Privacy Policy

Effective Date: 1 October 2026

Who We Are

Candour is operated by Sullivan Applications Ltd, a company registered in England and Wales. When this policy refers to "we", "our", or "us", it means Sullivan Applications Ltd.

Candour is a platform that gives restaurants, cafes, pubs, and other food businesses a single QR code linking their customers to a digital menu, Wi-Fi, loyalty stamp cards, and a feedback form - with no app download required for your customers.

This policy explains what data we collect, why we collect it, and how we handle it. We keep it in plain English.

The Two Types of People Who Use Candour

Candour has two distinct groups of users, and we treat their data differently:

Data We Collect From Business Owners

Account Information

When you create a Candour account, you sign in with your email address and a password. Some older accounts sign in with Apple instead - for those, we receive your Apple user ID and, if you chose to share it, your email address. While you are setting up, the app may give you a temporary anonymous sign-in so your progress is saved. We also ask you to provide your business name and address to set up your profile.

Enquiries, Demo Requests and Sign-ups

If you request a demo, fill in an enquiry form on candour.app, join the Android waitlist or sign up for Candour, we keep your email address and anything else you give us (such as your name, business name and phone number), your language setting, and where your request came from (for example, which page or ad). We use this so we can reply to you.

Scanner App for Staff Devices

If you use the loyalty stamp card feature, you can install the Candour Scanner app on a staff device - for example, an Android phone or tablet kept at the counter - to stamp customers' loyalty cards. There are two ways to set a device up:

Once a device is set up, we issue it a unique device token - a random identifier that authorises that specific device to stamp cards for your business. We store this token, in hashed form, so we can recognise the device and revoke it if needed. The token is tied to the device rather than to any individual member of staff, and it contains no personal information. You can remove a device at any time from your dashboard, which immediately revokes its token.

The scanner reads your customers' loyalty QR codes in order to add stamps. It does not collect any new information about those customers.

Menu Data

If you use the digital menu feature, you can upload photos of your menu or enter menu items manually. These files are stored securely in Google Firebase Storage. If you use our AI menu reader, images or text are sent to Anthropic's API to extract menu items automatically. We do not use your menu data to train AI models.

Wi-Fi Credentials

If you use the Wi-Fi feature, your Wi-Fi network name (SSID) and password are stored in our database so they can be shared with customers who tap your QR code. This data is encrypted at rest.

Loyalty and Customer Analytics

If you use the loyalty stamp card feature, your customers join with their name and email address, and we store their stamp counts and card status. You can see your members in your dashboard, along with aggregate analytics (e.g. total stamps issued, cards completed). See "Data We Collect From Customers" below for what customers give us and how they can delete it.

Subscription and Billing

There are no in-app purchases in Candour. If you are on a paid plan, we set it on your account ourselves, and we store which plan you are on and when it ends.

If you purchase physical products (QR stands) through the Candour shop, in the app or on the web dashboard, payments are processed by Stripe. Stripe handles all payment data in accordance with their own privacy policy. We receive order confirmation and fulfilment details only.

Feedback Received at Your Venue

Feedback submitted by your customers through your Candour profile is stored in our database and made available to you in your dashboard. See the section below on customer data for what is collected from the person submitting feedback.

Data We Collect From Customers

Customers are people who tap a QR code or NFC stand at a venue. We deliberately collect as little data as possible from this group.

How We Use Your Data

We do not sell your data. We do not use your data for advertising.

Third-Party Services We Use

Candour is built on a number of third-party services. Here is what each one does and why we use it:

International Data Transfers

Some of our third-party service providers, including Anthropic, are based in the United States. When we send data to these providers for processing (for example, menu images for AI parsing), that data may be transferred to and processed in the US or other countries outside the UK and European Economic Area.

Where such transfers occur, we rely on appropriate safeguards, including standard contractual clauses approved by the UK Information Commissioner's Office (ICO), to ensure your data is protected to a standard equivalent to UK GDPR. By using Candour, you acknowledge that your data may be processed in this way.

Data Retention

We keep your business account data for as long as your account is active. If you close your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or financial compliance purposes.

If you get in touch but don't create an account, we keep your enquiry details for up to 24 months and then delete them. If you ask us not to contact you, we keep only a one-way scrambled copy of your email address (a hash) so we can make sure we don't contact you again.

If you sign up for Candour and later delete your account, we delete the details we noted about your sign-up. If we had already sent you our one founder email, we keep only a one-way scrambled copy of your email address and the fact that the email was sent, so we never send it to you twice.

If you reply to our founder email, we keep a short excerpt of each message in the conversation for up to 90 days, so we have the context to reply, and then delete it automatically.

Feedback and loyalty cards are kept for as long as the venue's account is active, so it can access its history, and are deleted when the venue closes its account. A customer can delete their loyalty card and their details at any time from the link in the email that comes with their loyalty pass, or by asking the venue or us. We then remove their name, email address and birthday, and keep only anonymous visit counts and a record that they withdrew their consent.

If you disable the Wi-Fi feature, your stored Wi-Fi credentials (network name and password) are deleted from our systems immediately. If your account is closed, any stored Wi-Fi credentials are deleted as part of the standard account deletion process.

Your Rights

Whether you run a business on Candour or you are a customer of one, you have the following rights under UK GDPR:

To exercise any of these rights, contact us at the email address below. We will respond within 30 days.

Data Security

We take reasonable steps to protect your data, including encryption at rest, secure HTTPS connections, and access controls on our backend systems. No system is completely immune to risk, and we cannot guarantee absolute security, but we take this responsibility seriously.

Children

Candour business accounts are not intended for anyone under the age of 18. Customers must confirm they are 13 or over (18 or over at some venues) before agreeing to marketing emails. We do not knowingly collect data from children under 13.

Changes to This Policy

We may update this policy from time to time. If we make significant changes, we will notify business account holders by email. The effective date at the top of this page will always reflect the most recent version.

Contact Us

If you have any questions about this policy or want to exercise your data rights, please contact us at contact@candour.app.

Sullivan Applications Ltd, United Kingdom.