Privacy notice
Last updated 16 September 2026
Who we are
Hospitality Kit is run by Disruptality Ltd, a company registered in England and Wales (company number [COMPANY NUMBER]), registered office [REGISTERED OFFICE]. In this notice, “we” and “us” mean Disruptality Ltd.
We are the data controller for the personal data described here. If you have a question about any of it, email [CONTACT EMAIL].
The short version
We hold the details you give us to run your account, and we record which tools get used so we know what to build next. Photographs, artwork and PDFs you put into the tools are worked on inside your own browser and are not uploaded to us at all — with two exceptions, the reference image in the Image Studio and flipbooks you choose to publish, both explained below. We do not sell your data, and we do not share it with anyone except the suppliers who help us run the service.
What we collect, and why
- Your account
- Your name, email address and password (stored only as a cryptographic hash — we never see it). We need this to give you an account at all, so the lawful basis is performance of our contract with you.
- Your venue
- The name, type and town of each venue you set up, and who else you invite to it. Same basis: it is the service.
- What you make
- Campaigns, image templates, QR codes, saved campaign P&Ls and similar. This is your business content rather than personal data, but it can contain personal data if you put some in.
- How the tools get used
- When a tool is opened or run we record which tool, which venue, when, and a small amount of context — for example the format an image was converted to. We use this to see what is worth building and what is broken. The lawful basis is our legitimate interest in improving the product; you can object at any time.
- QR code scans
- When somebody scans one of your dynamic QR codes we record the time, the broad device type (mobile, tablet or desktop) and the country. We do not record IP addresses, and we do not set a cookie on the person scanning. It is deliberately too coarse to identify anybody.
- Cookies and analytics
- Only if you agree. See the cookies section below.
- Support messages
- If you email us, we keep the message and our reply so we can pick up where we left off.
Files you put into the tools
The image converter, the PDF tools and the artwork rendering in the Image Studio all run inside your browser. The file is opened, worked on and saved back on your own computer. It is never sent to us, so there is nothing on a server for us to keep, lose or be asked to hand over. Closing the tab is all it takes to be rid of it.
The first exception is the Image Studio’s “build a template from a poster” feature. That sends a reduced-size copy of the image you upload to Google’s Gemini API, which reads the layout and sends back where the text sits. We use a paid Gemini account, under terms where Google does not use what we send to train their models and does not have people read it. The image is used for that one request and is not stored by us. If you would rather it never left your machine, build the template by hand instead — the rest of the studio does not use it.
Published flipbooks are the other exception. Making a flipbook, and downloading it, happens in your browser like everything else. If you press Publish, each page is uploaded to us as an image — not the PDF itself — so it can be shown at its link and on any website you embed it on. Anybody with the link can see those pages. They stay until you delete the flipbook, and deleting it removes the images too.
Who else sees it
We use a small number of suppliers to run the service. They process data on our instructions and cannot use it for their own purposes.
- Supabase
- Our database and sign-in. Your account and content are stored in their London (eu-west-2) region.
- Vercel
- Hosting. Requests to the site pass through their network, which is worldwide.
- Tag Manager and Analytics, if you accept cookies. Gemini, for the Image Studio feature described above.
Google and Vercel are based in the United States. Where data reaches them, it is transferred under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses. We will update this list before we add anyone new — a payment provider and an email provider are both expected.
We will also disclose data where the law requires it, or to establish or defend a legal claim. We do not sell personal data, and we never have.
Prize games run by a venue
Venues using Hospitality Kit can run prize games — a wheel, a scratch card or an instant win — that guests play from a QR code. If you play one, this is what happens to your information.
- What is collected
- Only what the venue has chosen to ask for: any of your name, date of birth, mobile number and email address, and whether you ticked the box agreeing to hear from them. Some games ask for nothing at all. We also record the play itself — when, and what you won — which on its own does not identify you.
- Who is responsible for it
- The venue is the data controller: it decides what to ask for and what to do with it, and its own privacy policy applies (the game page links to it when the venue has given us one). Hospitality Kit is a data processor, storing and handling it on the venue's instructions.
- Marketing
- The tick box is your consent to the venue contacting you, not us. We never use guests' details to contact them ourselves. Some venues make ticking the box a condition of entering a game; where they do, the game page says so before you play.
- Where and for how long
- In our database, hosted by Supabase in London, encrypted at rest. Details are kept for the period the venue sets for that game — between one and thirty-six months — and then deleted automatically. The venue can download them for its own records, and can delete them at any time.
- Age
- A game can set a minimum age. If you are under it, you cannot play and nothing you entered is kept.
- Being forgotten
- Ask the venue that ran the game — it can find and delete your details in seconds. Or email us and we will pass the request to them and make sure it is done.
Cookies
Nothing that identifies you is set until you say yes. When you first arrive, analytics and advertising storage are switched off, and stay off unless you accept. We use Google Tag Manager and Google Analytics to count how the site is used.
The cookies we cannot avoid are the ones that keep you signed in and protect the site from abuse. Those are strictly necessary, so they do not need consent — but they also do nothing except run the service.
On a venue’s prize game page (addresses starting /g/) we set one more: bb_play, a random id kept for a year. It is what holds each phone to the game’s play limit. We store only a scrambled (hashed) version of it against a play, never the id itself, and it is not linked to an account, an IP address or anything else about the phone.
How long we keep it
- Your account and content: while your account is open, and for 30 days after you close it, so an accidental deletion can be undone.
- Usage records: two years, then deleted.
- QR scan records: two years, so you can compare a campaign against last year's.
- Emails to support: two years from the last message.
- Anything we have to keep for tax or accounting: six years, as the law requires.
Your rights
Under UK data protection law you can ask us for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict what we do with it, object to processing we do on the basis of legitimate interests, and ask for a portable copy. There is no charge, and we will answer within one month.
Email [CONTACT EMAIL] to exercise any of them. If you think we have got it wrong, please tell us first so we can put it right — but you can also complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113.
Security
Traffic is encrypted in transit, data is encrypted at rest, and access to the database is restricted at row level so one venue’s account cannot read another’s. Passwords are hashed, never stored. No system is perfect; if there is ever a breach that puts you at risk we will tell you and the ICO within 72 hours of finding out.
Children
Hospitality Kit is a tool for licensed trade businesses and is not intended for anyone under 18. We do not knowingly collect data about children.
Changes
If we change this notice we will update the date at the top, and for anything significant we will email account holders before it takes effect.
Our terms sit alongside this notice.