1. Who this policy covers
Soupy is operated by Filly Campbell and provides software for hospitality organisations. This policy explains how personal information is handled through our website, accounts, connected services and workspaces. You can contact us at filly@soupy.ai.
When a venue, employer or other organisation uses Soupy to manage its customers, staff, bookings or messages, that organisation decides why it uses those records. Soupy processes those records on its behalf. Its own privacy notice also applies. Please contact the organisation first about a booking, purchase, employment record or message it holds; we can help route a request if needed.
Soupy is responsible for information we use to administer our own service relationships, handle enquiries and protect the service.
2. Information we handle
The information depends on the features you or your organisation use:
- Account and contact details, organisation membership, roles and permissions.
- Records entered into a workspace, such as customer enquiries, bookings, ticket orders, contact preferences and staff information.
- Connected-service information, including the Gmail information described below, and payment or delivery references returned by providers.
- Support correspondence, security and audit events, and technical information needed to operate and diagnose the service.
Information may come from you, your organisation, someone contacting that organisation, or a service the organisation has connected. Information required for a feature must be provided for that feature to work. Connecting Gmail and using AI assistance are optional.
3. Why we use information
We use information to provide the features requested, maintain accounts and permissions, respond to support and privacy requests, protect the service, investigate problems and meet applicable legal obligations. Customer workspace information is processed according to the customer organisation's instructions and enabled features.
For processing for which Soupy is responsible, the relevant legal basis depends on the purpose: performing a contract with you, legitimate interests in running and securing our service and responding to enquiries, compliance with law, or consent where required. A customer organisation is responsible for the legal basis for its own customer and staff records. Authorising Google access does not itself create permission to send marketing emails.
4. Your Gmail connection
When you connect a mailbox, Google asks you to authorise Soupy to read email and send messages on your behalf. Basic Google account information identifies the mailbox being connected. Soupy receives an access credential, not your Google password, and stores the refresh credential encrypted so synchronisation can continue while you are away.
Soupy imports email into the connecting organisation's shared Inbox. Staff with permission to use that Inbox can access its conversations; access is not limited to the person who connected the mailbox. Only connect a mailbox you are authorised to share with that organisation.
Imported information includes sender and recipient details, subjects, message text, previews, dates, thread identifiers and attachment metadata. Soupy also stores the mailbox address, Google account identifier, granted permissions and connection and sync records. Supported attachments are retrieved from the provider when an authorised user requests a download.
This information supports reading, assigning and responding to conversations. An email may be matched to an existing customer in the same organisation. Reviewed actions can link an enquiry to a booking or other enabled operational record. Approved replies are sent through the connected Gmail account.
Google data: limited use
Soupy's handling of information obtained through Google Workspace APIs follows the Google Workspace API User Data and Developer Policy, including its Limited Use requirements. We use this information for the requested, visible features. We do not sell it, use it for advertising or credit decisions, or use it to train general-purpose AI models.
5. Optional AI features
If an authorised user requests an AI reply draft, booking extraction or help from Soupy Assistant, relevant conversation content and authorised workspace records needed for that request are sent to OpenAI to generate an answer or suggestion. That content may contain personal information from email or workspace records. Prompts, generated suggestions and related records are stored with the workspace's AI activity. Manual reading and replies do not require using these AI features.
AI suggestions can be incorrect. A user reviews a reply before sending it and explicitly confirms a supported Booking or Event proposal before it is created. Event drafts are published separately. These features do not make decisions with legal or similarly significant effects on people without human involvement. Soupy does not use Google-derived information to train general-purpose models.
7. Retention and deletion
Workspace records, imported messages, drafts and AI activity are retained to provide the customer organisation's service. The retention criteria are the organisation's instructions, whether the records remain needed for that service, applicable legal obligations and the handling of outstanding requests or disputes. There is currently no automatic age-based deletion of imported Gmail messages. The initial email import window is not a deletion schedule.
Closing a conversation, disabling a mailbox or revoking Google access does not erase information already imported into Soupy. Revocation stops ongoing Google access once existing access tokens are invalidated; stored Soupy records need a separate deletion request.
Stop Google access
Open your Google Account connections, select Soupy and remove its access. You can also ask your organisation's administrator for assistance.
Request deletion of information held in Soupy
Email filly@soupy.ai with the organisation, connected mailbox and records your request concerns. Do not send passwords or access tokens. We will verify your identity and authority, coordinate with the organisation where it controls the records, and explain the outcome and any lawful retention requirement. A Gmail-data request can include imported messages, connection credentials and related AI records.
8. Security and service locations
Soupy uses authenticated accounts, organisation-scoped permissions and encrypted storage of Gmail refresh credentials. Access controls are designed to keep one organisation's workspace separate from another's. No system can guarantee absolute security.
Hosting and service providers may process information in countries outside the United Kingdom. Contact us for the processing locations and transfer arrangements relevant to your organisation and enabled services. We do not represent all workspace data as UK-only.
Account services use cookies or similar storage to maintain sign-in, security and preferences. Browser controls can restrict these technologies, but doing so may prevent account features from working. Customer organisations are responsible for notices and choices for tracking they enable on their own sites.
9. Your rights and choices
Depending on the applicable law and processing purpose, you can request access, correction, deletion, restriction or a portable copy of your personal information. You can withdraw consent for processing that relies on consent without affecting processing already carried out lawfully.
Your right to object
You can object to processing based on legitimate interests and to the use of your information for direct marketing. Contact us at filly@soupy.ai. For records controlled by a venue or employer, we will direct the request to that organisation or assist it in responding.
You can raise a concern with us or complain to the UK Information Commissioner's Office, or the data protection authority where you live or work.
10. Contact and policy changes
For privacy questions or requests, email filly@soupy.ai. Include enough information to identify the service or organisation involved, without sending unnecessary sensitive information.
We update this page when our practices change and show the revision date above. Where a change requires a separate notice or consent, we will provide it before applying that change to your information.