Bottle Trust Centre
Bottle is made by Sorteo Ltd, a company registered in England and Wales. We look after the records a distributor trusts us with: customers, orders, deliveries, cash and invoices.
Security is part of how Bottle is built, from how people sign in to how backups are kept. The documents below set out the detail for anyone choosing Bottle or reviewing it as a supplier.
Documents are shared under a short NDA. Access lasts 30 days.
- Hosted in Europe and the UK
- Two-step sign-in for all staff
- Backed up twice a day
- Staff access with your say-so
Last updated 30 September 2026
Questions about security? Email security@getbottle.app.
Compliance
The laws and rules we work to. We follow them; we do not claim a certificate for them.
- We follow
UK GDPR and the Data Protection Act 2018
We are the processor for the records your business keeps in Bottle, and the controller for our own. A data processing agreement is available on request.
- We follow
PECR
No advertising or tracking cookies, on our website or in the app. The only cookies Bottle sets are ones it needs to work, such as keeping you signed in.
- We follow
HMRC record keeping
Invoices, orders and cash records are kept for six years, as the tax rules require, and nothing is kept longer than it needs to be.
Documents
Detailed documents for security reviews and supplier questionnaires.
Hosting and data location
Where the app, the database, files and backups are kept, and who provides each.
Under NDARequest accessBackups and recovery
How often we back up, how backups are protected, and how a restore works.
Under NDARequest accessAccess to customer data
When Bottle staff can see inside a business, how that is granted, and what is recorded.
Under NDARequest accessApplication security
Sign-in, sessions, rate limits, uploads, keys and how we test the API.
Under NDARequest accessData protection
Who is controller and who is processor, retention, erasure and our sub-processors.
Under NDARequest accessIncident response
How we handle a security incident and how we keep you told.
Under NDARequest accessNon-disclosure agreement
The short agreement you accept before reading. Read it any time.
PublicRead
Security controls
What we do to keep your data safe. The documents under NDA go into the detail.
Infrastructure security
- The app and database run in an EU data centre; files and backups are kept in London.
- The database is not reachable from the internet.
- Every connection is encrypted with HTTPS, and browsers are told to use nothing else.
Data security
- The database is backed up twice a day, and every uploaded file is copied to a backup.
- Backups are kept apart from the systems that run Bottle and used only to recover from a failure.
- Uploaded files and backups are encrypted at rest.
Access control
- Support staff see inside your account only when you allow it, for a day or a week. The rare exception is recorded with a written reason.
- Bottle staff cannot reach the staff console without two-step sign-in.
- Owners, admins and drivers each see only what their role allows; drivers see their own round.
Application security
- Passwords are at least 12 characters and stored only as a one-way hash.
- Anyone can turn on two-step sign-in, with an authenticator app or codes by email.
- Sign-in attempts are limited, and each business has its own request allowance.
Monitoring and incident response
- Everything staff do in the console, and inside an account, is written to a log that is never deleted.
- A written process for incidents: contain, understand, fix, tell the people affected, learn.
- If an incident touches your data, your owners are told by email what happened and what to do.
Organisational security
- Made and run by Sorteo Ltd, registered in England and Wales.
- Your data is never used for our own purposes, including training AI models.
- We do not sell personal data or share it for anyone else's marketing.
Subprocessors
The companies that handle data for Bottle, what for and where.
| Company | What for | Where |
|---|---|---|
| Hetzner Online GmbH | Hosting the app and its database | Germany or Finland |
| Amazon Web Services | Uploaded files and backups | London |
| Cloudflare | Domains, our website, its form and visit counts | Global |
| Resend | Sending email | United States company |
| Stripe | Bottle's subscription billing | International |
| Stripe Connect | Card payments, when a business switches them on | UK accounts |
| Xero | Accounting sync, when a business connects it | Set by Xero |
| Apple Push Notification service | Notifications to the iPhone driver app | Global |
| Firebase Cloud Messaging | Notifications to the Android driver app | Global |
| postcodes.io | Turning a postcode into a point on the map | Not fixed |
The full list, with what reaches each one, is on our third parties page.
Updates
Recent changes to how Bottle looks after data.
30 September 2026
Trust centre opened
Our security documents are now available here, under a short NDA.
30 September 2026
Files and backups move to London
Uploaded files and backups are now held with Amazon Web Services in London, and backups are kept for 90 days.
30 September 2026
Backups twice a day
The database is now backed up twice a day, up from once.
30 September 2026
How the office uses Bottle
We now record which pages signed-in office users open, without cookies, to see where people get stuck.
28 September 2026
Policies published
Our terms, privacy policy and third parties page were first published.
Frequently asked questions
Who can read the documents?
Anyone with a good reason, such as choosing a supplier or a security review. You accept the NDA, confirm your email address, and someone at Bottle approves your request. Bottle customers can fill the request in from their account.
How long does access last?
30 days from when it is given. After that you can ask again at any time.
How is the NDA signed?
You tick the box on the request form, then confirm your email address with the link we send. It counts from then, and we email you a PDF copy with a certificate of your acceptance.
Where is our data stored?
The app and its database are in an EU data centre, in Germany or Finland. Uploaded files and backups are in London.
Can Bottle staff see our customers?
Only when an owner or admin of your business allows it, for a day or a week. The rare emergency exception needs a written reason and is recorded.
Do you have a data processing agreement?
Yes. Ask for one at privacy@getbottle.app.
Do you use our data to train AI?
No. We use your data only to run Bottle for you.
How do we report a security problem?
Email security@getbottle.app. A person reads it and will reply to say we are looking.