Effective and last reviewed: 21 July 2026
Pivot Digital Pty Ltd (Australia) · privacy@catercloud.io
CaterCloud is a business-management platform for catering and events businesses, operated by Pivot Digital Pty Ltd, a company based in Australia (“CaterCloud”, “we”, “us”, “our”). This Privacy Policy explains what personal information we handle, why, who we share it with, and the choices and rights you have.
For any privacy question, or to exercise a right described below, contact us at privacy@catercloud.io.
CaterCloud is used by catering businesses (our “customers” or “operators”) to run their operations. This means we handle personal information in two distinct roles, and it matters which one applies to you:
Where you are a business that subscribes to CaterCloud, we act as a controller of your account and business information — we decide how it is handled to provide and improve the service.
Where an operator uses CaterCloud to manage information about their own customers, guests, leads and staff, that operator is the controller of that information and we act as their processor — we handle it on their instructions to provide the service. If you are an event client, guest or staff member of a business that uses CaterCloud and you want to access, correct or delete your information, please contact that business first; we will support them in responding.
Depending on how CaterCloud is used, the information we handle includes:
Some information handled through CaterCloud can be sensitive — in particular dietary requirements, allergies and intolerances (which can reveal health information, and sometimes religious belief), emergency-contact details, electronic signatures, and staff attendance location/photos.
Where an operator records this information about their guests or staff, the operator is responsible for having a proper legal basis and any consent required, and for only collecting what they need. We handle sensitive information only to provide the service, apply appropriate safeguards, and do not use it for any purpose of our own.
We use personal information to:
Several features use AI to help you work faster — for example drafting a quote, website section, email reply, menu summary or advertising suggestion. These outputs are drafts and suggestions for you to review; you decide whether to use or send them.
When you use an AI feature, the content you submit is processed by our AI provider (Anthropic) to generate the response. Under our provider’s commercial terms, your content is not used to train their general AI models. We do not use AI to make decisions that produce legal or similarly significant effects about you without human involvement.
AI output can be inaccurate or incomplete and is not professional (including legal, tax, financial or dietary/health) advice. Always review AI output before relying on it.
Where the GDPR or a similar law applies, we rely on: performance of a contract (to provide the service you signed up for); our legitimate interests (to secure, support and improve the service, and to run our business) balanced against your rights; your consent (for example for certain cookies or messages, which you can withdraw); and compliance with legal obligations. Where we act as a processor for an operator, that operator is responsible for the legal basis for their processing.
We do not sell personal information. We share it only as needed to run the service:
CaterCloud and several of our sub-processors operate in, or transfer data to, countries outside your own — including the United States and other regions. Where we transfer personal information across borders, we rely on appropriate safeguards (such as standard contractual clauses or equivalent mechanisms and our providers’ data-processing terms) to protect it.
We apply security measures appropriate to the data, including:
We keep personal information for as long as your account is active and as needed to provide the service. When an account is deleted, we remove or de-identify the associated tenant data within approximately 30 days, other than data we must retain for legal, tax, accounting, dispute-resolution or security reasons, and copies that persist temporarily in encrypted backups until they cycle out. We also retain suppression/opt-out records for as long as needed to honour those choices.
No method of transmission or storage is completely secure; while we work hard to protect your information, we cannot guarantee absolute security.
Depending on where you are, you may have rights to access, correct, delete, restrict or object to the processing of your personal information, to data portability, and to withdraw consent. Account owners and admins can export core account data from within CaterCloud and can delete their account and associated data.
To make a request, contact privacy@catercloud.io. If your information is held by a catering business that uses CaterCloud (that is, we are their processor), please contact that business directly; we will assist them. See the jurisdiction notes below for how your rights apply in your region, and how to complain to a regulator.
We use cookies and similar technologies as described in our Cookie Policy, including a banner that records your choice about non-essential cookies.
CaterCloud is a business tool and is not directed to children. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
We may update this policy from time to time. If we make material changes we will take reasonable steps to notify you, for example by posting the updated policy with a new effective date or by email. Your continued use of CaterCloud after an update means you accept the revised policy.
If you have a privacy question, request or complaint, contact privacy@catercloud.io. We will acknowledge and work to resolve it. If you are not satisfied, you may also contact the privacy regulator for your region — see the jurisdiction notes below.
To offer this feature we request a single Google OAuth scope — https://www.googleapis.com/auth/adwords (the Google Ads API). We request no other Google scopes for it. Connecting is entirely optional and initiated by you from the CaterCloud Ads page; you can decline consent, and you can disconnect at any time.
Once you connect, and solely to provide the advertising features you use, we access data from the Google Ads account(s) you authorise: your accessible accounts and campaign structure, performance metrics (such as impressions, clicks, cost, and conversions), and conversion-tracking settings. On your instruction we also create and update budgets, campaigns, ad groups, keywords, ads, conversion actions, and campaign status through Google’s Ads API. We do not access this data for any purpose other than providing and improving these features for you.
The authorisation you grant (an OAuth refresh token) is encrypted at rest and stored only to keep your connection working; you can revoke it at any time. Campaign and performance data is stored isolated per business (tenant), separated from other customers, and used to render your own dashboards, reporting, and coaching.
We do not sell Google user data, and we do not transfer it to third parties except: to sub-processors that operate our service (such as cloud hosting and database providers) strictly to provide these features to you; to Google’s own Ads API to carry out the actions you request; or where required by law. We do not use Google user data for advertising to you or anyone else.
Some ads features use AI to summarise your campaign performance and suggest changes for you to review. CaterCloud’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular: Google user data is used only to provide or improve user-facing features that are prominent in CaterCloud’s Ads experience; it is not used to develop, improve, or train generalised or non-personalised AI/ML models; it is not transferred to others except as needed to provide or improve those features, to comply with law, or as part of a merger/acquisition with notice; and humans do not read it except with your explicit consent (for example, support you ask us for), where necessary for security or to comply with law, or on data that has been aggregated and anonymised.
You can disconnect your Google Ads account at any time from within CaterCloud, and you can revoke CaterCloud’s access directly from your Google Account at myaccount.google.com → Security → Third-party access. Revoking stops all further access immediately; we then delete or disable the stored authorisation for that connection.
We use the trusted providers below to run CaterCloud. Each may only use your data to provide its service to us. We keep this list current as our providers change.
| Provider | Purpose | Data | Region |
|---|---|---|---|
| Amazon Web Services / Supabase | Cloud database, file storage, and realtime infrastructure | Effectively all account, business, customer, staff and event data; uploaded files (logos, photos, documents) | Primarily Asia-Pacific (Singapore) region |
| Vercel | Application hosting and content delivery | Request/traffic data, IP addresses, technical logs | United States / global edge network |
| Stripe | Subscription billing, and payment processing for payments you take from your own customers (Stripe Connect) | Billing contact details, payment/card data (held by Stripe, not by us), transaction amounts | United States / global |
| Square | Alternative payment processing, where you choose it | Payment and transaction data (held by Square, not by us) | United States / global |
| Anthropic | AI features (drafting quotes, website copy, email replies, menu analysis, support and advertising assistance) | The content you submit to an AI feature — which may include enquiry, contact, menu, event or message text | United States |
| Resend | Sending and receiving email on your behalf (transactional and marketing) | Recipient names and email addresses, and email message content | United States |
| MessageMedia (Sinch) | Sending and receiving SMS on your behalf | Recipient phone numbers and SMS message content | Australia |
| Cloudflare | Bot/abuse protection (Turnstile), DNS and sending-domain provisioning, and webinar video streaming | Visitor IP addresses and challenge tokens; DNS configuration; video content | United States / global |
| Sentry | Error and performance monitoring so we can find and fix faults | Diagnostic and error data, which may incidentally include limited personal data present at the time of an error | United States |
| Inngest | Running background jobs (message sequences, calendar sync, scheduled tasks) | Job payloads, which may reference account, contact and record identifiers | United States |
| Map and location providers (OpenStreetMap, CARTO, Nominatim) | Displaying maps and converting addresses to map locations | Address text and map viewport coordinates; your device IP when a map loads | European Union / global |
| Optional "Sign in with Google", and — where you connect it — the Google Ads integration | Your Google account email and profile; and, if connected, your Google Ads account and campaign data | United States / global |
Your rights and how we handle your information depend on where you access CaterCloud. The notes below outline the regime for each market we serve.
If you access CaterCloud from Australia or New Zealand, we handle your personal information in line with the applicable Privacy Act and privacy principles, including access and correction rights and notification of eligible data breaches. Please raise any concern with us first; if it is not resolved you may complain to the relevant privacy regulator.
Oversight: the Office of the Australian Information Commissioner (OAIC), or the NZ Privacy Commissioner.
If you access CaterCloud from the UK, Ireland or the EEA, you have rights under the GDPR including access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent and to lodge a complaint with your local supervisory authority. We rely on the lawful bases described above and use appropriate safeguards for international transfers.
Oversight: your local data protection authority (e.g. the ICO in the UK, the DPC in Ireland).
If you are a California resident, you have rights under the CCPA/CPRA including the right to know, delete, and correct your personal information, and to opt out of its “sale” or “sharing”. We do not sell personal information, and we do not share it for cross-context behavioural advertising.
Oversight: the California Privacy Protection Agency (CPPA).
If you access CaterCloud from Canada, we handle personal information consistent with PIPEDA and applicable provincial privacy laws. You may request access to or correction of your information, and complain to the OPC if a concern is not resolved.
Oversight: the Office of the Privacy Commissioner of Canada (OPC).
If you access CaterCloud from South Africa, we process personal information in line with POPIA. You may exercise your data-subject rights, including access and correction, and lodge a complaint with the Information Regulator.
Oversight: the Information Regulator (South Africa).