Legal

Privacy policy

Pip Social is built for UK pubs, restaurants and hospitality groups. This policy explains what personal data we handle, why we handle it, who we share it with and what you can ask us to do about it. It is written to meet the UK GDPR and the Data Protection Act 2018.

Last updated 18 August 2026

1. Who we are

Pip Social is operated by FortitudeOS Ltd. Where this policy says we, us or Pip Social, it means that company.

Legal entity
FortitudeOS Ltd, trading as Pip Social
Registered in
England and Wales, company number 17347903
Registered office
The Old Farmhouse, Crain Syke Farm, North Rigton, Leeds LS17 0AD
Privacy contact
humans@go-pip.com

If you have a question about this policy, or you want to make a request about your data, email humans@go-pip.com.

2. Two kinds of data, two different roles

This matters, so it comes first. Pip Social handles two very different sets of personal data and our responsibility is not the same for each.

Your data. We are the controller.

This is the information about your business and the people who work in it: your account, your team, your venue details, your billing and the content you make with Pip.

  • We decide how this information is used, so we are the data controller for it.
  • Everything in the sections below on what we collect, why, and how long we keep it applies to this data.

Your customers' data. We are the processor.

This is your contact list: the guests and customers whose names, email addresses and mobile numbers you upload or collect so you can send them email and SMS.

  • You remain the data controller for your customers. We only act on your instructions.
  • We do not sell it, we do not market to your customers on our own behalf, and we do not use it for any venue but yours.
  • We will sign a data processing agreement with you. Ask us and we will send the current version.

Pip Social is a business product. We do not knowingly collect data from children, and the app is not intended for anyone under 18.

3. What we collect, why, and our lawful basis

We only collect what the service actually needs. Here is the full picture for the data we control.

WhyWhatLawful basis
Running your accountName, work email address, mobile number, job role, the venues you belong to, your login history and the device you signed in from.Performance of our contract with your business.
Keeping the service secureSign-in codes, IP address, session and audit records of significant actions taken in the app.Our legitimate interests in preventing unauthorised access, fraud and abuse.
Making your marketingYour venue details, menus, events, brand voice, opening hours, and the photos, videos, captions, posts, emails and texts you create in Pip.Performance of our contract with your business.
Camera, microphone and photo libraryPhotos and video you capture, audio you record, and sampled camera frames used for live filming guidance. Nothing is captured until you grant the permission on your device, and you can withdraw it at any time in your phone settings.Performance of our contract, with your device-level consent for each permission.
Taking paymentBilling contact, billing address, VAT details, invoices and a record of what you spent. Card details are entered directly with our payment provider and never reach our systems.Performance of our contract, and our legal obligation to keep accounting records.
Support and enquiriesThe messages you send us, the form you completed, and enough account context to answer you.Our legitimate interests in supporting our customers, and performance of our contract.
Telling businesses about PipBusiness contact details for pubs, restaurants and hospitality groups, including people who ask for a demo or start a signup and do not finish.Our legitimate interests in marketing a business product to other businesses. You can object at any time and we will stop.
Improving the productAggregated, non-identifying usage patterns, plus faults and errors reported by the app.Our legitimate interests in making the service work properly.

We do not sell personal data, we do not share it with data brokers, and we do not use it to build advertising profiles.

4. Your customers, and what you are responsible for

When you upload a contact list or collect customer details through Pip, you stay in charge of that data. We process it only to do what you have asked: to store the list, to send the email or SMS you have written, and to record who opened, clicked or opted out so your reporting is honest.

  • You need a lawful basis to hold your customers' details and a valid reason to market to them. For SMS and email marketing to consumers in the UK, that normally means consent or the soft opt-in under the Privacy and Electronic Communications Regulations.
  • Every marketing email we send for you carries a one-click unsubscribe, and every marketing SMS carries an opt-out. We honour those automatically and add the person to your do-not-contact list. Neither you nor we can send to them again.
  • If one of your customers contacts us directly about their data, we will point them to you as the controller and tell you promptly so you can respond.
  • You must not upload special category data, such as health or religious information, into Pip. It is not designed to hold it.

5. How Pip uses AI

  • Pip uses third party AI models to draft copy, review content before it goes out, transcribe what you say, generate images, music and video, and give live filming guidance while you shoot.
  • We send those models only what is needed for the task in front of you. We do not send them your customer contact lists.
  • We use these providers on business terms that do not permit your content to be used to train their public models.
  • Live filming guidance samples camera frames on your phone while the camera is open and sends them for a short coaching response. The frames are not kept as a record of your venue.
  • Pip is an assistant, not the publisher. Nothing goes to your customers until a person at your venue sends it.

6. Who we share data with

We use a small set of specialist providers to run the service. Each one is bound by a contract that limits them to acting on our instructions. Some are only involved if you use the feature they power, for example AI video or social publishing.

ProviderWhat they handleWhere they process it
SupabaseDatabase and file storage for your account, content and mediaUnited Kingdom (London)
VercelHosting and delivery of our websites, app back end and background jobsEuropean Union and United States
ResendSending the marketing and transactional email you createEuropean Union
InfobipSending the SMS you createEuropean Union
TwilioReceiving inbound SMS replies and opt-out messagesEuropean Union and United States
StripeCard payments, subscriptions and invoicingEuropean Union and United States
OpenAIText generation and speech to text transcriptionUnited States
AnthropicText generation and content reviewUnited States
GoogleLive camera coaching while you filmUnited States
fal.aiAI music and video generationUnited States
ZernioConnecting and publishing to your social accountsEuropean Union
ApifyFinding public mentions of your venueEuropean Union and United States
SerpApiReading your public reviews and local search resultsUnited States
PexelsStock photography searchEuropean Union
ExpoPush notifications to your phoneUnited States
Trigger.devRunning background jobs such as scheduled sends and media processingEuropean Union and United States
CloudflareDNS and the sending domain used for your venue emailGlobal network

We may also share data where the law requires it, to establish or defend a legal claim, or if the business is sold or reorganised, in which case the buyer is bound by this policy until it tells you otherwise.

7. Where your data is stored

Your account, your content and your customer lists are stored in a database and file store hosted in the United Kingdom, in London.

Some of the providers in the table above process data outside the UK, mainly in the European Economic Area and the United States. Where data leaves the UK we rely on UK adequacy regulations, or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with additional safeguards where they are needed.

8. How long we keep it

WhatHow long
Your account and content while you are a customerKept for as long as your account is open, so the service works and your history is there when you need it.
After you close your accountHeld for 90 days so you can change your mind or export what you need, then permanently deleted. Your customer contact lists, imports, media and content are deleted outright.
Financial recordsInvoices, credit and payment records are kept for 6 years after the end of the accounting period, as UK tax law requires. Personal details on those records are reduced to what the law needs.
Unsubscribe and do-not-contact recordsKept for as long as your venue is trading with us, because we have to be able to honour an opt-out. Deleting them would let a person who opted out be contacted again.
Unfinished signupsDeleted automatically a short time after the resume window closes if the signup is never completed.
Security and audit logsKept for a limited period for security and dispute investigation, then removed or stripped of identifying detail.

If you belong to more than one venue or group, closing one account never erases your identity on the others.

9. How we protect it

  • Every venue account is separated at the database level, so one venue cannot see another venue's data.
  • Sign-in is passwordless: a one-time code to your work email, with optional biometric unlock on your phone.
  • Data is encrypted in transit and at rest with our hosting providers.
  • Access to production data by our own team is restricted, logged and used only to run and support the service.
  • Sending is blocked when your account has no credit or has hit its cap, which limits the damage any misuse could do.

If a personal data breach is likely to put people at risk, we will report it to the Information Commissioner's Office within 72 hours and tell you without undue delay.

10. Cookies

This website uses only the cookies and local storage needed to make it work, such as keeping you signed in and remembering where you are in a form. We do not use advertising cookies and we do not track you across other websites, so there is no consent banner to click through.

11. Your rights

You have the following rights over your own personal data.

Access
Ask for a copy of the personal data we hold about you.
Rectification
Ask us to correct anything that is wrong or incomplete.
Erasure
Ask us to delete your personal data, where we have no lasting reason to keep it.
Restriction
Ask us to pause how we use your data while a question about it is resolved.
Portability
Ask for the data you gave us in a common, machine readable format.
Objection
Object to any use we base on legitimate interests, including our marketing to businesses.

Email humans@go-pip.com and we will respond within one month. There is no charge. If you are one of a venue's customers rather than one of our own, contact that venue first, because it is the controller of your data.

If you are not happy with how we have handled your request you can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or on 0303 123 1113. We would rather you came to us first so we can put it right.

12. Changes to this policy

When we change this policy we update the date at the top of the page. If a change materially affects how we use your data, we will tell you in the app or by email before it takes effect.