Privacy Policy
Last updated 24 September 2026
Eventifood is ordering software for food vans and mobile caterers. This policy explains what personal data we hold, why we hold it, who else sees it, how long we keep it and what you can ask us to do about it. It covers eventifood.com, every seller store on a *.eventifood.com subdomain, and the Eventifood apps.
Who is responsible for your data
Eventifood is the data controller for the accounts we hold, the platform itself and the caterer directory. You can reach us at hello@eventifood.com.
One important distinction. When you place an order with a food van through Eventifood, the van — not us — decides what to do with your order and is the controller of it. We process that order on the van's behalf, as its processor. If you want an order deleted or corrected, the van is the first place to ask; write to us and we will help you reach them.
What we collect, and why
We collect what the software needs to work, and we ask for it at the point it is needed rather than up front.
If you buy food
| Data | Why | Lawful basis |
|---|---|---|
| Your name | So the van can call the order out and hand it to the right person | Contract |
| Your email address | To send your receipt and tell you when the order is ready | Contract |
| Your phone number, if you give one | Optional. For an SMS when the order is ready | Contract |
| Your order, any notes and the table number | To cook and hand over what you asked for | Contract |
| Payment confirmation | To know the order is paid. We never see or store your card number | Contract |
You do not need an account to order. Allergy or dietary information you type into the notes field is health data, so please give only what the van needs to serve you safely — it is passed to them and kept with the order.
If you run a van or a business on Eventifood
| Data | Why | Lawful basis |
|---|---|---|
| Name, email, password (hashed) | Your account and sign-in | Contract |
| One-time codes sent to your email | Two-factor sign-in, which is on by default | Contract |
| Business and trading details, menu, prices | To run your store | Contract |
| Payout and identity details you give Stripe, PayPal or GoCardless | To pay you and to meet anti-money-laundering law. Held by them, not by us | Legal obligation |
| Sales, orders and receipts you record | Your own books, and the tax records HMRC requires | Legal obligation |
If you are listed in the caterer directory
Some directory entries began as public records from the Food Standards Agency's open data, published so organisers can find caterers. Entries stay unpublished until claimed. Caterer contact details are never shown publicly — an organiser uses an enquiry form and we pass the message on, so you choose whether to reply. Our basis is legitimate interests: running a directory that helps caterers get work. You can ask us to remove a listing at any time and we will.
If you contact us, or comment
When you email us we keep what you send and our reply, so that we can answer you and remember the conversation. If you comment on an article we keep the name and email address you gave, the comment itself and the IP address it came from — the IP address so that we can deal with spam and abuse. Legitimate interests.
When you simply visit the site
We count visits ourselves rather than handing the job to an advertising company. For each page view on our public pages we record the page, where you arrived from, any campaign tags in the link, your browser and whether you are on a phone or a computer, a rough location worked out from your IP address — usually the town — and how long you stayed. A random identifier stored in your browser links the pages of one visit together and expires after 30 minutes of inactivity.
We do not store your IP address with these records, we do not know who you are, the data never leaves our own servers, and it is not used for advertising or shared with anyone. Our basis is legitimate interests: knowing which pages are worth keeping. Say no by turning on “Do Not Track” or blocking scripts, or email us and we will tell you how to opt out permanently.
Where your data is held
Our servers and database are hosted in the United States, and some of the providers above process data outside the UK. Where that happens, the transfer is covered by the UK International Data Transfer Addendum to the European Commission's Standard Contractual Clauses, or by UK adequacy regulations where they apply.
How long we keep it
| What | How long |
|---|---|
| Orders, receipts and the records behind them | Six years after the end of the tax year, because HMRC requires it |
| Your account | While it is open, then 30 days after you close it |
| Sign-in codes and session records | Minutes to days — they expire on their own |
| Visit records from our own analytics | Two years, then deleted automatically |
| Enquiries and support email | Two years from the last message |
| An unclaimed directory listing | Until claimed, or until you ask us to remove it |
Tax records are the one thing we cannot delete on request: the obligation to keep them overrides erasure while it lasts.
Your rights
Under UK GDPR you can ask us to:
- give you a copy of the personal data we hold about you;
- correct it if it is wrong;
- delete it, where we are not required to keep it;
- restrict or object to how we use it, including anything based on legitimate interests;
- send it to you, or to someone else, in a machine-readable form.
Write to hello@eventifood.com and we will answer within one month. There is no charge.
If you are unhappy with how we have handled it, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you came to us first, but you do not have to.
Deleting your data
There is no self-service delete button, so ask us and we will do it: a seller closing an account, a customer who ordered without one, or a caterer in the directory. Email hello@eventifood.com with enough detail to find the record: the email address used, and roughly when. We remove the account and the personal data in it within 30 days, keeping only the tax records described above, and confirm when it is done.
Security
Passwords are hashed, never stored in a form we could read. Sellers have two-factor sign-in by default. Traffic is encrypted in transit. Each seller's data sits in its own database schema, so one seller cannot reach another's. Card numbers never touch our servers.
Children
Eventifood is not aimed at children, and we do not knowingly collect data from anyone under 13. If you believe a child has given us data, tell us and we will remove it.
Changes to this policy
If we change anything material we will update the date at the top and, where it affects you directly, tell account holders by email. This version is dated 24 September 2026.