, and we never sell their data.
3. The Shop's obligations
The Shop is responsible for:
- having a lawful basis for collecting its customers' data, which is normally performance of the contract to supply the food;
- its own privacy notice to customers, which should say that the Shop uses Orderhatch to take orders;
- the accuracy of what it asks Orderhatch to process;
- its use of any data it exports from Orderhatch, and anything it sends customers outside Orderhatch.
4. Sub-processors
The Shop gives general authorisation for the sub-processors below. We will give at least 30 days' notice by email of any addition or replacement. If the Shop objects on reasonable data protection grounds and we cannot resolve the objection, the Shop may cancel before the change takes effect.
| Sub-processor | What for | Location and safeguard |
|---|---|---|
| Supabase Inc. | Database, sign-in and file storage | [EU/UK region selected]; UK International Data Transfer Addendum where data leaves the UK |
| Vercel Inc. | Website hosting and server functions | UK International Data Transfer Addendum or UK–US data bridge |
| Resend Inc. | Order emails | UK International Data Transfer Addendum or UK–US data bridge |
| Twilio Inc. | Order text messages | UK International Data Transfer Addendum or UK–US data bridge |
| Stripe Payments Europe Ltd and Stripe, Inc. | Orderhatch's own subscription billing for the Shop. Stripe does not receive the Shop's customer data through this service | UK International Data Transfer Addendum or UK–US data bridge |
We impose data protection terms on each sub-processor that are no less protective than this agreement, and we remain responsible to the Shop for their work.
5. Security measures
- Encryption in transit (HTTPS everywhere) and at rest (provider-managed).
- The database is not reachable through the public API. All access goes through the Orderhatch server, which checks that the signed-in person belongs to the Shop and what their role allows.
- Shop staff accounts see only the stores they have been added to.
- Access to production systems is limited to named Orderhatch staff and protected with multi-factor authentication.
- Payment events are accepted only when verified with Stripe's signature.
- IP addresses used to stop fake orders are stored only as salted hashes and deleted after 24 hours.
- Backups are provided by the hosting provider.
6. Customer rights requests
The Shop can export all its customer data at any time from Settings → Download customer data. If a customer contacts Orderhatch directly, we will pass the request to the Shop within 5 working days and will not answer it ourselves unless the Shop asks us to.
7. When the Shop leaves
When the subscription ends, the Shop can download its data for 30 days. After that, Orderhatch deletes customers' names, email addresses and phone numbers from all order records, and keeps only anonymous order totals that the Shop may need for its accounts. Backups roll off within [35] days.
8. Personal data breaches
Orderhatch will tell the Shop without undue delay, and in any case within 48 hours of becoming aware of a breach affecting the Shop's customer data. We will include what we know, the likely consequences, and what we are doing about it, so the Shop can meet its own 72-hour duty to report to the ICO.
9. General
This agreement is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction. If it conflicts with the Terms of Service on data protection, this agreement wins. Questions about it go to [contact email].