Privacy policy

Clear records need clear privacy.

This policy covers the Food Hygiene Record Book iPhone app, optional cloud backup and team access, account activity, and this support website.

Last updated: 28 August 2026

Local firstDaily records can stay on your iPhone.
Cloud by choiceBackup and team access need a verified account.
Selected sharingOnly the business you enable is shared with its authorised team.
Analytics by choiceWebsite analytics starts only after you accept it.

1. Who we are and when this policy applies

Food Hygiene Record Book is operated by Faisal Badshah, trading as Faisal Badshah Creation, based in Southampton, United Kingdom. For account administration, support, website use and the limited service-activity information described below, Faisal Badshah Creation is the data controller.

When a restaurant or other food business records information about its staff, suppliers or other people, that business decides why the information is used and will normally be the controller for that record. Faisal Badshah Creation processes cloud record content only to provide the backup and team functions chosen by the app user.

Privacy questions and data-rights requests can be sent to fayxalbadshah@gmail.com or through the contact page.

2. Information processed

Food-business records

You decide what to enter. Records may include business names and locations, kitchen details, equipment and food temperatures, stock levels, cleaning checks, initials, signatures, notes, food waste, SFBB diary and review entries, date labels and shelf-life dates, supplier and delivery checks, timed food batches, HACCP hazards, controls, critical limits, monitoring, corrective action and review dates, staff training, fire-safety information and inspection-report content.

Account and team information

If you use cloud features, the app processes your email address, Firebase account identifier, email-verification status and authentication tokens. Team access also uses invitation details, the selected business, member display names, email addresses, assigned roles, custom role names, join dates and shared-record activity.

When complimentary access is granted or extended, we use the recipient email address, access period, seat allowance and, where available, business name to send a service confirmation. This is an operational message about account access, not marketing.

Limited account activity

For a verified cloud account, the app may send a small service heartbeat no more than periodically. It contains the app version, build number and platform. The authenticated request also lets the service associate the heartbeat with the account email, display name if supplied, verification status, sign-in time and an opaque account identifier.

The account-activity service does not receive temperatures, cleaning checks, food-waste entries, food-control or HACCP records, staff records, SFBB entries, fire-safety records, business names or PDF contents. It is used to understand whether the service is active, support users on older versions and improve reliability.

In-app service announcements

The app may show an operational or product announcement to all users or to a particular verified account. To deliver the notice reliably, avoid repeatedly showing a dismissed notice and understand whether it was useful, the service stores the announcement identifier, platform, a pseudonymous recipient hash derived from the Firebase account identifier, and the dates and times when the notice was delivered, opened or dismissed.

The recipient hash is not used to recover an email address, build an advertising profile or track activity in other apps or websites. For an announcement addressed to one account, the administrator must use that account's email address to select the recipient.

Technical, website and support information

Firebase Authentication may process credentials, IP addresses and user-agent information to sign users in and prevent abuse. Firebase App Check processes device or app-attestation material and short-lived tokens to help reject unauthorised clients.

Firebase Hosting processes ordinary web-request information, including IP addresses, to deliver and protect this website. The support form prepares a message in your own email app; it does not upload the form to this website. If you send the email, we receive the information included in it.

Optional website analytics

Google Analytics 4 runs only after you choose Accept analytics. If accepted, it helps us understand page visits, approximate country or region, device and browser type, referring campaigns, feature-preview use, FAQ openings, and clicks leading to the App Store, Google Play, support or other websites. We use this information to improve the website and understand which marketing is useful.

We do not send names, email addresses, support-form contents, account identifiers, food-safety records or app activity to website analytics. Advertising storage, advertising personalisation and Google Signals are disabled. Google Analytics may set first-party _ga cookies to distinguish visits and maintain a session. We configure them to expire no later than about 13 months from first use.

You can reject analytics without losing any website function. You can also change your choice later through Cookie settings in the website footer. Withdrawing consent removes the website's Google Analytics cookies where the browser permits this and stops the Google tag loading on later pages.

3. Where information comes from

  • directly from you when you create records, an account or a support message;
  • from a business owner or administrator who invites your verified email address and assigns your role;
  • from authorised team members when they update a shared business; and
  • from Apple, Firebase and hosting infrastructure when they provide security, authentication and request information.

4. Local records and device security

Record-book data is stored in the app's private iPhone container so normal work can continue offline. Authentication credentials are stored using the iOS Keychain with device-only accessibility. The app covers its content when it moves into the background to reduce exposure in the app switcher.

If cloud backup is not enabled, deleting the app, losing the iPhone or losing access to the device may permanently remove records that have not been exported. Device passcode, Face ID, iOS updates and secure device handling remain the user's responsibility.

5. Optional cloud backup and team access

A verified account is required for cloud backup and team access. Backup uploads use separate generations so an interrupted upload does not replace the last completed backup. Temporary uploads and older inactive generations are routinely cleaned up; the active backup remains until it is replaced or deleted.

Team access starts only when an authorised person enables it for a selected business. The current business records are then uploaded to a protected team workspace. Personal backups and other businesses are not added to that workspace.

Invitations are sent to a specific verified email address and expire after seven days. Access is controlled through these roles:

  • Owner: full control of records, people and business access;
  • Administrator: all records and invitations for managers, staff and viewers;
  • Manager: all food-safety records and business details;
  • Staff: daily temperature, cleaning, waste and SFBB diary records; and
  • View only: review access without editing.

Authorised members can see the shared business records their role allows. Recent shared-record activity identifies the member and whether a record was updated or removed.

6. Subscriptions and payment

Business access can be paid for through an Apple auto-renewable subscription, or granted free of charge by us as complimentary access.

We never see your card details. Payment is taken by Apple under your Apple Account. We do not receive, store or process card numbers, billing addresses or any other payment instrument.

When you subscribe, the app sends Apple's signed transaction to our protected service so the correct business can be unlocked. From that transaction we store the original transaction identifier, the product identifier, the current status and renewal or expiry date, the business the purchase applies to, and the owner email address associated with it. Apple also sends us server notifications about renewals, cancellations, billing retries, grace periods, refunds and expiry so that access stays accurate.

This information is processed to perform our agreement with you: to unlock and maintain the access you paid for, to keep it correct when Apple reports a change, and to prevent one business's purchase being used to unlock another. Records of a transaction are also kept where needed for tax, accounting and dispute-handling duties.

Complimentary access does not involve any payment and never becomes a charge. It is recorded as an access grant against the business, with its period, seat limit and an internal administrative note.

Apple's handling of your purchase is governed by Apple's own privacy policy. To cancel, use your Apple Account subscription settings; we cannot cancel an Apple subscription for you.

7. Why information is used and our lawful bases

Provide the service
Account sign-in, cloud backup, restoration, team access, service announcements, support and account deletion are processed to perform our agreement with you or take steps you request.
Protect and improve the service
Security checks, abuse prevention, fault diagnosis, minimal account-activity reporting and announcement delivery, opening and dismissal information are processed for our legitimate interests in operating a secure, reliable and understandable service.
Website analytics
Optional Google Analytics is processed only with your consent. You may reject or withdraw that consent at any time through Cookie settings without losing website functionality.
Meet legal duties
Information may be processed where necessary to comply with applicable law, resolve legal claims or respond to a valid authority request.

A food business using the app is responsible for identifying its own lawful basis before entering or sharing personal information about staff or other people. The app is not intended for special-category information such as medical records; avoid entering it unless the business has confirmed that it is necessary and lawful.

8. Who information is shared with

  • Google Firebase: authentication, App Check, Cloud Firestore backup and team data, and website hosting;
  • Cloudflare: protected infrastructure for the limited account-activity service, owner reporting, in-app announcements and reliable notification queuing;
  • Resend: delivery of transactional emails confirming complimentary access and extensions;
  • authorised business members: the selected shared business according to each person's role;
  • services you choose: Mail, Messages, AirDrop, Files or another destination when you share a PDF; and
  • authorities or advisers: only where disclosure is legally required or necessary to protect legal rights.

Google, Cloudflare and Resend act as service providers for the relevant cloud functions. We do not sell personal information, use it for third-party advertising or use it to track you across other companies' apps and websites.

9. International processing

Cloud providers operate internationally. Firebase Authentication is operated from the United States, while Cloud Firestore, App Check, Hosting, Cloudflare and Resend may process information in the UK, EEA, United States or other locations where those providers operate.

Where personal information is transferred outside the UK, the relevant provider terms use recognised safeguards where required, such as adequacy regulations or approved contractual clauses. More information is available in Firebase privacy and security information and Cloudflare's data processing addendum.

10. How long information is kept

  • Local records: until you remove them in the app or delete the app.
  • Current cloud backup: until replaced or the backup account and cloud records are deleted.
  • Backup upload remnants: abandoned uploads become eligible for cleanup after 24 hours; older inactive generations become eligible after seven days while recent fallbacks are retained.
  • Team invitations: seven days, unless accepted, declined or cancelled sooner.
  • Shared business records: while the workspace remains active or until an authorised member removes them. Leaving a business removes your access but does not delete the owner's business records.
  • Daily activity markers: 90 days. The latest account activity, version and platform remain for account support until the account activity is deleted.
  • Access-notification delivery records: successful outbox records are removed after 30 days; undelivered records are removed after 90 days. The access grant itself remains in the access audit history.
  • In-app announcements and receipts: an announcement is removed 180 days after it expires or is revoked. Its pseudonymous delivery, opening and dismissal receipts are removed with it. An announcement with no expiry remains until it is revoked and then enters the same 180-day cleanup period.
  • Support messages: while reasonably needed to answer the request, prevent repeated problems and meet legal obligations.
  • Website security logs: according to Firebase Hosting's operational retention, which Google describes as a few months for IP data.
  • Optional website analytics: Google Analytics is configured to retain event-level data for two months and user-level data for 14 months. Google states that these controls do not affect most standard reporting, which uses aggregated data. First-party analytics cookies expire no later than about 13 months from first use.

After account deletion, service providers may retain limited residual copies in protected backup systems for their published deletion period. Google states that some Firebase Authentication data may take up to 180 days to be removed from live and backup systems.

11. Sign-out, removal and deletion controls

Signing out removes saved cloud credentials from the iPhone and removes local copies of businesses you joined as a team member. It does not delete your personal cloud backup or the business owner's shared records.

An owner or administrator can remove a member's access. A non-owner can leave a shared business. The shared records remain available to the business owner and other authorised members.

To delete a backup account, first remove or leave shared-business memberships, then open Home > Secure cloud backup > Backup account > Delete backup account and cloud records. The app requests deletion of account activity, cloud backup data and the Firebase Authentication account. Local records on that iPhone remain until removed separately.

Deleting an account does not cancel an Apple subscription. Cancel the subscription separately in your Apple Account subscription settings before deleting the account if you do not want it to renew.

PDFs saved or shared outside the app must be deleted from the destination service or device separately.

12. Security

Security measures include HTTPS, Firebase security rules, verified-email access, role checks, Firebase App Check with Apple's App Attest or DeviceCheck, device-only Keychain storage and restricted administrative access. Firebase states that Authentication, Cloud Firestore and App Check data is encrypted in transit and at rest.

Cloud records are protected by provider encryption and access controls, but they are not end-to-end encrypted with a recovery key held only by the user. No system can guarantee complete security.

13. What our administrators can and cannot see

We operate a private administration console so we can run the service, support customers and manage access. Access to it requires a verified administrator account and every access change it makes is recorded in an audit log with the acting administrator and the time.

Administrators cannot open your food-safety records. Temperatures, cleaning checks, food waste, date labels, delivery checks, timed batches, HACCP controls, SFBB entries, staff training, fire-safety records, signatures, notes and inspection PDFs are not readable from the console.

Administrators can see:

  • account email address, display name if supplied and email-verification status;
  • whether an account has been active recently, the app version and platform;
  • business names, the business owner's email address and how many team seats are in use;
  • whether a business has active access, and whether that access is a paid subscription, a complimentary grant or protected legacy access, with its start and expiry dates; and
  • in-app announcements, the target email for an individually addressed notice, and aggregate delivery, opening and dismissal counts. General-announcement receipt rows use pseudonymous hashes rather than showing an account email; and
  • aggregated totals such as how many businesses are active, how many are on complimentary access and how many subscriptions renew or lapse in a period.

Administrators can grant, extend or revoke complimentary access, and can correct an owner email address on a business account. Revoking access never deletes records: local viewing, creation and editing continue, while new inspection-report exports, cloud synchronisation and team collaboration pause until active access is restored.

We use this information for our legitimate interests in operating, supporting and understanding a reliable paid service. You may object using the contact details in this policy.

14. Your data-protection rights

Depending on the circumstances and lawful basis, you may have rights to be informed, access personal information, correct it, erase it, restrict its use, object to its use and receive portable information you supplied.

Send a request to fayxalbadshah@gmail.com. We may need to verify your identity. There is normally no charge and we aim to respond within one month, subject to lawful extensions or exemptions.

For personal information entered by your employer or another food business, contact that business first because it normally controls those records.

15. Automated decisions and marketing

The service does not make decisions with legal or similarly significant effects using automated processing. It does not create advertising profiles or send marketing email from the account-activity system. It may send necessary service emails when complimentary access is granted or extended and may display operational or product announcements inside the app. These announcements are not third-party advertising and are not used to profile users.

16. Children

The app is intended for food-business record keeping and is not directed to children. Do not create an account or enter a child's personal information unless the food business has confirmed that doing so is necessary and lawful.

17. Changes, questions and complaints

This policy may be updated when app functions, providers or legal requirements change. The latest version and update date will remain on this page.

Please contact us first if you have a concern so we can investigate. You also have the right to complain to the UK Information Commissioner's Office. Visit the ICO complaints page or call 0303 123 1113.