Privacy Policy — Rafters Food Services
Last updated: August 2026
This policy explains what personal information Rafters Food Services collects when you use our app and website, why we use it, who we share it with, how long we keep it, how we protect it, and the rights you have over it.
1. Who is responsible for your information
The data controller is Cafe Le Monde Limited, trading as Rafters Cafe, of Unit 3, Crookstown Business Park, Crookstown, Co. Kildare, R14 ND91, Ireland. Throughout this policy, "we", "us" and "our" mean that company.
Responsibility for your information sits with us and does not transfer to anyone else. We use specialist providers to build, host, operate and monitor the systems the app runs on. Those providers act only as data processors under Article 28 of the GDPR: they work solely on our documented written instructions, are bound by confidentiality and security obligations, may not use your information for their own purposes, may not engage a further sub-processor without our written authorisation, and must return or delete the information when their engagement ends. Where you have a concern about your data, you raise it with us and we answer for it.
Schools tell us which pupils are enrolled for meals and which entitlements apply. Each school is a separate controller for its own pupil records. We are the controller for the account, ordering and payment information created through the app.
For any question about this policy or about your information, contact our privacy contact at info@raftersfoodservices.ie, or write to the address above marked "Data Protection".
2. What this policy covers
This policy applies when you:
- use the Rafters Food Services mobile app;
- visit www.raftersfoodservices.ie or any page that links to this policy;
- order meals, top up a wallet, or take part in our rewards programme; or
- contact us for support, by email, by phone, or through the in-app assistant.
It does not cover other companies' websites or services that you may reach from ours. Those have their own privacy policies.
3. The information we collect
Information you give us
- Identity and contact details: first and last name, email address, phone number, username.
- Account security data: your password, held only as a salted hash, never in readable form.
- School details: the school, school type, class year and teacher relevant to your account.
- Allergen and dietary information, where you choose to record it (see section 4).
- Child profile details, where you order for a child in your care (see section 5).
- Anything you write to us in a support request or in the in-app assistant.
Information created by using the service
- Orders: the items chosen, the day and school they are for, and which profile they were placed under.
- Wallet activity: balance, top-ups, charges and refunds.
- Rolling Order settings and any meal automatically assigned under them.
- Rewards activity: points earned and redeemed, your referral code, and referrals made.
- Support history: the questions you have asked us and our replies.
Information about your device
- A push notification token, if you allow notifications, so messages reach your device.
- Your platform (iOS or Android) and the installed app version, so we can support you and prompt updates.
- Technical error information when something goes wrong, which we keep free of personal data.
Payment information
Card details are entered into and processed by Stripe. We never see or store a full card number, expiry date or security code on our systems. We hold only the result of a payment: the amount, the date, whether it succeeded, and a reference from Stripe.
Avatars
The avatars in the app are illustrations built into the app itself. The one chosen for each profile is stored only on your own device. It is never uploaded to our servers, never shared, and is removed if you delete the app.
Camera
The app asks for camera access only when you choose to scan a QR code. The image is read on your device to decode the QR code. We do not store or transmit it.
What we do not do
- We do not sell your personal information, and we never have.
- We do not buy personal data from data brokers or list vendors.
- We do not use third-party advertising trackers in the app.
- We do not track your location. The app requests no location permission for its own features.
- We do not build advertising or behavioural profiles about you or your children.
4. Allergen and dietary information
We process it on the basis of your explicit consent, given when you choose to record it against a profile. It is used for two purposes only: to filter the menu so unsuitable dishes are not offered, and to tell the kitchen and school staff who prepare and hand over a meal what they must avoid.
It is never used for marketing, never used to price a meal differently, never shared with anyone beyond the people preparing or handing over that meal, and never transferred outside the European Economic Area.
You can withdraw your consent at any time by removing the information from the profile in the app. Withdrawing consent does not affect anything lawfully done before you withdrew it. If you remove allergen information, the menu will stop filtering on it, so please tell the school directly if a serious allergy remains.
5. Children and child profiles
Accounts are held by adults. Parents, guardians, school staff, and students aged 18 or over may register. We do not knowingly allow anyone under 18 to create their own account, and we do not market to children.
We do process information about children, because meals are ordered for them. A parent, guardian, or authorised school staff member creates a child profile containing the child's first and last name, school, class year, teacher, and any allergens recorded for them. This is the minimum needed to prepare the right meal and hand it to the right child safely.
The adult account holder provides that information and controls it. They can view, correct or delete a child profile at any time in the app under Profile, then Child Profiles. Deleting a profile removes the child's details from the account.
Children's information is held to the same standard as the rest, with the allergen protections in section 4 on top. It is not used for marketing, profiling, or any purpose beyond providing meals. If you believe a child's information has been added without proper authority, contact us at info@raftersfoodservices.ie and we will remove it promptly.
6. Why we use your information, and our legal basis
The GDPR requires a lawful basis for every use of personal information. Ours are set out below.
To provide the service — Article 6(1)(b), contract
- Creating and running your account and any child profiles under it.
- Taking, changing, cancelling and fulfilling your orders.
- Operating your wallet, taking payment, and issuing refunds.
- Providing order history, receipts and the order calendar.
- Answering your support requests.
With your consent — Article 6(1)(a), and Article 9(2)(a) for health data
- Recording and acting on allergen and dietary information.
- Sending push notifications to your device.
- Sending marketing messages, where you have opted in.
To meet legal obligations — Article 6(1)(c)
- Keeping transaction and tax records for the period the law requires.
- Responding to lawful requests from authorities.
- Food safety and allergen record-keeping under food law.
For our legitimate interests — Article 6(1)(f)
- Keeping the service secure and preventing fraud and abuse.
- Diagnosing faults and improving how the app works.
- Operating the rewards and referral programme.
Where we rely on legitimate interests, we have weighed our interest against your rights and only proceed where yours are not overridden. You can object to any of it — see section 13. You can withdraw consent at any time, without affecting anything lawfully done beforehand.
7. Automated processing, Rolling Orders and the in-app assistant
We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you within the meaning of Article 22 of the GDPR. We do not profile you, score you, or use your data to train advertising models.
Rolling Orders
If you switch Rolling Orders on, and a day's ordering deadline passes without an order for that child, the system assigns a suitable meal automatically so the child is not left without one. The choice respects the allergens recorded on that profile. It is an optional convenience you turn on and off yourself, it applies a rule you have set rather than an assessment of you, and you can see and query any meal assigned this way in your order history.
The in-app assistant
The in-app assistant is an automated system, not a person. You are talking to software. Questions you type are sent to our servers so an answer can be produced and so we can improve our help content. Please do not type sensitive personal information, payment details or passwords into it. Its answers are general guidance and may be incomplete or out of date; the order details shown in the app and our written replies take precedence. You can always reach a person at info@raftersfoodservices.ie.
8. Who we share your information with
We share only what is necessary, only with those listed below, and only for the purposes given.
- Schools and catering staff: the minimum needed to prepare and hand over the right meal — the pupil's name, class, meal, and recorded allergens.
- Stripe Payments Europe Ltd: to take payments, hold card details, and process refunds.
- Google Ireland Ltd (Firebase): to deliver push notifications and, if you choose it, to verify Google sign-in.
- Apple and Microsoft: only where you choose to sign in using those accounts, to verify who you are.
- Our IT, hosting and support providers: acting as processors under written contract, on our instructions only, to run and monitor the systems.
- Professional advisers: our auditors, accountants, insurers and lawyers, where they need it and are bound by confidentiality.
- Authorities and courts: where the law requires it, or to establish or defend legal claims.
- A buyer or successor: if the business is sold or reorganised, under equivalent protection and with notice to you.
Every provider acting for us is bound by a written contract meeting Article 28 of the GDPR. None of them may use your information for their own purposes. We assess each one before engaging them and review them while they are engaged.
9. Where your information is stored, and transfers abroad
We aim to keep personal information within the European Economic Area. Allergen and dietary information, and child profile details, are not transferred outside the EEA.
Some of the providers listed in section 8 operate globally, so limited information may be processed outside the EEA. Where that happens, we rely on one of the safeguards permitted under Chapter V of the GDPR: an adequacy decision by the European Commission, or the European Commission's Standard Contractual Clauses together with a transfer risk assessment and any additional technical measures that assessment calls for.
You can ask us for a copy of the safeguards that apply to any particular transfer by writing to info@raftersfoodservices.ie.
10. How long we keep your information
We keep information only as long as we need it, then delete it or anonymise it.
- Account and profile details, including child profiles: while your account is open, then deleted within 30 days of closure.
- Allergen and dietary information: while the profile it belongs to exists, or until you remove it, whichever is sooner.
- Order records: for the current and previous school year, to answer queries and disputes.
- Payment and transaction records: six years from the end of the relevant financial year, as tax and company law require.
- Support messages and assistant conversations: 24 months.
- Push notification tokens: until the app is uninstalled, you turn notifications off, or the token stops working.
- Technical and security logs: 90 days, other than where a log is needed for an ongoing investigation.
Where we must keep a record for legal reasons after you close your account, we restrict it so it is used only for that purpose and for nothing else.
11. How we protect your information
Article 32 of the GDPR requires security appropriate to the risk. Because we hold information about children and about allergies, we treat the risk as high and apply the measures below.
Protecting information in transit
- All communication between the app and our servers uses HTTPS with modern TLS.
- The app refuses to send anything over an unencrypted connection: App Transport Security is enforced on iOS and plaintext traffic is blocked on Android.
- The app will not run against a non-HTTPS server address in a released build.
Protecting information at rest and on your device
- Passwords are stored only as salted hashes and cannot be read back by anyone, including us.
- No card numbers are held on our systems at any point.
- App data is excluded from device backups on Android, so it cannot be lifted out of a backup file.
- Released builds of the app write no personal information to the device log.
- Signing in issues a short-lived access token; a failed or expired session signs you out rather than lingering.
Controlling who can see what
- Staff and school access is granted on a least-privilege basis: people see only the records their role requires.
- Catering and school staff see the meal and allergen details needed to serve a pupil, not the account, payment or contact records behind them.
- Access is tied to named individual accounts, reviewed periodically, and revoked promptly when a role ends.
- Everyone with access is bound by confidentiality obligations and is trained in handling personal and allergen data.
Keeping it that way
- Security is reviewed as part of every significant change to the app or its systems.
- Our providers are assessed before engagement and monitored during it.
- We keep backups so that information can be restored if a system fails.
- We maintain a documented procedure for detecting, reporting and investigating security incidents.
No system can be guaranteed completely secure, and we do not claim otherwise. What we commit to is applying measures proportionate to how sensitive this information is, and to reviewing them as the risks change. You can help by using a strong, unique password and keeping your device locked and up to date.
If you believe you have found a security weakness in our app or systems, please report it to info@raftersfoodservices.ie. We will acknowledge your report and investigate it, and we will not pursue anyone who reports a genuine issue to us in good faith.
12. If something goes wrong
If a personal data breach occurs, we will investigate it immediately, contain it, and record what happened.
Where the breach is likely to result in a risk to your rights and freedoms, we will report it to the Data Protection Commission without undue delay and, where feasible, within 72 hours of becoming aware of it, as Article 33 of the GDPR requires. Where it is likely to result in a high risk to you, we will tell you directly and without undue delay under Article 34, in plain language, explaining what happened, what it means for you, what we are doing about it, and what you can do.
13. Your rights
Under the GDPR and the Data Protection Act 2018 you have the following rights over your information:
- Access — to be told whether we hold information about you and to receive a copy of it (Article 15).
- Rectification — to have inaccurate information corrected and incomplete information completed (Article 16).
- Erasure — to have your information deleted where there is no longer a good reason for us to hold it (Article 17).
- Restriction — to have us pause our use of your information while a dispute about it is resolved (Article 18).
- Portability — to receive information you gave us in a structured, commonly used, machine-readable format, and to have it sent to another provider (Article 20).
- Objection — to object to processing based on our legitimate interests, and to object to direct marketing at any time, which we will always honour (Article 21).
- Withdrawal of consent — to withdraw consent at any time, including for allergen information and notifications (Article 7(3)).
- Not to be subject to automated decision-making producing legal or similarly significant effects (Article 22).
How to use them
Much of this you can do yourself in the app: correct your details under Profile, then Edit Profile; manage or delete a child profile under Profile, then Child Profiles; and close your account under Profile, then Delete Account.
For anything else, email info@raftersfoodservices.ie. We will respond within one month. If your request is complex or you have made several, we may extend that by up to two further months, and we will tell you within the first month if we do. There is no charge. We may need to verify who you are before we act, and where you ask about a child profile we may need to confirm your relationship to that child.
14. Cookies, tracking and storage on your device
Our website uses cookies. Cookies that are strictly necessary for the site to work are set automatically. Any others — including analytics — are set only with your consent, which we ask for on your first visit and which you can change at any time. This reflects the ePrivacy Regulations 2011 (S.I. 336/2011) and the Data Protection Commission's guidance on cookies.
The app uses no advertising cookies and no third-party advertising or analytics trackers. It stores your signed-in session, your preferences and your chosen avatars on your own device so the app works between launches. Uninstalling the app removes that storage.
Some browsers offer a Do-Not-Track signal. There is still no agreed standard for how sites should respond to it, so we do not act on it. Our cookie consent controls give you the same choice directly.
15. Marketing
We send marketing messages only where you have opted in, and never on the basis of allergen or child profile information. Every message has an unsubscribe link, and you can opt out at any time in the app or by replying to us. Opting out of marketing does not stop service messages such as order confirmations, deadline reminders and account or security notices, which are part of providing the service.
16. Complaints
If you are unhappy with how we have handled your information, please tell us first at info@raftersfoodservices.ie so we can put it right.
You also have the right to complain to the supervisory authority at any time. In Ireland that is the Data Protection Commission, 6 Pembroke Row, Dublin 2, D02 X963 — www.dataprotection.ie. If you live in another EU or EEA country, you may complain to your local supervisory authority instead.
17. Changes to this policy
We review this policy regularly and update it when the law changes or when we add or change a feature. The date at the top shows the current version. Where a change materially affects how we use your information, we will tell you in the app or by email before it takes effect, and where the law requires it we will ask for your consent again.
18. How to contact us
Cafe Le Monde Limited, trading as Rafters Cafe Unit 3, Crookstown Business Park, Crookstown, Co. Kildare, R14 ND91, Ireland Email: info@raftersfoodservices.ie
For data protection matters, mark your message "Data Protection" so it reaches the right person.