Privacy & cookie policy
Last updated 19 August 2026.
What we collect
If you post a brief: your name, email, phone number if you give one, and the event details you enter. If you register: the same, plus a password stored as a PBKDF2 hash — we never hold the password itself.
If you list a catering business: your business details, contact details and service capabilities, all of which appear on your public profile.
Message content is stored so both parties can read the thread. Treat it as you would any hosted inbox.
What we do not collect
We do not run analytics, advertising or third-party tracking, and there are no tracking cookies on this site. Card details are entered on Stripe's own pages and never reach FeastMatch.
Cookies
One cookie, fm_session, which keeps you signed in. It is HttpOnly, Secure and SameSite=Lax, and it expires after fourteen days. Operators may also hold fm_admin. Neither is used for tracking, so there is no consent banner to click.
Who else sees your data
Caterers you are matched with see your brief and your messages. Stripe processes payments and receives the amount, the booking reference and your email address. Cloudflare hosts the site and its database. Nobody else.
How long we keep it
Briefs and threads until you ask us to delete them. Transaction records for six years, which is the UK statutory retention period for financial records.
Your rights
Under UK GDPR you may request access, correction, deletion or a copy of your data. Email hello@brandwest.co.uk. You may also complain to the Information Commissioner's Office.