Privacy

Privacy policy for hospitality teams using Yumpit.

This page explains how Yumpit handles the operational and account information that flows through the platform.

Updated April 22, 202611 sections4 min read
01

Who is responsible for your data

Yumpit LLC, a limited liability company formed in the State of Wyoming, United States, registered at 5830 E 2nd St, Ste 7000 #37603, Casper, WY 82609, United States, is responsible for the personal data described in this policy.

Two roles are worth separating. For your account and billing records we are the controller and this policy applies. For the personal data inside your workspace — your staff, your suppliers' contacts — you are the controller and we act on your instructions; the Data Processing Addendum governs that.

Privacy questions, and requests to exercise your rights: privacy@yumpit.com.

02

Who else can see your data

Running Yumpit means relying on a small number of specialist providers — for database hosting, payments, transactional email, error monitoring and analytics. Each receives only what it needs for its purpose.

We publish every one of them, what each can access and where it holds data, at /legal/subprocessors. If a provider is not on that list, it does not have access to your data.

We do not sell personal data, and we do not share it for advertising.

03

What we collect

Yumpit stores the information needed to run the platform, including account details, venue setup, product catalogs, recipe data, purchasing records, and operational stock events.

We may also collect basic technical signals such as browser type, device information, and usage analytics so we can improve performance, reliability, and security.

04

How the data is used

We use your information to provide the service, authenticate access, calculate costs, generate inventory and purchasing insights, and support your team when issues arise.

Operational data may also be used in aggregated and anonymized form to understand product quality, feature adoption, and platform stability.

05

Sharing and protection

We do not sell customer data. Information is shared only with infrastructure, analytics, and support providers that help us operate the service, and only to the extent required for that work.

We apply access controls, audit logging, and environment-level protections designed to reduce unauthorized access and keep sensitive operational data protected.

06

Your choices

You can request updates to account information, ask for a copy of your business data, or request deletion subject to legal, contractual, and security retention requirements.

If you have questions about privacy or data handling, contact the Yumpit team before using the platform for regulated or highly sensitive workflows.

07

Your rights, wherever you are

Whatever country you are in, you can ask us what personal data we hold about you, ask for it to be corrected, ask for a copy, or ask us to delete it. You can also delete your own account from inside the app at any time, on web or mobile.

We answer these requests within one month. If a request is complex we will tell you and explain why. We do not charge for this, and we will never treat you differently for asking.

Requests go to privacy@yumpit.com. We may need to confirm who you are first — not to obstruct you, but because handing someone else's data to the wrong person is the failure this is meant to prevent.

08

If you are in the European Economic Area, the UK or Switzerland

You have the rights of access, rectification, erasure, restriction of processing, data portability, and objection to processing, under the GDPR and UK GDPR.

Our legal bases are: performing our contract with you, where processing is needed to provide the service you signed up for; our legitimate interests in keeping the service secure and improving it; consent, where we ask for it; and legal obligation, where the law requires us to keep records.

You have the right to lodge a complaint with your local supervisory authority. We would rather you came to us first, but that right is yours regardless.

09

If you are in California

Under the CCPA as amended by the CPRA, you have the right to know what personal information is collected and for what purpose, to request deletion, to request correction, and not to be discriminated against for exercising those rights.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. There is therefore nothing for you to opt out of on that front.

We do not knowingly collect sensitive personal information beyond what is needed to run an account, and we do not use it to infer characteristics about you.

10

If you are elsewhere

Morocco's Law 09-08, Brazil's LGPD, Canada's PIPEDA and comparable laws grant similar rights, and we honour them on the same terms set out above rather than asking you to prove which law applies to you.

Where your country requires data to be held locally, tell us before you sign up — our subprocessor list shows where data actually sits, and we would rather be honest about a mismatch upfront than discover it during your audit.

11

Data inside your workspace

One distinction matters if you are an employee rather than an account owner. The records your employer keeps in Yumpit about you — attendance, scheduling, who counted what — belong to your employer, not to us. We hold them on their behalf.

So if you want those corrected or removed, ask your employer. If you contact us instead, we will not act on our own initiative; we will tell them and point you their way, which is what our Data Processing Addendum obliges us to do.