Who we are
Sovrin is operated by Pulp Potomy Limited, a company registered in England and Wales. We are the data controller for personal information collected through this website, sovrin.restaurant. This policy explains what we collect, why we collect it, and the rights you have under UK data protection law (the UK GDPR and the Data Protection Act 2018) and, if you are in the European Economic Area, the EU GDPR.
This policy covers this website and, further down, what happens if you connect a Google account to Sovrin. When a restaurant uses the Sovrin platform, information about that restaurant’s own customers is handled under our customer agreement with the restaurant, which has its own data protection terms.
The short version
- We only collect what you type into our two forms, plus standard server logs.
- No tracking cookies, no advertising pixels, no analytics scripts.
- We never sell personal information, to anyone, ever.
- You can ask to see or delete what we hold at any time.
What we collect
| Where | What | Why |
|---|---|---|
| The free audit form | Your restaurant’s website domain, restaurant name, area, postcode, and your email address | To run your audit, show you the report, and follow up with you about your results |
| The Book a demo form | Company name, your name, your email address, and optionally a phone number | To reply to you and arrange the demo |
| Server and security logs | IP address, browser type, pages requested | To keep the site secure, fast, and available (handled by our host, Cloudflare) |
When you submit the audit form, your answers are passed to our audit tool at audit.sovrin.restaurant, which stores them in order to build and keep your report.
This website is aimed at businesses. We do not knowingly collect information from anyone under 16.
Cookies
This website sets no cookies and runs no analytics or advertising trackers. Fonts are served from our own domain, not from Google. If any of that changes, we will update this policy first and, where the law requires it, ask for your consent.
Our lawful bases
- Demo requests: taking steps at your request before entering into a contract (Article 6(1)(b)).
- The free audit and follow-up about your results: our legitimate interest in delivering and discussing a report you asked us to run (Article 6(1)(f)). You can tell us to stop at any time and we will, immediately.
- Server and security logs: our legitimate interest in keeping the site safe and working.
- Any further marketing: only where the law allows it, always with a working unsubscribe, honoured instantly.
Who processes it for us
We share personal information only with the service providers who run this site for us, and only so they can do their job:
| Provider | Job |
|---|---|
| Cloudflare | Hosts and delivers the website, provides security logs |
| Resend | Delivers our emails, including demo-request emails |
| Supabase | The database where audit requests are stored |
We may also disclose information where the law requires it. We never sell personal information.
If you connect a Google account to Sovrin
Part of the Sovrin service is looking after a restaurant’s Google Business Profile. If you choose to connect your Google account, permission is granted through Google’s own consent screen, and:
- we access your Google Business Profile data (business details, hours, posts, photos, reviews, and performance insights) through Google’s official APIs, and nothing beyond the scopes you approve
- we use that access for one purpose only: providing the service you asked for, keeping your profile accurate, up to date, and responsive, and reporting the results back to you
- we do not use Google user data for advertising, do not sell it, and do not share it with anyone except the service providers listed above, acting under our instructions
- no human reads your Google user data except with your permission, where needed for security or to comply with the law, or where it has been aggregated for internal operations
- access tokens are stored securely and encrypted, and we keep only the Google data the service needs
- you can disconnect Sovrin at any time at myaccount.google.com/permissions or by contacting us, and we delete the Google user data we hold about you on request
Sovrin’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
International transfers
Some of our providers process data in the United States. Where they do, the transfer is protected by recognised safeguards: the UK extension to the EU-US Data Privacy Framework, or standard contractual clauses approved under UK and EU law.
How long we keep it
We keep audit and enquiry details only while they are relevant to following up with you, and no longer than 24 months after our last contact. If you ask us to delete your information sooner, we will.
Your rights
Under UK and EU data protection law you can ask us to:
- show you the personal information we hold about you (access)
- correct it if it is wrong (rectification)
- delete it (erasure)
- limit how we use it (restriction)
- stop using it, including for any marketing (objection)
- hand it over in a portable format (portability)
- withdraw any consent you have given, at any time, without affecting what happened before you withdrew it
We do not make automated decisions about you that have legal or similarly significant effects.
To use any of these rights, contact us using the details below. We respond within one month. You also have the right to complain to the UK Information Commissioner’s Office at ico.org.uk or, if you are in the EEA, to your local data protection authority.
Contact
For anything in this policy, contact Pulp Potomy Limited via the Book a demo form on our homepage: every message goes straight to the founder, and you can use it for any question or request, not just demos.
Changes to this policy
If we change this policy, the new version appears on this page with an updated date at the top.