Signing you in…

Privacy Policy

1. Information We Collect

IMPORTANT: This section describes all data we may collect. By using the Service, you consent to this data collection as described.

Local Storage Data: The following data is stored locally in your browser and never leaves your device unless you choose to export it or sign in:

  • Favorite recipes and collections
  • Meal plans and calendar entries
  • Grocery lists and shopping items
  • Recipe notes and personal modifications
  • Pantry ingredients
  • User preferences (units, theme, etc.)
  • Calorie tracking data and meal logs
  • Weight logs and health metrics
  • Family member information (if using Family Plan)
  • Budget tracking data
  • Water intake logs
  • Analytics and usage statistics
  • Search history and filters

Authentication Data: If you sign in with email or Google, we use Supabase for authentication. Your email address is stored securely with Supabase. We do not have access to your password (if applicable). Google OAuth provides us with your email and basic profile information only.

Subscription Data: When you subscribe, we collect and store:

  • Subscription plan type and status
  • Billing period (monthly/yearly)
  • Transaction IDs and payment history
  • Subscription start and end dates
  • Payment method type (not full card details)

Usage Data: We may collect anonymous usage statistics such as:

  • Features used and frequency
  • Recipe views and interactions
  • Search queries (anonymized)
  • App performance metrics
  • Error logs (without personal information)

Device Information: We may collect device information including:

  • Browser type and version
  • Operating system
  • Screen resolution
  • IP address (for security and analytics)

2. How We Use Your Information

We use your information to:

  • Provide and improve the Service
  • Personalize your experience (recommendations, preferences)
  • Authenticate your account and manage subscriptions
  • Process payments and manage billing
  • Sync your data across devices (when signed in)
  • Provide customer support
  • Analyze usage patterns to improve features
  • Send you important updates (if you opt in)
  • Detect and prevent fraud or abuse
  • Comply with legal obligations

We do NOT:

  • Sell your personal information to third parties
  • Use your data for advertising without consent
  • Share your recipe data, meal plans, or personal notes
  • Access your local storage data unless you sign in and sync

3. Data Storage

Local Storage: Most of your data (favorites, meal plans, grocery lists, notes, calorie logs, family data) is stored in your browser's local storage. This data is private to you and not transmitted to our servers unless you choose to sign in and sync.

Cloud Storage (Supabase): If you sign in, the following data may be stored securely with Supabase:

  • Authentication credentials (email, OAuth tokens)
  • User profile information
  • Subscription status and billing information
  • Synced data (if you choose to sync across devices)
  • A summarized taste profile for paying subscribers (inferred cuisines and meal types from your activity), stored as part of synced preferences when you qualify

Data Retention: We retain your data for as long as your account is active or as needed to provide services. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal purposes.

Data Backup: We recommend using the Export Data feature regularly to backup your information. We are not responsible for data loss due to browser data clearing, device failure, or other circumstances.

4. Third-Party Services

Supabase: We use Supabase for authentication and database storage. Your authentication data is handled by Supabase according to their privacy policy. Learn more at supabase.com/privacy.

Google OAuth: If you sign in with Google, Google handles the authentication process. We receive your email address and basic profile information. Your use of Google OAuth is subject to Google's Privacy Policy.

Payment Processors: We use Stripe, Paddle, and Paystack to process payments. These services collect and process payment information according to their privacy policies. We do not store full credit card numbers or CVV codes.

YouTube: We embed YouTube videos in our Cooking Skills feature. YouTube may collect usage data when you watch embedded videos. This is subject to YouTube's Privacy Policy and Terms of Service.

Analytics: We may use analytics services to understand how the app is used. These services collect anonymous usage data and do not identify individual users.

CDN and Hosting: Recipe images and static assets are served through content delivery networks (CDNs) which may log IP addresses for performance and security purposes.

5. Data Sharing and Disclosure

We do NOT sell your data: We do not sell, trade, or rent your personal information to third parties for marketing purposes.

Service Providers: We may share your information with trusted service providers who assist us in operating the app, including:

  • Payment processors (Stripe, Paddle, Paystack) - for billing
  • Authentication providers (Supabase, Google) - for sign-in
  • Hosting and CDN services - for app delivery
  • Analytics services - for understanding usage (anonymized)

Legal Requirements: We may disclose your information if required by law, court order, or government regulation, or to:

  • Comply with legal obligations
  • Protect our rights and property
  • Prevent fraud or abuse
  • Protect user safety

Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred to the new entity, subject to the same privacy protections.

Aggregated Data: We may share aggregated, anonymized data that does not identify individual users for analytics, research, or business purposes.

6. Your Rights and Choices

Access Your Data: You can access and export all your data at any time using the "Export All Data" feature in your Profile settings. This downloads a JSON file with all your information.

Modify Your Data: You can modify most of your data directly through the app settings, Profile page, or within individual features (meal plans, grocery lists, etc.).

Delete Your Data: You can delete your account and all associated data using the "Delete Account" feature in your Profile settings. This action is permanent and cannot be undone. We recommend exporting your data first.

Opt Out of Data Collection: You can use the app without signing in to minimize data collection. Most features work with local storage only. Signing in enables cloud sync and subscription features.

Cookie and Local Storage Control: You can clear your browser's local storage and cookies at any time through your browser settings. Note: This will delete all locally stored data including favorites, meal plans, and preferences.

Subscription Management: You can manage your subscription, update payment methods, and cancel at any time through your Profile → Billing Management page.

GDPR Rights (EU Users): If you are in the European Union, you have additional rights under GDPR:

  • Right to access your personal data
  • Right to rectification (correction)
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • Right to withdraw consent

CCPA Rights (California Users): If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information is collected
  • Right to know if personal information is sold or disclosed
  • Right to opt-out of sale of personal information
  • Right to access your personal information
  • Right to deletion
  • Right to non-discrimination for exercising your rights

To exercise any of these rights, please contact us at support@whts4dinner.com, through your Profile settings, or visit the Help page.

7. Data Security

Security Measures: We implement industry-standard security measures to protect your information:

  • Encryption in transit (SSL/TLS) for all data transmission
  • Secure authentication through Supabase
  • PCI DSS compliance for payment processing
  • Regular security audits and updates
  • Access controls and authentication requirements
  • Secure data storage with Supabase

Local Storage Security: Data stored locally in your browser is protected by your browser's security features. However, anyone with access to your device and browser can potentially access this data.

No Guarantee: While we implement reasonable security measures, no method of transmission over the internet or electronic storage is 100% secure. You use the Service at your own risk. We cannot guarantee absolute security.

Your Responsibility: You are responsible for:

  • Keeping your account credentials secure
  • Not sharing your account with others
  • Logging out on shared devices
  • Using strong, unique passwords (if applicable)
  • Keeping your device and browser secure

Data Breach: In the unlikely event of a data breach, we will notify affected users and relevant authorities as required by law.

8. Children's Privacy

Age Requirement: Our Service is not intended for children under 13 (or 16 in the EU). We do not knowingly collect personal information from children under the applicable age limit.

Family Plan: The Family Plan feature allows parents/guardians to manage family members including children. When you add a child to your Family Plan, you are responsible for their data and consenting on their behalf. We do not directly collect information from children.

Parental Rights: If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately. We will delete such information upon verification.

COPPA Compliance: We comply with the Children's Online Privacy Protection Act (COPPA) and do not knowingly collect information from children under 13 without parental consent.

9. International Data Transfers

Data Location: Your data may be stored and processed in countries other than your country of residence. By using the Service, you consent to the transfer of your information to these countries.

EU Users: If you are in the European Union, we ensure appropriate safeguards are in place for data transfers, including standard contractual clauses and adequacy decisions.

Data Processing: Supabase and other service providers may process your data in various locations. We ensure they comply with applicable data protection laws.

10. Cookies and Tracking Technologies

Local Storage: We use browser local storage to save your preferences, favorites, and other data. This is not the same as cookies but serves a similar purpose.

Session Storage: We use session storage for temporary data that is cleared when you close your browser.

Third-Party Cookies: Third-party services (payment processors, analytics) may set cookies. These are subject to their respective privacy policies.

Do Not Track: We respect "Do Not Track" browser settings where technically feasible.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by:

  • Posting the new Privacy Policy on this page
  • Updating the "Last updated" date
  • Sending an email notification (if you're subscribed)
  • Displaying a notice in the app for significant changes

Continued Use: Your continued use of the Service after changes become effective constitutes acceptance of the updated Privacy Policy. If you do not agree with the changes, you should stop using the Service and delete your account.

12. Payment Data

Payment Information: When you subscribe to a paid plan, we collect payment information through our payment processors (Stripe, Paddle, Paystack). We do not store your full credit card number, CVV, or other sensitive payment details on our servers. Payment data is handled securely by our payment processors according to PCI DSS standards.

Billing Information: We may collect and store billing information such as billing address, payment method type (credit card, PayPal, etc.), and transaction history. This information is used to process payments and provide you with billing history.

Payment Processor Data Sharing: Your payment information is shared with our payment processors to process transactions. These processors have their own privacy policies and security measures. We recommend reviewing their privacy policies:

  • Stripe: stripe.com/privacy
  • Paddle: paddle.com/privacy
  • Paystack: paystack.com/privacy

13. Payment Security

Security Measures: We implement industry-standard security measures to protect your payment information. All payment transactions are encrypted using SSL/TLS technology. We comply with PCI DSS requirements for handling payment card data.

No Storage of Sensitive Data: We do not store your full credit card number, CVV, or PIN on our servers. All sensitive payment data is handled exclusively by our PCI-compliant payment processors.

14. Data Retention

Active Accounts: We retain your data for as long as your account is active or as needed to provide services to you.

Deleted Accounts: When you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for:

  • Legal compliance and obligations
  • Dispute resolution
  • Enforcement of agreements
  • Fraud prevention

Backup Data: Deleted data may persist in backups for up to 90 days before being permanently deleted.

Anonymized Data: We may retain anonymized, aggregated data that does not identify you for analytics and business purposes indefinitely.

15. Special Categories of Data

Health and Medical Data: The app may collect health-related information such as:

  • Calorie intake and meal logs
  • Weight and BMI data
  • Allergy and dietary restriction information
  • Family member health data (Family Plan)

Consent: By using features that collect health data, you consent to the collection and processing of this information. You can stop using these features or delete your data at any time.

Protection: We treat health-related data with extra care and security. However, this data is NOT protected health information (PHI) under HIPAA, as we are not a healthcare provider.

Not Medical Records: This data is for personal tracking purposes only and does not constitute medical records. We are not a healthcare provider and this data is not subject to medical privacy laws like HIPAA.

16. Contact Us

The Service is operated by Whts4Dinner Limited (company number 9395904, NZBN 9429053357120), a New Zealand limited company. Our registered office address is available on the New Zealand Companies Register. For all inquiries, please use the contact details below.

If you have any questions about this Privacy Policy, please visit the Help page or contact us at support@whts4dinner.com or through your Profile settings.

Data Protection Officer: For privacy-related inquiries, you may contact us at: support@whts4dinner.com.

Response Time: We will respond to privacy inquiries within 30 days as required by applicable law.

17. Your Consent

BY USING THE SERVICE, YOU EXPLICITLY CONSENT TO:

  • The collection, use, and processing of your information as described in this Privacy Policy
  • The transfer of your data to servers and service providers located in various countries
  • The use of cookies, local storage, and similar technologies
  • Receiving important service-related communications
  • Our data retention practices as described herein

You may withdraw your consent at any time by deleting your account and discontinuing use of the Service. However, withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.