Privacy Policy
Effective Date: 1 October 2026
Who We Are
Candour is operated by Sullivan Applications Ltd, a company registered in England and Wales. When this policy refers to "we", "our", or "us", it means Sullivan Applications Ltd.
Candour is a platform that gives restaurants, cafes, pubs, and other food businesses a single QR code linking their customers to a digital menu, Wi-Fi, loyalty stamp cards, and a feedback form - with no app download required for your customers.
This policy explains what data we collect, why we collect it, and how we handle it. We keep it in plain English.
The Two Types of People Who Use Candour
Candour has two distinct groups of users, and we treat their data differently:
- Business owners - restaurants, cafes, pubs, and similar businesses that create a Candour account to manage their profile.
- Customers - members of the public who tap a QR code or NFC stand at a venue. No account or app download is needed.
Data We Collect From Business Owners
Account Information
When you create a Candour account, you sign in with your email address and a password. Some older accounts sign in with Apple instead - for those, we receive your Apple user ID and, if you chose to share it, your email address. While you are setting up, the app may give you a temporary anonymous sign-in so your progress is saved. We also ask you to provide your business name and address to set up your profile.
Enquiries, Demo Requests and Sign-ups
If you request a demo, fill in an enquiry form on candour.app, join the Android waitlist or sign up for Candour, we keep your email address and anything else you give us (such as your name, business name and phone number), your language setting, and where your request came from (for example, which page or ad). We use this so we can reply to you.
Scanner App for Staff Devices
If you use the loyalty stamp card feature, you can install the Candour Scanner app on a staff device - for example, an Android phone or tablet kept at the counter - to stamp customers' loyalty cards. There are two ways to set a device up:
- Sign in - an owner or manager signs in with their Candour account email and password to authorise the device. We use this once to set the device up. We do not keep staff signed in, and the sign-in details are not stored on the device.
- Pairing code - alternatively, you generate a short, single-use code in your dashboard and enter it on the device. No staff login is needed.
Once a device is set up, we issue it a unique device token - a random identifier that authorises that specific device to stamp cards for your business. We store this token, in hashed form, so we can recognise the device and revoke it if needed. The token is tied to the device rather than to any individual member of staff, and it contains no personal information. You can remove a device at any time from your dashboard, which immediately revokes its token.
The scanner reads your customers' loyalty QR codes in order to add stamps. It does not collect any new information about those customers.
Menu Data
If you use the digital menu feature, you can upload photos of your menu or enter menu items manually. These files are stored securely in Google Firebase Storage. If you use our AI menu reader, images or text are sent to Anthropic's API to extract menu items automatically. We do not use your menu data to train AI models.
Wi-Fi Credentials
If you use the Wi-Fi feature, your Wi-Fi network name (SSID) and password are stored in our database so they can be shared with customers who tap your QR code. This data is encrypted at rest.
Loyalty and Customer Analytics
If you use the loyalty stamp card feature, your customers join with their name and email address, and we store their stamp counts and card status. You can see your members in your dashboard, along with aggregate analytics (e.g. total stamps issued, cards completed). See "Data We Collect From Customers" below for what customers give us and how they can delete it.
Subscription and Billing
There are no in-app purchases in Candour. If you are on a paid plan, we set it on your account ourselves, and we store which plan you are on and when it ends.
If you purchase physical products (QR stands) through the Candour shop, in the app or on the web dashboard, payments are processed by Stripe. Stripe handles all payment data in accordance with their own privacy policy. We receive order confirmation and fulfilment details only.
Feedback Received at Your Venue
Feedback submitted by your customers through your Candour profile is stored in our database and made available to you in your dashboard. See the section below on customer data for what is collected from the person submitting feedback.
Data We Collect From Customers
Customers are people who tap a QR code or NFC stand at a venue. We deliberately collect as little data as possible from this group.
- Feedback - if a customer submits feedback, we store the text and any photo they add. No name, email, or account is needed to leave feedback, and feedback is anonymous unless the customer chooses to add their details.
- Contact requests - if a customer asks the venue to get back to them about their feedback, they give a name and a phone number, email address or WhatsApp number. The venue sees these alongside the feedback. If they give an email address, it is also added to that venue's customer list (see below).
- Sentiment check - to decide whether to invite a customer to leave a Google review, we check whether their feedback reads as positive. In the App Clip, this happens on the customer's iPhone using Apple's built-in language tools. On the web page, the feedback text is sent to Google's Cloud Natural Language API. We do not use feedback text to train AI models.
- Google Reviews redirect - if feedback is positive, the customer may be shown a prompt to leave a Google review. Clicking that link takes them to Google, which is governed by Google's own privacy policy. We do not receive any data from Google about whether they completed a review.
- Loyalty cards - to join a venue's loyalty scheme, a customer gives their name and email address. We use these to issue their card as an Apple Wallet or Google Wallet pass, email it to them, and keep their stamps up to date. Their name appears on the pass.
- Wi-Fi - some venues ask for an email address, and optionally a first name, before showing their Wi-Fi details.
- Venue customer lists - email addresses given at a venue (to join its loyalty scheme, to get its Wi-Fi, or with feedback) go on that venue's customer list, with the customer's first name if they gave one and a count of their visits. The venue can see this list in its dashboard. For this list, the venue decides how the details are used, and we hold them on the venue's behalf.
- Marketing emails - a venue can only send marketing emails to customers who ticked the box agreeing to them and then confirmed by clicking the link in the email we send. Customers who have agreed may also choose to give their birthday (day and month only, never the year) for a birthday treat. Every marketing email has an unsubscribe link. When a customer ticks the box, we keep a record of what they agreed to and when, with a scrambled (hashed) copy of their IP address as proof.
- Lawful basis - we rely on the customer's consent for marketing emails, and on providing the service they asked for (a loyalty card, Wi-Fi access, or a reply to their feedback) for everything else.
- Analytics, no advertising - the Candour web page and App Clip that open when a customer taps a QR code use Google Analytics for Firebase to count how they are used (for example, which features are tapped). On the web page, this sends anonymous usage information to Google Analytics without setting cookies. Firebase also keeps an anonymous app installation ID in the browser's storage, and the web page stores a few small settings on the device - for example, whether the customer has already given their email at that venue, so they are not asked again. We do not serve ads to customers or sell their data.
How We Use Your Data
- To create and manage your Candour account and business profile
- To provide the features you have enabled (menu, Wi-Fi, loyalty, feedback, customer list)
- To send customers their loyalty pass, and the marketing emails they agreed to receive from a venue
- To process and confirm your subscription or shop orders
- To provide you with feedback and loyalty analytics in your dashboard
- To improve the reliability and quality of our service
- To contact you about your account or service updates
- To send you one personal email from our founder after you get in touch or sign up, and to reply if you answer it. We don't add you to a marketing list. If you'd rather not hear from us, reply and say so, or email contact@candour.app, and we won't email you again.
- If you reply to our founder email, your message is processed by an AI service (Anthropic) to draft a response. A person reads and edits every draft, and a person sends every reply - nothing is sent automatically. We only do this for messages from people who contacted us or whom we have emailed, and we do it on the basis of our legitimate interest in answering you, the same as for the founder email itself.
We do not sell your data. We do not use your data for advertising.
Third-Party Services We Use
Candour is built on a number of third-party services. Here is what each one does and why we use it:
- Google Firebase - our database (Firestore), file storage, sign-in (Firebase Authentication), and backend infrastructure. Your data is stored on Google Cloud servers, primarily in the EU. Firebase is operated by Google LLC.
- Google Analytics for Firebase and Firebase Crashlytics - usage analytics for the Candour app, App Clip, web dashboard and customer web pages, and crash reports from the Candour app. On candour.app's home page, analytics cookies are only set if you accept cookies.
- Google Cloud - the Cloud Natural Language API checks the sentiment of feedback left on the web page, and the Cloud Vision API checks images uploaded to demo pages for inappropriate content.
- Google Wallet - loyalty cards added to Google Wallet are created through Google's Wallet API, including the customer's name shown on the card.
- Anthropic - we use Anthropic's AI API to parse menu content, to answer your questions about your feedback in the dashboard assistant, to help build demo pages, and to draft our replies when you answer our founder email (a person reviews and sends every reply). Text or images are sent to Anthropic's servers for processing. Anthropic does not retain this data for model training.
- ScrapeCreators - when someone builds a demo page from an Instagram account, we fetch that account's public profile and recent posts through ScrapeCreators.
- Apple - some older accounts sign in with Apple. Apple Wallet passes for loyalty cards are delivered and updated via Apple's infrastructure.
- Stripe - payment processing for physical product orders placed through the Candour shop.
- Sentry - error reports from candour.app and the web dashboard, so we can fix bugs. Reports contain technical details about the error, such as the page and browser.
- Microsoft Clarity - if you accept cookies on candour.app's home page, Clarity records how the page is used (for example, clicks and scrolling).
- Resend - our email delivery provider. We use Resend to send emails from candour.app. It processes the recipient's email address and the content of the email in order to deliver it.
- Google - positive feedback may prompt customers to leave a review on Google. We link to Google Reviews but do not exchange personal data with Google in this flow.
International Data Transfers
Some of our third-party service providers, including Anthropic, are based in the United States. When we send data to these providers for processing (for example, menu images for AI parsing), that data may be transferred to and processed in the US or other countries outside the UK and European Economic Area.
Where such transfers occur, we rely on appropriate safeguards, including standard contractual clauses approved by the UK Information Commissioner's Office (ICO), to ensure your data is protected to a standard equivalent to UK GDPR. By using Candour, you acknowledge that your data may be processed in this way.
Data Retention
We keep your business account data for as long as your account is active. If you close your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or financial compliance purposes.
If you get in touch but don't create an account, we keep your enquiry details for up to 24 months and then delete them. If you ask us not to contact you, we keep only a one-way scrambled copy of your email address (a hash) so we can make sure we don't contact you again.
If you sign up for Candour and later delete your account, we delete the details we noted about your sign-up. If we had already sent you our one founder email, we keep only a one-way scrambled copy of your email address and the fact that the email was sent, so we never send it to you twice.
If you reply to our founder email, we keep a short excerpt of each message in the conversation for up to 90 days, so we have the context to reply, and then delete it automatically.
Feedback and loyalty cards are kept for as long as the venue's account is active, so it can access its history, and are deleted when the venue closes its account. A customer can delete their loyalty card and their details at any time from the link in the email that comes with their loyalty pass, or by asking the venue or us. We then remove their name, email address and birthday, and keep only anonymous visit counts and a record that they withdrew their consent.
If you disable the Wi-Fi feature, your stored Wi-Fi credentials (network name and password) are deleted from our systems immediately. If your account is closed, any stored Wi-Fi credentials are deleted as part of the standard account deletion process.
Your Rights
Whether you run a business on Candour or you are a customer of one, you have the following rights under UK GDPR:
- Access - you can request a copy of the data we hold about you.
- Correction - you can ask us to correct inaccurate data.
- Deletion - you can ask us to delete your account or your details, and associated data.
- Portability - you can request your data in a portable format.
- Objection - you can object to certain types of processing.
To exercise any of these rights, contact us at the email address below. We will respond within 30 days.
Data Security
We take reasonable steps to protect your data, including encryption at rest, secure HTTPS connections, and access controls on our backend systems. No system is completely immune to risk, and we cannot guarantee absolute security, but we take this responsibility seriously.
Children
Candour business accounts are not intended for anyone under the age of 18. Customers must confirm they are 13 or over (18 or over at some venues) before agreeing to marketing emails. We do not knowingly collect data from children under 13.
Changes to This Policy
We may update this policy from time to time. If we make significant changes, we will notify business account holders by email. The effective date at the top of this page will always reflect the most recent version.
Contact Us
If you have any questions about this policy or want to exercise your data rights, please contact us at contact@candour.app.
Sullivan Applications Ltd, United Kingdom.