US privacy · TDPSA
PassReady — Privacy Policy (United States)
Who we are
PassReady is operated by Resilient Platforms Ltd, a company registered in England and Wales (Companies House number: 17196249).
PassReady is a food safety compliance tool designed to help food business owners in the United States prepare for health inspections. We help you organise your food safety records, practice for inspections, and understand the rules that apply to your business.
- Website: passready.us
- Privacy contact: privacy@passready.us
- Postal address: 66 Paul Street, London, England, EC2A 4NA
What information we collect
Information you give us directly
| Category | Examples |
|---|---|
| Account information | Name, email address, password (hashed — we never store plain text passwords) |
| Business information | Business name, business address, type of food establishment |
| Food safety records | Self-audit responses, temperature logs, staff training records, allergen information, illness reports |
| Subscription information | Subscription plan, billing address — card details are handled by Stripe and never stored by PassReady |
Information we collect automatically
| Category | Examples |
|---|---|
| Usage data | Which features you use, how often you log in, pages visited within the app |
| Device and technical data | IP address, browser type, operating system, device type |
| Session data | Login timestamps, session duration |
Information we do not collect
- We do not collect Social Security numbers or government IDs
- We do not collect health or medical information about you personally
- We do not collect information about children
- We do not build advertising profiles or track you across other websites
How we use your information
We do not sell your personal information to third parties for money.
We use Google Analytics and Google Ads cookies on our public marketing pages to measure how people find us and whether our advertising works. You can switch these off at any time using the "Cookie settings" link in the footer of any page.
| Purpose | Legal basis | Examples |
|---|---|---|
| Providing the service | Contract | Running your account, processing your food safety records, displaying your audit scores |
| Payments | Contract | Processing your subscription via Stripe |
| Customer support | Contract / Legitimate interests | Responding to questions and resolving problems |
| Security | Legitimate interests | Detecting fraud, protecting accounts, preventing abuse |
| Service improvement | Legitimate interests | Understanding which features are used, fixing bugs, improving the app |
| Website analytics | Consent | Seeing which pages visitors read and where they leave, so we can improve them |
| Advertising measurement | Consent | Measuring whether our adverts lead to trial signups |
| Legal compliance | Legal obligation | Responding to lawful requests from authorities |
Google API Services User Data Policy Disclosure
1. Data Accessed
Our application accesses and interacts with specific Google user data via Google API Services to facilitate automated outreach tracking and service functionality. Specifically, we access:
- Your Google User Profile information (such as name and email address) for user authentication and identification.
- Limited email transmission metadata required to securely route outreach emails through authenticated channels when initiated by the user.
2. Data Usage and Purpose
The Google user data accessed by our application is processed strictly for the purpose of managing and executing user-initiated B2B outreach campaigns, tracking response metrics within your secure dashboard, and maintaining application logs. We do not use this data for any marketing or advertising purposes.
3. Data Storage and Retention
Google user data is stored securely using industry-standard encryption protocols. We only retain authentication tokens and relevant metadata for as long as your account remains active or as required to fulfill the operational tracking services provided by our platform. Users may revoke access at any time via their Google Security Settings.
4. Data Sharing and Transfer
PassReady does not sell, lease, or share Google user data with third parties. Your data is never transferred to external platforms or used to train artificial intelligence or machine learning models. Data transmission is restricted entirely to fulfilling the core operational functionality of the PassReady application as explicitly authorized by the user.
Where your data is stored
PassReady's application servers are located in the United States (Oregon, US West). Your data may also be processed in the European Union via our database provider. By using PassReady, you consent to your data being transferred to and processed in these locations.
Your rights under Texas law
If you are a Texas resident, the Texas Data Privacy and Security Act (TDPSA) gives you the following rights. You can exercise any of these rights by emailing privacy@passready.us or using the form at passready.us/privacy-request (US users only).
How we respond: We will acknowledge your request within 5 business days and complete it within 45 days. If we need more time, we will let you know and explain why (we can extend by a further 45 days in complex cases).
| Right | What it means |
|---|---|
| Access | You can ask us to confirm whether we process your personal data and receive a copy of it |
| Correction | You can ask us to correct inaccurate personal data we hold about you |
| Deletion | You can ask us to delete your personal data |
| Portability | You can ask for a copy of your data in a format you can take to another service |
| Opt out of sale | You can opt out of the sale of your personal data — note: we do not currently sell personal data |
| Opt out of targeted advertising | You can opt out of targeted advertising — note: we do not currently conduct targeted advertising |
| Opt out of profiling | You can opt out of profiling that produces legal or significant effects on you — note: PassReady does not conduct this type of profiling |
| Non-discrimination | We will not discriminate against you for exercising any of your privacy rights |
| Appeal | If we decline to act on your request, you may appeal by replying to our response email. If your appeal is denied, you may contact the Texas Attorney General |
Do Not Sell or Share My Personal Information
We do not sell your personal information for money.
We do use Google Analytics and Google Ads cookies on our public marketing pages. Under some US state privacy laws, including the California Consumer Privacy Act as amended, advertising cookies of this kind may count as “sharing” personal information for cross-context behavioural advertising.
The fastest way to opt out is the "Cookie settings" link in the footer of any page, which switches analytics and advertising cookies off immediately. You can also record a formal opt-out preference:
- Email: privacy@passready.us with the subject line "Do Not Sell — Opt Out"
- In-app: Go to Account Settings → Privacy → Do Not Sell
- Your opt-out will be recorded and we will confirm it within 5 business days.
Do Not Sell My Personal Information
We do not sell your personal information. You can formally record your opt-out preference using the button below.
To record your preference, please sign in or email privacy@passready.us with the subject line "Do Not Sell — Opt Out".
Data retention
When you delete your account, we delete or anonymise all personal data within 30 days, except where we are legally required to retain it (e.g. payment records).
| Data type | How long we keep it |
|---|---|
| Active account data | For as long as your account is active |
| Food safety records | For the duration of your subscription, plus 90 days after cancellation |
| Payment records | 7 years (legal/tax requirement) |
| Usage logs | 12 months rolling |
| Deleted account data | Purged within 30 days of account deletion request |
Security
We protect your data using:
- Encrypted connections (HTTPS/TLS) for all data in transit
- Encrypted database storage at rest
- Password hashing (bcrypt — your plain-text password is never stored)
- Access controls limiting which staff can access production data
- Regular security reviews
No system is 100% secure. If you believe your account has been compromised, contact us immediately at privacy@passready.us.
Children
PassReady is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has created an account, contact us at privacy@passready.us and we will delete it.
Changes to this policy
If we make material changes to this policy, we will notify you by email at least 30 days before the changes take effect. For minor changes (such as correcting a typo or updating contact details), we will update the "Last updated" date at the top of this page.
How to contact us
For privacy requests (access, deletion, correction, opt-out)
- Email: privacy@passready.us
- Subject line: "Privacy Request — [your name and account email]"
- Response time: 5 business days to acknowledge, 45 days to complete
For general enquiries
- Email: hello@passready.us
Postal address (required for formal legal requests)
- Resilient Platforms Ltd
- 66 Paul Street, London, England, EC2A 4NA
- Preston, Lancashire
- United Kingdom
Note on applicable law
PassReady is operated by a UK-registered company. Where applicable, your data is also subject to UK GDPR. Our full UK/EU privacy policy is available at passready.us/privacy.
The TDPSA applies to our processing of Texas residents' personal data. If you are located outside Texas but within the United States, the rights described in this policy still apply to you as a matter of our voluntary practice.
This policy was last reviewed and verified for TDPSA compliance in June 2026.
Google API Services User Data Policy Disclosure
1. Data Accessed
Our application accesses and interacts with specific Google user data via Google API Services to facilitate automated outreach tracking and service functionality. Specifically, we access:
- Your Google User Profile information (such as name and email address) for user authentication and identification.
- Limited email transmission metadata required to securely route outreach emails through authenticated channels when initiated by the user.
2. Data Usage and Purpose
The Google user data accessed by our application is processed strictly for the purpose of managing and executing user-initiated B2B outreach campaigns, tracking response metrics within your secure dashboard, and maintaining application logs. We do not use this data for any marketing or advertising purposes.
3. Data Storage and Retention
Google user data is stored securely using industry-standard encryption protocols. We only retain authentication tokens and relevant metadata for as long as your account remains active or as required to fulfill the operational tracking services provided by our platform. Users may revoke access at any time via their Google Security Settings.
4. Data Sharing and Transfer
PassReady does not sell, lease, or share Google user data with third parties. Your data is never transferred to external platforms or used to train artificial intelligence or machine learning models. Data transmission is restricted entirely to fulfilling the core operational functionality of the PassReady application as explicitly authorized by the user.