1. Introduction
KTCHP ("we," "our," or "us") operates the KTCHP mobile application (the "App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App.
By using KTCHP, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies, please do not use our App.
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, password (encrypted)
- Profile Information: Profile picture, family size, dietary preferences
- User Content: Restaurant reviews, ratings, photos you upload
- Payment Information: Processed securely by Stripe; we do not store credit card numbers
- Communications: Bug reports, support requests, feedback
2.2 Information Collected Automatically
- Device Information: Device type, operating system, unique device identifiers
- Location Data: With your permission, for finding nearby restaurants
- Usage Data: App features used, pages visited, search queries
- Log Data: IP address, access times, app crashes
2.3 Information from Third Parties
- Social Login: If you sign in with Facebook or Google, we receive your name, email, and profile picture
- Restaurant Data: From Google Places API to display restaurant information
3. How We Use Your Information
We use collected information for:
- Providing and maintaining our App services
- Processing transactions and subscriptions
- Sending you notifications about nearby deals (with permission)
- Personalizing your experience and recommendations
- Improving our App and developing new features
- Communicating with you about updates and promotions
- Detecting and preventing fraud or abuse
- Complying with legal obligations
4. Information Sharing & Disclosure
We may share your information with:
4.1 Service Providers
- Stripe: Payment processing
- Google: Maps and Places API, Analytics
- MongoDB: Database hosting
- Expo: App infrastructure
- AdMob: Advertising (for free tier users)
4.2 Affiliate Partners
When you use affiliate links, our partners may receive:
- Click and conversion tracking data
- No personally identifiable information is shared
4.3 Other Users
- Your public reviews and ratings are visible to other users
- Your profile name is visible to friends you connect with
4.4 Legal Requirements
We may disclose information if required by law or to protect our rights, safety, or property.
5. Data Retention
We retain your information for as long as:
- Your account is active
- Needed to provide services to you
- Required by law (e.g., tax records)
- Necessary for legitimate business purposes
After account deletion, we may retain anonymized data for analytics. Personal data is deleted within 30 days of account deletion request.
6. Your Privacy Rights
6.1 GDPR Rights (EU/EEA Users)
Under the General Data Protection Regulation, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your data ("Right to be Forgotten")
- Portability: Receive your data in a machine-readable format
- Restriction: Limit how we process your data
- Objection: Object to certain processing activities
- Withdraw Consent: Withdraw consent at any time
6.2 CCPA Rights (California Residents)
Under the California Consumer Privacy Act, you have the right to:
- Know: What personal information we collect and how it's used
- Delete: Request deletion of your personal information
- Opt-Out: Opt-out of sale of personal information (we don't sell data)
- Non-Discrimination: Not be discriminated against for exercising your rights
6.3 Exercising Your Rights
To exercise any of these rights, contact us at:
We will respond within 30 days (or as required by applicable law).
7. Children's Privacy (COPPA Compliance)
KTCHP is a family-friendly app, but account creation requires users to be 13 years or older (or the minimum age in your jurisdiction).
- We do not knowingly collect personal information from children under 13
- Family profiles allow parents to manage children's preferences without collecting children's data
- If we discover we have collected data from a child under 13, we will delete it immediately
Parents or guardians who believe we have collected information from a child under 13 should contact us immediately.
8. Data Security
We implement industry-standard security measures:
- Encryption: All data transmitted via HTTPS/TLS
- Password Security: Passwords are hashed using bcrypt
- Access Controls: Limited employee access to user data
- Secure Infrastructure: Cloud hosting with security certifications
- Payment Security: PCI-DSS compliant via Stripe
- Rate Limiting: Protection against brute force attacks
10. Third-Party Services
Our App integrates with third-party services with their own privacy policies:
| Service | Purpose | Privacy Policy |
|---|---|---|
| Maps, Places, Auth | View | |
| Stripe | Payments | View |
| Facebook/Meta | Social Login | View |
| Google AdMob | Advertising | View |
11. Changes to This Policy
We may update this Privacy Policy periodically. Changes will be posted on this page with an updated "Last Modified" date.
For significant changes, we will notify you via:
- In-app notification
- Email (if you've provided one)
- Push notification
Continued use of the App after changes constitutes acceptance of the updated policy.
12. Contact Us
For privacy-related questions or to exercise your rights:
We aim to respond to all inquiries within 30 days.
Additional Disclosures
International Data Transfers
Your data may be transferred to and processed in countries outside your residence. We ensure appropriate safeguards are in place for such transfers.
Do Not Track
Our App does not currently respond to "Do Not Track" browser signals.
California Shine the Light
California residents may request information about data shared with third parties for direct marketing. Contact us for details.