Draft privacy notice — this document must be reviewed and completed by the site owner before relying on it for legal compliance.

Privacy notice

Last updated: [DATE — please insert before launch]

Who we are

This privacy notice explains how personal information is handled when you use DadTheFoodie (www.dadthefoodie.com).

Data controller: [YOUR LEGAL NAME OR BUSINESS NAME]
Address: [YOUR POSTAL ADDRESS]
Contact email: [YOUR CONTACT EMAIL]

What information we collect

Depending on how you use the website, we may process:

  • Account information — email address and password when you register or log in (handled through Supabase authentication)
  • Saved recipes — recipes you choose to save to your account
  • Meal plan data — meals you add to your weekly meal planner, including dates, servings, and notes
  • Shopping list data — ingredients and items you add to your shopping list
  • Private recipe notes — personal cooking notes you save on recipe pages (visible only to your account through the website)
  • Recipe collections — personal lists you create to organise saved recipes
  • Recipe ratings — star ratings you submit for published recipes, linked to your account
  • Made recipe records — when you mark a published recipe as made, we store that choice with your account
  • Recipe requests — recipe ideas you submit and requests you support when logged in, linked privately to your account ID
  • Community comments — text comments you submit on published recipe pages, shown with your member display name after moderation
  • Community food photographs — optional food photographs uploaded with comments, stored privately until approved
  • Comment reports— when you report another member's approved comment, we store the reason and any details you provide
  • Recently viewed recipes — a history of published recipe pages you have opened while logged in
  • Technical and security logs — basic server, hosting, and security information (such as IP address, browser type, and request timestamps) collected by our hosting provider

How we use your information

  • To create and manage your member account
  • To provide saved recipes, meal planning, and shopping list features
  • To store private notes, personal collections, recipe ratings, made-recipe records, and recently viewed recipe history for members
  • To review, moderate, and display community comments and member food photographs on published recipe pages
  • To review, moderate, merge, publish or remove recipe requests submitted by members
  • To display approved recipe request text and anonymous support totals on public pages
  • To investigate community reports and enforce community guidelines
  • To keep the website secure and prevent misuse
  • To respond to contact enquiries where you get in touch with us

We do not sell your personal information. We do not use your data for third-party advertising on this website.

Legal bases (UK GDPR)

Where UK GDPR applies, we rely on appropriate legal bases including:

  • Contract — to provide member features you sign up for
  • Legitimate interests — to operate, secure, and improve the website
  • Consent — where required for optional processing

[Please review these bases with your adviser to confirm they are correct for your situation.]

Recipe requests

Logged-in members may submit recipe ideas and support requests made by other members. This information is associated privately with your account ID.

  • Approved request titles and optional details may appear publicly on the recipe requests page.
  • Public support totals show how many members requested a recipe; they do not identify individual supporters.
  • Requests may be moderated, merged with similar requests, rejected, or removed by administrators.
  • Administrator notes about requests are never shown publicly or to members.

[Please review this section with your adviser before launch.]

Ingredient finder

When you use the “What can I cook?” ingredient finder, ingredients you enter are used only to calculate recipe matches during that visit.

  • Ingredient entries are not linked to a persistent visitor identifier by the first-party analytics feature.
  • DadTheFoodie does not store your complete ingredient list in anonymous analytics by default.
  • Shopping-list items are saved only when a logged-in member deliberately adds missing ingredients.

[Please review this section with your adviser before launch.]

Installable web app

DadTheFoodie can be installed as a web app on supported phones and computers. Installing the web app does not create a separate account.

  • A local preference may remember if you dismissed the homepage installation card.
  • The first installed version still needs an internet connection for most features.
  • A service worker may store basic public assets and the offline fallback page on your device.
  • Private account and administrator pages are not intentionally cached for offline use.

[Please review this section with your adviser before launch.]

Anonymous operational analytics

DadTheFoodie records anonymous operational analytics to understand how published recipes are used — for example recipe views, searches, Cook Mode starts, print actions and share actions.

  • These first-party analytics do not use cookies, localStorage or a persistent visitor identifier.
  • Analytics events do not store IP addresses, email addresses, user IDs, authentication tokens, full referrer URLs or complete browser user-agent strings.
  • Search phrases from recipe searches may be stored anonymously to help identify which recipes visitors want next.
  • Analytics failures never block normal use of the website.
  • Administrators may delete older analytics records from time to time.

Error monitoring and performance information

When configured, DadTheFoodie may use Sentry for optional error and performance monitoring in production. This can include technical information such as browser type, page path, error messages and Core Web Vitals measurements (for example LCP, CLS, INP, FCP and TTFB).

  • Sentry is disabled when no DSN is configured.
  • DadTheFoodie configures Sentry not to send default personal information, cookies, authentication headers, passwords, reset tokens or complete form bodies.
  • Session replay and keystroke recording are not enabled.

When Sentry or other providers are configured, some technical data may be processed by those third-party services under their own terms.

Service providers

We use trusted providers to run the website, including:

  • Sentry — optional error and performance monitoring when NEXT_PUBLIC_SENTRY_DSN is configured in production
  • Supabase — authentication, database, and file storage
  • Vercel (or your hosting provider) — website hosting
  • OpenAI— when an administrator uses the AI recipe importer, recipe text supplied by the administrator may be sent to OpenAI for processing. When enabled, community comment text and uploaded food photographs may also be sent to OpenAI's moderation service for automated review before administrator approval. Member account data is not sent to OpenAI through the recipe importer.

Providers process data on our instructions and under appropriate agreements. [Confirm provider details and locations before launch.]

How long we keep information

We keep personal information only for as long as needed to provide the service, comply with legal obligations, or resolve disputes. You may request deletion of your account — [describe your deletion process here].

Your rights

Under UK data protection law, you may have rights to:

  • Access the personal information we hold about you
  • Ask us to correct inaccurate information
  • Ask us to delete your information in certain circumstances
  • Object to or restrict certain processing
  • Data portability where applicable
  • Withdraw consent where processing is based on consent

To exercise your rights, contact [YOUR CONTACT EMAIL]. We may need to verify your identity before responding.

Complaints

If you are unhappy with how we handle your personal information, please contact us first. You also have the right to complain to the Information Commissioner's Office (ICO) in the UK: ico.org.uk/make-a-complaint.

Community content retention

Community comments and food photographs may be kept while your account is active and for a reasonable period afterwards so we can maintain moderation records, respond to reports, and enforce our guidelines. If you delete your comment, related pending photographs are removed from private storage where practical. Approved public comments and photographs may remain visible until an administrator removes them or you delete your comment.

Public recipe summaries

When members rate recipes or mark them as made, the website may show aggregate counts and averages on published recipe pages — for example, how many ratings a recipe has received or how many members have marked it as made. These public summaries do not show your name, email address or other personal details.

Local browser storage

If you browse recipes without logging in, the website may store a short list of recently viewed recipe page addresses in your browser's local storage (up to 10 entries). This stays on your device, is not sent to our servers, and can be cleared using the "Clear history" control where shown.

Changes

We may update this notice from time to time. The latest version will always be published on this page.

Contact us →