What we store
- Your business and location details, and the person in charge and verifier (name and title).
- Your plan answers, menu items, recipes and the plan files.
- Your logs, with staff initials, not full names.
- Your inspector's contact, only if you add it.
What we never store
- Social Security numbers or tax IDs.
- Health data.
- Payment card details. Whop, our checkout partner, handles payment; we never see your card.
- Passwords. You sign in with Google or a one-time email link.
How it is protected
- Hosting: the site and app run on Cloudflare. Plans and logs are stored in Cloudflare's database and file storage.
- In transit: every connection uses HTTPS (TLS). The service that renders your PDFs only accepts signed requests from our app.
- Access: each account sees only its own business. Kitchen staff log in to a location with a code and PIN and can only add log entries.
- Inspector links: read-only, a long random token, revocable any time, and they expire after 90 days.
- Sign-in: no passwords to leak. One-time links expire quickly and work once.
Your data, your call
- Export any log or plan, any time, free, even after your paid logging period ends.
- Ask us to delete your account and data. We will warn you first, because health departments may ask to see your records.
We do not claim any security certification. If that changes, this page will say so with the report.
Report a security problem
Found a vulnerability? Email help@clearhaccp.com with the subject "Security report". Please give us a reasonable time to fix it before sharing it. We will reply within one business day. More on data use in the privacy policy.