Privacy Policy
Last updated: February 2026
1. Who We Are
HygieneFix is operated by Anthony Johnson. We provide a food hygiene rating check service using publicly available data from the Food Standards Agency (FSA). For data protection enquiries, contact us at privacy@hygienefix.co.uk.
2. What Data We Collect
We collect the following categories of personal data:
Search queries: When you search for a business by postcode or name, we pass your query to the Food Standards Agency API. We do not store your search queries on our servers.
Email addresses: If you voluntarily sign up for our email list or request an action plan, we collect your email address. This is stored securely and used only for the purposes you consented to.
Payment data: If you purchase an action plan, payment is processed by Stripe. We never see, store, or have access to your full card details. See Stripe's privacy policy at stripe.com/privacy.
Analytics data: We use Google Analytics 4 (GA4) via Google Tag Manager to understand how visitors use our site. This collects anonymised usage data including pages visited, time on site, and device type. Analytics cookies are only set after you provide consent via our cookie banner.
3. Lawful Basis for Processing
Under the UK General Data Protection Regulation (UK GDPR), we process your data on the following bases:
Consent: For email marketing and analytics cookies. You may withdraw consent at any time.
Contractual necessity: For processing payment and delivering action plans you have purchased.
Legitimate interest: For basic site functionality and security monitoring.
4. Food Hygiene Rating Data
Food hygiene ratings displayed on this site are sourced from the Food Standards Agency's public API under the Open Government Licence v3.0. This data is publicly available and includes business names, addresses, ratings, and local authority information.
We maintain a database of food establishments rated 0–2 on the Food Hygiene Rating Scheme to provide our service and detect rating changes. This data is refreshed daily from the FSA register. For sole traders operating food businesses, this publicly available data may be associated with an individual and may therefore constitute personal data under UK GDPR. The lawful basis for this processing is legitimate interest in providing a service that helps food businesses improve their hygiene standards.
Establishments that have been rated 3 or above for six or more months are removed from our active database. If you are a sole trader and wish to have your data removed from our database, contact privacy@hygienefix.co.uk.
5. Cookies
Essential cookies: Required for basic site functionality. No consent needed.
Analytics cookies: Google Analytics (GA4) cookies are set only after you accept analytics cookies via our cookie banner. You can reject these and the site will function normally.
You can manage cookie preferences at any time through your browser settings or by clearing your cookies to reset the consent banner.
6. Third-Party Processors
We use the following third-party services that may process your data:
Google Analytics / Google Tag Manager: Usage analytics (USA-based, EU-US Data Privacy Framework certified).
Stripe: Payment processing (USA-based, PCI DSS Level 1 certified).
Vercel: Website hosting (USA-based).
Resend: Transactional email delivery (USA-based).
Supabase: Database hosting for service data (USA-based).
Anthropic: AI processing for action plan generation. Establishment data is sent to Claude for checklist generation. No personal customer data is included in AI requests.
7. Data Retention
Email addresses are retained until you unsubscribe. Payment records are retained for 7 years as required by UK tax law. Analytics data is retained for 14 months (Google Analytics default). Search queries are not stored.
8. Your Rights
Under UK GDPR, you have the right to: access your personal data, rectify inaccurate data, erase your data ("right to be forgotten"), restrict processing, data portability, and object to processing. To exercise any of these rights, contact privacy@hygienefix.co.uk. We will respond within 30 days.
9. Complaints
If you are unhappy with how we handle your data, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
10. Changes to This Policy
We may update this privacy policy from time to time. The "last updated" date at the top of this page indicates the latest revision. Continued use of the site after changes constitutes acceptance of the updated policy.