Back to homeLegal

Privacy Policy

Let's Get Food Inc. · Effective date: 2026-09-01 (production launch)

Draft — pending final review by legal counsel. This document is provided as a placeholder and does not yet constitute final legal terms.

This Privacy Policy explains how Let's Get Food Inc. (“we”, “us”) collects, uses, discloses, and protects personal information when you use the Let's Get Food customer app, merchant app, admin tools, and website (together, the “Services”). We are a Canadian company and this policy is designed to align with the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, Quebec's Law 25.

1. Information we collect

CategoryExamples
Account & identityName, email, phone number, profile photo, role (customer / merchant owner / merchant staff)
Event & order detailsEvent intents, quote requests, bookings, package selections, dietary preferences, guest counts, delivery/venue addresses
Payment referencesStripe customer/payment references and transaction status — we do not store full card numbers on our servers (see Section 4)
CommunicationsChat/support messages, SMS/email delivery status, notification preferences
Device & usagePush notification (FCM) tokens, app version, device type, crash/diagnostic logs, approximate location if you enable location services for merchant discovery
Merchant compliance documentsBusiness registration, food-safety certificates, insurance documents (merchant accounts only, stored in private storage)
Marketing preferencesEmail and SMS marketing opt-in status (see Section 6)

2. Why we collect it

  • To create and operate your account and match customers with merchants
  • To process bookings, quotes, payments, and payouts
  • To send transactional notifications (booking confirmations, OTP codes, order updates) by SMS, email, and push
  • To provide customer support and investigate disputes or fraud
  • To improve the Services, including limited use of AI-assisted recommendations (see Section 5)
  • To meet legal, tax, and regulatory obligations
  • To send marketing communications, but only where you have given express consent (see Section 6)

3. Third-party service providers (sub-processors)

We share the minimum necessary personal information with the following service providers so they can perform services on our behalf. A full, regularly-updated list is published on our sub-processors page.

ProviderPurposeData involved
SupabaseDatabase, authentication, file storage, backend functionsAll account, order, and compliance-document data
StripePayment processing and merchant payouts (Stripe Connect)Payment method tokens, billing details, transaction amounts
TelnyxSMS delivery (OTP codes, booking notifications)Phone number, message content
ResendTransactional and marketing email deliveryEmail address, message content
Google Firebase (FCM)Push notificationsDevice push token
Google GeminiOptional AI-assisted planning suggestionsMinimized event-intent text; we avoid sending unnecessary personal information
MapboxGeocoding and map displayAddress/city text you enter, resulting coordinates
Zoho CRMInternal sales/support relationship management (derived copy; Postgres remains the source of truth)Contact and account details for merchants and key accounts
CloudflareDNS, content delivery, and web application firewallNetwork/request metadata for the public website

4. Payment data

Card details are entered directly into Stripe-hosted payment fields and never touch our servers or database. We store only payment references, status, and amounts. Our payment flow is designed to qualify for the lowest PCI DSS self-assessment tier (SAQ-A).

5. Automated features & AI

Certain planning features may use AI (Google Gemini) to suggest merchants, packages, or itineraries based on the event details you provide. We aim to minimize the personal information included in AI prompts and do not use your data to train third-party foundation models.

6. Marketing communications & CASL

Transactional messages (OTP codes, booking/order updates, receipts) are sent as part of operating the Services and are not “marketing” under Canada's Anti-Spam Legislation (CASL). Marketing emails and SMS are sent only if you provide express opt-in consent at signup or in your notification settings. You can withdraw consent at any time by:

  • Using the unsubscribe link included in every marketing email, or
  • Replying STOP to any marketing SMS, or
  • Updating your notification preferences in the app, or
  • Emailing team@letsgetfood.com

7. Data retention

We retain personal information for as long as your account is active and as needed to provide the Services, comply with legal/tax obligations, resolve disputes, and enforce our agreements. When you request account deletion, we anonymize bookings, payments, and reviews associated with your account and permanently delete device tokens, saved items, and notification records, subject to what we must retain for legal, accounting, or fraud-prevention purposes.

8. Your rights

Subject to applicable law, you may:

  • Access a copy of the personal information we hold about you
  • Correct inaccurate or outdated information via your profile
  • Delete your account and associated personal information — in-app via Settings → Delete Account (OTP-verified), or via our account-deletion page
  • Export your data by contacting support
  • Withdraw consent for marketing communications at any time

To exercise these rights, contact team@letsgetfood.com. We will respond within a reasonable time as required by PIPEDA.

9. Cross-border data transfers

We are a Canada-first company and prioritize Canadian data residency where practical (e.g., Supabase Canada Central region, Telnyx Canada routing, Zoho .ca data centre). Some service providers (including Resend, Google Gemini, Mapbox, and Firebase) may process or store data outside Canada, including in the United States. Where personal information is transferred internationally, we take steps to ensure appropriate contractual protections are in place with our sub-processors.

10. Cookies

Our marketing website and admin tools use cookies for essential site functionality and basic analytics. See our Cookie Notice for details.

11. Children's privacy

The Services are not directed to children, and we do not knowingly collect personal information from children under 13 (or the applicable age of consent in your province).

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated in-app or by email. Continued use of the Services after a change takes effect constitutes acceptance of the updated policy.

13. Contact us

Let's Get Food Inc. · Email: team@letsgetfood.com