Privacy Policy
Last updated 23 August 2026
Draft — not yet reviewed by a lawyer.
This document is a working draft prepared for review. It is not legal advice and has not been checked by a qualified adviser. If you are relying on it for anything, email support@runsheetco.com first.
1. Who we are
Sugarsplashes, of Aussailles Road 1, Fond du Sac, Mauritius, operates Runsheet Co. For anything on this page, write to support@runsheetco.com.
2. Two different kinds of data
This matters, so it comes first.
Your data, as our customer. Your name, your email, your business details, your subscription. We decide how this is used, so we are the controller of it.
Your customers' data, which you put into the app. The people who order flowers or cakes from you: their names, contact details and order history. We hold this only because you asked us to run your order book. You are the controller of it and we are your processor. We act on your instructions, we do not decide what it is used for, and we never market to your customers.
TODO — a Data Processing Addendum covering that second relationship is needed before launch and is not yet in place.
3. What we collect and why
Because you gave it to us
- Account details: your name, email address and password, held hashed and never in readable form.
- Business details: shop name, trade, address, timezone, currency.
- Anything you enter in the app: orders, customers, payments, capacity settings, notes.
- Anything you send us by email or through the contact form.
- Your email address, if you asked to be told about new features. We record what you agreed to and when.
Because using the service creates it
- Sign-in and session records, to keep you logged in and to spot unauthorised access.
- Server logs including IP address, browser and pages requested, used to keep the service running and secure.
- Records of emails sent on your behalf, so both of us can see what went out and when.
What we do not do
- We do not sell your data or your customers' data. Not to anyone, for any price.
- We do not use advertising trackers or third-party advertising cookies.
- We do not build profiles of your customers or market to them.
4. Our legal grounds
- Performance of a contract — running the service you have signed up for.
- Legitimate interests — keeping the service secure, preventing abuse, and improving it. We balance these against your rights.
- Consent — for product update emails, where you ticked a box. You can withdraw it at any time.
- Legal obligation — where we must keep records, for example for tax.
5. Who else touches it
We use a small number of sub-processors, each doing one job. TODO — confirm this list against the deployed stack before launch and keep it accurate thereafter.
- Hosting and database — runs the application and stores its data.
- Paddle.com Market Ltd — merchant of record. Handles checkout, payment, invoicing and sales tax. Card details go to Paddle and their processors, never to us; we never see or store a card number.
- Resend — sends transactional email, including the "your order is ready" message we send to your customers on your behalf.
We will also disclose data where we are legally required to, and to professional advisers where necessary. If the business is ever sold, data may transfer with it, and you would be told before that happened.
6. Where it is stored
Data is stored on servers operated by our hosting provider. Some of our sub-processors operate internationally, which means data may be transferred outside your own country. Where that happens we rely on appropriate safeguards, such as standard contractual clauses. TODO — confirm the hosting region and the specific safeguards before launch.
7. How long we keep it
These are proposals pending a decision. TODO — confirm before launch.
- While your account is active — for as long as you keep using the service.
- After you cancel — 90 days, so you can come back or export, and then deleted. You can ask for immediate deletion instead.
- Billing records — kept as long as tax law requires, typically seven years.
- Server logs — 30 days.
- Marketing list — until you unsubscribe, plus a record that you did.
8. Your rights
Depending on where you live, you may have the right to see the data we hold about you, to correct it, to have it deleted, to restrict or object to how we use it, to get a portable copy, and to withdraw consent.
To use any of these, email support@runsheetco.com. We will respond within 30 days. We will not charge you and we will not make it difficult.
You can export your orders and customers as a spreadsheet yourself at any time, without asking us.
If your data is in the app because a shop put it there, that shop is the controller. Ask them, and if they need us to act, we will act on their instruction.
If you think we have handled your data badly you can complain to your local data protection authority.
9. Cookies
We use a session cookie to keep you signed in and a cookie to protect forms against cross-site request forgery. Both are strictly necessary for the service to work, so no consent banner is required.
We do not use advertising or tracking cookies. TODO — if analytics are added, choose a cookieless provider so this stays true; if a cookie-setting provider is chosen instead, a compliant consent banner becomes mandatory.
10. Security
Traffic is encrypted in transit. Passwords are hashed. Every record in the application belongs to exactly one business, and the code refuses to run a query that has not been told which business it is for — it fails rather than returning data belonging to someone else, and that behaviour is tested.
No system is perfectly secure. If a breach affects your data we will tell you and the relevant authority as the law requires.
11. Children
The service is for businesses and is not directed at children. We do not knowingly collect data from anyone under 16.
12. Changes
If we change this policy in a way that materially affects you, we will email you before it takes effect. The date at the top always shows the current version.