Privacy Policy
Last updated: [LAST UPDATED] · Effective: [EFFECTIVE DATE]
Draft — not legal advice. Review with a privacy attorney before use, and confirm it matches your production integrations. GDPR/UK‑GDPR, CCPA/CPRA, and other laws impose specific requirements not fully resolved in this template.
[COMPANY LEGAL NAME] ("[PLATFORM NAME]," "we," "us") provides a marketplace connecting customers with cooks, teams, and food companies. This Privacy Policy explains what personal information we collect, how we use and share it, and your choices and rights.
1. Information we collect
You provide to us:
- Account & profile — name, email, password (stored only as a secure hash), and optional profile photo. If you sign in with Google, Facebook, or Microsoft, we receive basic profile information from that provider.
- Contact & verification — email (verified via link) and, for vendors, a phone number (verified via SMS code).
- Addresses — your saved delivery address; vendors' business addresses. Each order stores a snapshot of its delivery address so later edits don't rewrite past orders.
- Vendor/business information — display name, bio, dish listings, prices, availability, credentials, and (for companies) outbound links.
- Payment information — processed by Stripe. We do not store full card numbers; we receive limited transaction data (e.g., status, amounts, and processing‑fee details) and, for vendors, Stripe Connect account identifiers and payout status.
- Communications & bookings — messages you exchange with other users, and reservation/catering details (times, attendee counts, dish selections).
- Media — photos and videos you upload for listings/profiles.
- Reviews & ratings you submit.
- Support & other — information you provide when contacting us or reporting issues.
Collected automatically:
- Device & usage data — IP address, browser/device type, pages and actions, and timestamps (server logs).
- Approximate location — we may derive an approximate location from your IP to show nearby listings; vendor listing locations are geocoded from the address the vendor provides.
- Cookies & similar technologies — see the Cookie Policy.
From third parties: OAuth login providers; our payment processor; delivery providers (delivery status); and, if you connect a calendar, your calendar provider (via tokens you authorize).
We do not intentionally collect special‑category data. Please don't send us sensitive information except what's necessary (e.g., dietary/allergen notes you choose to include for an order).
2. How we use information
- Provide and operate the Platform: accounts, listings, discovery/search, ordering, reservations and catering, messaging, delivery coordination, reviews, and notifications.
- Process payments and vendor payouts, calculate fees and taxes, and manage refunds, disputes, and chargebacks.
- Verify identity/eligibility (email, phone), prevent fraud and abuse, enforce our policies, and keep the Platform secure.
- Communicate with you — transactional email/SMS (e.g., verification, order and reservation updates, catering confirmations) and, where permitted, service or marketing messages you can opt out of.
- Improve, debug, and develop the Platform (analytics, error tracking).
- Comply with law and enforce our agreements.
Legal bases (GDPR/UK‑GDPR) where applicable: performance of a contract; legitimate interests (security, improvement, preventing fraud); consent (e.g., certain cookies/marketing); and legal obligation. You may withdraw consent at any time.
3. How we share information
- Between users to complete transactions. To fulfill an order, reservation, or catering booking, we share the information necessary with the other party — for example, a vendor receives the customer's name, delivery address, order/catering details, and, on a confirmed catering booking, a copy of the conversation and the agreed plan; a customer sees the vendor's public profile and location.
- Service providers ("processors"). Companies that help us run the Platform, under contract and limited to our instructions — for example: Stripe (payments and payouts); delivery providers you select (e.g., courier and parcel carriers) to dispatch and track deliveries; email and SMS providers for transactional messages; mapping/geocoding providers to place addresses; cloud hosting and object storage for the app and media; and, if enabled, analytics/error‑tracking providers.
- Legal and safety. When required by law or to protect rights, safety, and the integrity of the Platform.
- Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
- With your direction or consent.
We do not sell your personal information for money. Some sharing for analytics or advertising may be considered a "sale" or "sharing" under certain U.S. state laws — where it is, we honor opt‑out rights (see Section 6). [Confirm based on the trackers you actually deploy.]
4. Retention
We keep personal information for as long as your account is active and as needed to provide the Platform, then retain what we must for legitimate business, tax, accounting, dispute‑resolution, fraud‑prevention, and legal purposes (for example, transaction and payout records). We delete or de‑identify information when it is no longer needed, subject to backups.
5. Security
We use technical and organizational measures to protect personal information (for example, encrypted passwords, restricted access, and use of a PCI‑compliant payment processor). No system is perfectly secure; we cannot guarantee absolute security.
6. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to the processing of your personal information, to opt out of certain sharing or targeted advertising, and to withdraw consent. California residents (CCPA/CPRA) may request access/deletion/correction, opt out of "sale"/"sharing," and are entitled to non‑discrimination for exercising rights.
- Manage much of your information in your account settings (profile, address, notifications, connected logins/calendars).
- To exercise other rights, contact [privacy@…]. We will verify your request and respond within the timeframes required by law. You may use an authorized agent where permitted.
- You can unsubscribe from marketing messages via the message or your settings; transactional messages are necessary to provide the service.
- We honor recognized browser opt‑out signals (e.g., Global Privacy Control) where required.
If you are in the EEA/UK and have concerns, you may also lodge a complaint with your local supervisory authority.
7. Children
The Platform is not directed to children under [MINIMUM AGE / 13], and we do not knowingly collect their information. If you believe a child provided us information, contact [privacy@…] and we will delete it.
8. International transfers
We may process and store information in [COUNTRY/REGION] and other countries. Where we transfer personal information across borders, we use appropriate safeguards (e.g., Standard Contractual Clauses) where required.
9. Third‑party links and services
The Platform links to and integrates third‑party services (payments, delivery, login, calendars, and vendors' own external links). Their privacy practices are governed by their policies, not this one.
10. Changes
We may update this Policy; we'll post the new version with an updated date and, for material changes, provide additional notice.
11. Contact
Privacy contact / Data Protection Officer: [DPO / PRIVACY CONTACT] · [privacy@…] · [COMPANY LEGAL NAME], [MAILING ADDRESS]. [If you serve the EU/UK, name an EU/UK representative here if required.]