Last updated: 20 June 2026
Effective from: 20 June 2026
Version: 1.0
This policy explains how Paul Hepple, a sole trader trading as DarkByte Creations retains, reviews, deletes, anonymises or returns personal data handled in connection with NibbleKit.
In this policy, DarkByte, NibbleKit, we, us and our refer to Paul Hepple trading as DarkByte Creations.
We do not keep personal data indefinitely merely because it might be useful in the future.
We retain personal data only for as long as it is reasonably needed for:
At the end of the applicable period, personal data is deleted, anonymised, returned or placed beyond ordinary use unless a documented exception applies.
This policy applies to personal data handled through NibbleKit services that link to it, including:
This public policy summarises standard retention periods. DarkByte also maintains a more detailed internal retention schedule identifying relevant systems, owners, deletion methods, exceptions and review dates.
NibbleKit is a white-label platform used by participating Merchants.
DarkByte controls retention for records it processes for its own purposes, including relevant:
A Merchant normally controls retention for records it uses for:
Where DarkByte acts solely as a processor, the Merchant's documented instructions and the applicable data-processing agreement determine how long the relevant data is held, subject to law.
Where the same information is used separately by DarkByte and a Merchant, each may apply a different justified retention period to its own copy.
The Merchant's privacy notice should explain the Merchant's independent retention periods.
The periods below are standard maximum periods, not minimum periods.
Information may be deleted earlier where:
Information may be held longer only where there is a documented reason, such as:
A retention period ordinarily begins from the most recent relevant event stated below. Calendar days and calendar months are used unless stated otherwise.
The periods below reflect the standard NibbleKit configuration and may be adjusted only where a documented legal, security, accounting, dispute or operational reason requires it.
Customer name, contact details, account preferences and ordinary profile information are retained while the account is active.
Following account deletion or closure, information that is not covered by another category will be deleted or anonymised from ordinary live systems within 30 calendar days.
Residual copies may remain in backups for the period described in section 12.
Where an account has been inactive for 24 months, we may give at least 30 days' notice and close or anonymise it unless:
Active sessions and authentication tokens are retained only for their configured validity period.
They will be revoked:
The verified maximum validity periods are:
Password hashes or equivalent credentials are deleted or disabled when the associated account is deleted, except where a short security hold is reasonably required.
Plain-text passwords are not retained.
Email-verification and password-reset links or tokens expire after:
Used, expired or revoked tokens are made unusable.
Limited records showing that verification or a reset occurred may be retained for 12 months for account security, support and fraud-prevention purposes.
Records showing acceptance of the Terms, End User Licence Agreement or Acceptable Use Policy, and records showing that a privacy notice was presented, are retained while the account or contractual relationship remains active and for six years afterwards.
These records may include:
A record that a privacy notice was shown is not treated as privacy consent.
Where consent is relied upon, a record of:
is retained while the consent is relied upon and for six years after the consent is withdrawn or ceases to be relied upon.
The retained compliance record should not contain more underlying sensitive information than is necessary to demonstrate the consent and its withdrawal.
Saved allergy information is retained while:
When the user removes the information, withdraws the applicable explicit consent or deletes the account, the saved profile data will be removed from ordinary live profile systems within 30 calendar days.
It may remain in protected backups for up to up to 90 days unless a shorter configured backup cycle applies before expiry or overwriting.
A minimal record of the consent and its withdrawal may be retained separately under section 5.5. That record must not unnecessarily reproduce the user's complete allergy profile.
Allergy or dietary-safety information associated with an order is distinct from a reusable profile.
Where the Merchant controls the order record, the Merchant determines the lawful retention period and DarkByte retains the processor copy according to the Merchant's documented instructions.
Where DarkByte has an independent need to retain a limited copy for a platform complaint, safety incident or legal claim, the relevant information will be retained only for the duration of that matter and for the period reasonably needed to resolve the matter and any related legal claim where reasonably necessary.
Order-specific health information must not be retained merely because general financial metadata relating to the order has a longer accounting period.
Order contents, status history, Merchant identity, delivery or collection details and operational communications are retained:
Operational order data should be separated or minimised once it is no longer needed for fulfilment, ordinary customer support or account order history.
A longer financial retention period does not automatically justify retaining detailed delivery instructions, free-text notes or allergy information for the same duration.
NibbleKit is designed not to retain full card numbers or card security codes.
DarkByte may retain limited information such as:
Records needed solely for an ordinary payment-status workflow are retained for the period needed for reconciliation and provider settlement checks.
Records relating to a refund, chargeback or payment dispute are retained until the matter is finally closed and for the period reasonably needed to resolve the matter and any related legal claim, unless a longer legal-claims period is justified.
Payment providers and Merchants may independently retain records under their own legal duties and privacy notices.
DarkByte invoices, fee records, accounting entries and evidence required for DarkByte's own tax or accounting obligations are retained for the statutory accounting and tax retention period that applies to DarkByte.
Only information reasonably needed for the accounting purpose should be included in the longer-retained record.
A Merchant remains responsible for its own accounting and tax records.
Ordinary support correspondence, case notes and attachments are retained for 24 months after the support case is closed.
A record may be retained longer where it is relevant to:
Attachments containing unnecessary identity, payment or health information should be removed earlier.
Ordinary order or service complaints handled by DarkByte are retained for 24 months after closure.
Where the Merchant is responsible for the complaint, DarkByte may retain only:
A complaint involving injury, alleged food-safety harm, fraud, litigation or regulatory investigation may be retained under a documented legal hold.
The full working file for a privacy rights request is retained for three years after final closure.
A more limited compliance record may be retained for six years after closure and may include:
Identity documents supplied solely for verification will be deleted within 30 days after verification unless a documented dispute or fraud concern requires temporary retention.
The full data-protection complaint file is retained for three years after the final outcome.
A limited outcome and compliance log may be retained for six years after closure so that DarkByte can demonstrate:
Where legal proceedings, an Information Commissioner's Office investigation or another regulatory matter remains possible or active, the record may be placed under a legal hold.
Ordinary authentication, access, network, rate-limiting, fraud and security-event logs are retained for 12 months after creation.
Short-lived diagnostic logs that are not needed for security are retained for no longer than 90 days.
A relevant extract may be retained longer where it is connected with:
A security-incident file is retained for six years after the incident is closed unless a shorter period is justified or a legal hold applies.
Records of Merchant and administrative actions, such as role changes, content edits, order-status changes and security-sensitive settings, are retained for 24 months after the event.
Relevant records may be retained longer for:
Audit access is restricted according to role and need.
Merchant User profile and role information is retained while the individual remains authorised.
Access should be removed promptly when:
Information not needed under another category is deleted or anonymised within 30 calendar days after access ends.
A limited audit record identifying past security-sensitive actions may remain for the period in section 5.16.
Merchant contracts, material contract communications, service configuration approvals, data-processing instructions and account-termination records are retained during the relationship and for six years after it ends.
Operational copies of Merchant Customer data are not retained for that full period merely because the Merchant contract is retained.
A push-notification or similar device token is retained while:
A token will be removed or made inactive following logout, account deletion, revocation, provider invalidation or 30 days of confirmed invalidity.
Notification preference records are retained while needed to honour the user's current selection.
Marketing preference and consent records are retained while marketing remains active and for six years after the last relevant consent, withdrawal or communication.
Where a person opts out, a minimal suppression record may be retained for as long as DarkByte continues marketing through that channel so that the opt-out can be respected.
A suppression record must not be used to resume marketing or for an unrelated purpose.
Crash reports and identifiable technical diagnostics are retained for 90 days after collection unless:
Anonymised aggregate reliability statistics may be kept longer where individuals cannot reasonably be identified.
Records used to protect public pages, forms, verification endpoints and reset services are retained for 12 months, subject to shorter provider-level technical periods.
Form submissions are retained under the category appropriate to their content, such as support, privacy request or complaint.
Incomplete form drafts must not be retained beyond the active browser or server session only unless the user expressly saves them.
Demo, test and trial workspaces are not intended for real Customer, payment, health or confidential information.
Demo data may be reset or deleted at any time and will normally be deleted no later than 30 days after the end of the relevant trial, demonstration or test.
Where real personal data is entered into a demo or test environment contrary to instructions:
Information submitted during registration but not verified or completed will be deleted or anonymised within 30 days after the registration expires.
Security information associated with suspected abuse may be retained under section 5.15.
Personal data submitted in a genuine business or Merchant enquiry is retained for 12 months after the last substantive contact where no contract is entered into.
Where a contract is entered into, relevant information is retained under the Merchant-contract category.
Any record relevant to actual or reasonably anticipated:
may be placed under a documented legal hold.
A legal hold suspends scheduled deletion only for information that may be relevant.
Legal holds will be reviewed at reasonable intervals and removed when no longer justified. The ordinary retention period will then resume or the record will be deleted.
Closing an account does not automatically delete every related record.
On account deletion, DarkByte will:
Order records controlled by a Merchant may remain with that Merchant.
Where deletion cannot be completed immediately because an active order, refund, dispute, safety issue or legal obligation remains, the account will be restricted where reasonably possible and the remaining information will be deleted when the reason for retention ends.
When a Merchant's NibbleKit service ends, processor data will be handled according to the Merchant agreement and data-processing agreement.
Subject to legal obligations and documented exceptions, DarkByte will:
A Merchant must retrieve any permitted export within the stated period. An export does not authorise the Merchant to retain personal data for longer than its own lawful purposes require.
Where a service provider processes personal data for DarkByte, the applicable contract should require the provider to:
Some providers, such as payment providers or app stores, may act as independent controllers for parts of their processing. Their own privacy and retention terms may apply to those independent records.
DarkByte will not represent that it can delete a provider's independent record where DarkByte has no legal or technical control over it.
DarkByte will review the internal retention schedule at least annually and following material changes to:
The review will consider:
Where technically proportionate, automated expiry or deletion will be used rather than relying solely on manual review.
Deletion means removing personal data from ordinary use so that it is no longer available for the relevant purpose.
Where immediate physical erasure is not technically possible, the information will be restricted and placed beyond ordinary use until overwritten or securely destroyed.
Information is anonymised only where individuals are no longer identifiable by reasonably likely means.
Properly anonymised information is no longer personal data and may be retained for:
Anonymised information must not be combined with other data for the purpose of re-identifying an individual.
Pseudonymised information remains personal data where an individual can be identified using additional information.
Pseudonymisation is a security and minimisation measure. It does not permit indefinite retention.
Electronic records are deleted using methods appropriate to the system and risk.
Paper records, where used, are securely shredded or destroyed.
Devices and storage media are securely erased or destroyed before disposal or reuse where they may contain personal data.
You may ask:
A request to delete data will be considered in relation to the specific information and purpose. We will not refuse an entire request merely because one part of a record must be retained.
Where only part of a record remains necessary, we will consider removing or anonymising the unnecessary parts.
Requests may be submitted through the Privacy Rights and Data Protection Complaints page.
Backups are retained for a maximum rolling period of 90 days unless a shorter or provider-specific backup cycle applies.
Backup copies are:
Where deleted data is restored as part of disaster recovery, deletion instructions and suppression records will be reapplied within a reasonable period after restoration once the restored data has been identified.
A legal hold may preserve a relevant backup or extract, but only where reasonably necessary and documented.
DarkByte may retain a minimal record showing that:
The deletion record must not recreate the substantive personal data that was deleted.
We may update this policy to reflect changes in law, platform functions, service providers, Merchant arrangements or the internal retention schedule.
The current version will show its last-updated date and version number.
Where a change materially extends retention for an existing category, we will assess whether further notice or another lawful step is required before applying the longer period.
Previous material versions are available on reasonable request from support@nibblekit.com.
NibbleKit is operated by:
Paul Hepple, a sole trader trading as DarkByte Creations 152 Lindhurst Road, Barnsley, S71 3DG Email: support@nibblekit.com
Privacy rights and complaints: