Privacy Policy
Let's Get Food Inc. · Effective date: 2026-09-01 (production launch)
This Privacy Policy explains how Let's Get Food Inc. (“we”, “us”) collects, uses, discloses, and protects personal information when you use the Let's Get Food customer app, merchant app, admin tools, and website (together, the “Services”). We are a Canadian company and this policy is designed to align with the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, Quebec's Law 25.
1. Information we collect
| Category | Examples |
|---|---|
| Account & identity | Name, email, phone number, profile photo, role (customer / merchant owner / merchant staff) |
| Event & order details | Event intents, quote requests, bookings, package selections, dietary preferences, guest counts, delivery/venue addresses |
| Payment references | Stripe customer/payment references and transaction status — we do not store full card numbers on our servers (see Section 4) |
| Communications | Chat/support messages, SMS/email delivery status, notification preferences |
| Device & usage | Push notification (FCM) tokens, app version, device type, crash/diagnostic logs, approximate location if you enable location services for merchant discovery |
| Merchant compliance documents | Business registration, food-safety certificates, insurance documents (merchant accounts only, stored in private storage) |
| Marketing preferences | Email and SMS marketing opt-in status (see Section 6) |
2. Why we collect it
- To create and operate your account and match customers with merchants
- To process bookings, quotes, payments, and payouts
- To send transactional notifications (booking confirmations, OTP codes, order updates) by SMS, email, and push
- To provide customer support and investigate disputes or fraud
- To improve the Services, including limited use of AI-assisted recommendations (see Section 5)
- To meet legal, tax, and regulatory obligations
- To send marketing communications, but only where you have given express consent (see Section 6)
3. Third-party service providers (sub-processors)
We share the minimum necessary personal information with the following service providers so they can perform services on our behalf. A full, regularly-updated list is published on our sub-processors page.
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, file storage, backend functions | All account, order, and compliance-document data |
| Stripe | Payment processing and merchant payouts (Stripe Connect) | Payment method tokens, billing details, transaction amounts |
| Telnyx | SMS delivery (OTP codes, booking notifications) | Phone number, message content |
| Resend | Transactional and marketing email delivery | Email address, message content |
| Google Firebase (FCM) | Push notifications | Device push token |
| Google Gemini | Optional AI-assisted planning suggestions | Minimized event-intent text; we avoid sending unnecessary personal information |
| Mapbox | Geocoding and map display | Address/city text you enter, resulting coordinates |
| Zoho CRM | Internal sales/support relationship management (derived copy; Postgres remains the source of truth) | Contact and account details for merchants and key accounts |
| Cloudflare | DNS, content delivery, and web application firewall | Network/request metadata for the public website |
4. Payment data
Card details are entered directly into Stripe-hosted payment fields and never touch our servers or database. We store only payment references, status, and amounts. Our payment flow is designed to qualify for the lowest PCI DSS self-assessment tier (SAQ-A).
5. Automated features & AI
Certain planning features may use AI (Google Gemini) to suggest merchants, packages, or itineraries based on the event details you provide. We aim to minimize the personal information included in AI prompts and do not use your data to train third-party foundation models.
6. Marketing communications & CASL
Transactional messages (OTP codes, booking/order updates, receipts) are sent as part of operating the Services and are not “marketing” under Canada's Anti-Spam Legislation (CASL). Marketing emails and SMS are sent only if you provide express opt-in consent at signup or in your notification settings. You can withdraw consent at any time by:
- Using the unsubscribe link included in every marketing email, or
- Replying STOP to any marketing SMS, or
- Updating your notification preferences in the app, or
- Emailing team@letsgetfood.com
7. Data retention
We retain personal information for as long as your account is active and as needed to provide the Services, comply with legal/tax obligations, resolve disputes, and enforce our agreements. When you request account deletion, we anonymize bookings, payments, and reviews associated with your account and permanently delete device tokens, saved items, and notification records, subject to what we must retain for legal, accounting, or fraud-prevention purposes.
8. Your rights
Subject to applicable law, you may:
- Access a copy of the personal information we hold about you
- Correct inaccurate or outdated information via your profile
- Delete your account and associated personal information — in-app via Settings → Delete Account (OTP-verified), or via our account-deletion page
- Export your data by contacting support
- Withdraw consent for marketing communications at any time
To exercise these rights, contact team@letsgetfood.com. We will respond within a reasonable time as required by PIPEDA.
9. Cross-border data transfers
We are a Canada-first company and prioritize Canadian data residency where practical (e.g., Supabase Canada Central region, Telnyx Canada routing, Zoho .ca data centre). Some service providers (including Resend, Google Gemini, Mapbox, and Firebase) may process or store data outside Canada, including in the United States. Where personal information is transferred internationally, we take steps to ensure appropriate contractual protections are in place with our sub-processors.
10. Cookies
Our marketing website and admin tools use cookies for essential site functionality and basic analytics. See our Cookie Notice for details.
11. Children's privacy
The Services are not directed to children, and we do not knowingly collect personal information from children under 13 (or the applicable age of consent in your province).
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated in-app or by email. Continued use of the Services after a change takes effect constitutes acceptance of the updated policy.
13. Contact us
Let's Get Food Inc. · Email: team@letsgetfood.com