Privacy policy
Last updated: 17 July 2026 · Version 1.0
1. Who we are
Rated5 ("we", "us", "our") is a UK food-safety compliance product, currently operated by its founder, Ben Bowen, trading as Rated5. Full registered company details will be added here once incorporated — in the meantime, the contact point for any privacy query is [email protected].
2. What we collect, and where
On this website (rated5.app), we collect:
- Contact form submissions — name, email address, and the content of your message.
- Basic, aggregated, cookieless analytics via Cloudflare Web Analytics (see our cookie policy) — no personal data is collected by this.
In the Rated5 app (go.rated5.app), once you sign up:
- Account data — your name, email address, and password (stored as a salted hash, never in plain text).
- Business data — your premises details, appliances, suppliers, and team roster.
- Food-safety records — temperature readings, checklist answers, cleaning logs, corrective actions, training records, and documents your business creates in the course of using the app. Where these records include the names of your staff (for example, who recorded a reading, or who signed off a safe method), we process that data as a data processor on your business's behalf — your business is the data controller for its own operational records, and we are the controller only for account-level data (your own login, billing, and support communications).
3. Payment information
Card details never touch Rated5's servers. Payments are handled entirely by Stripe, our payment processor — we only ever store the card brand, last four digits, and expiry month/year, purely for display purposes (for example, "Visa ending 4242").
4. Lawful bases for processing
- Contract — account data and food-safety records, to provide the service you've signed up for.
- Legitimate interests — responding to contact form enquiries; keeping the site and app secure and functioning.
- Legal obligation — where retaining certain records helps demonstrate compliance with food-safety law (this is your business's obligation as the data controller for those records; Rated5 supports it by keeping records intact and exportable).
5. Retention
Food-safety records in the app are never automatically deleted — the whole point of the product is a permanent, unfalsifiable diary. If a subscription lapses or is cancelled, the account is paused rather than deleted, and the account owner retains the ability to log in and export a full copy of every record at any time. There is currently no automated data-deletion or retention-window process; if you'd like your data removed, contact us at the address above and we'll handle it manually.
6. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Have inaccurate data corrected
- Request erasure of your data, subject to our legal obligations
- Object to or restrict certain processing
- Receive your data in a portable format (the app's own export features cover most of this directly)
To exercise any of these rights, email [email protected]. If you're not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection regulator.
7. Sub-processors
We use the following sub-processors to run Rated5:
- Railway — application hosting.
- Cloudflare (including R2 object storage) — content delivery, DNS, and file storage for photos, documents, and signatures.
- Brevo — transactional email (invites, password resets, reminders, notifications).
- Stripe — payment processing and card storage.
Each of these providers may process data outside the UK; each maintains its own UK/EU data transfer safeguards (such as Standard Contractual Clauses) as part of their standard terms of service. We choose providers with credible security and compliance commitments, and review this list as our sub-processors change.
8. Security
Passwords are stored as salted hashes, never in plain text. Sessions use secure, httpOnly cookies. Food-safety records are immutable once written — nothing is silently edited or deleted, which is both a product feature and a security property.
9. Changes to this policy
We'll update the "last updated" date above whenever this policy changes, and post material changes here.