Privacy Policy
Last updated: 6 October 2026
This policy explains how IT Nest Limited ("IT Nest", "we", "us") handles personal data when you visit staffchecklist.com, use the Staff Checklist app at app.staffchecklist.com, or contact us.
1. Who we are
Staff Checklist is operated by IT Nest Limited, a company registered in Hong Kong (Business Registration Number 77297048), Office 3906, 39/F, The Center, 99 Queen's Road Central, Central, Hong Kong.
- Privacy questions and requests: privacy@staffchecklist.com
- Everything else: support@staffchecklist.com
Requests under the Hong Kong Personal Data (Privacy) Ordinance can be sent to our Privacy Officer at privacy@staffchecklist.com or at the postal address above.
2. Two roles: when your employer decides and when we decide
Records inside a business account. When a business, such as a restaurant or hotel, uses Staff Checklist, it decides what its team records: checklists, temperatures, notes, photos and so on. For this data the business is the controller and we are its processor. We handle it only on the business's instructions, under our Data Processing Addendum. If you work for one of our customers, your employer's privacy notice explains how it uses your work records, and requests about them should go to your employer first. We help them respond.
Everything else. We are the controller for our website, accounts and sign-in, billing, security, product analytics, support and marketing. The rest of this policy covers that.
3. What we collect, why, and for how long
| Purpose | Personal data | Lawful basis | How long we keep it |
|---|---|---|---|
| Create your account and sign you in | Email address, name, optional phone number and photo, language, time zone; sign-in codes (stored hashed, valid 15 minutes); session records (device name, browser, hashed IP address) | Contract with you (business owners). For staff accounts: our legitimate interest in providing the service your employer chose | While your account exists. Sessions end after 60 days at most |
| Billing (business owners) | Business name and address, billing contact, plan, invoices and payment status. Card details are handled by Stripe, not by us | Contract; legal obligation (tax and accounting) | 7 years after the transaction (invoices are kept in Stripe) |
| Keep the service secure and prevent abuse | IP address, device and browser details, sign-in attempts, rate-limit records, bot-check results (Cloudflare Turnstile), account events in the audit log | Legitimate interests: protecting users and the service | Security logs up to 90 days. Audit events stay with the business's records |
| Product analytics and error reports | Pages and features used, device type, app version and errors, linked to a random account ID, never to your name or email. Screen recordings of owner and manager screens with all text, inputs and images hidden. We don't record staff or shared-tablet screens | In the UK: legitimate interests, with notice and an easy opt-out. Elsewhere: only with your consent | Events up to 1 year. Recordings 30 days |
| Service emails and notifications | Email address, push subscription for your device, the message (for example "Opening checks are overdue") | Contract; legitimate interests | Until you turn them off or remove the device |
| Early access and pilot emails | Email, name, business name and type, number of locations, interest in a pilot | Consent, which you can withdraw at any time | Until you unsubscribe, or 12 months after our last email to you |
| Support | What you send us and our replies | Legitimate interests: helping you | Normally up to 3 years after the conversation ends |
| Legal claims and compliance | Records needed to establish or defend legal claims or meet legal duties | Legitimate interests; legal obligation | As long as needed for that purpose |
A business that invites you gives us your name, email address and role. Email is required; the other profile fields are optional.
Your right to object. You can object at any time to processing based on our legitimate interests. To stop analytics, turn off "Share usage data" in Settings > Privacy and data, or email us. To stop marketing emails, use the unsubscribe link in any email.
4. Our website
staffchecklist.com sets no cookies and stores nothing on your device. We count visits and clicks on the website with PostHog in cookieless mode, hosted in the EU. PostHog uses your IP address and browser details to make a code that changes every day; your IP address is not stored, so we can't recognise you from one day to the next, and the counts are never linked to your name or email address. We rely on our legitimate interest in knowing which pages help people. If your browser sends a Global Privacy Control or Do Not Track signal, we don't count your visit. You can also object by emailing privacy@staffchecklist.com. Website events are kept for up to 1 year. If you join early access, we use what you enter in the form as described in section 3.
5. AI features
Some features use AI: drafting a checklist from your text, photo or file (Anthropic), translating checklist text (DeepL) and turning voice notes into text (Deepgram). They run only when someone in a business uses them, and a business owner can turn them off. We set up these providers so that data sent to them is not used to train their models. AI results can be wrong, so a person should check them before relying on them. We don't make decisions about anyone based solely on automated processing that have legal or similarly significant effects.
6. Who we share data with
- Service providers that host and run Staff Checklist for us. They are listed with their location and purpose on our Sub-processors page.
- Push services. Notifications travel encrypted through the push service of your browser's maker (Apple, Google, Mozilla or Microsoft).
- Stripe processes payments and acts as an independent controller for payment data.
- Food Standards Agency. To show a business's public food hygiene rating we send the business name and postcode to the FSA's open data service. No personal data is sent.
- When the law requires it, to protect rights and safety, or to a buyer if our business is sold, who must keep the protections in this policy.
We don't sell personal data.
7. International transfers
IT Nest is based in Hong Kong, and some of our providers are in the United States or elsewhere. Staff Checklist runs on Cloudflare's global network, so data may be processed in the UK, the EU, the US and other countries, and our team may access data from outside the UK and the EU. Where UK or EU law requires safeguards for these transfers, we use the European Commission's standard contractual clauses with the UK International Data Transfer Addendum, or an adequacy decision such as the EU-US Data Privacy Framework and its UK Extension where the provider is certified. Email privacy@staffchecklist.com for a copy of the safeguards that apply.
8. How we protect data
Connections are encrypted, and our hosting provider encrypts stored data. Sign-in uses one-time codes and links instead of passwords, and we store codes, session tokens and kiosk PINs only in hashed form. Sign-in is protected by rate limits and bot checks. Every request is limited to the business it belongs to, permissions follow each person's role, and each business has an audit log of changes. Only IT Nest personnel who need it can access production systems. Backups are kept for 30 days. No system is perfectly secure; if a breach affects you, we will tell you and the authorities as the law requires.
9. How long business records are kept
Records inside a business account are kept as the business chooses in its settings (for example 2 years or 5 years). They are deleted 30 days after the business closes its account. A Free account with no sign-ins for 12 months is deleted 30 days after we email the owner. Backups are overwritten within a further 30 days.
Deleting your account. In Settings > Privacy and data you can delete your account. We then remove your sign-in identity and profile straight away: your email address, profile name and photo, sessions and devices. Work you recorded for a business stays in that business's records, including your name as it appears there, because those records belong to the business. Ask the business if you want them changed. Business owners must close their business before deleting their account.
10. Your rights
You can ask to access, correct, delete or move your personal data, to restrict or object to its use, and to withdraw consent at any time. You can download your data and delete your account in the app (Settings > Privacy and data), or email privacy@staffchecklist.com. We reply within one month (or 40 days for requests under Hong Kong law) and may ask you to confirm who you are. For your work records, contact your employer first; we will help them.
11. Complaints
Please tell us first at privacy@staffchecklist.com. We acknowledge complaints within 30 days and tell you the outcome. You can also complain to the UK Information Commissioner's Office (ico.org.uk), to the data protection authority where you live or work in the EU, or to Hong Kong's Privacy Commissioner for Personal Data (pcpd.org.hk).
12. Age
Staff Checklist is a work tool for people aged 16 or over. Businesses must not invite anyone younger. If you believe someone under 16 has an account, tell us and we will delete it.
13. Direct marketing (Hong Kong)
We intend to use your name and email address to send you emails about Staff Checklist early access and pilots, but only with your consent. You can withdraw consent at any time, free of charge, by using the unsubscribe link or emailing privacy@staffchecklist.com.
14. Changes to this policy
We post updates on this page with a new date. Before significant changes take effect, we tell account holders by email or in the app.
Related: Cookies · Terms of Service · Data Processing Addendum · Sub-processors