Picnic Privacy Policy

Last Updated: 13 June 2026

1. Introduction

This Privacy Policy explains how Picnic ("we", "our", "us") collects, uses, stores, and protects personal information when providing the Picnic platform.

We are committed to protecting privacy and complying with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable privacy laws.


2. Who This Policy Applies To

This Policy applies to:

  • Customers using Picnic
  • Employees of Customer organisations
  • Managers and administrators
  • Loyalty programme users
  • Website visitors
  • Mobile application users

3. Data Controller and Data Processor Roles

For Customer business data:

  • The Customer is generally the Data Controller.
  • Picnic acts as a Data Processor.

For account, billing, and platform administration data:

  • Picnic acts as a Data Controller.

4. Information We Collect

Account Information

  • Names
  • Email addresses
  • Telephone numbers
  • User roles
  • Login credentials

Employment Information

Where entered by Customers:

  • Employee names
  • Contact details
  • Payroll information
  • Scheduling information
  • Attendance records
  • Training records
  • Holiday records
  • Absence records

Customer and Loyalty Information

Where applicable:

  • Customer names
  • Contact information
  • Loyalty balances
  • Transaction histories
  • Marketing preferences

Technical Information

  • IP addresses
  • Device identifiers
  • Browser information
  • Operating system information
  • Application usage logs
  • Error logs

Local Server Information

Where Local Servers are installed:

  • Server identifiers
  • Synchronisation status
  • Software versions
  • Diagnostic information
  • Connectivity information

5. How We Use Information

We use personal information to:

  • Provide Picnic services
  • Authenticate users
  • Process transactions
  • Manage schedules
  • Support payroll functions
  • Deliver learning content
  • Provide loyalty functionality
  • Maintain security
  • Diagnose technical issues
  • Improve the platform
  • Respond to support requests
  • Comply with legal obligations

6. Lawful Bases for Processing

Depending on the circumstances, processing may be based on:

  • Contractual necessity
  • Legitimate interests
  • Legal obligations
  • Consent
  • Employment-related obligations

7. Sharing Information

We may share information with:

Service Providers

Including providers of:

  • Cloud hosting
  • Email delivery
  • SMS delivery
  • Payment processing
  • Data storage
  • Analytics
  • Monitoring

Legal Authorities

Where required by law or regulatory obligations.

Customer Organisations

Employees and users access data under the authority of their employer or organisation.

We do not sell personal information.


8. International Transfers

Data may be processed outside the United Kingdom.

Where this occurs, we implement appropriate safeguards including:

  • Adequacy regulations
  • Standard contractual clauses
  • Equivalent legal protections

9. Data Retention

We retain personal information only for as long as necessary.

Retention periods vary according to:

  • Legal obligations
  • Employment requirements
  • Accounting requirements
  • Customer instructions
  • Operational requirements

Following termination, data may be retained for backup, legal, or compliance purposes before deletion.


10. Security

We implement appropriate technical and organisational measures including:

  • Encryption in transit
  • Access controls
  • Authentication systems
  • Audit logging
  • Security monitoring
  • Software updates
  • Backup procedures

No internet-based system can be guaranteed completely secure.


11. Cookies and Similar Technologies

Picnic websites and applications may use:

  • Essential cookies
  • Authentication cookies
  • Preference cookies
  • Analytics technologies

Customers may manage cookie preferences through browser settings where applicable.


12. Mobile Applications

Picnic mobile applications may request access to:

  • Camera
  • Photo library
  • Notifications
  • File storage
  • Device identifiers

Permissions are requested only when required for functionality.


13. Employee Data

Where Customers use Picnic for HR, payroll, scheduling, attendance, or learning management:

  • Customers remain responsible for ensuring a lawful basis for processing employee data.
  • Picnic processes such information on behalf of the Customer.

Employees should contact their employer regarding questions about workplace data processing.


14. Your Rights

Subject to applicable law, individuals may have rights to:

  • Access personal information
  • Correct inaccurate information
  • Delete personal information
  • Restrict processing
  • Object to processing
  • Data portability
  • Withdraw consent

Requests should normally be directed to the relevant Customer organisation where Picnic acts as a processor.


15. Automated Decision Making

Picnic may provide recommendations, forecasts, scheduling suggestions, labour calculations, or AI-assisted features.

Final decisions remain under the control of Customer users.

Picnic does not make legally binding employment decisions without human involvement.


16. Children's Privacy

Picnic is not intended for use by children under the age of 13.

Where Customers employ younger workers, processing occurs under the authority and responsibility of the Customer organisation.


17. Changes to this Policy

We may update this Privacy Policy periodically.

Updated versions will be published through the Service and will take effect upon publication unless otherwise stated.


18. Contact

Questions regarding this Privacy Policy or data protection matters should be directed to the contact details published on the Picnic website.

Individuals also have the right to complain to the UK Information Commissioner's Office (ICO).

Website: https://ico.org.uk