Privacy Notice

What we collect

[Not yet written. Real, current answer (not to be invented - re-derive from the live schema before publishing): guest checkout name/phone/email (transactions), staff account email (auth.users), staff profile name (profiles, not yet applied), a business's own customer records including marketing_consent (customers), stock request contact details (stock_requests), employee task activity/tokens (tasks/task_token_ledger). See 11_RAIEX_LEGAL_TRUST_FOUNDATION.md Section 5 for the fuller, already-audited list.]

Children's data

[Not yet written. child_profiles (schema only, not a working feature yet) may eventually hold a child's name/DOB/gender/height, entered by a parent/guardian about their own child - never collected directly from a child, never public. State this plainly once the feature is real; today it holds no live data and nothing reads or writes it.]

Why we collect it

[Not yet written. Order fulfilment, staff task administration, and (only where explicitly opted in) marketing - never collected for a purpose beyond what's stated.]

How long we keep it

[Not yet written. Real retention periods - not yet decided anywhere in this codebase. Flag for founder decision, informed by UK GDPR's storage-limitation principle.]

Your rights

[Not yet written. Access, correction, deletion, objection to marketing - UK GDPR data-subject rights. No self-service mechanism exists yet for any of these; today a request would need to be handled manually by the business. State this honestly rather than implying a working portal exists.]

Marketing communications

[Not yet written. Only sent where marketing_consent (customers/transactions) is explicitly true - never inferred, never pre-ticked. See src/app/shop/checkout/page.tsx's own checkbox for the real, current mechanism.]

Who we share data with

[Not yet written. SumUp (payment processing) and Supabase (hosting/database infrastructure) - the only two third parties this codebase actually integrates with today.]