A privacy checklist draft for the customer data we hold: online preorders through Square, a loyalty sign-up sheet at the counter, a Mailchimp newsletter, and catering inquiries that arrive by email. Show where each lives, who can see it, and how long we keep it.
What is missing today
This is a draft starting point. Review and adapt before use. Not legal, financial, or compliance advice.
Owner: Owner/manager · Review: every 3 months
| Data | Where it lives | Who can see it | Keep for |
|---|---|---|---|
| Online preorders (name, phone, order) | Square | Owner, shift leads | Square's records; export only what you need |
| Loyalty sign-ups (name, email) | Paper sheet at the counter → typed into Mailchimp weekly | Owner | Shred the sheet once typed in |
| Newsletter list | Mailchimp | Owner | Until the person unsubscribes |
| Catering inquiries | Bakery email inbox | Owner, catering lead | 12 months after the event, then delete |
If a sheet is lost or an account is used by someone who should not have access, write down what happened and when, change the passwords, and ask an advisor whether customers need to be told.
[End of draft. Customize this document before sharing or publishing it.]
Next 90 days
Example drafts in the AI Orchestrator's format (2026-10-05).
Join the waitlist: 30% off Pro for your first 12 months
Get drafts like these for your own business when Pro opens.
Join the waitlist