managero Privacy Policy

1. Who we are

managero is provided by Toby Nieman, a sole trader, trading as managero.

2. Controllers and processors

Which relationship you are in decides who answers you.

A restaurant with a managero account is the controller of the records it keeps about its staff and about incidents in its business. We are its processor. You decide what goes in. We hold it and act on your instructions. Our obligations to you are in the Data Processing Terms.

An employee invited to managero by a manager should ask their employer about their data. The employer is the controller. If you write to us we will acknowledge you, tell you which business holds your data and pass the request to them. We cannot correct or delete an employer's records on your instruction.

For our own account and billing records — the name and email of the person who signs up, what they pay, and the emails we send them — we are the controller.

3. What we hold, and why

3.1 The account holder (we are the controller)

WhatSourceLawful basis
Name, email addressSign-upContract, Article 6(1)(b)
Sign-in credentials, handled by Firebase Authentication. We do not see your passwordSign-upContract, Article 6(1)(b)
Business name, site names and site addressesYour setup of the accountContract, Article 6(1)(b)
Emails we send you: staff invitations, failure and miss alerts, the owner digest, payment notices, the export on cancellationAutomaticContract, Article 6(1)(b)
Billing records: customer and subscription ids, status, amounts, renewal datesYou, and StripeContract, Article 6(1)(b), and legal obligation, Article 6(1)(c), for tax records
Security and diagnostic data: IP address, browser user agent, error logsAutomaticLegitimate interests, Article 6(1)(f): keeping the service secure and working

Providing this data is a contractual requirement, not a statutory one. Without it we cannot open or run an account for you.

3.2 Your employees (you are the controller; we process on your instructions)

This data reaches us either from you or from the employee, who enters it when completing their invitation. The lawful basis column gives the basis a UK restaurant ordinarily relies on. The basis is yours to determine, not ours.

WhatWhere in the appLawful basis the controller ordinarily relies on
Name (first and last)Invitation completion; copied onto every record the person createsContract, Article 6(1)(b): the employment contract
Email addressThe invitation; sign-inContract, Article 6(1)(b)
Phone numberInvitation completionContract, Article 6(1)(b), and legitimate interests, Article 6(1)(f): reaching staff about shifts
Date of birthEntered by the employee on the invitation pageLegal obligation, Article 6(1)(c): age governs the hours a young worker may lawfully work, and identity checks; and contract, Article 6(1)(b)
Home addressA field exists in the data model but no screen captures it and nothing writes itNot processed at present
Emergency contact name, relationship and phone numberInvitation completionVital interests, Article 6(1)(d), for the emergency itself; legitimate interests, Article 6(1)(f), for holding it in advance. This is personal data about a third party: the employee should tell the person they name
Signature imagesSigning a form, and counter-signing an incident report. Stored as a PNG in Cloud StorageLegal obligation, Article 6(1)(c): a food-safety record must be attributable; and legitimate interests, Article 6(1)(f)
IP address and browser user agentCaptured into the audit block of every signature, with the time and the account email. Shown on screen and printed in the exportLegitimate interests, Article 6(1)(f): the audit trail is what makes a signed record stand up
Photographs taken as evidenceDaily checks, corrective actions, deliveries, incident scenes, Camera Uploads of completed sheets, and photo answers inside forms. People frequently appear in themLegal obligation, Article 6(1)(c), and legitimate interests, Article 6(1)(f)
Right-to-work check answers and document imagesThe built-in right-to-work form template: full name, date of birth, document reference and a photograph of the identity documentLegal obligation, Article 6(1)(c): the statutory excuse under immigration law depends on holding the check
Training records and quiz resultsTraining screens. A quiz attempt stores the paper, the answers, the marking and the scoreLegal obligation, Article 6(1)(c): food handlers must be supervised and trained; and legitimate interests, Article 6(1)(f)
Certificates uploaded about a named personThe document vault, where a document can have a person as its subjectLegal obligation, Article 6(1)(c), and legitimate interests, Article 6(1)(f)
Shift and rota data: who worked, when, in what role, and who requested or approved a shift swapRota planning and publicationContract, Article 6(1)(b), and legal obligation, Article 6(1)(c): working time records
Attribution on operational records: who recorded each temperature, check, delivery, note and correction, and whenAutomatic, on every recordLegal obligation, Article 6(1)(c): an unattributable food-safety record is not a record
Free-text notes typed by managers about recordsRecord notes and correctionsLegitimate interests, Article 6(1)(f). Text typed into a free-text box is personal data if it is about a person, and what goes in one is the controller's responsibility

Not collected. managero holds no location or GPS data, no National Insurance number, no bank details, no salary or pay rate, and no staff health questionnaire.

3.3 Incident and injury records: special category data

An incident report in managero can hold: the injured person's name; whether they are staff, a customer, a contractor or a delivery driver; their organisation; their contact number, email address and postal address; a narrative of what happened; a description of the injury; what treatment was given and by whom; the names and contact details of witnesses; photographs of the scene; whether a RIDDOR prompt was raised; a counter-signature with its audit block; and any later corrections.

A description of an injury and of the treatment given is data concerning health. Health data is special category personal data under Article 9(1) of the UK GDPR and may not be processed unless a condition in Article 9(2) is met in addition to an Article 6 basis.

The Article 9 conditions relied on:

Schedule 1, Part 4 of the Data Protection Act 2018 requires a controller relying on that paragraph to have an Appropriate Policy Document in place. If you use managero to record injuries to your staff, that document is your obligation, not ours.

Consent is not relied on for any of this. An employer cannot take freely given consent from an employee for something the employee cannot realistically refuse, and a record that disappears when consent is withdrawn is not a record.

As processor we do not choose these conditions. The controller does.

Controls in the app. Reading an incident record requires being the account owner or holding an explicit permission. Incident records are excluded from ordinary employee views and from the owner digest email, and an export containing them carries a special-category warning. The public counter-signing link shows the injured party only what they need to sign and withholds the date of birth field.

3.4 On your device

4. Recipients and sub-processors

4.1 Google (Firebase and Google Cloud): the platform

Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions and Firebase Hosting. Everything described in section 3 is stored on Google's infrastructure. There is no other database.

4.2 Google (Gemini, via the Google AI Studio API): document and photo import

If you photograph a paper form, a menu or a recipe and use managero's import feature, that file is sent to Google.

Do not use the import features on a completed form containing personal information about a named person unless you are content for that image to be sent to Google. Import is designed for blank forms, menus and recipes. To put a completed sheet on file, use Camera Upload instead: a sheet filed there is kept as an image and is not read, extracted or sent to any model, which the app states on the record itself — "Managero has not read this photograph." The one exception is a temperature sheet you choose to transcribe from Camera Upload: that photograph is sent to Google in the same way as an import, and every value it proposes is displayed beside the photograph and confirmed by a person before it is saved.

4.3 Domeneshop: email delivery

Outbound email — staff invitations, failure and miss alerts, the owner digest, payment notices and the export on cancellation — is sent through Domeneshop's SMTP service. Domeneshop receives the recipient's email address and the content of the message. An invitation names the business, the person who invited you, the sites you will work at and any forms waiting for you.

4.4 Stripe: payments

Subscriptions are taken through Stripe Payments UK Ltd. Stripe receives your name, your email address and your card details, and it holds the card: we do not see or store a card number. You type it on Stripe's own page, not on ours.

From Stripe we receive only what tells us whether your account is paid: a customer id, a subscription id, the status, the amount, the renewal date and whether a payment failed. That is what your account's billing record holds.

Stripe is a controller in its own right for fraud prevention and its own legal obligations, and a processor on our behalf for the rest. Its privacy policy is at https://stripe.com/gb/privacy. No employee record, compliance record or incident report is sent to Stripe.

5. Where your data is stored, and transfers out of the UK

Your records are stored in the United Kingdom. The Firebase project is managero-162d0. Its Cloud Firestore database is in Google Cloud region `europe-west2`, which is London, and uploaded files — signature images, evidence photographs and documents — are in the Cloud Storage bucket managero-162d0.firebasestorage.app, also in `europe-west2`. Both are single-region, not multi-region. The region was read back off the created database on 31 August 2026. A Cloud Firestore database cannot be moved once it exists.

Two things are processed outside the UK:

For both, the transfer relies on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, which Google Cloud, Firebase and Stripe incorporate into their terms as standard.

6. Retention, and the right to erasure

Retention. managero keeps records for at least five years, and nothing hard-deletes. This is enforced in the database rules: a function that refuses deletion is applied to every record collection, and signed forms and quiz attempts refuse updates as well. Removing an item archives it.

The right. Article 17 of the UK GDPR gives a person the right to have their personal data erased. It is not absolute. How the two fit together, category by category:

  1. Compliance records are retained and are not erased on request. Temperature readings, daily checks, deliveries, signed forms, self-audits, training records, quiz attempts, Camera Uploads and incident reports are kept because the restaurant is under a legal obligation to keep them: food hygiene record-keeping duties, RIDDOR, accident book requirements, working time records. Article 17(3)(b) of the UK GDPR disapplies the right to erasure where processing is necessary for compliance with a legal obligation. That is why a leaver cannot have the fridge temperatures they recorded in March deleted.
  1. A person's name stays on the record they made. The name, the time and the audit block are the record. They are retained on the basis in point 1.
  1. HR details that are not part of a compliance record can be erased. Once someone has left, their date of birth, phone number, emergency contact details and any address details are no longer needed: the record needs to say who did the thing and when. On the controller's written instruction we delete or minimise those fields on a leaver's profile and leave the compliance records intact. So the answer to "can you delete me" is: most of you, yes; the records you made, no.
  1. Right-to-work document images are retained for the statutory period after employment ends and then deleted, on the controller's instruction.
  1. Photographs in which a person appears incidentally are part of the evidence record and are retained under point 1. A photograph that captured something it should not have is deleted on the controller's instruction.
  1. Account holders' own data — name, email and billing history — is retained while you have an account, and afterwards for as long as it is needed for tax and for the free read-only access promised in section 8 of the Terms of Service.

Two qualifications.

Unresolved. Where a former employee insists their name be removed from records the restaurant must keep, points 1 and 2 collide with Article 17 directly, and the balance is a legal judgement that needs legal advice. Until that advice is taken we apply the position above, tell the person asking what we are doing and why, and tell them they may complain to the ICO.

7. Your rights

You have the right to be informed, to access your data, to have inaccurate data corrected, to erasure (subject to section 6), to restrict processing, to data portability, and to object. Where processing relies on consent you may withdraw it. There is no automated decision-making with legal or similarly significant effects in managero.

Complaints. You can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint, or on 0303 123 1113. You do not have to raise it with us first.

8. Security

Breaches. If a personal data breach affects data we hold for you, we notify you without undue delay, so that you can meet your own 72-hour duty to the ICO. The detail is in the Data Processing Terms, clause 11.

9. ICO registration and the data protection fee

managero is not yet registered with the Information Commissioner's Office and no registration number is claimed here.

Under the Data Protection (Charges and Information) Regulations 2018, organisations including sole traders that use personal information must pay a data protection fee unless they are exempt. The exemptions apply only where processing is limited to purposes such as staff administration, accounts and records, and marketing. Running a customer account system does not clearly fall inside them. The fee is therefore treated as payable at Tier 1 — £52, or £47 by direct debit — for an organisation with a turnover under £632,000 or no more than 10 staff, and registration will be completed before the service launches. The registration number will appear here when it is issued.

Exemption from the fee would not affect any other obligation in this policy.

10. Changes

If we change this policy materially we email account holders and update the date below. The current version is always at https://managero.co.uk/privacy.


Last updated: 2026-08-31.