Privacy Policy
Effective: 15 March 2026 · Last updated: 6 April 2026
Plateful ("we," "our," or "us"), based in Bengaluru, India, is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share your information when you use our mobile app and website (plateful.live), in compliance with the Digital Personal Data Protection Act, 2023 (DPDPA) and other applicable laws.
1. Data We Collect
1.1 Account Information
- Google Sign-In: Your Google account name, email address, and profile picture
- Profile details: Any additional information you provide in your Plateful profile (e.g. food preferences, dietary restrictions)
1.2 User-Generated Content
- Dish posts, ratings, reviews, and photos you share on Plateful
- Saved dishes and collections
1.3 Location Data
- GPS-based location data to show you relevant dishes and restaurants near you (with your permission)
1.4 Behavioural Data
- Viewing history, dish saves, and interaction patterns used to build your taste profile and personalise your feed
1.5 Website Data
- Contact form: Name, email address, and message content
- Account deletion requests: Email address and optional reason
- Device type, browser type, operating system, IP address, and approximate location (city level)
2. How We Use Your Data
- To personalise your dish feed based on your taste profile
- To show you relevant dishes and restaurants near your location
- To enable social features (following friends, sharing recommendations)
- To respond to support queries and suggestions
- To process account deletion requests
- To improve our app and website
- To analyse usage patterns and app performance
3. Legal Basis for Processing (DPDPA Compliance)
We process your personal data based on your explicit consent, obtained through affirmative action (signing in with Google, granting location permission, or submitting forms on our website). You have the right to withdraw consent at any time by contacting us.
4. Data Storage and Security
- Your data is stored securely on Supabase infrastructure. Servers may be located in the US or EU data centres.
- We implement encryption in transit (TLS) and at rest.
- Access to personal data is restricted to authorised personnel only.
- The app uses on-device storage (AsyncStorage) for session management — we do not use browser cookies in the mobile app.
- Images uploaded to Plateful are stored publicly and do not require authentication to access.
5. Third-Party Services
We do not sell your personal data. We may share data with the following service providers, only to the extent necessary to provide our services:
- Google: Sign-In authentication and Google Places API for restaurant data
- Supabase: Database hosting
- Firebase: App infrastructure and push notifications
- Vercel: Website hosting
- Google Analytics: Website analytics (website only)
6. Your Rights Under DPDPA
As a data principal, you have the right to:
- Access: Request information about your personal data we hold
- Correction: Request correction of inaccurate data
- Erasure: Request deletion of your personal data
- Withdraw consent: Withdraw your consent at any time
- Grievance redressal: File a complaint with our Grievance Officer
7. Account Deletion
You can request account deletion through the app or by visiting plateful.live/delete-account. Upon deletion, your profile, posts, and activity history will be deleted within 7 days. Certain logs and records may be retained for legal and security compliance.
8. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law.
9. Children's Data
Plateful is not intended for users under the age of 13 (or 16 in the EU). We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will delete it promptly.
10. Cookies and Analytics
Our mobile app does not use cookies — it uses on-device AsyncStorage for session management. Our website (plateful.live) may use Google Analytics and Vercel Analytics, which may use cookies or similar technologies. You can disable cookies through your browser settings.
11. Grievance Officer
For any data privacy concerns or to exercise your rights, please contact our Grievance Officer:
Email: vedantchandak1706@gmail.com
Response time: Within 30 days of receiving your request
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes through the app or our website. Your continued use of our services after changes constitutes acceptance of the updated policy.
13. Contact Us
If you have questions about this Privacy Policy, please contact us at vedantchandak1706@gmail.com.