FridgeFlow
Back
Business Privacy

Business Privacy Policy

Last updated: May 1, 2026 · Applies to FridgeFlow Business accounts. View personal privacy policy

1. Introduction

This Business Privacy Policy supplements our General Privacy Policy and explains how FridgeFlow collects, uses, stores, and protects data specifically for business customers — restaurants, cafes, catering companies, cloud kitchens, and similar food-service operations. Note: FridgeFlow Business is currently in early access and available by waitlist only. Some features described below may not yet be available.

By creating a FridgeFlow Business account, you agree to the practices described in this policy. If you are an administrator inviting staff members, you are responsible for informing them about data processing activities related to their use of the platform.

2. Business Data We Collect

When you use FridgeFlow Business, we collect the following categories of information:

  • Business profile: Business name, type, and contact information provided during registration.
  • Inventory data: Stock items, quantities, unit costs, expiry dates, storage zones, and categories.
  • Waste records: Spoilage logs, waste reasons, and associated cost data.
  • Purchase records: Supplier names, purchase orders, item costs, and delivery dates.
  • Maintenance records: Fridge care schedules, task completion logs, and maintenance history per appliance.
  • Staff information: Names, email addresses, and roles of staff members you invite.
  • Usage activity: Actions taken on the platform (who added, edited, or removed items) for audit trail purposes.
  • AI configuration: Your chosen AI provider and an encrypted reference to your API key (if you use the BYOK feature). We never store your raw API key in plaintext.

3. How We Use Your Business Data

We use your business data for the following purposes:

  • Providing and improving the FridgeFlow Business platform and its features.
  • Generating waste reports, cost analytics, and consumption insights for your business.
  • Powering AI-assisted features such as demand forecasting and reorder suggestions.
  • Sending operational notifications (expiry alerts, low-stock warnings).
  • Maintaining security and investigating fraudulent or abusive activity.
  • Complying with legal obligations.

We do not use your business data to train general AI models, sell to third parties, or share with competitors.

4. Staff Data and Multi-User Access

When you invite staff to your Business workspace, their activity (logins, edits, waste logs) is visible to workspace administrators. Staff members can view their own profile and activity but cannot see other staff members' personal details beyond their display name and role.

As the account administrator, you are the data controller for your staff's data within the platform. You are responsible for ensuring staff have been notified about data collection and for removing staff access promptly when they leave your organisation.

5. Data Retention

We retain your business data for as long as your account is active. Upon account termination:

  • You may request a full data export within 30 days of termination.
  • After 30 days, your data will be queued for deletion and permanently removed within 90 days.
  • Audit logs may be retained for up to 12 months for security and compliance purposes.

6. Data Security

We implement industry-standard security measures to protect your business data, including:

  • TLS encryption for all data in transit.
  • Encrypted storage for sensitive fields (such as API keys).
  • Row-Level Security policies to ensure strict data isolation between businesses.
  • Audit trails for all data modifications.
  • Regular security reviews and penetration testing.

In the event of a data breach affecting your business data, we will notify you within 72 hours of becoming aware of the incident, in accordance with applicable regulations.

7. Third-Party Services

FridgeFlow Business integrates with the following third-party services:

  • Supabase: Database and authentication infrastructure. Data is stored in Supabase-managed PostgreSQL instances.
  • AI providers (OpenAI, Google Gemini, Anthropic): Used only when you configure a BYOK API key. When using the built-in AI features, your inventory context is sent to Google Gemini to generate insights, demand forecasts, and suggestions. No other business data is included in AI requests.

We do not integrate with advertising networks, social media trackers, or analytics providers that would have access to your business data.

8. Your Rights

As a business customer, you have the right to:

  • Access: Request a copy of all data we hold about your business.
  • Portability: Export your inventory, waste, and purchase data in CSV format at any time from Settings → Import/Export.
  • Correction: Update inaccurate information directly within the platform or by contacting us.
  • Deletion: Request permanent deletion of your business account and all associated data.
  • Restriction: Request that we restrict processing of your data in certain circumstances.

To exercise any of these rights, contact us at lewisvillamor26@gmail.com. We will respond to verified requests within 30 days.

9. Changes to This Policy

We will notify Business account administrators of material changes to this Privacy Policy by email and/or by a prominent notice within the platform at least 14 days before the changes take effect. Continued use of the platform after this period constitutes acceptance of the updated policy.

10. Contact

For privacy-related enquiries, data subject access requests, or to report a security concern:

Email: lewisvillamor26@gmail.com