vouched ← Home

Privacy Policy

Last updated: [date]

This policy is written to be clear and honest about how Vouched handles data. Before public launch it should be reviewed by a data-protection professional, and the [bracketed] details filled in.

Vouched (“we”, “us”) is a tool that lets hospitality venues request and give staff references. This policy explains what personal data we handle, why, and what your rights are. Vouched is operated by [legal entity, e.g. Hot Milk Ltd], [registered address]. You can reach us at [contact email].

The two kinds of data we hold

It helps to split them, because we treat them very differently:

What we collect

Why we use it, and our lawful basis

Referees and candidates

If a venue asks you for a reference, your details were given to us by that venue for that one purpose. The reference you give is shared with the venue that requested it and is treated as confidential. We don’t use referee or candidate data for marketing.

How long we keep it

Deletion is enforced automatically by a scheduled job, not left to chance.

Who we share it with

We do not sell personal data. We share it only with:

If the business is sold

Vouched may one day be acquired by or merged with another company. If that happens, the data held in Vouched may transfer to the new owner as part of the business, and it would continue to be handled under a policy at least as protective as this one. We tell you this up front rather than spring it on you later.

Where your data lives

Our database is hosted in the EU (Frankfurt), and our email provider processes sending data in the EU (Ireland). Some service providers may process limited data elsewhere; where they do, appropriate safeguards are in place.

Your rights

Under UK data protection law you can ask us to give you a copy of your data, correct it, delete it, or stop certain uses of it, and you can withdraw marketing consent at any time. To exercise any of these, email [contact email]. If you’re unhappy with how we’ve handled your data you can complain to the Information Commissioner’s Office (ICO) at ico.org.uk.

Security

Data is encrypted in transit, access is controlled so each venue only sees its own data, and sensitive operations run through locked-down server functions. No system is perfectly secure, but we take it seriously.

Cookies

We use only what’s needed to keep you signed in. We don’t run advertising or third-party tracking cookies. If that changes, we’ll update this policy and ask where required.

Changes

If we change this policy we’ll update the date above and, for significant changes, let account holders know.

Questions? Email [contact email].