BakeCadence Back to BakeCadence
Privacy

Your bakery data stays yours.

This policy explains what BakeCadence collects, why we use it, and the choices available to bakery owners and their customers.

Effective September 8, 2026

Information we collect

We process account details supplied through secure sign-in, including your name and email address. If you use Sign in with Apple, Apple supplies a stable account identifier and may supply your verified email address and name, including an Apple private-relay address when you choose Hide My Email. The BakeCadence server stores only a one-way hash of Apple's identifier. The iPhone app stores the opaque identifier itself in the device-only Keychain solely to check whether Apple authorization remains valid. It does not store the Apple identity token or authorization code and removes the identifier after confirmed sign-out, account deletion, or a revoked or unavailable credential state. We also store the bakery information you enter, such as products, inventory, pickup details, orders, customer contacts, and workspace settings.

When a customer places an order through a bakery storefront, we process the name, email address, order contents, pickup details, and optional note needed to fulfill that order. Existing records added by a bakery may also include a customer phone number. We also process limited technical information, such as IP-derived rate-limit identifiers and browser information, to protect storefronts from abuse.

Payments and subscriptions

Stripe processes paid subscriptions and one-time digital-product purchases. BakeCadence receives billing identifiers, payment status, purchase or subscription details, renewal information where applicable, receipt or invoice references, and the email supplied at checkout. A paid Checkout Session identifier may be used to verify access to a purchased download. BakeCadence does not receive or store complete card numbers. Stripe's handling of payment data is governed by its own privacy policy.

Free calculator

The free bakery pricing calculator stores the draft you enter in your own browser so you can return to it on that device. BakeCadence does not require an account or transmit that calculator draft to our server. You may clear the saved draft through your browser's site-data controls.

How information is used

We use information to provide and secure the platform, synchronize subscriptions, enforce plan limits, support bakery operations, prevent abuse, respond to support requests, and improve service reliability. We do not sell personal information.

Sharing and retention

Information is shared only with service providers needed to operate BakeCadence, such as authentication, hosting, infrastructure, and payment providers, or when required by law. We retain data while an account is active and as reasonably needed for security, billing records, dispute handling, and legal obligations.

Service providers may use BakeCadence information only to deliver their services or meet legal obligations, and must protect it consistently with this policy. Pseudonymous storefront abuse-prevention keys become eligible for deletion 24 hours after their last use and are removed opportunistically during subsequent storefront activity.

Sign in with Apple challenges expire after five minutes and are retained only briefly for replay prevention. The iPhone app holds the opaque session in a Secure, HTTP-only, host-only cookie, while the server stores only a one-way hash of that session token. Apple sessions expire after 30 days. While an Apple-linked account remains active, BakeCadence keeps the Apple refresh credential encrypted so Apple access can be revoked if the account is deleted. That credential is never exposed to page scripts or browser storage. Account deletion revokes the Apple grant, removes identities and sessions, and keeps only a hashed Apple-identifier tombstone during the 24-hour deletion-safety period before it becomes eligible for removal.

When a workspace change has not yet been confirmed by the server, BakeCadence may keep a temporary copy of that pending workspace data in local browser storage on the device for retry. It is scoped to the signed-in account and workspace, expires after 30 days without an update, and is removed after confirmation, account change or sign-out, or account deletion.

Your choices

You may request access to, correction of, or export of your account information. The BakeCadence iPhone app also provides a direct account-deletion control under More. Account deletion permanently removes the bakery workspace and its customer records after any active subscription is safely canceled. Limited transaction records, pseudonymous deletion-integrity records (including random save-receipt tombstones that prevent an old offline save from restoring deleted data), and non-customer-facing canceled-payment references may be retained where required for tax, accounting, fraud prevention, dispute handling, deletion integrity, or other legal obligations. Bakery customers should first contact the bakery that collected their order information; the bakery controls that customer relationship.

Contact

Questions or privacy requests can be sent to support@bakecadence.com. We may update this policy as the service changes and will post the revised effective date here.

© 2026 BakeCadence
TermsPrivacySupport