managero Privacy Policy
1. Who we are
managero is provided by Toby Nieman, a sole trader, trading as managero.
- Contact for anything in this policy: hello@managero.co.uk
- The service: https://app.managero.co.uk
2. Controllers and processors
Which relationship you are in decides who answers you.
A restaurant with a managero account is the controller of the records it keeps about its staff and about incidents in its business. We are its processor. You decide what goes in. We hold it and act on your instructions. Our obligations to you are in the Data Processing Terms.
An employee invited to managero by a manager should ask their employer about their data. The employer is the controller. If you write to us we will acknowledge you, tell you which business holds your data and pass the request to them. We cannot correct or delete an employer's records on your instruction.
For our own account and billing records — the name and email of the person who signs up, what they pay, and the emails we send them — we are the controller.
3. What we hold, and why
3.1 The account holder (we are the controller)
| What | Source | Lawful basis |
|---|---|---|
| Name, email address | Sign-up | Contract, Article 6(1)(b) |
| Sign-in credentials, handled by Firebase Authentication. We do not see your password | Sign-up | Contract, Article 6(1)(b) |
| Business name, site names and site addresses | Your setup of the account | Contract, Article 6(1)(b) |
| Emails we send you: staff invitations, failure and miss alerts, the owner digest, payment notices, the export on cancellation | Automatic | Contract, Article 6(1)(b) |
| Billing records: customer and subscription ids, status, amounts, renewal dates | You, and Stripe | Contract, Article 6(1)(b), and legal obligation, Article 6(1)(c), for tax records |
| Security and diagnostic data: IP address, browser user agent, error logs | Automatic | Legitimate interests, Article 6(1)(f): keeping the service secure and working |
Providing this data is a contractual requirement, not a statutory one. Without it we cannot open or run an account for you.
3.2 Your employees (you are the controller; we process on your instructions)
This data reaches us either from you or from the employee, who enters it when completing their invitation. The lawful basis column gives the basis a UK restaurant ordinarily relies on. The basis is yours to determine, not ours.
| What | Where in the app | Lawful basis the controller ordinarily relies on |
|---|---|---|
| Name (first and last) | Invitation completion; copied onto every record the person creates | Contract, Article 6(1)(b): the employment contract |
| Email address | The invitation; sign-in | Contract, Article 6(1)(b) |
| Phone number | Invitation completion | Contract, Article 6(1)(b), and legitimate interests, Article 6(1)(f): reaching staff about shifts |
| Date of birth | Entered by the employee on the invitation page | Legal obligation, Article 6(1)(c): age governs the hours a young worker may lawfully work, and identity checks; and contract, Article 6(1)(b) |
| Home address | A field exists in the data model but no screen captures it and nothing writes it | Not processed at present |
| Emergency contact name, relationship and phone number | Invitation completion | Vital interests, Article 6(1)(d), for the emergency itself; legitimate interests, Article 6(1)(f), for holding it in advance. This is personal data about a third party: the employee should tell the person they name |
| Signature images | Signing a form, and counter-signing an incident report. Stored as a PNG in Cloud Storage | Legal obligation, Article 6(1)(c): a food-safety record must be attributable; and legitimate interests, Article 6(1)(f) |
| IP address and browser user agent | Captured into the audit block of every signature, with the time and the account email. Shown on screen and printed in the export | Legitimate interests, Article 6(1)(f): the audit trail is what makes a signed record stand up |
| Photographs taken as evidence | Daily checks, corrective actions, deliveries, incident scenes, Camera Uploads of completed sheets, and photo answers inside forms. People frequently appear in them | Legal obligation, Article 6(1)(c), and legitimate interests, Article 6(1)(f) |
| Right-to-work check answers and document images | The built-in right-to-work form template: full name, date of birth, document reference and a photograph of the identity document | Legal obligation, Article 6(1)(c): the statutory excuse under immigration law depends on holding the check |
| Training records and quiz results | Training screens. A quiz attempt stores the paper, the answers, the marking and the score | Legal obligation, Article 6(1)(c): food handlers must be supervised and trained; and legitimate interests, Article 6(1)(f) |
| Certificates uploaded about a named person | The document vault, where a document can have a person as its subject | Legal obligation, Article 6(1)(c), and legitimate interests, Article 6(1)(f) |
| Shift and rota data: who worked, when, in what role, and who requested or approved a shift swap | Rota planning and publication | Contract, Article 6(1)(b), and legal obligation, Article 6(1)(c): working time records |
| Attribution on operational records: who recorded each temperature, check, delivery, note and correction, and when | Automatic, on every record | Legal obligation, Article 6(1)(c): an unattributable food-safety record is not a record |
| Free-text notes typed by managers about records | Record notes and corrections | Legitimate interests, Article 6(1)(f). Text typed into a free-text box is personal data if it is about a person, and what goes in one is the controller's responsibility |
Not collected. managero holds no location or GPS data, no National Insurance number, no bank details, no salary or pay rate, and no staff health questionnaire.
3.3 Incident and injury records: special category data
An incident report in managero can hold: the injured person's name; whether they are staff, a customer, a contractor or a delivery driver; their organisation; their contact number, email address and postal address; a narrative of what happened; a description of the injury; what treatment was given and by whom; the names and contact details of witnesses; photographs of the scene; whether a RIDDOR prompt was raised; a counter-signature with its audit block; and any later corrections.
A description of an injury and of the treatment given is data concerning health. Health data is special category personal data under Article 9(1) of the UK GDPR and may not be processed unless a condition in Article 9(2) is met in addition to an Article 6 basis.
The Article 9 conditions relied on:
- Injured person is a worker — Article 9(2)(b): processing necessary for carrying out the obligations and exercising the specific rights of the controller or the data subject in the field of employment law and social security law. In UK law that condition requires an authorising provision, which is Schedule 1, Part 1, paragraph 1 of the Data Protection Act 2018 (employment, social security and social protection). The obligations served are the duty to report certain injuries under the Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013 (RIDDOR) and the duty to keep an accident book under the Social Security (Claims and Payments) Regulations 1979.
Schedule 1, Part 4 of the Data Protection Act 2018 requires a controller relying on that paragraph to have an Appropriate Policy Document in place. If you use managero to record injuries to your staff, that document is your obligation, not ours.
- Injured person is not a worker (a customer, a delivery driver, a contractor): the employment condition does not apply. The condition relied on is Article 9(2)(f), processing necessary for the establishment, exercise or defence of legal claims, with Article 6(1)(f), legitimate interests. A contemporaneous record of an injury on your premises exists because a claim may follow.
- Article 9(2)(c), vital interests, may apply in the moment of a serious incident where the person cannot consent, for example when emergency contact details are used. It is not relied on for keeping the record afterwards.
Consent is not relied on for any of this. An employer cannot take freely given consent from an employee for something the employee cannot realistically refuse, and a record that disappears when consent is withdrawn is not a record.
As processor we do not choose these conditions. The controller does.
Controls in the app. Reading an incident record requires being the account owner or holding an explicit permission. Incident records are excluded from ordinary employee views and from the owner digest email, and an export containing them carries a special-category warning. The public counter-signing link shows the injured party only what they need to sign and withholds the date of birth field.
3.4 On your device
- A photo queue in your browser's IndexedDB. Photographs taken while offline are held on the device, compressed, until they upload. This is what makes recording work in a walk-in fridge with no signal.
- Sign-in state and the selected site, in browser storage, so you are not signed out between screens.
- Firebase Analytics, if it initialises, sets cookies for usage measurement. It is optional in the code and non-fatal if it fails.
4. Recipients and sub-processors
4.1 Google (Firebase and Google Cloud): the platform
Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions and Firebase Hosting. Everything described in section 3 is stored on Google's infrastructure. There is no other database.
4.2 Google (Gemini, via the Google AI Studio API): document and photo import
If you photograph a paper form, a menu or a recipe and use managero's import feature, that file is sent to Google.
- The features are form import, menu import and recipe import (recipe import exists in the codebase but is not currently deployed).
- The file is first stored in your own area of Cloud Storage. The Cloud Function then downloads it and sends it to Google's Gemini API at generativelanguage.googleapis.com.
- For a photograph or a PDF the whole original file is sent, base64-encoded, as you uploaded it. There is no cropping, redaction or OCR step in between. A name, signature or handwriting on that sheet of paper goes to Google with it.
- For a Word document, only the extracted text is sent, not the file.
- The model returns a draft for someone in your business to check and confirm. It is not published automatically. The import prompts forbid the model from producing allergen information of any kind.
- The uploaded original stays in your Cloud Storage area afterwards. Nothing deletes it.
Do not use the import features on a completed form containing personal information about a named person unless you are content for that image to be sent to Google. Import is designed for blank forms, menus and recipes. To put a completed sheet on file, use Camera Upload instead: a sheet filed there is kept as an image and is not read, extracted or sent to any model, which the app states on the record itself — "Managero has not read this photograph." The one exception is a temperature sheet you choose to transcribe from Camera Upload: that photograph is sent to Google in the same way as an import, and every value it proposes is displayed beside the photograph and confirmed by a person before it is saved.
4.3 Domeneshop: email delivery
Outbound email — staff invitations, failure and miss alerts, the owner digest, payment notices and the export on cancellation — is sent through Domeneshop's SMTP service. Domeneshop receives the recipient's email address and the content of the message. An invitation names the business, the person who invited you, the sites you will work at and any forms waiting for you.
4.4 Stripe: payments
Subscriptions are taken through Stripe Payments UK Ltd. Stripe receives your name, your email address and your card details, and it holds the card: we do not see or store a card number. You type it on Stripe's own page, not on ours.
From Stripe we receive only what tells us whether your account is paid: a customer id, a subscription id, the status, the amount, the renewal date and whether a payment failed. That is what your account's billing record holds.
Stripe is a controller in its own right for fraud prevention and its own legal obligations, and a processor on our behalf for the rest. Its privacy policy is at https://stripe.com/gb/privacy. No employee record, compliance record or incident report is sent to Stripe.
5. Where your data is stored, and transfers out of the UK
Your records are stored in the United Kingdom. The Firebase project is managero-162d0. Its Cloud Firestore database is in Google Cloud region `europe-west2`, which is London, and uploaded files — signature images, evidence photographs and documents — are in the Cloud Storage bucket managero-162d0.firebasestorage.app, also in `europe-west2`. Both are single-region, not multi-region. The region was read back off the created database on 31 August 2026. A Cloud Firestore database cannot be moved once it exists.
Two things are processed outside the UK:
- Google's Gemini API, used only when you choose to import a form, menu or recipe from a photograph or a document. What you upload for that purpose may be handled outside the UK. No employee record, injury report or signature is sent to it.
- Stripe, which handles subscription payments and operates internationally. It receives your billing details and no compliance record.
For both, the transfer relies on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, which Google Cloud, Firebase and Stripe incorporate into their terms as standard.
6. Retention, and the right to erasure
Retention. managero keeps records for at least five years, and nothing hard-deletes. This is enforced in the database rules: a function that refuses deletion is applied to every record collection, and signed forms and quiz attempts refuse updates as well. Removing an item archives it.
The right. Article 17 of the UK GDPR gives a person the right to have their personal data erased. It is not absolute. How the two fit together, category by category:
- Compliance records are retained and are not erased on request. Temperature readings, daily checks, deliveries, signed forms, self-audits, training records, quiz attempts, Camera Uploads and incident reports are kept because the restaurant is under a legal obligation to keep them: food hygiene record-keeping duties, RIDDOR, accident book requirements, working time records. Article 17(3)(b) of the UK GDPR disapplies the right to erasure where processing is necessary for compliance with a legal obligation. That is why a leaver cannot have the fridge temperatures they recorded in March deleted.
- A person's name stays on the record they made. The name, the time and the audit block are the record. They are retained on the basis in point 1.
- HR details that are not part of a compliance record can be erased. Once someone has left, their date of birth, phone number, emergency contact details and any address details are no longer needed: the record needs to say who did the thing and when. On the controller's written instruction we delete or minimise those fields on a leaver's profile and leave the compliance records intact. So the answer to "can you delete me" is: most of you, yes; the records you made, no.
- Right-to-work document images are retained for the statutory period after employment ends and then deleted, on the controller's instruction.
- Photographs in which a person appears incidentally are part of the evidence record and are retained under point 1. A photograph that captured something it should not have is deleted on the controller's instruction.
- Account holders' own data — name, email and billing history — is retained while you have an account, and afterwards for as long as it is needed for tax and for the free read-only access promised in section 8 of the Terms of Service.
Two qualifications.
- There is no self-service erasure button and no automated deletion. The app has no user-facing delete for anything except a pending invitation that was never accepted. Erasure under points 3, 4 and 5 is a manual operation we perform on the controller's written instruction. Write to hello@managero.co.uk.
- There is no automatic deletion at five years. Five years is a floor, not a ceiling, and no code enforces a ceiling.
Unresolved. Where a former employee insists their name be removed from records the restaurant must keep, points 1 and 2 collide with Article 17 directly, and the balance is a legal judgement that needs legal advice. Until that advice is taken we apply the position above, tell the person asking what we are doing and why, and tell them they may complain to the ICO.
7. Your rights
You have the right to be informed, to access your data, to have inaccurate data corrected, to erasure (subject to section 6), to restrict processing, to data portability, and to object. Where processing relies on consent you may withdraw it. There is no automated decision-making with legal or similarly significant effects in managero.
- If you are an employee: ask your employer. They control the records. If you write to hello@managero.co.uk we acknowledge you, tell you which business holds your data, and pass the request to them.
- If you are an account holder: write to hello@managero.co.uk. We answer within one month.
Complaints. You can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint, or on 0303 123 1113. You do not have to raise it with us first.
8. Security
- Data is separated per account by Firestore and Cloud Storage security rules, enforced by the server rather than by the app in your browser.
- Signature images, evidence photographs, uploaded documents and imports are write-once at the storage layer: the rules refuse update and delete on those paths.
- Signed forms and quiz attempts cannot be edited after signing. Corrections are appended as new entries, so a change is visible rather than silent.
- Incident records are restricted to the account owner and holders of an explicit permission.
- Passwords are handled by Firebase Authentication. We do not see or store them.
- The Google AI key is a server-side secret and is not in the browser bundle. The browser does not talk to a model directly.
- Access to the production project is limited to the person named in section 1.
Breaches. If a personal data breach affects data we hold for you, we notify you without undue delay, so that you can meet your own 72-hour duty to the ICO. The detail is in the Data Processing Terms, clause 11.
9. ICO registration and the data protection fee
managero is not yet registered with the Information Commissioner's Office and no registration number is claimed here.
Under the Data Protection (Charges and Information) Regulations 2018, organisations including sole traders that use personal information must pay a data protection fee unless they are exempt. The exemptions apply only where processing is limited to purposes such as staff administration, accounts and records, and marketing. Running a customer account system does not clearly fall inside them. The fee is therefore treated as payable at Tier 1 — £52, or £47 by direct debit — for an organisation with a turnover under £632,000 or no more than 10 staff, and registration will be completed before the service launches. The registration number will appear here when it is issued.
Exemption from the fee would not affect any other obligation in this policy.
10. Changes
If we change this policy materially we email account holders and update the date below. The current version is always at https://managero.co.uk/privacy.
Last updated: 2026-08-31.