Privacy Policy

Last updated 29 September 2026

In short: The Mise is a private, code-gated tool built for the venues that use it, not a public app with open sign-up. We collect only what running a kitchen's prep book, compliance records and guest allergen page requires, we don't sell it or use it for advertising, and the guest-facing allergen page collects nothing about the guest at all. Full detail below.

1. Who this covers

This policy covers themise.com.au and everything served from it: the public homepage, the staff prep-book app, the compliance records app, and the guest-facing allergen and dietary page, for every venue running The Mise. It's operated by The Mise, based in Byron Bay, New South Wales ("we", "us"). If a particular venue has its own privacy arrangements with its staff, this policy sits alongside those, not in place of them.

2. Information we collect

To open the book. A staff code or chef passcode, entered on a device. There's no open sign-up and no email-and-password account — access is by code. A venue can record a staff member's name against their own code, so edits and sign-offs show who made them.

What gets recorded once inside. Depending on which part of The Mise is being used:

The guest allergen and dietary page. This page is read-only and doesn't ask a guest for anything — no form, no account, no cookie set on their device. It simply displays information the venue has entered about a dish.

Wedding and event planner. When a couple uses their venue's wedding drinks planner, it keeps what they enter — names, wedding date, contact number, email address and drinks choices — so the venue can prepare their order, and emails a copy of the docket when they ask it to.

The Plate. A mystery-shopper report records the reviewer's scores and comments. Their name is optional and isn't shown to the venue.

The public homepage. As at the date above, themise.com.au's homepage runs no analytics, advertising or tracking scripts of any kind — no cookies are set here either. If that changes, this policy will change with it and say so plainly.

3. How we use it

To run the service: showing the right venue's book to the right device, keeping compliance records intact and exportable, and surfacing permit reminders before they lapse. We don't use venue data to advertise to anyone, we don't sell it, and we don't hand it to a third party except where section 4 says so.

4. Who else sees it

The Mise is hosted on Netlify (including Netlify Blobs for storage) and its infrastructure providers, who process data on our behalf under their own security commitments and never on their own account. Three other services handle specific tasks: when a chef imports a menu or recipe document, its contents are sent to Anthropic's Claude API to be read and turned into recipes; emails (wedding dockets, reviewer invites, training sign-offs and backup alerts) are sent through Resend; and once a night a backup copy of each venue's recipes, allergen register, prep lists, specials, food safety records and wedding orders is saved to a Google Drive account belonging to The Mise, through Google's API, so the service can be restored if its primary storage is ever lost. Staff codes and PINs are never included in that backup. None of these services uses that data for its own purposes. We don't use payment processors or marketing platforms — if we add a service that sees venue or guest data, this section will name it before it happens, not after.

5. Access within a venue

A staff code opens read access to that venue's book. A separate chef passcode is needed to write or edit anything, and can also read. A code only opens its own venue — it has no reach into any other venue's records. Repeated failed attempts are rate-limited.

6. How long we keep it

Compliance records are kept for as long as the food safety laws and local council requirements a venue operates under require it to keep them — this varies by state and by council, and it's the venue's responsibility to know its own retention period. We don't delete a month's records while anyone could still reasonably be asked to produce them. Once a record is no longer required to be kept, we take reasonable steps to delete or de-identify it.

7. Your rights

Under the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles, you can ask what personal information we hold about you and request a correction. Contact us using the details below and we'll respond within a reasonable time, generally within 30 days. If you're not satisfied with our response, you can raise a complaint with the Office of the Australian Information Commissioner (oaic.gov.au).

8. Security

Access is gated by code, sessions are signed and expire, and failed sign-in attempts are rate-limited. No method of transmission or storage is completely secure, and we can't guarantee absolute security — but we take reasonable, industry-standard steps to protect what's recorded.

9. Children

The Mise is a workplace tool for hospitality staff and isn't directed at children. The guest allergen and House Dishes pages are informational only and don't collect anything from anyone who views them, including a child.

10. An important limitation

The Mise is a record-keeping and operations tool. It does not itself guarantee that a venue is complying with food safety law, replace the judgement of a qualified food safety professional, or account for every local council requirement. Nothing here overrides your rights under the Australian Consumer Law.

11. Changes to this policy

If we materially change what we collect or how we use it, we'll update this page and change the date at the top. Significant changes will be flagged to venues directly.

12. Contact us

Questions about this policy, or a request about your information: hello@themise.com.au.