Legal
Privacy Policy
Version 1.1 · Last updated 30 September 2026
This policy explains how Minnie Platform Limited, trading as Minnie ("we", "us"), uses personal information — on our website, when you get in touch or sign up, and when you or your team use the Minnie platform.
1. Who we are
Minnie Platform Limited, trading as Minnie · company number 17473700 · registered office 11 Mulcture Hall Road, Halifax, HX1 1SP.
Contact for anything in this policy: info@minnieplatform.com. ICO registration number: ZC255033.
2. Our two roles — please read this first
When we decide how your information is used, we are the "controller". That covers our website, enquiries, sign-ups, questionnaires, our customer relationships, and the accounts people use to log in to Minnie. This policy explains that use.
When a venue uses Minnie to run its business, the venue is the controller and we are its "processor". That covers information the venue puts into Minnie about its staff (rotas, hours, holidays, onboarding documents), its guests (bookings, enquiries, marketing contacts) and its suppliers. We only use that information on the venue's instructions, under a written data processing agreement. If you are a member of staff or a guest of a venue that uses Minnie, the venue's own privacy notice applies, and you should contact the venue first — we will help them respond to you.
3. What we collect and why
| Who you are | What we collect | Why | Lawful basis |
|---|---|---|---|
| Website visitor | Pages requested and basic technical information (IP address, browser) in our web server's logs | To run, secure and fix the website | Legitimate interests |
| Someone using the website chat assistant | What you type into the chat | To answer your question (see section 6) | Legitimate interests |
| Someone who signs up or enquires | Name, role, email, phone, venue name, type and size, number of sites, the systems you use (till, rota, clock-in), how you heard about us, and your message | To respond, and to assess whether Minnie suits your venue | Steps before a contract, and legitimate interests |
| A prospective customer we send a questionnaire to | Your contact details and your answers about how your venue runs | To assess fit and prepare a proposal | Steps before a contract, and legitimate interests |
| A business we contact about Minnie | Business contact details published by your venue — for example on its website or social media — such as the venue name, a business email address and a social media handle | To introduce Minnie to hospitality businesses that may benefit from it | Legitimate interests (you can opt out at any time — see section 8) |
| A customer contact | Name, job title, work email and phone, billing details (including the bank account used for your Direct Debit), and our correspondence with you, including your configuration pack | To set up and provide Minnie, bill for it and support you | Contract, and legal obligation (tax and accounting records) |
| A Minnie user | Name, email, role, the venues you can access, a securely hashed password, login activity, and which parts of the platform you use and for how long | To give you secure access, protect accounts, provide support, and show your venue's directors how the platform is used | Contract with your employer, and legitimate interests (security and service) |
We do not collect payment card details — card payments in your venue are handled by your till or payment provider, not by Minnie.
We never ask for passwords by form or email.
4. Cookies
Website: our website does not use advertising or analytics cookies.
Platform: when you log in, Minnie sets a single strictly necessary cookie to keep you signed in securely. It cannot be switched off, because the platform cannot work without it. We may also remember simple preferences in your browser (such as which tab you last had open); these stay on your device.
5. Who we share information with
We do not sell personal information. We share it only with:
Service providers who help us run Minnie ("sub-processors"):
| Provider | What they do for us | Where |
|---|---|---|
| Hostinger | Hosts our servers and all live data | United Kingdom (Manchester) |
| Anthropic | AI processing (see section 6), including the website chat assistant | United States |
| OpenRouter | Back-up route to the same AI models, used if the main connection is unavailable | United States |
| Resend | Sends emails from Minnie, such as questionnaire invitations and sign-up confirmations | United States |
| Backblaze | Stores our off-site backups — encrypted by us before they leave our servers, so Backblaze cannot read them | EU (Amsterdam, Netherlands) — a US company |
| GoCardless Ltd | Sets up and collects our customers' Direct Debit payments, and holds the bank details for the mandate | UK |
| Sends and receives email for a venue's own mailbox, only where that venue chooses to connect its Google account | United States |
Others, only where necessary: our professional advisers (such as accountants and solicitors); the police, regulators or courts where the law requires it; and a buyer of our business, who would have to treat your information in line with this policy.
6. How we use AI
Minnie uses AI (Anthropic's Claude models) to help with specific tasks: reading supplier invoices, drafting replies to booking enquiries, writing up meeting minutes, suggesting rotas, summarising end-of-day issues, and answering questions in our website chat.
- We do not use your information to train AI models, and our AI providers' terms do not allow them to use it to train theirs.
- AI suggestions are for people to check. Replies to guests are never sent without a person approving them, and rota suggestions are only suggestions. Minnie does not make decisions about people that have legal or similarly significant effects by automated means alone.
- Meeting recordings are turned into text on our own servers — the audio is not sent to any third party. Only the resulting text is sent to the AI to write up the minutes.
CCTV bar monitoring is an optional add-on that is not generally available. It is only switched on for a venue after a data protection impact assessment, with the venue as controller. It counts drinks served; it does not use facial recognition and does not identify individuals.
7. International transfers
All live data is stored in the United Kingdom. Where a provider in section 5 is outside the UK, we transfer information only with the safeguards UK law requires, such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or the UK–US data bridge where the provider is certified.
8. Our emails about Minnie
If we contact your business about Minnie, every email tells you who we are and how to opt out. Reply "unsubscribe" or email info@minnieplatform.com and we will stop, and keep only the minimum needed to make sure we don't contact you again.
9. How long we keep information
| Information | How long |
|---|---|
| Enquiries, sign-ups and questionnaires where you don't become a customer | 12 months after our last contact, then deleted |
| Prospecting contacts (section 3) | Until you opt out, or 24 months after our last contact |
| Customer and billing records | For the life of the contract, then 6 years for tax and legal purposes |
| User accounts and login activity | While the account is active, then deleted when the venue's contract ends (below) |
| A venue's data in the platform | For the contract, then 30 days so the venue can take a copy, then deleted; encrypted backup copies expire within 12 months |
| Web server logs | 90 days |
10. How we protect information
- All live data is held in the United Kingdom.
- Connections to our website and platform are encrypted (TLS 1.2 or higher).
- Passwords are stored as secure hashes, never in plain text.
- Each venue's data is kept separate, and each person only sees what their role allows.
- Logins and important changes are logged.
- Daily backups are encrypted before they are stored off-site, and we regularly test that they can be restored.
No system is completely secure. If a breach affects your information in a way that puts you at risk, we will tell you, and the ICO where required.
11. Your rights
You have the right to:
- access the personal information we hold about you;
- have it corrected if it is wrong;
- have it deleted, or its use restricted, in some circumstances;
- object to our using it on the basis of legitimate interests — and to stop any direct marketing at any time;
- receive it in a portable format, where the law allows.
Email info@minnieplatform.com to use any of these rights. We will reply within one month. We may need to confirm your identity first.
If the information is held for a venue (section 2), we will pass your request to that venue and help them respond.
Complaints. Please contact us first so we can put things right. You can also complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.
12. Children
Minnie is a business service and is not intended for anyone under 16.
13. Changes to this policy
We will update this policy when how we use information changes. The date at the top shows when it was last changed. If a change significantly affects how we use your information, we will tell customers directly.