Encrypted connections
Blueroll states that data is encrypted in transit using TLS/SSL and encrypted at rest.
This page summarises how Blueroll protects account and food safety data. It is intentionally specific about the controls we state — and avoids certifications or guarantees we cannot substantiate.
The governing detail is in the Privacy Policy. This overview makes the core safeguards easier to find and evaluate.
Blueroll states that data is encrypted in transit using TLS/SSL and encrypted at rest.
Account authentication is handled with Supabase Auth. Users should keep their sign-in credentials private.
Database row-level security policies are used so authenticated users can access data permitted for their account.
Customer data is stored using Supabase infrastructure hosted on Amazon Web Services. Data may be stored in EU or US regions.
Mobile subscription payments are processed by Apple or Google. Blueroll says it does not receive or store payment card details.
Blueroll says it does not collect precise geolocation or device contacts. It does collect the account, business and operational data needed to provide the service.
These are the retention periods stated in the current Privacy Policy. Legal obligations can require specific records to be kept longer.
Account and service data is retained while the account is active and the subscription is current.
Data is retained for 90 days so the account can be reactivated and records recovered.
Personal data is deleted within 30 days, except where retention is required by law.
Certain food safety records may be retained for up to two years after deletion when required for regulatory compliance.
Avoid shared credentials. Give team members the access they need and remove access when responsibilities change.
Store exported compliance reports according to your own retention policy and legal obligations.
Use screen locks, current operating-system updates and appropriate device controls on phones and tablets used in the kitchen.
If you believe an account or record may have been exposed, contact Blueroll with the affected account and a concise description. Do not email passwords or secret keys.
Email hello@blueroll.app with “Security report” in the subject. Include the affected URL or account, time observed, reproducible steps and potential impact. Please do not access data that is not yours, disrupt the service or publish sensitive details before there has been a reasonable opportunity to investigate.
This page is a product-security overview, not a warranty, certification or substitute for the Privacy Policy and Terms of Use. No method of electronic storage or transmission is completely secure.