Pricing Book a Demo Start for Free

Solutions for

Independent restaurants Multi-site groups New Franchises Hospitality groups

Benefits

Inspection-ready compliance Consistency across sites Team accountability Time & paper savings Compare food-safety apps

Product

HACCP ChecklistsAllergen MatrixAI Recipe ImportCompliance ReportsDeliveriesDocumentsTeam Management

Free Tools

Free Self-AuditCheck a Hygiene RatingSee all free tools

 

PricingBook a DemoStart for Free
Security & privacy

Your compliance records deserve clear safeguards.

This page summarises how Blueroll protects account and food safety data. It is intentionally specific about the controls we state — and avoids certifications or guarantees we cannot substantiate.

TLS/SSL in transitEncryption at restRow-level access policiesReviewed 20 July 2026
Controls

How data is protected.

The governing detail is in the Privacy Policy. This overview makes the core safeguards easier to find and evaluate.

Transport

Encrypted connections

Blueroll states that data is encrypted in transit using TLS/SSL and encrypted at rest.

Identity

Managed authentication

Account authentication is handled with Supabase Auth. Users should keep their sign-in credentials private.

Access

Row-level policies

Database row-level security policies are used so authenticated users can access data permitted for their account.

Hosting

Supabase on AWS

Customer data is stored using Supabase infrastructure hosted on Amazon Web Services. Data may be stored in EU or US regions.

Payments

No card storage

Mobile subscription payments are processed by Apple or Google. Blueroll says it does not receive or store payment card details.

Minimisation

Limited device access

Blueroll says it does not collect precise geolocation or device contacts. It does collect the account, business and operational data needed to provide the service.

Data lifecycle

Retention and deletion.

These are the retention periods stated in the current Privacy Policy. Legal obligations can require specific records to be kept longer.

While the account is active

Account and service data is retained while the account is active and the subscription is current.

After subscription cancellation

Data is retained for 90 days so the account can be reactivated and records recovered.

After an account-deletion request

Personal data is deleted within 30 days, except where retention is required by law.

Compliance-record exception

Certain food safety records may be retained for up to two years after deletion when required for regulatory compliance.

Responsibility

What customers should do.

Use individual accounts

Avoid shared credentials. Give team members the access they need and remove access when responsibilities change.

Check exported records

Store exported compliance reports according to your own retention policy and legal obligations.

Protect devices

Use screen locks, current operating-system updates and appropriate device controls on phones and tablets used in the kitchen.

Report concerns quickly

If you believe an account or record may have been exposed, contact Blueroll with the affected account and a concise description. Do not email passwords or secret keys.

Report a security issue

Email hello@blueroll.app with “Security report” in the subject. Include the affected URL or account, time observed, reproducible steps and potential impact. Please do not access data that is not yours, disrupt the service or publish sensitive details before there has been a reasonable opportunity to investigate.

This page is a product-security overview, not a warranty, certification or substitute for the Privacy Policy and Terms of Use. No method of electronic storage or transmission is completely secure.