Privacy Policy
This policy explains how Mango App Ltd, a company registered in England and Wales (company number 17433893) with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ ("Mango App", "Mango", "we", "us"), collects, uses and protects personal data in connection with the Mango App platform at mangoapp.co.uk and associated customer ordering portals (the "Service").
1. Our two roles
Mango App is business software used by fresh produce wholesalers (our "customers"). We handle personal data in two distinct roles:
- As a controller for the data of the people who deal with us directly: our customers' account holders and staff users, billing contacts, and people who contact us.
- As a processor for the business data our customers manage inside the Service, such as their own customers' names, contact details, addresses, orders, invoices and payment status ("Customer Data"). For Customer Data, our customer is the controller and we act on their instructions. If you are a buyer whose details are held in a wholesaler's Mango App account, please direct privacy queries to that wholesaler first; we will assist them in responding.
2. What we collect
- Account data: name, business name, email address, phone number, role and login credentials for the people who use the Service.
- Enquiry and application data: the details submitted through our contact, demo booking and join forms, such as name, company, email address, phone number and the content of the enquiry.
- Customer Data: the records our customers keep in the Service, including their customers' contact details, delivery and billing addresses, orders, invoices, credit notes, prices and notes.
- Integration data: data exchanged with the third-party services a customer connects, described in section 4.
- Technical data: server logs, IP addresses, device and browser information, and error reports used to keep the Service secure and working.
The Service handles business records only. Nothing in it asks for, or has a place to store, sensitive personal details such as health, biometric or ethnicity information.
3. Why we use it (lawful bases)
- To provide, operate and support the Service (performance of a contract).
- To secure the Service, prevent abuse, and monitor for and fix errors (legitimate interests).
- To communicate service messages, such as changes to features or these terms (legitimate interests or contract).
- To respond to enquiries, assess applications to join the Service, and keep in touch about the Service with businesses that have expressed interest; you can ask us to stop such messages at any time (legitimate interests).
- To comply with legal obligations, such as accounting and tax record requirements.
We do not sell personal data, we do not use it for third-party advertising, and we do not use it to train machine-learning models.
4. Accounting and payment integrations
Customers can connect their own third-party accounts to the Service. Every connection is made by the customer, uses the provider's official authorisation flow (OAuth), and can be disconnected by the customer at any time from the Service's settings, which removes our access.
QuickBooks Online (Intuit) and Xero
- When a customer connects QuickBooks Online or Xero, we access their accounting system solely to provide the sync features they have enabled: creating and updating invoices, credit notes, customer records and product items, and reading company settings needed to do that correctly, such as the chart of accounts and tax codes.
- Data obtained from QuickBooks Online or Xero is used only to provide those features to that customer. It is not sold, is not used for advertising or profiling, is not shared with other customers or unrelated third parties, and is not used to train machine-learning models.
- Authorisation tokens are encrypted at rest with AES-256 and are accessible only to our server-side systems; they are never exposed to browsers or stored in plain text.
- A log of sync activity is retained for 90 days so customers can see what was sent, then deleted automatically.
- Disconnecting the integration revokes our authorisation with the provider and deletes the stored tokens.
GoCardless (Direct Debit)
- Where a customer enables Direct Debit collection, payments are collected by GoCardless Ltd, an FCA-authorised payment institution. Bank account details are collected and held by GoCardless; Mango App never holds funds and does not store full bank details.
- We store mandate and payment references and statuses so the customer can see what has been collected. GoCardless processes personal data under its own privacy notice.
5. Who we share data with
We share personal data only with the service providers that run the platform, with the third-party services a customer has connected (at their instruction), and where required by law. Our providers are:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication and file storage | United Kingdom (London) |
| Vercel | Application hosting and serverless compute | United States |
| Cloudflare | Document (PDF) storage and delivery; bot protection on public forms | EU / United States |
| Railway | Document rendering infrastructure | EU / United States |
| Resend | Transactional email delivery | United States |
| Google Fonts | Typeface delivery for our web pages (receives the requesting IP address) | United States |
| Sentry | Error monitoring (configured to strip request data and personal identifiers) | EU (Germany) |
| GoCardless | Direct Debit payment collection (when connected) | United Kingdom |
| Intuit (QuickBooks Online) | Accounting sync (when connected) | United States |
| Xero | Accounting sync (when connected) | Global (Xero-managed) |
If Mango App is ever sold, merged or restructured, personal data may be transferred as part of that transaction, under protections no weaker than this policy.
6. International transfers
Customer Data is stored in the United Kingdom. Some processing takes place outside the UK by the providers listed above. Where personal data is transferred internationally we rely on appropriate safeguards, including the UK International Data Transfer Agreement or Addendum, standard contractual clauses, and, where applicable, the UK Extension to the EU-US Data Privacy Framework.
7. Security
- All traffic is encrypted in transit (TLS); data is encrypted at rest.
- Integration tokens and payment credentials are additionally encrypted at application level (AES-256) and are accessible only to server-side systems.
- Each customer's data is isolated from every other customer's with database-level access controls (row-level security).
- Access to production systems is restricted, and we operate monitoring, error tracking and independent health checks on automated jobs.
8. Retention
- Account data and Customer Data are retained while the customer's subscription is active. On termination, the customer may request an export within 30 days, after which data may be deleted from live systems, with backups expiring on a rolling basis.
- Integration sync logs are deleted automatically after 90 days.
- Records we need for our own legal obligations (such as billing records) are kept for the statutory period.
9. Cookies and local storage
The Service uses only essential cookies and browser storage: session tokens to keep users signed in, and local preferences such as theme. We do not use advertising or cross-site tracking cookies. Public forms use Cloudflare Turnstile to block automated abuse; it checks technical browser signals and may set its own cookie for that purpose. Error monitoring may record technical details of a failure; it is configured not to collect request bodies or personal identifiers.
10. Your rights
Under UK data protection law you may have the right to access, correct, delete, restrict or object to our processing of your personal data, and to data portability. To exercise a right, contact us through the in-app support button or our contact form; we respond within one month. Where your data is held in a wholesaler's account we may refer your request to them as controller. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).
11. Children
The Service is business software and is not directed at children. We do not knowingly collect personal data from anyone under 18.
12. Changes to this policy
We may update this policy from time to time. Material changes will be notified by email or in the Service, and the date at the top of this page shows when it was last revised.
13. Contact
Mango App Ltd
71-75 Shelton Street
Covent Garden
London, WC2H 9JQ
The quickest way to reach us is through our contact form.
Email: use the contact form