Version 1.2 · Last updated [DATE]
Privacy notice
This notice explains how Mise-OS Limited (trading as TrayLora) handles personal data under UK GDPR, the Data Protection Act 2018 and PECR.
Who we are
Mise-OS Limited, trading as TrayLora, company number 17481581, registered office Stable Block, Hursley Park Road, Hursley, SO21 2JN.
ICO registration number: [ICO REGISTRATION NUMBER — to be added once the data protection fee is paid].
Contact: traylora@mise-os.app.
Our two roles
- Bakers' account data: we are the controller of the personal data of bakers who sign up (account, shop, billing and usage details) and of visitors to this website.
- Customers' order data: the baker you order from is the controller of your order details. They decide why and how those details are used for your order. We are their processor and handle the data only on their instructions, under our Data Processing Terms. If you want to exercise your rights over order data, contact the baker first; we will help them respond.
Mise-OS does not sell the food and is not the merchant of record for customer purchases.
What we collect
Bakers: name, email, password (hashed), shop name and details, menu, availability, orders, quotes, payment status, subscription records, and the optional signup answer to "How did you find us?". Subscription card details are handled by Stripe; full card numbers never reach us.
Customers (entered when ordering): name, email, phone number, order details, collection choices, messages, custom-request photos, and allergy or dietary information you choose to provide. Card payments, when offered, are processed by Stripe for the baker; we do not receive your full card number.
Visitors: technical data needed to deliver and secure the site (such as IP address) and anything you type into a form.
Site statistics: our hosting provider, Lovable, counts page visits in aggregate (page viewed, referring site, device type, country derived from IP address, and page-speed measurements). It does not set analytics cookies, store anything in your browser, build profiles or follow you across visits. We use this only to understand and improve how TrayLora works (legitimate interests; statistical purposes under PECR as amended by the Data (Use and Access) Act 2025). You can object at any time by emailing traylora@mise-os.app.
Allergy and dietary information
Allergy and dietary information may be special category health data. The baker asks for it and relies on your explicit consent (the tick box on checkout or a custom request) so they can prepare your order safely. We process this information only on the baker's instructions. We pass it to your baker and keep it visible on your order while it is managed. You can withdraw consent by contacting the baker (or us); withdrawing consent may mean the order cannot proceed. Platform allergen tags are tools only — not a Mise-OS safety verification. Please do not include unrelated health information.
Why we use data and our legal bases
| Use | Basis |
|---|---|
| Baker accounts and providing the service | Contract |
| "How did you find us?" (signup attribution) | Legitimate interests (product improvement / marketing attribution; objectable; not required for the contract) |
| Subscription billing (£6.99/month, no VAT charged at present) and tax records | Contract; legal obligation |
| Service emails via Lovable Emails | Contract; legitimate interests |
| Security and abuse prevention | Legitimate interests |
| Customer order data for a baker | The baker's basis; we process on their instructions |
| Allergy and dietary data | Explicit consent (baker as controller; we process on their instructions) |
| Support requests | Legitimate interests |
The signup attribution answer is non-sensitive. We keep it for the life of the baker account, or a shorter period if we decide. Bakers may object by emailing traylora@mise-os.app.
We do not use your data for marketing unless you tell us you want it, and we do not make decisions about you using automated processing that has legal or similarly significant effects.
Sub-processors / recipients
| Provider | What for |
|---|---|
| Lovable Cloud (Supabase) | Hosting, database, sign-in and file storage — London, UK |
| Stripe | Payments and subscriptions (Stripe also acts as an independent controller for payment data) |
| Lovable (Lovable Emails) | Transactional, order and service emails |
| Google Fonts (if still loaded from Google) | Fonts; Google may receive your IP address when a page loads — we prefer to self-host where practical |
Lovable (visitor analytics): aggregate, cookie-free page-visit statistics for the site owner.
Customer order details are shared with the baker you order from. We do not sell personal data.
International transfers
Primary hosting is in London, UK. Where providers process data outside the UK, we rely on UK adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework where the recipient is certified) or, where those do not apply, the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
How long we keep data
These are our default periods. Bakers can delete their customers' details sooner at any time. If there is a complaint, claim or dispute, we keep the relevant records until it is closed plus 12 months, then the normal period applies.
- Baker account data: while your account is active, then 30 days to allow you to export it, then deleted.
- Trial accounts that never become paid: deleted 90 days after the trial ends.
- Billing and accounting records: 6 years after the end of the accounting period they relate to.
- Records of the terms you accepted (bakers): for the life of your account plus 6 years.
- Customer contact details and order notes: 12 months after the collection date, then erased from the order.
- Allergy and dietary details and the consent record: 12 months after the collection date, then erased.
- Order sales record (items, price, dates and payment status, without name or contact details): 6 years after the end of the tax or accounting year of the sale, so the baker can meet record-keeping and legal-claims needs.
- Support emails: 24 months after the matter is resolved.
- Email delivery logs: 90 days. Security and website technical logs: 12 months.
- Records of data rights requests: 3 years after the request is closed.
- Backups: deleted data drops out of backups within [35 days — CONFIRM WITH HOSTING PROVIDER].
Your rights
You may ask for access, correction, deletion, restriction, objection, or a copy of your data (portability), and withdraw consent where we (or the baker) rely on it. Some rights are limited where records must be kept by law.
- Order data → contact the baker first
- Baker account or site data → traylora@mise-os.app
You can complain to the Information Commissioner's Office at ico.org.uk; we would appreciate the chance to put things right first.
Security
We use appropriate technical and organisational measures, but no online service can promise absolute security.
Cookies
See our Cookie notice. TrayLora uses essential cookies and storage only. We do not use advertising cookies or analytics cookies; aggregate, cookie-free visit statistics are explained above. If that changes, we will update the Cookie notice and obtain PECR consent first where required.
Children
Baker accounts are for adults operating food businesses. Order forms are aimed at adults.
Changes
We will update this notice when things change and show the version and date at the top. Material changes that affect bakers as controllers, or our role as processor, follow the notice rules in the Terms (including sub-processor notice).