Last updated: 20 June 2026
Effective from: 20 June 2026
Version: 1.0
This Privacy Policy explains how Paul Hepple, a sole trader trading as DarkByte Creations handles personal data in connection with NibbleKit.
In this policy, DarkByte, NibbleKit, we, us and our refer to Paul Hepple trading as DarkByte Creations.
This policy applies to NibbleKit services that link to it, including, where applicable:
NibbleKit is a white-label technology platform. A NibbleKit-powered service may display a participating Merchant's brand.
A Merchant may have its own privacy notice covering its independent use of personal data. This policy does not replace that notice.
DarkByte's contact details are:
Paul Hepple, a sole trader trading as DarkByte Creations 152 Lindhurst Road, Barnsley, S71 3DG Email: support@nibblekit.com Privacy contact: privacy@darkbyte.uk Telephone: 07549 253991 ICO registration number: not published here; available where legally required
In this policy:
Privacy roles are determined by the actual decisions each party makes about the purposes and essential means of processing. A contractual label does not by itself determine the role.
DarkByte acts as an independent controller where it decides why and how personal data is used for its own purposes.
A Merchant acts as an independent controller where it decides why and how data is used for its sales, fulfilment, food-safety, customer-service and business purposes.
DarkByte acts as a processor where it stores, transmits or otherwise handles data solely on a Merchant's documented instructions.
A payment provider, app store, bank, delivery provider or other third party may act as a separate controller for its own regulated, contractual, security or commercial processing.
Two parties are not joint controllers merely because they both receive the same data or work together. Joint controllership arises only where they jointly determine the purposes and essential means of a particular processing activity.
The table below describes the standard NibbleKit platform position.
Optional features apply only where they are enabled in the relevant NibbleKit environment, Merchant configuration or checkout flow.
| Processing activity | DarkByte's role | Merchant or other party's role | Personal data and purpose | DarkByte lawful basis where DarkByte is controller |
|---|---|---|---|---|
| Public NibbleKit websites and policy pages | Independent controller | A Merchant may separately control its own pages | Device, browser, request, security and communication information used to deliver and protect pages | Legitimate interests under Article 6(1)(f); consent where required for optional storage or access technologies |
| Customer account registration, authentication and account security | Independent controller for standard NibbleKit authentication and platform account security | Merchant may be a separate controller for its branded customer relationship | Name, email, telephone number, identifiers, authentication state, credentials, preferences and security events | Contract under Article 6(1)(b); legitimate interests under Article 6(1)(f); legal obligation under Article 6(1)(c) where applicable |
| Merchant User authentication and platform access | Independent controller for platform identity, role security and audit | Merchant is an independent controller for deciding who is authorised and for its staff administration | Name, work contact details, Merchant, role, permissions, login and audit information | Legitimate interests under Article 6(1)(f); performance of the Merchant contract where Article 6(1)(b) applies; legal obligation where applicable |
| Merchant menus, product information and availability | Normally processor for the Merchant's published business content; controller for platform-security logs | Merchant is controller for menu and product information linked to Customers or staff | Product interactions, configuration and limited audit information | Merchant determines the basis for processor activity; DarkByte relies on legitimate interests for its separate security and audit processing |
| Customer order submission, order management and fulfilment | Processor for the Merchant's order processing, except for separate DarkByte purposes identified in this table | Merchant is independent controller and seller | Customer identity, contact details, order contents, address, delivery or collection details, instructions and order status | Merchant determines the basis for processor activity; DarkByte may rely on contract, legitimate interests or legal obligation for limited platform records used for its own account, security, dispute or compliance purposes |
| Customer order history displayed in an account | Processor for Merchant order records; controller for account access and security | Merchant is controller for the underlying order and customer relationship | Historic orders, Merchant, dates, status, totals and related account linkage | Merchant determines the basis for order records; DarkByte uses contract and legitimate interests for secure account presentation |
| Payments, refunds and chargebacks | Independent controller for DarkByte platform payment configuration, security, reconciliation, fee and dispute records; processor where handling Merchant-controlled order payment records on Merchant instructions | Merchant, Stripe/payment provider, bank, card network and wallet provider may have separate roles | Amount, currency, transaction identifiers, Merchant account, status, refund, fraud and dispute information | Contract, legitimate interests and legal obligation, depending on the payment, dispute, accounting or security purpose |
| Transactional order messages | Normally processor where sent for the Merchant | Merchant is controller for order communications | Contact details, order reference and status | Merchant determines basis; DarkByte uses contract or legitimate interests for separate platform-delivery and security records |
| DarkByte account, verification and security messages | Independent controller | Messaging provider acts as processor unless it has a separate stated role | Email, telephone number, device token and message-delivery information | Contract, legal obligation or legitimate interests |
| Merchant order support and complaints | Processor where DarkByte acts only on Merchant instructions; independent controller for DarkByte platform support | Merchant is controller for product, fulfilment, refund and food-safety complaints | Contact information, order information, correspondence and evidence | Merchant determines the processor basis; DarkByte uses contract, legal obligation or legitimate interests for its own platform support and claims |
| Saved allergy or dietary-safety profile | Independent controller for the standard optional profile and warning function as configured for the standard NibbleKit feature | Merchant becomes a separate controller only where relevant information is disclosed to it for an order | Allergy selections and other health-related dietary information used to provide optional profile warnings | Consent under Article 6(1)(a) and explicit consent under Article 9(2)(a) |
| Allergy or health information attached to an order | Processor while transmitting or hosting information for the Merchant | Merchant is independent controller for use in preparation, fulfilment and food safety | Allergy selections, order notes and related warnings | Merchant determines its Article 6 basis and Article 9 condition; DarkByte has no separate basis as processor |
| DarkByte use of health information for a safety incident, complaint or legal claim | Independent controller only to the extent necessary for that separate purpose | Merchant may separately retain information for its own investigation | Relevant order, allergy, complaint and incident evidence | Legitimate interests or legal obligation under Article 6; Article 9(2)(f) where processing is necessary for legal claims, or another documented condition where applicable |
| Platform security, abuse prevention and fraud investigation | Independent controller for the NibbleKit platform | Merchant and payment providers may be separate controllers for their own fraud and security processing | Account, device, IP, log, transaction, behavioural and incident information | Legitimate interests, recognised legitimate interests or legal obligation, as applicable |
| Diagnostics, reliability and crash investigation | Independent controller | Diagnostic provider acts as processor unless it has a separate disclosed role | Device, app version, fault, crash and performance information | Legitimate interests; consent or a valid PECR exception where device storage or access is involved |
| Privacy rights requests | Independent controller for requests concerning DarkByte | Merchant is controller for requests concerning Merchant processing; DarkByte may assist as processor | Identity, contact, authority, request and response records | Legal obligation under Article 6(1)(c); legitimate interests for administration and legal claims |
| Data-protection complaints | Independent controller for complaints about DarkByte processing or conduct | Merchant is controller for complaints about Merchant processing | Complaint, correspondence, evidence, investigation and outcome records | Legal obligation under Article 6(1)(c); legitimate interests for investigation, improvement and legal claims |
| DarkByte direct marketing | Independent controller | Merchant is separate controller for Merchant marketing | Contact details, marketing preferences and interaction records | Consent under Article 6(1)(a), or legitimate interests where lawful; PECR consent or a valid soft opt-in must also apply to electronic mail |
| Merchant direct marketing | Normally processor only where the Merchant instructs use of a platform messaging tool | Merchant is controller | Contact details, preferences and campaign records | Merchant determines the lawful basis and PECR position |
| App Store and Google Play administration | Independent controller for data DarkByte receives and uses to administer an app | Apple or Google acts as an independent controller for its Store processing | App identifiers, Store receipt or purchase data, diagnostic and publication information | Contract, legitimate interests or legal obligation |
| DarkByte business, tax, legal and contract administration | Independent controller | Advisers and authorities may be processors or separate controllers | Merchant contacts, invoices, correspondence, contracts and legal records | Contract, legal obligation and legitimate interests |
| Demo or trial administration | Independent controller for demo access and support | Prospective Merchant may be a separate controller for its staff | Business contact, login, activity and support information | Legitimate interests and steps taken at the person's request before contract |
| Joint-controller activities | No joint-controller activities have been identified in the standard NibbleKit demo/platform service | Not applicable unless a specific feature notice states otherwise | Not applicable unless a specific feature notice states otherwise | Not applicable unless a specific feature notice states otherwise |
Where a feature operates differently from the standard position, an additional notice will identify:
A Merchant is normally responsible for giving Customers privacy information about the Merchant's use of personal data for:
A Merchant's notice should identify the Merchant's full legal identity and contact details.
Where DarkByte is the Merchant's processor, the Merchant determines:
DarkByte's processing for a Merchant is governed by a written data-processing agreement containing the requirements applicable to processors.
DarkByte and a Merchant will be treated as joint controllers only for a processing activity where they jointly determine its purposes and essential means.
Where joint controllership applies:
A joint-controller arrangement does not prevent you from contacting DarkByte through the Privacy Rights and Data Protection Complaints page.
Depending on how you use NibbleKit, we may collect or receive the following categories.
This may include:
This may include:
We do not retain plain-text account passwords.
This may include:
This may include:
NibbleKit is designed not to store full card numbers or card security codes on DarkByte systems.
This statement reflects the current NibbleKit payment architecture and must be reviewed before any new live payment integration is enabled.
This may include:
This information may be special-category health data.
This may include:
This may include:
This may include:
This may include data stored or accessed through:
The Cookies and Similar Technologies Policy provides further details.
This may include:
This may include:
We may obtain personal data:
Where another person provides your information, that person should have proper authority and should provide you with relevant privacy information where required.
Some information is required to provide a requested service.
For example:
If required information is not provided, the relevant function may be unavailable.
Optional information includes:
Declining an optional field should not prevent access to unrelated core functions.
Where DarkByte is a controller, it uses one or more of the following lawful bases.
We use personal data where necessary to:
We do not rely on contract merely because processing is mentioned in contractual terms. The processing must be objectively necessary for the relevant contract.
We use personal data where necessary to comply with an obligation imposed by law, including applicable:
We use personal data where necessary for legitimate interests that are not overridden by your interests, rights or freedoms.
Those interests may include:
We assess:
Where appropriate, we document a legitimate-interests assessment.
We rely on consent for a specific optional purpose where consent is appropriate.
Consent must be:
Accepting the Terms, EULA or this Privacy Policy is not treated as consent to an unrelated optional purpose.
In a genuine emergency, personal data may be used where necessary to protect someone's life or physical safety and another appropriate basis is unavailable.
This basis is not used for routine food-order processing.
Allergy, intolerance and related dietary-safety information may reveal health information and may therefore be special-category data.
Where DarkByte provides the standard optional saved allergy-profile function, DarkByte relies on:
The explicit-consent request will be separate from:
Before giving consent, the user will be told:
The current disclosure from an allergy profile to a Merchant is:
Saved allergy selections and the no-known-allergies flag are stored on the customer profile for warning features. Where relevant to an order, allergy selections, order-specific allergy or dietary notes and warning context may be included in order data visible to authorised Merchant, admin and kitchen users who need it for preparation, handover, support or safety purposes.
Saving an allergy profile is optional.
A Customer can update or remove saved allergy information through:
the onboarding allergy step or the Food allergies section on the user/profile screen
A Customer can withdraw explicit consent through:
the user/profile screen where editable, or the Data Request page at https://nibblekit.com/policies/data-request/
Withdrawal stops future processing based on that consent. It does not make earlier consent-based processing unlawful.
Limited information may still be retained where necessary for:
Where a Merchant receives health information for an order, the Merchant becomes responsible for identifying and communicating its own Article 6 basis and Article 9 condition.
DarkByte does not use saved allergy data for advertising.
DarkByte does not disclose saved allergy data to an artificial-intelligence provider or permit it to be used to train a general-purpose model unless this is separately and prominently disclosed and an appropriate lawful basis and Article 9 condition have been established.
This provider statement must be reviewed before any new payment, app-store, wallet or third-party integration is enabled.
A Customer may place an order for another person.
Where you provide another person's contact, delivery, allergy or dietary information, you must:
You should not save another adult's health information to a reusable profile without their knowledge and appropriate authority.
A parent or person with legal responsibility may provide information for a child where appropriate.
Payments may be processed using:
Stripe Connect for card payments and supported wallet methods, plus any cash or offline payment option expressly enabled by the Merchant.
The standard card-payment architecture uses Stripe Connect direct charges on the Merchant connected account where the current PaymentIntent flow is enabled. Stripe processes the payment, the Merchant connected account is the primary recipient for Merchant food or order funds, and checkout or receipt information should identify the relevant Merchant and payment method. DarkByte does not receive full card details and does not act as your card issuer, acquiring bank or payment account provider.
If a Merchant enables a materially different payment flow, the checkout flow, receipt or Merchant-specific terms should identify the payment recipient, refund controller, statement descriptor and relevant provider role before you place the order.
A payment provider may receive information such as:
DarkByte may receive limited payment metadata needed to:
The payment provider may act:
Its own privacy information applies to independent processing.
Apple Pay, Google Pay, banks, card networks and card issuers may also process payment information independently.
Where an App is distributed through Apple or Google, the Store provider may independently process:
DarkByte may receive limited information from a Store, such as:
Current digital in-app purchase or subscription processing is:
The standard NibbleKit app is currently a free download and does not receive App Store or Google Play digital purchase data for in-app purchases or subscriptions. App stores may still process download, account, device and diagnostic data under their own terms.
Apple and Google normally act as independent controllers for their Store services.
DarkByte is responsible for keeping its App Store privacy information and Google Play Data Safety disclosures accurate and consistent with:
Service messages are communications needed to provide, protect or administer a requested service.
They may include:
A service message is not treated as marketing merely because it uses a Merchant's branding.
You may be unable to opt out of a message that is genuinely necessary for an active account, pending order, security issue or legal obligation.
DarkByte will send direct marketing by email, text, push notification or similar electronic message only where:
Every marketing message will identify the sender and provide a simple way to opt out.
A device permission to receive notifications is not, by itself, consent to receive marketing.
A Merchant is responsible for its own marketing purposes, audience selection, lawful basis and PECR compliance.
Where DarkByte sends a Merchant campaign solely on the Merchant's instructions, DarkByte acts as processor.
Marketing choices for one Merchant will not automatically be treated as consent to marketing from DarkByte or another Merchant.
Where you opt out, a minimal suppression record may be retained so that the choice can be respected.
A suppression record will not be used to restart marketing.
NibbleKit may use technologies that store information on or access information from a device, including:
These rules apply to mobile applications and webviews as well as conventional websites.
The NibbleKit Cookies and Similar Technologies Policy identifies:
Where consent is required under PECR, the technology will not be enabled before valid consent is obtained.
A UK GDPR lawful basis is also required where the technology involves personal data.
We may process account, device, request, payment-status and behavioural information to:
Security decisions may result in:
Where an urgent automated security control temporarily restricts access, an appropriate review route will be available where the restriction materially affects the user.
We do not treat ordinary business convenience as sufficient justification for intrusive monitoring.
NibbleKit may use or integrate automated tools for functions such as:
An enabled AI or automated feature must be identified in this section or in a feature-specific notice.
Current enabled AI or automated integrations are:
| Feature | Provider | Data supplied | Purpose | Provider retention or model-training position | DarkByte role |
|---|---|---|---|---|---|
| No advertising or cross-service tracking feature in the core NibbleKit demo unless separately enabled | Not applicable unless separately enabled | Not applicable unless separately enabled | Not applicable unless separately enabled | as configured for the standard NibbleKit feature | Not applicable unless separately enabled |
We will not intentionally submit:
to a general-purpose AI service.
An automated allergen warning is a supplementary information function. It does not decide whether food is legally or medically safe and normally does not have a legal or similarly significant effect.
The current position on solely automated significant decisions is:
DarkByte does not currently make a significant decision about an individual based solely on automated processing in the standard NibbleKit demo/platform service. Automated security, payment, delivery-area, allergy-warning, pricing and order-status checks support workflows but are not intended to produce a legal or similarly significant decision without human or Merchant involvement where required.
Where DarkByte makes a significant decision based solely on automated processing, DarkByte will provide the safeguards required by applicable law, including as appropriate:
Special-category data will not be used for a solely automated significant decision unless the processing is legally permitted and the required additional safeguards are in place.
We disclose personal data only where reasonably necessary for a lawful purpose.
A Merchant may receive information needed to:
The Merchant acts as an independent controller for those purposes unless the specific activity states otherwise.
The exact provider set may vary by environment, Merchant configuration and enabled features. The current public register for the NibbleKit demo/platform services is:
| Provider category | Typical provider | Typical data | Purpose | Typical role |
|---|---|---|---|---|
| Hosting and cloud infrastructure | Firebase and Google Cloud | Account, order, log and configuration data | Host and operate NibbleKit | Processor and/or infrastructure provider |
| Database and storage | Cloud Firestore and Firebase Storage | Account, order, Merchant, support and media data | Store platform data | Processor and/or infrastructure provider |
| Authentication | Firebase Authentication and supported identity providers | Identity, account, token and security data | Authenticate users and protect accounts | Processor and/or independent provider controller depending on feature |
| Payment processing | Stripe Connect and enabled wallet/payment methods | Payment, order, fraud, refund and dispute data | Process payments, pre-authorisations, refunds and disputes | Independent controller and/or processor depending on provider function |
| Transactional email | Configured SMTP/email provider and Firebase email action links | Name, email, message and delivery status | Send verification, receipt, support and service messages | Processor/provider |
| Push notifications | Firebase Cloud Messaging and device operating-system services | Device token, account link and message metadata | Deliver service notifications | Processor/provider; device platform may have independent role |
| Address, postcode, map and route services | Google Places/Maps and configured postcode/address providers | Address, postcode, place, route and request data | Address lookup, delivery area and route functions | Processor or independent provider controller depending on feature |
| Crash reporting and diagnostics | Firebase, Flutter/device diagnostics and hosting logs where enabled | Device, app, crash, log and diagnostic data | Reliability, security and fault investigation | Processor/provider |
| AI, image or nutrition services | Configured AI text, image-processing and nutrition providers where enabled | Menu, image, nutrition, prompt and generated-output data submitted to the feature | Menu assistance, image tools and nutrition lookup | Processor/provider depending on feature |
| Customer-support tooling | Internal email/support workflow unless another support tool is enabled | Contact, support, order and evidence data | Manage support cases | Controller for DarkByte support; processor where acting for Merchant |
| Account-deletion and privacy-request tooling | NibbleKit public form and internal case workflow | Request, identity, authority and case data | Manage rights and complaints | Controller for DarkByte requests; processor support where Merchant-controlled data is involved |
A more detailed material provider or subprocessor list is available from privacy@darkbyte.uk on reasonable request until a public register is published.
We may disclose information to:
where reasonably necessary and lawful.
If all or part of NibbleKit or DarkByte's business is sold, transferred, reorganised or evaluated for a genuine transaction, relevant information may be disclosed under appropriate confidentiality and data-protection safeguards.
Personal data will not be disclosed merely for speculative sale or unrelated marketing.
Some providers may process personal data outside the United Kingdom.
Current material hosting and processing locations are:
Firebase/Google Cloud resources are configured primarily in the project region used for the relevant environment, including europe-west2 for the demo functions, with provider support, security and subprocessor operations potentially outside the UK under appropriate safeguards
Where a restricted transfer occurs, we will use a lawful transfer mechanism, such as:
Where appropriate safeguards are used, we will complete and document the applicable transfer risk assessment or data-protection test and consider whether supplementary measures are needed.
An exceptional transfer derogation will be used only where its legal conditions are met and it is appropriate for the circumstances.
Where the EU GDPR separately applies, an appropriate EU transfer mechanism will also be used.
You may request information about the relevant transfer safeguard through the Privacy Rights and Data Protection Complaints page. Commercially confidential information may be redacted where lawful.
We retain personal data only for as long as reasonably necessary for:
Detailed periods are set out in the NibbleKit Data Retention and Deletion Policy.
Standard categories include:
Deleting an account does not necessarily delete:
Saved allergy-profile information is deleted separately from longer-lived financial metadata and is not retained merely because a related order amount must be retained for accounting.
We use technical and organisational measures designed to protect personal data against:
Measures may include, where appropriate:
Security measures are reviewed according to risk.
No internet or software service can be guaranteed completely secure. You should protect your credentials and report suspected unauthorised access promptly.
Where DarkByte becomes aware of a suspected personal-data breach, it will:
Where DarkByte acts as processor, it will notify the relevant Merchant without undue delay and provide reasonable assistance.
Where DarkByte acts as controller, a notifiable breach will be reported to the Information Commissioner's Office without undue delay and, where required, within the applicable 72-hour period.
The standard NibbleKit customer-account service is intended for people aged:
the minimum age stated in the relevant app, ordering service or Merchant terms
We do not knowingly permit a person below the stated minimum age to create an account unless:
A child may be the intended recipient of food ordered by an adult without becoming an account holder.
Where an online service is likely to be accessed by children, we will take children's needs and best interests into account when deciding:
A parent, guardian, Merchant or child who believes that personal data has been collected inappropriately should contact us through the privacy complaints route.
We may take reasonable steps to verify age or parental authority where necessary and proportionate.
Depending on the circumstances, you may have the right to:
Rights are subject to legal conditions and exemptions.
A deletion request does not automatically require deletion of every record. Where only part must be retained, we will consider deleting or anonymising the remainder.
Withdrawing consent does not affect processing carried out lawfully before withdrawal.
You may exercise a right through the NibbleKit Privacy Rights and Data Protection Complaints page at:
https://nibblekit.com/policies/data-request/
You may also contact:
You do not have to use a particular form or legal wording.
Please provide enough information for us to:
We will request identity evidence only where reasonably necessary and proportionate.
There is normally no fee.
We will normally respond within one month, subject to:
Where a Merchant is controller, we may securely forward the request, ask the Merchant to respond or assist it as processor. We will explain the routing where reasonably possible.
A data-protection complaint is separate from a request to exercise a right.
You may make a complaint where you believe that personal data has been handled in a way that breaches data-protection law.
Complaints may be submitted through:
When DarkByte receives a complaint about processing for which it is controller, we will:
The outcome will normally:
Where the complaint concerns Merchant-controlled processing, we may securely forward it to the Merchant or separate the Merchant and DarkByte issues.
You do not have to complete DarkByte's process before contacting the Information Commissioner's Office.
The Information Commissioner's Office is the United Kingdom's data-protection supervisory authority.
You may complain to the Information Commissioner's Office where you are concerned about how personal data has been handled.
Where another European supervisory authority has jurisdiction, you may also have a right to complain to that authority.
Contacting DarkByte first may allow the matter to be resolved more quickly, but it is not a precondition to making a regulatory complaint.
Where you are affected by a significant decision based solely on automated processing and applicable law requires safeguards, you may use the Privacy Rights and Data Protection Complaints page to:
Please identify:
Where a NibbleKit App permits account creation, deletion can be initiated:
Deleting the App from a device does not delete the account.
Account deletion normally:
Some records may remain for lawful reasons described in section 22.
A Merchant may separately retain order records for which it is controller.
We may update this policy to reflect changes in:
The current version will show its last-updated date and version number.
Where a material change affects how existing personal data is used, we will assess whether:
is required before the change is applied.
An earlier consent will not be treated as consent to a materially different purpose.
Previous material versions will be available at:
Previous material versions are available on reasonable request from support@nibblekit.com.
This policy should link to:
For questions about DarkByte's use of personal data:
Paul Hepple, a sole trader trading as DarkByte Creations 152 Lindhurst Road, Barnsley, S71 3DG Email: support@nibblekit.com Privacy email: privacy@darkbyte.uk Telephone: 07549 253991
For a Merchant's use of order, fulfilment, customer-service, food-safety or marketing information, contact the Merchant identified in the relevant ordering service, checkout or order confirmation.