CaterCloud

Privacy Policy

Effective and last reviewed: 21 July 2026

Pivot Digital Pty Ltd (Australia) · privacy@catercloud.io

1. Who we are and how to contact us

CaterCloud is a business-management platform for catering and events businesses, operated by Pivot Digital Pty Ltd, a company based in Australia (“CaterCloud”, “we”, “us”, “our”). This Privacy Policy explains what personal information we handle, why, who we share it with, and the choices and rights you have.

For any privacy question, or to exercise a right described below, contact us at privacy@catercloud.io.

2. Our two roles: controller and processor

CaterCloud is used by catering businesses (our “customers” or “operators”) to run their operations. This means we handle personal information in two distinct roles, and it matters which one applies to you:

Where you are a business that subscribes to CaterCloud, we act as a controller of your account and business information — we decide how it is handled to provide and improve the service.

Where an operator uses CaterCloud to manage information about their own customers, guests, leads and staff, that operator is the controller of that information and we act as their processor — we handle it on their instructions to provide the service. If you are an event client, guest or staff member of a business that uses CaterCloud and you want to access, correct or delete your information, please contact that business first; we will support them in responding.

3. The information we collect

Depending on how CaterCloud is used, the information we handle includes:

  • Account and identity data — name, email address, phone number, password (stored only as a secure hash), profile image, time zone and preferences, and two-factor authentication details.
  • Business profile data — your business name, contact details, business address (which for some sole operators may be a home address), tax identifiers such as an ABN, logos and branding, and connected-account identifiers.
  • Customer, lead and event data that operators enter — contact details of enquirers and clients, quotes and invoices, event details (dates, venues, locations, guest numbers), documents, and notes.
  • Dietary and related information — where operators record guest dietary requirements, allergies, intolerances or preferences (for example “severe nut allergy”, “halal”, “vegan”). This can be sensitive information (see section 4).
  • Staff and workforce data — staff contact details, emergency contacts, roles, pay rates, availability, shifts and timesheets, and — where enabled — shift check-in time, location and photos used for attendance.
  • Communications content — the emails, SMS, chat, support messages and call transcripts sent or received through the platform, and delivery/opt-out records.
  • Payment-related data — billing details and transaction records. We do not store full card numbers; card details are handled by our payment providers (Stripe, Square).
  • Signatures — where a quote or document is signed electronically, the signature image and the signer’s IP address and device information.
  • Usage, device and log data — IP address, browser/device information, pages and actions, and security/audit logs (including sign-in and, where applicable, support-access events).
  • Marketing attribution data — where you arrive via an ad or campaign, identifiers such as click IDs (for example Google’s gclid) and UTM parameters.
  • Cookies and similar technologies — see our Cookie Policy.

4. Sensitive information

Some information handled through CaterCloud can be sensitive — in particular dietary requirements, allergies and intolerances (which can reveal health information, and sometimes religious belief), emergency-contact details, electronic signatures, and staff attendance location/photos.

Where an operator records this information about their guests or staff, the operator is responsible for having a proper legal basis and any consent required, and for only collecting what they need. We handle sensitive information only to provide the service, apply appropriate safeguards, and do not use it for any purpose of our own.

5. How we use information

We use personal information to:

  • Provide, operate, secure and support the CaterCloud service and its features.
  • Power AI-assisted features you choose to use, such as drafting quotes, website copy, email replies and menu or advertising analysis (see section 6).
  • Process your subscription payments, and enable the payments, invoices and quotes you send to your own customers.
  • Send the transactional and marketing communications that you trigger or configure, and honour opt-outs and unsubscribe requests.
  • Detect, prevent and investigate fraud, abuse, security incidents and breaches of our terms.
  • Understand and improve the product, generally using aggregated or de-identified data.
  • Comply with our legal, tax and regulatory obligations, and enforce our agreements.

6. AI features and automated processing

Several features use AI to help you work faster — for example drafting a quote, website section, email reply, menu summary or advertising suggestion. These outputs are drafts and suggestions for you to review; you decide whether to use or send them.

When you use an AI feature, the content you submit is processed by our AI provider (Anthropic) to generate the response. Under our provider’s commercial terms, your content is not used to train their general AI models. We do not use AI to make decisions that produce legal or similarly significant effects about you without human involvement.

AI output can be inaccurate or incomplete and is not professional (including legal, tax, financial or dietary/health) advice. Always review AI output before relying on it.

7. Our legal bases (where GDPR or similar law applies)

Where the GDPR or a similar law applies, we rely on: performance of a contract (to provide the service you signed up for); our legitimate interests (to secure, support and improve the service, and to run our business) balanced against your rights; your consent (for example for certain cookies or messages, which you can withdraw); and compliance with legal obligations. Where we act as a processor for an operator, that operator is responsible for the legal basis for their processing.

8. How we share information

We do not sell personal information. We share it only as needed to run the service:

  • With sub-processors that provide the infrastructure and tools behind CaterCloud — see the sub-processor list at the end of this policy. They may only use the data to provide their service to us.
  • To carry out actions you direct — for example delivering an email or SMS you send, publishing a website you build, or processing a payment through your connected payment account.
  • With your connected third-party services (such as Google, Stripe, Xero) where you choose to connect them; those services are governed by their own terms and privacy policies.
  • Where required by law, legal process, or to protect rights, safety, or the security and integrity of the service.
  • In connection with a merger, acquisition, financing or sale of assets, subject to appropriate confidentiality and notice.

9. International transfers

CaterCloud and several of our sub-processors operate in, or transfer data to, countries outside your own — including the United States and other regions. Where we transfer personal information across borders, we rely on appropriate safeguards (such as standard contractual clauses or equivalent mechanisms and our providers’ data-processing terms) to protect it.

10. How we protect information

We apply security measures appropriate to the data, including:

  • Encryption of data in transit, and encryption at rest of stored access credentials and integration tokens (AES-256-GCM).
  • Strong tenant isolation so one business’s data is separated from another’s — enforced both in application code and by database-level row-level security.
  • Secure password hashing, optional two-factor authentication, session controls and sign-in throttling.
  • Audit logging of sensitive and support actions, including any staff access made to support you.
  • Access on a least-privilege basis and ongoing monitoring for faults and abuse.

11. How long we keep information

We keep personal information for as long as your account is active and as needed to provide the service. When an account is deleted, we remove or de-identify the associated tenant data within approximately 30 days, other than data we must retain for legal, tax, accounting, dispute-resolution or security reasons, and copies that persist temporarily in encrypted backups until they cycle out. We also retain suppression/opt-out records for as long as needed to honour those choices.

No method of transmission or storage is completely secure; while we work hard to protect your information, we cannot guarantee absolute security.

12. Your privacy rights

Depending on where you are, you may have rights to access, correct, delete, restrict or object to the processing of your personal information, to data portability, and to withdraw consent. Account owners and admins can export core account data from within CaterCloud and can delete their account and associated data.

To make a request, contact privacy@catercloud.io. If your information is held by a catering business that uses CaterCloud (that is, we are their processor), please contact that business directly; we will assist them. See the jurisdiction notes below for how your rights apply in your region, and how to complain to a regulator.

13. Cookies

We use cookies and similar technologies as described in our Cookie Policy, including a banner that records your choice about non-essential cookies.

14. Children

CaterCloud is a business tool and is not directed to children. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

15. Changes to this policy

We may update this policy from time to time. If we make material changes we will take reasonable steps to notify you, for example by posting the updated policy with a new effective date or by email. Your continued use of CaterCloud after an update means you accept the revised policy.

16. Contact and complaints

If you have a privacy question, request or complaint, contact privacy@catercloud.io. We will acknowledge and work to resolve it. If you are not satisfied, you may also contact the privacy regulator for your region — see the jurisdiction notes below.

Sub-processors we use

We use the trusted providers below to run CaterCloud. Each may only use your data to provide its service to us. We keep this list current as our providers change.

ProviderPurposeDataRegion
Amazon Web Services / SupabaseCloud database, file storage, and realtime infrastructureEffectively all account, business, customer, staff and event data; uploaded files (logos, photos, documents)Primarily Asia-Pacific (Singapore) region
VercelApplication hosting and content deliveryRequest/traffic data, IP addresses, technical logsUnited States / global edge network
StripeSubscription billing, and payment processing for payments you take from your own customers (Stripe Connect)Billing contact details, payment/card data (held by Stripe, not by us), transaction amountsUnited States / global
SquareAlternative payment processing, where you choose itPayment and transaction data (held by Square, not by us)United States / global
AnthropicAI features (drafting quotes, website copy, email replies, menu analysis, support and advertising assistance)The content you submit to an AI feature — which may include enquiry, contact, menu, event or message textUnited States
ResendSending and receiving email on your behalf (transactional and marketing)Recipient names and email addresses, and email message contentUnited States
MessageMedia (Sinch)Sending and receiving SMS on your behalfRecipient phone numbers and SMS message contentAustralia
CloudflareBot/abuse protection (Turnstile), DNS and sending-domain provisioning, and webinar video streamingVisitor IP addresses and challenge tokens; DNS configuration; video contentUnited States / global
SentryError and performance monitoring so we can find and fix faultsDiagnostic and error data, which may incidentally include limited personal data present at the time of an errorUnited States
InngestRunning background jobs (message sequences, calendar sync, scheduled tasks)Job payloads, which may reference account, contact and record identifiersUnited States
Map and location providers (OpenStreetMap, CARTO, Nominatim)Displaying maps and converting addresses to map locationsAddress text and map viewport coordinates; your device IP when a map loadsEuropean Union / global
GoogleOptional "Sign in with Google", and — where you connect it — the Google Ads integrationYour Google account email and profile; and, if connected, your Google Ads account and campaign dataUnited States / global

Jurisdiction-specific notes

Your rights and how we handle your information depend on where you access CaterCloud. The notes below outline the regime for each market we serve.

Privacy Act (Australia / New Zealand)

If you access CaterCloud from Australia or New Zealand, we handle your personal information in line with the applicable Privacy Act and privacy principles, including access and correction rights and notification of eligible data breaches. Please raise any concern with us first; if it is not resolved you may complain to the relevant privacy regulator.

Oversight: the Office of the Australian Information Commissioner (OAIC), or the NZ Privacy Commissioner.

UK / EU GDPR (United Kingdom, Ireland, EEA)

If you access CaterCloud from the UK, Ireland or the EEA, you have rights under the GDPR including access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent and to lodge a complaint with your local supervisory authority. We rely on the lawful bases described above and use appropriate safeguards for international transfers.

Oversight: your local data protection authority (e.g. the ICO in the UK, the DPC in Ireland).

CCPA / CPRA (United States — California)

If you are a California resident, you have rights under the CCPA/CPRA including the right to know, delete, and correct your personal information, and to opt out of its “sale” or “sharing”. We do not sell personal information, and we do not share it for cross-context behavioural advertising.

Oversight: the California Privacy Protection Agency (CPPA).

PIPEDA (Canada)

If you access CaterCloud from Canada, we handle personal information consistent with PIPEDA and applicable provincial privacy laws. You may request access to or correction of your information, and complain to the OPC if a concern is not resolved.

Oversight: the Office of the Privacy Commissioner of Canada (OPC).

POPIA (South Africa)

If you access CaterCloud from South Africa, we process personal information in line with POPIA. You may exercise your data-subject rights, including access and correction, and lodge a complaint with the Information Regulator.

Oversight: the Information Regulator (South Africa).

Privacy Policy — CaterCloud | CaterCloud