Privacy Policy
Last updated: 28 August 2026
BossOps provides hospitality operations software for supplier costs, recipes, rotas, attendance, HR records and related business workflows. This policy explains the information processed through BossOps and the controls available to customers and users.
Who is responsible for the data?
For account administration, product support and billing information, BossOps acts as the data controller. When a hospitality business uses BossOps to manage its employees, workers, suppliers or operational records, that business will normally be the controller of that information and BossOps processes it on the business's behalf.
Information we process
- Account information such as name, business name, email address, role and authentication records.
- Supplier, product, invoice, recipe, menu, stock and purchasing records.
- Employee information such as contact details, employment details, wages, rota, leave, availability, clocking and payroll-related records.
- HR documents, induction, training, performance and health-check records entered by an authorised customer.
- Location verification and optional clocking photographs where a customer enables those attendance controls.
- Photos and files deliberately selected for invoice, recipe, employee-document or attendance workflows.
- Security, audit, diagnostic and usage information required to operate and protect the service.
- Billing identifiers and subscription status. Card details are processed by Stripe and are not stored by BossOps.
How information is used
Information is used to provide the service, authenticate users, store customer records, calculate costs and margins, process approved uploads, operate workforce features, produce exports, administer subscriptions, prevent abuse, troubleshoot the service and respond to support requests.
Invoice and recipe extraction can use automated document processing. Extracted data is presented for human review before it should be relied upon as an approved operational record.
Camera, photos and location
Camera access is requested only when a user chooses a camera-based workflow. Location access may be requested when an authorised customer enables location verification for clocking. Optional attendance photos are tied to the relevant attendance record. These controls should only be enabled by customers where they have a lawful and proportionate basis for using them.
Service providers
BossOps may use service providers for cloud hosting and storage, payment processing, email or messaging delivery and document processing. Access is limited to what is needed to provide the relevant service. Customer data is not sold to advertisers.
Security
BossOps uses account-scoped access controls, role permissions, encrypted HTTPS connections, secure session cookies and cloud-hosted storage. No online service can promise absolute security, so customers should also protect administrator accounts and restrict access appropriately.
Retention and deletion
Operational records are retained while required to provide an active customer account and for reasonable backup, security and billing purposes. Customers can request export or deletion of their workspace data, subject to legal or security retention requirements. Employers remain responsible for deciding appropriate retention periods for employee records they place in BossOps.
Your rights
Depending on the circumstances, UK data-protection law may provide rights to access, correct, delete, restrict or obtain a copy of personal information, and to object to certain processing. Employees whose information is controlled by their employer should normally raise a request with that employer first.
Contact
Privacy and data requests: [email protected]
Website: boss-ops.co.uk