Back to Legal Documents

Privacy Policy

Last updated: April 2026

Privacy Policy

Last Updated: January 17, 2026

1. Introduction

Home Meal App ("we," "us," "our," or "Platform") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our home-cooked meal delivery marketplace platform, including our mobile applications, websites, and related services.

By using our Platform, you consent to the data practices described in this Privacy Policy. If you do not agree with this Privacy Policy, please do not use our Platform.

2. Information We Collect

2.1 Information You Provide Directly

Account Registration:

  • Name, email address, phone number
  • Date of birth (to verify age requirements)
  • Password (encrypted and hashed)
  • Profile photo (optional)
  • Language and communication preferences

Buyer Information:

  • Delivery addresses
  • Payment information (credit/debit cards, digital wallet details)
  • Dietary preferences and restrictions
  • Order history and favorites
  • Special delivery instructions

Seller Information:

  • Business name and description
  • Business address and service areas
  • Business license and permit numbers
  • Tax identification numbers (EIN/SSN)
  • Food handler certifications
  • Bank account information for payouts
  • Menu items, photos, and descriptions
  • Availability and preparation times

Driver Information:

  • Driver's license number and photo
  • Vehicle make, model, year, color, license plate
  • Auto insurance information
  • Background check consent and results
  • Social Security Number (for tax reporting)
  • Bank account or debit card for payouts
  • Emergency contact information

2.2 Information Collected Automatically

Device Information:

  • Device type, model, and operating system
  • Device identifiers (UDID, advertising ID)
  • IP address
  • Browser type and version
  • Mobile network information
  • App version and settings

Location Information:

  • Precise GPS location (with your permission)
  • Approximate location from IP address
  • Delivery and pickup addresses
  • Route and navigation data (for Drivers)

Usage Information:

  • Pages and features accessed
  • Search queries and filters
  • Time spent on pages
  • Click and interaction data
  • Orders placed, accepted, and completed
  • Performance metrics (ratings, completion rates)

Communication Data:

  • In-app messages between users
  • Customer support communications
  • Phone call metadata (not call content)
  • Push notification interactions
  • Call recordings (when enabled) with explicit user consent:
    • Support agent ↔ User calls
    • Seller ↔ Driver coordination calls
    • Driver ↔ Buyer delivery calls (when in range)
    • Admin quality monitoring calls
    • Purpose: Quality assurance, training, compliance, dispute resolution
    • Retention: 90 days from call date
    • Access: Authorized administrators only (Level 70+)
    • Your Rights: Request deletion or access by contacting support
    • Encryption: All recordings encrypted at rest (AES-256)
    • Consent: Required before each call; logged with timestamp and jurisdiction
    • Monitoring: Higher admin roles may listen to live calls for quality monitoring

2.3 Information from Third Parties

Payment Processors:

  • Transaction verification
  • Fraud detection data
  • Payment method validation

Background Check Providers (for Drivers and Sellers):

  • Criminal history records
  • Driving records (MVR)
  • Sex offender registry checks
  • Identity verification

Social Media (if you choose to connect):

  • Profile information
  • Email address
  • Friends/connections (for referrals)

Data Analytics and Advertising Partners:

  • Demographic information
  • Interest categories
  • Advertising interaction data

3. How We Use Your Information

3.1 Core Platform Operations

Order Processing and Fulfillment:

  • Facilitate orders between Buyers, Sellers, and Drivers
  • Process payments and issue payouts
  • Send order confirmations and status updates
  • Coordinate pickups and deliveries
  • Provide customer support

Account Management:

  • Create and maintain your account
  • Authenticate your identity
  • Verify eligibility and credentials
  • Process registration applications
  • Manage subscriptions and memberships

Communication:

  • Send transactional messages (order updates, receipts)
  • Provide customer support responses
  • Send service announcements and updates
  • Facilitate communication between users (masked contact info)

3.2 Platform Improvement and Personalization

Personalization:

  • Recommend meals based on preferences and history
  • Customize search results and listings
  • Remember your favorite items and Sellers
  • Tailor promotions and offers to your interests

Analytics and Insights:

  • Analyze usage patterns and trends
  • Measure feature performance and adoption
  • Identify bugs and technical issues
  • Conduct A/B testing for improvements
  • Generate business intelligence and reports

Quality and Safety:

  • Monitor and improve service quality
  • Detect and prevent fraud and abuse
  • Enforce our Terms and Conditions
  • Investigate complaints and disputes
  • Ensure food safety and platform integrity
  • Resolve support cases and disputes involving call recordings (when enabled)
  • Call Recording for Quality Monitoring:
    • Review recorded calls for agent training and performance evaluation
    • Monitor compliance with company policies and legal requirements
    • Investigate customer complaints and service quality issues
    • Ensure accurate translation and communication in multilingual calls
    • Track key performance indicators (KPIs) for support teams
    • Access restricted to Level 70+ administrators and owner (Level 999)
    • All monitoring activities encrypted to protect executive identity

3.3 Marketing and Promotions

Marketing Communications (with your consent):

  • Send promotional emails and notifications
  • Inform you of special offers and discounts
  • Share news and updates about the Platform
  • Conduct surveys and research
  • Send referral program invitations

Advertising:

  • Display targeted advertisements
  • Measure ad effectiveness
  • Retarget users who visited but didn't complete actions
  • Create lookalike audiences for user acquisition

3.4 Legal and Compliance

  • Comply with legal obligations and regulations
  • Respond to legal requests and court orders
  • Enforce our Terms and Conditions
  • Protect rights, property, and safety
  • Prevent fraud, abuse, and illegal activity
  • Conduct investigations and litigation
  • Issue tax documents (1099 forms)

4. How We Share Your Information

4.1 With Other Users

Buyers can see:

  • Seller business name, photo, and ratings
  • Driver first name, photo, and vehicle details
  • Estimated arrival times

Sellers can see:

  • Buyer first name and delivery address (for accepted orders)
  • Order details and special instructions
  • Driver details when assigned

Drivers can see:

  • Buyer first name and delivery address
  • Seller business name and pickup address
  • Order details for delivery

4.2 With Service Providers

We share information with third-party service providers who perform services on our behalf:

Payment Processing:

  • Stripe, PayPal, Square (payment processing)
  • Bank partners (payouts and transfers)
  • Fraud detection services

Technology and Infrastructure:

  • Cloud hosting providers (AWS, Google Cloud)
  • Database and storage services
  • Content delivery networks (CDN)
  • Email and SMS services

Analytics and Advertising:

  • Google Analytics
  • Facebook Pixel
  • Advertising networks
  • Marketing automation platforms

Background Checks:

  • Checkr, Sterling (for Drivers and Sellers)
  • Identity verification services

Customer Support:

  • Help desk software providers
  • Live chat services
  • Phone support providers

Other Services:

  • Mapping and navigation services
  • Insurance providers
  • Tax and accounting services
  • Legal service providers

4.3 Business Transfers

If we are involved in a merger, acquisition, asset sale, bankruptcy, or other business transaction, your information may be transferred as part of that transaction. You will be notified via email and/or prominent notice on our Platform of any change in ownership or uses of your personal information.

4.4 Legal Requirements

We may disclose your information if required by law or if we believe in good faith that such disclosure is necessary to:

  • Comply with legal obligations, court orders, or government requests
  • Enforce our Terms and Conditions and policies
  • Detect, prevent, or address fraud, security, or technical issues
  • Protect the rights, property, or safety of our Platform, users, or the public

4.5 With Your Consent

We may share your information for purposes not described in this Privacy Policy with your explicit consent.

4.6 Aggregated and De-identified Data

We may share aggregated or de-identified information that cannot reasonably be used to identify you. For example:

  • Market trends and statistics
  • Platform usage metrics
  • General demographic information
  • Industry reports and research

5. Your Privacy Rights and Choices

5.1 Access and Correction

You have the right to:

  • Access your personal information
  • Correct inaccurate information
  • Update your profile and preferences
  • Export your data

How to exercise: Log into your account and visit Settings, or contact us at privacy@home-meal.website.

5.2 Right to Erasure (Deletion)

You may request deletion of your account and personal information under GDPR Article 17 (Right to Erasure).

Response Timeframe:

  • We will respond to your deletion request within 1 month of receipt
  • For complex requests or multiple simultaneous requests, this may be extended by 2 additional months (total 3 months maximum)
  • We will notify you of any extension within the first month and explain the reasons

Processing Your Request: Once verified, we will:

  1. Anonymize your personal data in live production systems
  2. Remove your ability to log in and access the platform
  3. Retain minimal data only where legally required (see limitations below)
  4. Provide you with a confirmation once deletion is complete

Important Limitations - Your Right to Deletion Does NOT Apply When:

Under GDPR Article 17(3), we may refuse or delay your deletion request when we need to retain data for:

  1. Legal Claims (Article 17(3)(e)): Establishment, exercise, or defense of legal claims

    • Active disputes, litigation, or arbitration
    • Anticipated legal claims (e.g., pending chargebacks, complaints)
    • Regulatory investigations or audits
    • Action: Deletion paused until matter resolved; you will be notified
  2. Statutory Obligations (Article 17(3)(b)): Compliance with legal obligations

    • Tax Records: 7-10 years (varies by jurisdiction - IRS requires 7 years, Germany 10 years)
    • Financial Transactions: 5-7 years (SEC, anti-money laundering laws)
    • Employment Records: 2-3 years after termination (for Sellers/Drivers)
    • Food Safety Logs: 1-7 years (varies by state/country)
    • Background Checks: 7 years (regulatory requirement)
  3. Contractual Obligations: Outstanding payments, refunds, or service obligations

  4. Public Interest: Archiving for public health, scientific, or historical research purposes

What Happens to Your Data:

Immediate Anonymization (Within 30 days):

  • Name → "Deleted User"
  • Email → "deleted-[random-id]@deleted.local"
  • Phone, address, payment methods → Permanently deleted
  • Orders → Buyer link removed (kept for seller analytics)
  • Messages → Replaced with "[Message deleted for privacy]"
  • Reviews → Author shown as "Anonymous"

Legal Compliance Backups (If Applicable):

  • Encrypted backups may be retained for up to 7 years maximum
  • Used ONLY for legal disputes, tax audits, or regulatory compliance
  • Access restricted to Level 999 (Owner) with full audit trail
  • Automatically deleted when retention period expires
  • You may request access to these backups via Data Protection Officer

Legal Hold Notification: If your deletion request is subject to a legal hold:

  • You will receive notification within 1 month explaining:
    • Reason for hold (dispute, tax requirement, litigation, etc.)
    • Estimated duration of hold
    • Legal basis (GDPR Article 17(3) exception)
    • Contact information for questions
  • We will review the hold every 90 days
  • Deletion will resume automatically once legal matter is resolved
  • You may contact our Data Protection Officer at dpo@home-meal.website

Dispute After Deletion: If a legal dispute arises after your data has been deleted:

  • We will provide documentation of our compliant deletion process
  • Our audit trail proves deletion was lawful and timely
  • Encrypted compliance backups may be accessed if legally required
  • You may lodge a complaint with your national Data Protection Authority

How to Exercise Your Right:

Verification: To protect your privacy, we will verify your identity before processing deletion requests. You may be asked to provide:

  • Email confirmation
  • Two-factor authentication code
  • Government-issued ID (for high-risk deletions)

Note: Deleted accounts cannot be recovered. You must fulfill all outstanding obligations (payments, deliveries) before deletion.

5.3 Marketing Communications

You may opt out of marketing communications:

  • Email: Click "Unsubscribe" in any marketing email or adjust settings in your account
  • Push Notifications: Disable in device settings or app settings
  • SMS: Reply STOP to opt out of text messages

Note: You cannot opt out of transactional messages related to your orders or account.

5.4 Location Tracking

You can control location tracking:

  • Disable Location Services: Turn off in device settings (may limit functionality)
  • App-Level Control: Allow only while using the app
  • Go Offline (Drivers): Toggle offline in Driver app to stop tracking

5.5 Cookies and Tracking Technologies

You can control cookies through:

  • Browser Settings: Block or delete cookies
  • Cookie Preferences: Adjust settings in our cookie banner
  • Opt-Out Tools: Use industry opt-out tools (e.g., NAI, DAA)

Note: Disabling cookies may affect Platform functionality.

5.6 Do Not Track

Our Platform does not currently respond to "Do Not Track" signals. We may implement this feature in the future.

5.7 Rights Under Data Protection Laws

Depending on your location, you may have additional rights:

GDPR (European Union):

  • Right to access, rectification, erasure
  • Right to restriction of processing
  • Right to data portability
  • Right to object to processing
  • Right to withdraw consent
  • Right to lodge a complaint with supervisory authority

CCPA (California):

  • Right to know what information is collected
  • Right to delete personal information
  • Right to opt out of sale of personal information
  • Right to non-discrimination for exercising rights

Other Jurisdictions:

  • Similar rights may apply under local laws
  • Contact us to exercise your rights

How to exercise: Email privacy@home-meal.website with your request.

6. Data Security

6.1 Security Measures

We implement industry-standard security measures to protect your information:

Technical Safeguards:

  • Encryption in transit (TLS/SSL)
  • Encryption at rest for sensitive data
  • Secure database architecture
  • Firewall protection
  • Intrusion detection systems
  • Regular security audits and penetration testing

Organizational Safeguards:

  • Access controls and authentication
  • Employee training on data protection
  • Background checks for employees with data access
  • Data retention and disposal policies
  • Incident response plan

Payment Security:

  • PCI DSS compliance
  • Tokenization of payment information
  • We do not store full credit card numbers

6.2 Data Breach Notification

In the event of a data breach affecting your personal information, we will:

  • Notify affected users promptly (within 72 hours where required)
  • Provide details of the breach and data affected
  • Describe steps we are taking to address the breach
  • Advise on steps you can take to protect yourself
  • Notify regulatory authorities as required by law

6.3 Your Responsibility

You are responsible for:

  • Keeping your password confidential
  • Not sharing account access
  • Using strong, unique passwords
  • Logging out on shared devices
  • Reporting suspicious activity immediately

6.4 Limitations

No security system is perfect. While we strive to protect your information, we cannot guarantee absolute security. Use the Platform at your own risk.

7. Data Retention

7.1 Retention Periods

We retain your information for as long as necessary to provide services and fulfill purposes described in this Privacy Policy:

Active Accounts:

  • Retained indefinitely while account is active
  • Updated as you make changes

Inactive Accounts:

  • Accounts inactive for 2+ years may be deleted
  • You will receive notice before deletion

Deleted Accounts:

  • Most data deleted within 30 days
  • Some data retained for legal/business purposes (see below)

Legal and Business Records:

  • Transaction records: 7 years (tax and accounting requirements)
  • Background checks: 7 years (compliance requirements)
  • Communication logs: 90 days (unless part of ongoing dispute)
  • Dispute and legal matter records: Duration of matter + 7 years

Aggregated and De-identified Data:

  • Retained indefinitely for analytics and research

7.2 Retention After Deletion Request

After account deletion, we may retain:

  • Information required for legal compliance
  • Information needed for ongoing disputes or investigations
  • Backup copies (deleted in regular rotation)
  • Aggregated and de-identified information

8. Children's Privacy

8.1 Age Restrictions

The Platform is not intended for children under 18. We do not knowingly collect information from children under 18.

8.2 Parental Rights

If you believe we have inadvertently collected information from a child under 18, please contact us immediately at privacy@home-meal.website. We will take steps to delete such information promptly.

9. International Data Transfers

9.1 Cross-Border Transfers

Our Platform operates globally. Your information may be transferred to and processed in countries other than your country of residence, including the United States.

9.2 Data Protection Frameworks

We comply with applicable data protection frameworks:

  • EU-U.S. Privacy Shield (or successor frameworks)
  • Standard Contractual Clauses for EU data transfers
  • Adequacy Decisions where available
  • Other mechanisms as required by law

9.3 Your Rights

If your information is transferred internationally, you retain the rights described in this Privacy Policy and under applicable law.

10. Third-Party Links and Services

10.1 Third-Party Links

Our Platform may contain links to third-party websites, services, or applications. This Privacy Policy does not apply to third-party sites. We are not responsible for third-party privacy practices.

10.2 Social Media

We may have social media pages (Facebook, Instagram, Twitter). Your interactions on those platforms are governed by the platforms' privacy policies, not this Privacy Policy.

10.3 Third-Party Integrations

If you connect third-party services to your account (e.g., Google login, Apple Pay), those services' privacy policies apply to information they collect.

11. Changes to Privacy Policy

11.1 Modifications

We may update this Privacy Policy from time to time. Changes will be effective upon posting, unless otherwise stated.

11.2 Notice of Changes

For material changes, we will provide notice:

  • Email notification to registered users
  • Prominent notice on Platform
  • In-app notification
  • Updated "Last Updated" date at top of policy

11.3 Acceptance

Your continued use of the Platform after changes constitutes acceptance of the updated Privacy Policy. If you do not agree, stop using the Platform and delete your account.

12. California Privacy Rights

12.1 CCPA Rights

California residents have specific rights under the California Consumer Privacy Act (CCPA):

Right to Know:

  • Categories of personal information collected
  • Sources of personal information
  • Purposes for collecting personal information
  • Categories of third parties with whom we share information
  • Specific pieces of personal information collected

Right to Delete:

  • Request deletion of personal information (subject to exceptions)

Right to Opt Out:

  • Opt out of sale of personal information
  • Note: We do not sell personal information in the traditional sense, but sharing data with advertising partners may qualify as a "sale" under CCPA. Opt out via our Do Not Sell My Info page.

Right to Non-Discrimination:

  • We will not discriminate against you for exercising CCPA rights

Shine the Light:

  • Request information about sharing personal information with third parties for direct marketing (annually)

12.2 How to Exercise CCPA Rights

  • Online: Submit request at privacy.homemealapp.com
  • Email: privacy@home-meal.website
  • Phone: +1 (555) 123-4567
  • Authorized Agent: You may designate an agent to submit requests on your behalf

We will verify your identity before processing requests. Response time: 45 days (may extend 45 additional days with notice).

13. Nevada Privacy Rights

Nevada residents may opt out of the sale of covered personal information. We do not currently sell personal information as defined under Nevada law. If this changes, we will provide notice and opt-out mechanisms.

14. Contact Us

14.1 Privacy Questions

For questions or concerns about this Privacy Policy or our data practices:

Privacy Team:

14.2 Data Protection Officer

For GDPR-related inquiries:

14.3 Response Time

We will respond to privacy inquiries within:

  • 30 days (GDPR)
  • 45 days (CCPA)
  • 14 days (general inquiries)

15. Supplementary Privacy Notices

15.1 Role-Specific Privacy Practices

Buyers:

  • We share your delivery address with Sellers and Drivers for order fulfillment
  • Order history is visible to you in your account
  • We use your location to show nearby Sellers and estimate delivery times

Sellers:

  • Your business information is public on the Platform
  • We share pickup address with assigned Drivers
  • Earnings and payout data is private
  • We may use your meal photos in marketing (with permission)

Drivers:

  • We track your location while you are online
  • Background check results are confidential
  • Earnings data is private
  • Your first name and photo are visible to Buyers and Sellers

Admin Users:

  • Internal tools and dashboards may access user data for support and operations
  • Admin access is logged and audited
  • Admins must comply with data protection policies

16. Cookies and Tracking Technologies

16.1 Types of Cookies

We use the following types of cookies:

Essential Cookies:

  • Required for Platform functionality
  • Authentication and security
  • Cannot be disabled without affecting functionality

Performance Cookies:

  • Analytics and usage tracking
  • Error monitoring
  • A/B testing

Functional Cookies:

  • Remember preferences and settings
  • Language selection
  • Location data

Advertising Cookies:

  • Targeted advertising
  • Retargeting campaigns
  • Conversion tracking

16.2 Cookie Management

Manage cookies through:

  • Browser Settings: Block, delete, or manage cookies
  • Cookie Preferences: Adjust in our cookie banner
  • Opt-Out Links: NAI (networkadvertising.org), DAA (aboutads.info)

16.3 Other Tracking Technologies

  • Web Beacons: Small graphics for tracking email opens and clicks
  • Local Storage: HTML5 storage for preferences
  • Software Development Kits (SDKs): Third-party tools in mobile apps
  • Pixels: Tracking pixels for ad measurement

17. Automated Decision-Making

17.1 Use of Automated Systems

We use automated systems for:

  • Fraud detection and prevention
  • Matching Buyers with Sellers and Drivers
  • Surge pricing calculations
  • Personalized recommendations
  • Account risk assessments

17.2 Your Rights

Under GDPR, you have the right to:

  • Request human review of automated decisions
  • Object to automated decision-making
  • Receive explanation of decision logic

Contact privacy@home-meal.website to exercise these rights.

18. Accessibility

We are committed to making our Privacy Policy accessible to all users. If you need this policy in an alternative format (large print, audio, Braille), contact privacy@home-meal.website.


By using the Home Meal App Platform, you acknowledge that you have read, understood, and agree to this Privacy Policy.

For questions or to exercise your privacy rights, contact us at privacy@home-meal.website.

Effective Date: January 17, 2026 Version: 1.0