GetScran
For shop owners

Contents

  1. 1.Who we are
  2. 2.Who is responsible for what
  3. 3.What we collect
  4. 4.Why we use it, and our legal basis
  5. 5.Loyalty and franchise groups
  6. 6.Marketing messages
  • 7.When you ring the shop
  • 8.AI phone assistant
  • 9.Drivers and deliveries
  • 10.AI features
  • 11.Who else sees it
  • 12.Sending data abroad
  • 13.How long we keep it
  • 14.Your rights
  • 15.How to use those rights
  • 16.Children
  • 17.How we keep it safe
  • 18.Complaints
  • 19.Changes to this notice
  • Legal

    Privacy notice

    Last updated 8 September 2026

    What we collect, why we use it, who else sees it, how long we keep it, and the rights you have over it under UK GDPR. Written to be read, not to be survived.

    In short

    • The shop you order from is in charge of your data. We run the system for them. Your GetScran ID — your sign-in, addresses and loyalty card — is ours to look after, and no shop can touch it.
    • We never see your card details. Card payments happen inside our payment provider’s systems; there is nowhere in ours that a card number could sit.
    • Marketing is off until you switch it on, per channel, and “Reply STOP” works instantly.
    • Drivers see your name, address and phone for the day of your delivery, then it disappears — from their app and from what our servers will send it.
    • When you ring a shop we look your number up in that shop’s own customer book so they can greet you. No recording, nothing shared, gone in 24 hours.
    • No AI decides anything about you. AI drafts, forecasts and answers the phone; people decide.
    • You can download or delete everything from your account, in a couple of taps. Orders stay six years for HMRC — with your name taken off them.

    This summary is a courtesy, not the document. Where the two differ, the numbered sections below govern.

    Contents (19 sections)
    1. 1.Who we are
    2. 2.Who is responsible for what
    3. 3.What we collect
    4. 4.Why we use it, and our legal basis
    5. 5.Loyalty and franchise groups
    6. 6.Marketing messages
    7. 7.When you ring the shop
    8. 8.AI phone assistant
    9. 9.Drivers and deliveries
    10. 10.AI features

    1.Who we are, and what this notice covers

    GetScran is a platform for independent UK food and grocery shops — their till, their ordering website, their app, their kitchen screens and their delivery run. It is operated by Aliao Group Limited, a company registered in the United Kingdom, company number [to confirm], registered office [to confirm].

    We are registered with the Information Commissioner's Office under registration number [to confirm].

    This notice covers:

    • getscran.com and everything on it;
    • the ordering website and app of any shop that runs on GetScran;
    • your GetScran ID — the one account that works across every GetScran shop;
    • ordering in a shop at a till or a self-service kiosk;
    • our apps for drivers (ScranDrive) and for shop owners and staff (ScranHub, the till and the kiosk).

    Each shop also publishes its own privacy notice on its ordering site, naming its own company. Where the two cover the same thing, the shop’s notice governs what the shop does and this one governs what we do.

    2.Who is responsible for what

    The law separates the organisation that decides why and how personal data is used (the controller) from one that handles it on the controller’s behalf (the processor). Both roles apply here, and which one we are depends on the data. This is the most important thing on the page, so it is stated plainly:

    Questions?

    Anything on this page — including a request to see, correct or delete your data — goes to privacy@getscran.com. For anything about an order, support@getscran.com reaches a real person, and the shop you ordered from can usually sort it fastest.

    Unhappy with how we handled it? You can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you came to us first, but you never have to.

    The rest of the set

    • Terms of useThe rules for ordering — prices, payment, refunds, allergens, age-restricted items and who your contract is actually with.
    • Cookies & similar technologyEvery cookie and every piece of browser storage this site uses, what each one is for, and how long it lasts.
    • Delete your dataHow to delete your account and the personal data attached to it, what survives for tax, and how long it takes.

    Shop owners are also covered by a separate merchant agreement, which includes the data-processing terms we sign with every shop. Ask us for a copy.

    Aliao Group Limited, a company registered in the United Kingdom, company number [to confirm], registered office [to confirm].

    GetScran

    Order straight from your local shops.

    Built in Scotland

    For shops

    • Run a shop? See GetScran

    Company

    • About
    • Referral
    • Contact

    © 2026 Aliao Group Limited T/A GetScran

    Run a shop?PrivacyTermsCookiesDelete my datasupport@getscran.com
  • 11.Who else sees it
  • 12.Sending data abroad
  • 13.How long we keep it
  • 14.Your rights
  • 15.How to use those rights
  • 16.Children
  • 17.How we keep it safe
  • 18.Complaints
  • 19.Changes to this notice
    • When you order from a shop, that shop is the controller. The shop decides what it sells, how it contacts you, and how long it keeps your details. We hold that data on the shop’s behalf, as its processor, under a written agreement, and only to run the platform for it. We do not sell it, we do not use it to market to you on our own behalf, and we do not share one shop’s customers with another shop.
    • In a franchise group, head office and each branch are joint controllers. A franchise’s customer record is deliberately one shared record across the group, so that your loyalty points and your saved details work at every branch. That makes the franchisor and its branches jointly responsible for it. Either can action a request about it; a single branch cannot delete a group-wide account on its own.
    • For your GetScran ID itself, Aliao Group Limited is the controller. Your sign-in, your name, your saved addresses, your allergen preferences and your loyalty card belong to you and to your relationship with GetScran — not to any one shop. A shop can end its own relationship with you and erase what it holds; it cannot touch your GetScran ID. That boundary is enforced in the software, not just written here.
    • Aliao Group Limited is also the controller for getscran.com itself, for the shop owners and businesses that use the platform, and for its own staff and suppliers.

    3.What we collect, surface by surface

    Different people meet GetScran in different places and give up very different amounts of information. This is the honest list.

    If you order online or in an app with an account. Your name, mobile number and/or email; your delivery addresses (including the map pin you drop); what you ordered, when, from which shop, for how much, and any note you left for the kitchen; your loyalty balance and card number; your marketing choices; your reviews; the device you use, so we can send you order updates.

    If you tell us about allergies. Your saved allergen and dietary preferences are health data — the law treats it as a special category and so do we. You give it voluntarily to keep yourself safe, we use it for nothing else, and you can clear it at any time from your account.

    If you order age-restricted items. Your year of birth — not your full date of birth. That is the minimum that answers the question, so it is all we ask for. If a driver checks ID at the door, we record the fact that ID was checked, never the document.

    If you order at a kiosk or over the counter. Normally nothing — there is no account and no sign-in. If staff park your basket while you wait, they may note the name you gave and any allergy you mentioned, so the kitchen gets it right.

    If you order through WhatsApp. Your WhatsApp number, the branch you picked and where you are up to in the conversation. The messages themselves travel through WhatsApp (Meta) and are subject to their terms as well as ours.

    If you order through Just Eat, Uber Eats or Deliveroo. Those apps are the controller for your account with them. What reaches the shop through us is the order: the name, contact details and address they pass on, and the items.

    If you phone the shop. See sections 7 and 8 — caller recognition and, where the shop uses it, an AI phone assistant.

    If you drive for a shop. Your name, phone, vehicle details, your shifts, your GPS position while you are on shift, the drops you completed, cash you collected and any issues you raised. See section 9.

    If you work in a shop. Your name, role, login, your clock-in and clock-out PIN (stored only as a one-way hash — nobody, including us, can read it back), your shifts, cash-ups, tips allocated to you, and a record of actions like voids and refunds. Your employer is the controller for this; we hold it for them.

    If you run a shop. Your business details — company name and number, VAT number, registered address, contacts, bank and payment-provider identifiers, plan, invoices and payouts.

    If you just visit a website. A count that a page or a product was viewed, and the technical basics any web server sees. See our cookie notice for exactly what is stored on your device.

    We do not use CCTV, we do not profile you for advertising, and we do not buy personal data from anybody.

    4.Why we use it, and our legal basis for doing so

    UK GDPR makes us name a lawful basis for every use. Here they are, in the same words the law uses.

    Purposes and lawful bases
    What we doWhyLawful basis
    Take, price, cook and deliver your orderYou asked us toPerformance of a contract
    Your account, sign-in codes and order historySo you do not retype everything and can find past ordersPerformance of a contract
    Allergen preferencesSo we can warn you before you order something unsafeYour explicit consent (special-category data)
    Loyalty points and rewardsYou joined the schemePerformance of a contract
    Age checks on alcohol, tobacco, vapes and lotteryLicensing law requires itLegal obligation
    Keeping order, payment, VAT and commission recordsHMRC requires six years of accounting recordsLegal obligation
    Marketing texts, emails, push and WhatsApp messagesTo tell you about offers from a shop you have usedYour consent, per channel
    Recognising your number when you ring the shopSo the counter can greet you and pull up your usual addressLegitimate interests
    Fraud prevention, rate limits, security and audit logsTo keep accounts and shop takings safeLegitimate interests, and our security duty
    Counting page and product viewsTo see which menu items people look atLegitimate interests
    Driver location while on shift, and delivery recordsLive tracking, ETAs, proof of delivery, allocating the next dropLegitimate interests of the shop
    AI insights built from a shop’s own daily figuresTo help a shop staff and prep for the day aheadLegitimate interests

    Where we rely on legitimate interests we have weighed our interest against yours, and you can object at any time (section 15). Where we rely on consent you can withdraw it at any time, and withdrawing it never affects anything done before you did.

    5.Loyalty, and sharing inside a franchise group

    Loyalty is per shop, or per group of shops. If you join a franchise’s scheme — a chain with several branches under one brand — your customer record and your points are deliberately shared across every branch of that group, because that is the point of it: earn at one branch, spend at another.

    What that means in practice, said out loud:

    • Staff at any branch of that group can see you as a customer of the group, with your name, contact details and your points.
    • Opting out of marketing at one branch opts you out across the whole group, automatically — it is one record, so there is nothing to miss.
    • The same is true of a deletion request: it is actioned for the group, by head office.
    • Different brands never share. Two unrelated shops on GetScran cannot see each other’s customers, and the database enforces that at the row level, not by us remembering to filter.

    If you delete your account, any remaining points are forfeited — they are a reward, not money, and we cannot pay them out.

    6.Marketing messages, and how to stop them

    Under the Privacy and Electronic Communications Regulations we only send marketing texts, emails, push notifications or WhatsApp messages where you have agreed to that channel. Consent is recorded per channel and is off by default — an account starts with every marketing channel switched off until you turn one on.

    • Text: every marketing text ends with “Reply STOP to opt out.” Replying STOP stops it at the network, immediately.
    • Email: every marketing email carries an unsubscribe link.
    • Push: turn it off in your account, or in your phone’s settings.
    • WhatsApp: reply STOP, or block the number.
    • All of it, in one place:your account’s Marketing & privacy screen. Or tell any shop, or email us — staff can record an opt-out on your behalf, and the system will only ever let them remove a consent that way, never add one.

    Order updates are not marketing. “Your order is being cooked”, “the driver is on the way”, a receipt, or a code to sign in — those are part of the service you asked for and they keep coming while you have an open order.

    One thing we want to be straight about. After you have ordered, a shop may ask you to leave a review, by text or email. Today that ask is not gated on your marketing consent, and it should be. We are changing it so that a review request follows the same opt-out you set for everything else. Until then, replying STOP or telling the shop stops it, and we would rather tell you than let you find out.

    7.When you ring the shop (caller recognition)

    Many shops have a desk phone wired into their till. When it rings, the phone tells the till the caller’s number, and the till looks that number up in that shop’s own customer book so the person answering can say “Hi Sarah — same address?” instead of taking it all down again.

    Precisely what happens, and nothing more:

    • The only thing sent to us is the number that is calling, and only for a shop you have ordered from before.
    • It is matched against that one shop’s customers. Never across shops, never against a national directory, never against anything we bought.
    • No call is recorded. No audio is processed. Nothing is billed.
    • The record that the phone rang is readable for 24 hours and is not kept beyond that.
    • Withhold your number and nothing matches — the call simply comes through as unknown.

    We rely on legitimate interests for this: recognising an existing customer who has chosen to ring a shop they already use is what any good counter does from memory, and it is what you would expect. Tell the shop, or email us, if you would rather it did not.

    8.The AI phone assistant, where a shop uses one

    Some shops let an AI assistant answer the phone when nobody can get to it — it takes the order, answers questions about the menu, and hands over to a person when it is out of its depth. If a shop uses it, you are told at the start of the call that you are speaking to an automated assistant.

    • We do not keep a recording of your voice. The call audio is not stored by us.
    • We keep a written transcript of the call for the shop’s call log, plus the length of the call for billing. The transcript is deleted after 180 days.
    • The assistant can place an order and check the menu. It cannot take a card number and it cannot change your account.
    • You can ask for a person at any point, or hang up and ring back.

    The assistant is provided by ElevenLabs and the phone number by Twilio; both are listed in section 11.

    9.Drivers, delivery tracking, and the day it stops

    What a driver sees about you. For a drop they are carrying: your name, address, phone number and any delivery note. That is how the food reaches your door.

    And when they stop seeing it. Those four things are visible to a driver for the trading day of the delivery only. When the day rolls over they are gone from the driver’s app — and gone from what our servers will send it, so it is not a matter of the app being polite about hiding them. A shift’s worth of doorsteps does not sit in somebody’s personal phone forever. What a driver keeps is the non-personal record they need to check they were paid correctly: the shop, the time, the order code, the amount.

    Driver location. While a driver is on shift the app reports their position, so the shop can see the run and you can see the map. Raw position pings are deleted after 7 days. The position where a delivery was completed is kept for 13 months as the delivery record — and a deletion request from you outranks that.

    If you share your exact location to help a driver find you, that position is yours and is deleted with the rest of the delivery’s location data.

    Third-party couriers. Where a shop uses Stuart, Uber Direct or Deliveroo’s courier network instead of its own driver, your name, address, phone and delivery note are passed to that network so it can make the drop.

    Drivers’ own data. We keep a score for each driver used only to break a tie when allocating the next run and to set how many drops they can hold at once. It is written into our system, in as many words, that it is not a performance record, not evidence in a disciplinary, and that nothing may make pay depend on it — any consequence beyond allocation is a human decision with a written reason. A cash tip handed to a driver at the door is the driver’s own and is never shown to the shop.

    10.AI features, and what they never do

    We use AI in a handful of places. All of them assist a person; none decides anything about you.

    • Menu import. A shop uploads its printed menu and a model reads it into the system. That is menu text, not personal data.
    • Shop insights — a shift brief, a demand forecast and prep plan, a kitchen-timing coach, and a watch on refunds, voids and drawer activity. These read a nightly summary of the shop’s own numbers, not your order history. The staff view is restricted to the owner or a manager and is never available to a shared device.
    • Drafting help — product descriptions and suggested replies to reviews. A person edits and sends them.
    • The phone assistant — section 8.

    We make no solely automated decision that produces a legal effect for you, or anything similarly significant. No AI refuses your order, sets your price, closes your account, decides a refund, or scores you as a customer. Where a score does exist — for drivers — its only permitted effect is allocating the next run, and anything beyond that is a human decision with a written reason. If you ever think an automated step got something wrong, email us and a person will look at it.

    11.Who else sees your data

    The shop you ordered from — always, because they are cooking it.

    Suppliers who work for us. We use specialist companies to run parts of the service. Each is bound by contract to use the data only for what we ask, and may not use it for their own purposes.

    Our sub-processors
    SupplierWhat they do for usWhere
    Fly.ioRuns our serversLondon, UK
    NeonHosts the databaseEU/UK region
    VercelHosts the websitesEU/US
    CloudflareStores menu photos, serves and protects the sitesGlobal network
    Viva Wallet (ScranPay)Takes card payments in shop and onlineEU (Greece), UK
    TwilioSends texts; provides shop phone numbersUS/EU
    ResendSends email — receipts, codes, statementsUS/EU
    AnthropicThe AI behind menu import and shop insightsUS
    ElevenLabsThe AI phone assistantUS
    MetaWhatsApp ordering and messagingUS/EU
    HubRiseBridges orders from delivery appsEU (France)
    Just Eat, Uber Eats, DeliverooSend us orders placed in their appsEU/UK
    Stuart, Uber Direct, DeliverooCourier networks that make the dropEU/UK
    GoogleAddress lookup, maps, delivery route planningUS/EU
    Apple, GoogleHold your loyalty card in Apple/Google WalletUS/EU
    ExpoDelivers push notifications to phonesUS
    XeroAccounting export, for shops that use itUK/NZ
    SunmiTill and kiosk hardwareChina/EU

    Nobody else. We do not sell personal data, we do not share it with advertisers or data brokers, and we do not let one shop see another’s customers. We will disclose data where the law requires it — a court order, a licensing or trading standards request, a tax investigation — or to protect somebody’s safety.

    12.Sending data outside the UK

    Our servers and database are in the UK and the EU. Some of the suppliers above are based in the United States, so a limited amount of data reaches them — for example a phone number to send a text, or the words of a phone call to produce a transcript.

    Where that happens we rely on the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with each supplier’s own technical protections. You can ask us for a copy of the safeguards for any particular supplier.

    13.How long we keep things

    We do not keep things “just in case”. Every table in our database is on a list that either gives it a deletion window or records, in writing, why it is kept — and the build fails if somebody adds a new one and does not decide. These are the windows that matter to you:

    Retention periods
    WhatHow longWhy
    Order, payment, VAT and commission records6 yearsHMRC requires it. Your name and contact details are removed if you ask us to erase you — the money record stays, the identity does not
    Your account, addresses, loyaltyUntil you delete it, or ask us toIt is yours
    AI phone call transcripts180 daysLong enough to settle a dispute about an order
    Caller recognition records24 hoursOnly useful while the phone is ringing
    Raw driver GPS pings7 daysCleared nightly
    Delivered position (proof of delivery)13 monthsDelivery disputes
    Gift card recipient details30 days after the card is sentThey never signed up with us
    Page and product view counts90 days raw, then daily totals onlyAnonymous product interest
    Security and audit logs12 monthsProving who did what, including any deletion you ask for
    Sign-in codes, magic links, sessionsUntil they expireDead the moment they expire
    Tips allocation records3 yearsEmployment (Allocation of Tips) Act 2024

    14.Your rights

    Under UK GDPR you can:

    • Get a copy of the personal data held about you (a subject access request). Your account can produce this itself, as a file, immediately.
    • Correct anything wrong — most of it you can edit in your account.
    • Delete it. See our deletion page for exactly what goes and what must stay for tax.
    • Restrict how we use it while a dispute is sorted out.
    • Take it with you — your export is machine-readable.
    • Object to anything we do on the basis of legitimate interests, including caller recognition and view counting. You can object to direct marketing at any time and we must stop, no questions.
    • Withdraw consent — for marketing, or for holding your allergen preferences — at any time, without affecting anything done before.
    • Not be subject to a solely automated decision with legal or similarly significant effects. We do not make any (section 10).

    All of these are free, and we answer within one calendar month.

    15.How to exercise them

    In your account, immediately:Account → Marketing & privacy. You can download your data, change every marketing choice, and delete your account from that screen without asking anybody.

    By email: privacy@getscran.com, from the address or number on your account where you can. If we cannot tell it is you we will ask one question to check — we are not going to hand your order history to somebody who typed your name.

    Through the shop: where a shop is the controller you can go to the shop or come to us. Either way it gets dealt with; we will not bounce you between us.

    For a franchise group — a chain with several branches — a request about the shared record is actioned by head office, for the whole group at once.

    16.Children

    You must be 16 or over to hold a GetScran account. The service is not designed or marketed for children, and we do not knowingly collect data from a child. If you believe a child has an account, tell us and we will delete it.

    Ordering at a counter or a kiosk creates no account and asks for nothing about you. Age-restricted items are refused to anyone who cannot prove they are 25 or over — see our terms.

    17.How we keep it safe

    • We never see your card. Card payments — online, at the till and on the card machine — are handled inside our payment provider’s PCI-DSS environment. There is no card number, no expiry and no security code anywhere in our system, and no column that could hold one.
    • One shop cannot see another’s data. Separation is enforced by the database itself, on every single query, rather than by application code remembering to filter. It is the difference between a lock and a sign.
    • Data is encrypted in transit. Supplier credentials and integration keys are encrypted at rest with AES-256-GCM in a dedicated store.
    • Passwords and staff PINs are stored only as one-way hashes and are never compared in a way that could leak them.
    • Pulling a customer’s data requires a manager or owner sign-in. A shared counter device can never export somebody’s personal data, however busy the shop is.
    • Every access to, export of, or change to a customer record is written to an audit log — including the deletions we run for you.

    If something does go wrong and it is likely to be a risk to you, we will tell the ICO within 72 hours and tell you without undue delay.

    18.If you are not happy

    Come to us first — privacy@getscran.com — and we will try to put it right.

    You can complain to the Information Commissioner's Office at any time, and you never have to come to us first: ico.org.uk, or 0303 123 1113. Where a shop is the controller, the complaint can be made about the shop, about us, or about both.

    19.Changes to this notice

    When this notice changes we update the “Last updated” date at the top. If a change materially affects how your data is used, we will tell you — by email or in the app — rather than quietly editing the page and hoping you look.