Legal
Privacy
This notice describes personal data processing in the CAKE WHORE application as built today. It distinguishes current flows from planned live payment processing.
Last updated: 27 August 2026
Who is responsible
CAKE WHORE operates this website. Formal controller identity details (registered company name and address) for privacy correspondence are pending confirmation — see Contact.
What we collect today
Enquiries (Route B): name, email, occasion details, servings, message, and related fields you submit on an enquiry form. These are stored so a baker can respond with a quote. An enquiry is not a paid order.
Basket: an essential cookie stores which variants and baker are in your basket (see Cookies). It does not by itself identify you by name.
Checkout and paid orders: email and delivery address collected for Stripe Checkout (test mode on production today). When payment is confirmed by Stripe webhook, we store order and fulfilment records and may send transactional emails about that order.
Supplier (baker) accounts: bakers authenticate with email and password via Supabase Auth. Linked supplier profiles may include trading and legal names, premises address, FBO registration details, and optional hygiene rating. Private supplier fields (for example contact email used operationally, payout identifiers) are not shown on the public site.
What we do not currently collect
We do not currently run marketing or advertising trackers on this site. We do not operate a public customer account area. Card details are not stored by CAKE WHORE; card data is handled by Stripe on their hosted checkout. Transactional emails are not marketing and do not imply marketing consent.
Why we process data
To operate the marketplace: respond to enquiries, take and fulfil orders, disclose bakers correctly, enforce food-information and verification rules, notify parties about order status, secure supplier access, and host the application.
Processors and hosting
Application hosting: Vercel. Database and authentication: Supabase (Postgres and Auth). Payments: Stripe (test mode configured; live charges not authorised). Transactional email: Resend when configured (API key server-only; domain authentication may be required for production From addresses). These providers process data on our instructions for the services above.
Retention
Enquiry and order-related records are kept as needed to fulfil the request, meet legal obligations, and resolve disputes. Basket cookies expire after a limited period (currently up to 14 days). Supplier account data is retained while the baker relationship is active and thereafter as required for compliance.
Your rights
Under UK GDPR you may have rights to access, rectify, erase, restrict, or object to certain processing, and to data portability where applicable. To exercise rights, use the channel on Contact once published, or the enquiry route for product-specific questions in the meantime.
Children
The site is not directed at children. Do not submit personal data about children in message fields unless necessary for a legitimate cake inscription and you are entitled to do so.
Changes
We will update this page when processing changes materially — especially when Stripe payments go live or a public contact address is confirmed.