eventifood← Back to home

Privacy Policy

Last updated 24 September 2026

Eventifood is ordering software for food vans and mobile caterers. This policy explains what personal data we hold, why we hold it, who else sees it, how long we keep it and what you can ask us to do about it. It covers eventifood.com, every seller store on a *.eventifood.com subdomain, and the Eventifood apps.

Who is responsible for your data

Eventifood is the data controller for the accounts we hold, the platform itself and the caterer directory. You can reach us at hello@eventifood.com.

One important distinction. When you place an order with a food van through Eventifood, the van — not us — decides what to do with your order and is the controller of it. We process that order on the van's behalf, as its processor. If you want an order deleted or corrected, the van is the first place to ask; write to us and we will help you reach them.

What we collect, and why

We collect what the software needs to work, and we ask for it at the point it is needed rather than up front.

If you buy food

DataWhyLawful basis
Your nameSo the van can call the order out and hand it to the right personContract
Your email addressTo send your receipt and tell you when the order is readyContract
Your phone number, if you give oneOptional. For an SMS when the order is readyContract
Your order, any notes and the table numberTo cook and hand over what you asked forContract
Payment confirmationTo know the order is paid. We never see or store your card numberContract

You do not need an account to order. Allergy or dietary information you type into the notes field is health data, so please give only what the van needs to serve you safely — it is passed to them and kept with the order.

If you run a van or a business on Eventifood

DataWhyLawful basis
Name, email, password (hashed)Your account and sign-inContract
One-time codes sent to your emailTwo-factor sign-in, which is on by defaultContract
Business and trading details, menu, pricesTo run your storeContract
Payout and identity details you give Stripe, PayPal or GoCardlessTo pay you and to meet anti-money-laundering law. Held by them, not by usLegal obligation
Sales, orders and receipts you recordYour own books, and the tax records HMRC requiresLegal obligation

If you are listed in the caterer directory

Some directory entries began as public records from the Food Standards Agency's open data, published so organisers can find caterers. Entries stay unpublished until claimed. Caterer contact details are never shown publicly — an organiser uses an enquiry form and we pass the message on, so you choose whether to reply. Our basis is legitimate interests: running a directory that helps caterers get work. You can ask us to remove a listing at any time and we will.

If you contact us, or comment

When you email us we keep what you send and our reply, so that we can answer you and remember the conversation. If you comment on an article we keep the name and email address you gave, the comment itself and the IP address it came from — the IP address so that we can deal with spam and abuse. Legitimate interests.

When you simply visit the site

We count visits ourselves rather than handing the job to an advertising company. For each page view on our public pages we record the page, where you arrived from, any campaign tags in the link, your browser and whether you are on a phone or a computer, a rough location worked out from your IP address — usually the town — and how long you stayed. A random identifier stored in your browser links the pages of one visit together and expires after 30 minutes of inactivity.

We do not store your IP address with these records, we do not know who you are, the data never leaves our own servers, and it is not used for advertising or shared with anyone. Our basis is legitimate interests: knowing which pages are worth keeping. Say no by turning on “Do Not Track” or blocking scripts, or email us and we will tell you how to opt out permanently.

Cookies and browser storage

Most of what we store in your browser is there because the site would not work without it: staying signed in, keeping your basket between pages, remembering which seller's store you are on, showing you your recent orders and holding any dietary preferences you set. These are strictly necessary and do not require your consent.

The one exception is the visit identifier described above, which is measurement rather than necessity. We use no advertising cookies, no third-party trackers, and nothing that follows you to other websites.

Who else sees your data

We do not sell personal data, and we never will. We share it only with the companies that make the service work, each under contract and each only with what they need:

WhoWhat for
Stripe, PayPal, GoCardlessTaking payment and paying sellers out. They receive your payment details directly; we do not
ResendSending email — receipts, order updates, sign-in codes
TwilioSending SMS order updates, where a van has enabled them
RailwayHosting the application and its database
The food van you ordered fromYour order, so they can make it
HMRC, and others where the law requiresTax, or a valid legal request

Where your data is held

Our servers and database are hosted in the United States, and some of the providers above process data outside the UK. Where that happens, the transfer is covered by the UK International Data Transfer Addendum to the European Commission's Standard Contractual Clauses, or by UK adequacy regulations where they apply.

How long we keep it

WhatHow long
Orders, receipts and the records behind themSix years after the end of the tax year, because HMRC requires it
Your accountWhile it is open, then 30 days after you close it
Sign-in codes and session recordsMinutes to days — they expire on their own
Visit records from our own analyticsTwo years, then deleted automatically
Enquiries and support emailTwo years from the last message
An unclaimed directory listingUntil claimed, or until you ask us to remove it

Tax records are the one thing we cannot delete on request: the obligation to keep them overrides erasure while it lasts.

Your rights

Under UK GDPR you can ask us to:

  • give you a copy of the personal data we hold about you;
  • correct it if it is wrong;
  • delete it, where we are not required to keep it;
  • restrict or object to how we use it, including anything based on legitimate interests;
  • send it to you, or to someone else, in a machine-readable form.

Write to hello@eventifood.com and we will answer within one month. There is no charge.

If you are unhappy with how we have handled it, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you came to us first, but you do not have to.

Deleting your data

There is no self-service delete button, so ask us and we will do it: a seller closing an account, a customer who ordered without one, or a caterer in the directory. Email hello@eventifood.com with enough detail to find the record: the email address used, and roughly when. We remove the account and the personal data in it within 30 days, keeping only the tax records described above, and confirm when it is done.

Security

Passwords are hashed, never stored in a form we could read. Sellers have two-factor sign-in by default. Traffic is encrypted in transit. Each seller's data sits in its own database schema, so one seller cannot reach another's. Card numbers never touch our servers.

Children

Eventifood is not aimed at children, and we do not knowingly collect data from anyone under 13. If you believe a child has given us data, tell us and we will remove it.

Changes to this policy

If we change anything material we will update the date at the top and, where it affects you directly, tell account holders by email. This version is dated 24 September 2026.