Astera

Privacy policy

Last updated 14 August 2026

Applicability

This policy explains how Astera Global Inc (“Astera”, “we”) handles personal data in connection with the Astera platform at astera.catering.

Astera is a business platform for catering operations. It is used by staff at organisations that hold an agreement with us, and accounts are created by an administrator rather than by signing up. Which role we play depends on the data:

  • We are the controller of the data we hold in order to run the platform: account and sign-in records, information about how the platform is used, technical logs, and our correspondence with you. This policy describes that processing.
  • We are a processor for the operational data a customer organisation puts into the platform, including data about their own customers, suppliers and staff. That organisation decides what goes in and why, and we process it on their instructions under our agreement with them. Their own privacy notice governs that data, so a request about it is best directed to them first. We will help them answer it.

Information we collect

Account and sign-in information

  • Your name, work email address, the role assigned to you, and the organisation and kitchens you have access to. This is entered by your administrator or taken from your invitation.
  • If you sign in with Google or Microsoft, we receive your name, email address and that provider's account identifier. We request only the scopes needed to identify you (openid, email, profile). We do not request or receive access to your mail, files, calendar or contacts.
  • If you sign in with an email link, we store a hashed single-use token that expires within ten minutes.
  • Session records: the sign-in cookie, and when a session was created, last used and ended. Where an Astera administrator accesses the platform as you in order to investigate a problem, that is recorded against both identities.

Information your organisation puts into the platform

Quotes, orders, recipes, catalogue and pricing records, purchasing records, and the activity log that attributes each change to the user who made it. This is mostly business data, but it includes personal data such as the names and contact details of customer and supplier contacts. We act as a processor for it, as described above.

Usage information, analytics and session recording

We collect information about how the platform is used, and this includes session recordings: a replay of the pages you visited and what you entered into them, linked to your account. We record this because the platform is used in working kitchens, where a slow or confusing screen has a real cost, and a recording is how we find it. Passwords are masked and are never recorded. Other form fields are not masked, so you should assume that what you type into the platform may be captured. We also collect error reports describing the technical details of a failure.

We do not use this information for advertising, we do not sell or share personal data, we do not use it to make automated decisions about you, and there is no third-party advertising or tracking technology on the platform.

Technical information

Our hosting and security infrastructure logs the ordinary technical details of a request, including IP address, browser and device type, timestamps and the pages requested. We use these to keep the platform available and to investigate faults and abuse.

How we use information

We use the information described above to:

  • authenticate you and apply the permissions your role grants;
  • provide, maintain and support the platform, and respond when you contact us;
  • maintain an audit trail of who changed what, which the platform relies on;
  • secure the platform, investigate suspected misuse, and diagnose and fix faults;
  • understand how the platform is used so that we can improve it;
  • comply with our legal obligations and enforce our terms.

Where the UK GDPR or EU GDPR applies to processing for which we are the controller, we rely on the performance of our contract with your organisation in order to give you an account and run the service, and on our legitimate interests in securing, supporting and improving a business tool for the people it is issued to. Where we rely on legitimate interests we have considered the effect on you, and you may object as described under Your rights.

How we disclose information

We do not sell personal data. We disclose it to service providers who process it on our behalf, under contract and only for the purposes we set. We name them rather than describing them in the abstract:

  • Vercel: application hosting, and storage for uploaded files such as logos and attachments.
  • Neon: the Postgres database. Our production database is hosted in the London (eu-west-2) region.
  • PostHog: product analytics, session recording and error tracking, on their EU hosting.
  • Resend: delivery and receipt of email, such as sign-in links.
  • Google and Microsoft: identity providers, where your organisation signs in through them.
  • Airtable: where an organisation is moving from an existing Airtable system, we read from it in order to bring that data across.

We may also disclose information to other companies in our group who help operate the platform; where we are required to by law or in response to a valid legal request; to establish or defend legal claims; and to a buyer or successor if the business is sold or reorganised, in which case this policy continues to apply to the data transferred.

Cookies and tracking

We set a cookie to keep you signed in, and our analytics provider sets cookies to link events from the same browser into a single session. Both are necessary to provide and operate the platform. There are no advertising cookies. Blocking cookies will prevent you from signing in.

International transfers

Some of our service providers are established in the United States and may process data there, or in other countries, on our behalf. Where personal data leaves the UK or the European Economic Area, the transfer relies on the safeguards in that provider's data processing terms, which include the European Commission's standard contractual clauses and the UK international data transfer addendum, together with any adequacy decision or certification that applies to them.

How long we keep information

  • Account records: for as long as your organisation uses the platform. When an administrator removes your access, the account is deactivated rather than erased immediately, because the activity log has to keep attributing past changes to a real person.
  • Sign-in tokens and sessions: minutes to weeks. Tokens are consumed on first use or expire; sessions end on sign-out or expiry.
  • Operational data: for as long as the customer organisation's agreement with us continues, and afterwards for the period set in that agreement. That organisation decides when data it controls is deleted.
  • Email sent to our addresses: retained as a business record, including message content and attachments, for as long as we need it to operate the service — for example to process the order, request or enquiry it contains and to keep an accurate history of that processing.
  • Analytics and session recordings: on our analytics provider's retention schedule, currently a rolling period of no more than twelve months for recordings.
  • Technical logs: a short rolling period, typically weeks.

We may keep information for longer where we need it in order to comply with a legal obligation or to establish or defend a legal claim.

How we secure information

Access is restricted by role, and every query is scoped to the organisation you are signed in to, so one customer's data is not reachable from another's account. Data is encrypted in transit, and encrypted at rest by our hosting and database providers. Passwords, where they exist, and sign-in tokens are stored hashed. Access to production systems is limited to the people who operate the platform. No system is perfectly secure, but where a breach affects your personal data we will notify the people and the regulators that the law requires us to.

Your rights

Depending on where you live, you may have the right to ask for a copy of the personal data we hold about you, to have it corrected or erased, to restrict or object to how we use it, to receive it in a portable form, and to withdraw consent where we relied on it. You also have the right to complain to a data protection authority; in the UK that is the Information Commissioner's Office.

If you are in California, or another US state with comparable law, you may have the right to know what personal information we collect and disclose, to request its deletion or correction, and not to be treated differently for exercising those rights. We do not sell personal information and we do not share it for cross-context behavioural advertising.

Write to privacy@astera.catering and we will respond within the period the applicable law allows, normally one month. We may need to verify your identity first. Where your request concerns data we process for your organisation as their processor, we will refer you to them and support them in answering it, because they decide what happens to that data.

Minimum age

The platform is a workplace tool and is not directed at children. We do not knowingly collect personal data from anyone under 16.

Changes to this policy

We may update this policy. The date at the top of this page shows when it last changed. Where a change materially affects how we use personal data, we will notify the affected organisations directly rather than relying on you revisiting this page.

Contact

Astera Global Inc, by email to privacy@astera.catering. If your account was issued by your employer, their administrator is usually the fastest route for questions about your access or about the data in their account.