Radius Social Limited

Asporti Staff

Last updated 26 August 2026

Asporti Staff Privacy Policy

Asporti Staff is a business application operated by Radius Social Limited ("Radius", "we", "us" or "our"). It allows authorised users at participating businesses to manage products, stock, customer orders, refunds, shop sessions and operational reports.

This Privacy Policy explains how personal information is handled through the Asporti Staff app and the services that support it.

1. Who we are

Asporti Staff is operated by:

Radius Social Limited
Company number: 11310911
Registered office: 27 Old Gloucester Street, London, England, WC1N 3AX
Privacy contact: oh@radiussociallimited.com

Asporti currently operates in the United Kingdom.

2. Our role and the participating business's role

When a customer places an order with a business using Asporti, that business decides why the customer's information is needed and how it is used to prepare and fulfil the order.

For this customer and order information, the participating business is the data controller and Radius processes the information on its behalf in order to provide the Asporti service.

Radius does not use identifiable customer order information for advertising, marketing, customer profiling or other independent purposes.

Radius is separately responsible for information used to operate and protect the Asporti platform itself, including account administration, authentication, service security, technical monitoring and support.

If you are a customer with a question about an order or the personal information associated with it, you should normally contact the business with which you placed the order.

3. Information processed through Asporti Staff

Account and access information

Participating businesses are provided with private Asporti Staff accounts. Accounts cannot currently be created by users through the app.

We process information including:

  • the account username;
  • the associated participating business and store;
  • account identifiers;
  • account status and permissions; and
  • authentication information required to maintain an authorised session.

Passwords are handled through Amazon Cognito. The Asporti Staff app and Asporti application database do not store the account password.

A refresh token is stored securely using the Apple Keychain so an authorised session can be restored.

Customer order information

Staff may be able to view information provided by customers when placing an order, including:

  • customer name;
  • phone number;
  • products ordered;
  • collection time;
  • order status; and
  • optional order notes.

The order notes field allows customers to provide allergies or dietary requirements. Information entered there may in some circumstances reveal information about a person's health.

Radius processes this information only to provide the ordering service to the participating business and does not use it for its own marketing, profiling or advertising purposes.

The participating business is responsible for determining and communicating the lawful basis and, where relevant, the special-category data condition under which it collects and uses this information.

The customer's email address is used by the service to send order and refund confirmations. It is not shown in the Asporti Staff app or included in backup emails sent to the participating business.

Payment and transaction information

Asporti Staff may display or process operational payment information including:

  • order totals;
  • VAT information;
  • discounts;
  • payment status;
  • refund status; and
  • Stripe transaction references.

Customer card details are handled through Stripe's payment services. Full payment card details are not entered into or stored by the Asporti Staff app.

Operational information

The service processes information required to run a participating business's ordering operation, including:

  • products and stock availability;
  • stock movements;
  • shop opening and closing sessions;
  • collection-time availability;
  • order and refund records;
  • financial and operational reports; and
  • email alerts about new orders and completed refunds.

Closed-session reports contain financial and operational information but do not contain customer names, phone numbers or other customer-identifying details.

Business and store information

To set up and operate an ordering service for a participating business, we may process:

  • legal business name;
  • customer-facing address;
  • collection address;
  • customer-service phone number; and
  • customer-service email address.

This information is used to identify the business fulfilling an order, provide customers with accurate collection details and enable customers to contact the business about products, allergens, orders, cancellations or refunds. These details may be shown on the business's Asporti ordering pages, order confirmations, terms and privacy information.

Device and notification information

If notifications are enabled, the service processes information required to send operational push notifications, including:

  • an Apple Push Notification service registration;
  • application environment;
  • registration status; and
  • registration timestamps.

The Asporti application database stores a one-way identifier derived from the notification token and the associated AWS notification endpoint rather than storing the raw APNs token.

Notification messages are designed not to include customer names, phone numbers, order notes or basket contents.

Order and refund email alerts

A participating business may choose an email address to receive a backup alert when a new order is paid or a refund is completed.

These emails may contain an order number, collection time, ordered items and modifiers, total, payment or refund status, and the final three digits of the customer's phone number. They will not contain the customer's name, full phone number, email address, or the contents of order notes, allergy information or dietary requirements.

Staff must use the secure Asporti Staff app to see full customer contact details or preparation notes. The final three phone digits are provided only to help staff match the email to an order. They are not used as a security check.

Technical and security information

We process limited technical information to authenticate users, protect the service, investigate problems and maintain the reliability of Asporti.

This may include:

  • IP address;
  • account identifier;
  • app and device user-agent information;
  • authentication method;
  • request identifiers;
  • timestamps;
  • TLS and connection information; and
  • service and security events.

Amazon Cognito authentication and token-related activity can appear in AWS CloudTrail security records.

Asporti's application APIs do not intentionally log raw customer or staff request bodies, authentication headers or raw source IP addresses.

For customer checkout abuse protection, Asporti uses a keyed representation derived from an IP address rather than storing the raw IP address in the application database.

4. How we use information

Information processed through Asporti is used to:

  • authenticate authorised users;
  • restrict users to the appropriate participating business;
  • receive and manage customer orders;
  • prepare, complete, cancel and refund orders;
  • manage products, stock and collection availability;
  • send order and refund email alerts;
  • produce financial and operational reports;
  • provide and maintain the Asporti service;
  • investigate errors and service failures;
  • prevent misuse and protect accounts and services; and
  • meet applicable contractual, accounting, security or legal obligations.

Where Radius acts as a data controller, we process information where necessary to provide and administer the service and where we have legitimate interests in operating, supporting and securing Asporti. We may also process information where necessary to comply with a legal obligation.

Where Radius acts as a processor for customer and order information, we process that information on the instructions of the participating business.

5. What we do not do

Asporti Staff does not currently:

  • contain advertising;
  • use information for cross-app tracking;
  • sell personal information;
  • use customer information for Radius marketing;
  • create advertising profiles;
  • access the user's contacts;
  • request precise device location;
  • request access to photos;
  • request microphone access; or
  • use advertising identifiers.

We do not currently use third-party analytics or advertising SDKs in the Asporti Staff app.

6. Push notifications

Push notifications are optional and require permission through iOS.

If enabled, Apple Push Notification service and Amazon Web Services process information required to deliver notifications to the device.

Users can disable notifications at any time through iOS Settings. Disabling notifications may mean that new-order alerts are no longer received on that device.

7. Information stored on the device

Asporti Staff stores a refresh token in the Apple Keychain so an authorised session can be restored securely.

Signing out removes the app's active credentials. Access can also be revoked by Radius or the participating business.

Apple Keychain information may in some circumstances remain on a device following deletion and reinstallation of an app until it is removed, replaced or revoked.

The app may also store non-sensitive operational preferences on the device.

Current customer order information is used for display within the app and is not intentionally maintained in a separate permanent local order database.

8. Service providers

Amazon Web Services (AWS)
Used for authentication, application infrastructure, databases, security monitoring, logging, push notifications and sending order and refund emails. The primary Asporti AWS infrastructure is located in the London AWS region.

Apple
Provides the Apple Push Notification service and the iOS platform on which Asporti Staff operates.

Stripe
Processes customer payments and provides payment and refund information required to manage orders.

These providers may process information in accordance with their own contractual, security and legal obligations.

Where personal information is transferred outside the United Kingdom, we use or rely on appropriate safeguards as required by applicable data protection law.

We may also disclose information where required by law, where reasonably necessary to protect the service or its users, or in connection with a properly managed corporate transaction.

9. How long information is retained

We do not retain personal information for longer than it is reasonably needed for the purposes described in this policy.

Current operational retention periods include:

InformationRetention
Customer order recordsApproximately 35 days after creation
Closed-session reportsApproximately 30 days after closure
Asporti application and security logsApproximately 30 days
Records showing whether order and refund emails were sentApproximately 30 days. Asporti does not keep a separate copy of the email after it has been sent
AWS Cognito and CloudTrail security eventsUp to 90 days
Push-notification registrationsApproximately 180 days after the last registration
Customer checkout abuse-protection recordsApproximately one hour after the associated reservation ends
Device refresh tokenUntil sign-out, revocation, replacement or removal
Business account and store informationFor the duration of the business relationship

Some automated database expiry processes are asynchronous, so deletion may occur shortly after a stated expiry time rather than at an exact moment.

Encrypted backups and recovery copies may remain for a limited additional period until the relevant recovery window expires.

If a participating business stops using Asporti or validly requests closure of its service, its remaining store information will normally be deleted within 7 days, except where limited information must be retained for legal, security, dispute-resolution or backup purposes.

Stripe and participating businesses may be required to retain transaction, tax or accounting records for longer periods independently of Asporti's operational retention periods.

Copies of order and refund emails sent to a participating business are kept in that business's email account. They are not automatically deleted when Asporti deletes the related order records. Participating businesses are responsible for deciding how long to keep those emails.

10. Security

We use technical and organisational measures intended to protect information processed through Asporti.

These include encrypted network connections, encryption at rest, managed authentication, store-specific authorisation, restricted cloud permissions, secure device storage and security monitoring.

No electronic service can guarantee absolute security, and our security measures are reviewed as the service develops.

11. Your rights and choices

Depending on the circumstances, UK data protection law may provide rights including the right to:

  • request access to your personal information;
  • ask for inaccurate information to be corrected;
  • request deletion of information;
  • ask us to restrict certain processing;
  • object to certain processing; and
  • request certain information in a portable format.

These rights are subject to applicable legal conditions and exemptions.

Customers

If your information relates to an order placed with a participating business, you should normally contact that business directly. The participating business controls the customer order information and Radius will assist it where necessary to respond to valid privacy requests.

Questions about food, allergens, order fulfilment, refunds or other matters relating to a purchase should also be directed to the business from which the order was placed.

Asporti Staff users

Questions relating to an Asporti Staff account, authentication information or Radius's operation of the platform can be sent to:

oh@radiussociallimited.com

If a participating business stops using Asporti, its account and store information can be removed as described in the retention section above.

You also have the right to complain to the Information Commissioner's Office (ICO) if you are concerned about how your personal information has been handled.

12. Children

Asporti Staff is a workplace application intended for authorised users acting on behalf of participating businesses. It is not directed at children.

13. Changes to this policy

We may update this Privacy Policy when the Asporti service, our data practices or applicable requirements change.

The date at the top of this policy identifies the current version.

14. Contact us

For questions about this Privacy Policy or Radius's processing of personal information, contact:

Radius Social Limited
Company number: 11310911
27 Old Gloucester Street
London
England
WC1N 3AX

Email: oh@radiussociallimited.com