DinDin Privacy Policy
DinDin, 77 Lower Camden Street, Saint Kevin’s, Dublin, D02 XE80 (“DinDin”, “we”) is the data controller for the personal data described here. This policy explains what we collect when you use the DinDin app and dindin.recipes, why, where it is stored, who sees it and what your rights are. Questions: [email protected].
1. What we collect and why
| Data | Where it comes from | Why we use it | Legal basis (GDPR) |
|---|---|---|---|
| Account: email address, Google account identifier, sign-in times | You, when you sign in with Google or email | To create and secure your account | Contract (Art. 6(1)(b)) |
| Profile: nickname, avatar choice | You | Shown to other users who follow you or share a kitchen | Contract |
| Home cuisine (the region you pick as “familiar”) | You | Personalises your map and suggestions; visible only to you | Contract |
| Activity: quiz answers, dishes you save, plan or cook, ratings and comments, shopping lists, kitchens you belong to, who you follow, kudos you give | You, as you use the app | To run the features you use and compute your progress and achievements | Contract |
| Photos of dishes you cooked | You (camera or photo library, only when you choose to upload) | Shown on your profile and to users who follow you or share your kitchen | Contract |
| Subscription status and purchase events (product, dates, an anonymised App Store transaction reference) | Apple, via RevenueCat | To unlock paid features and keep purchase records | Contract; legal obligation for accounting records |
| Technical data: device type, app version, crash and error logs, IP address in server logs | Your device automatically | To keep the service running and secure | Legitimate interest (Art. 6(1)(f)) |
| Notifications you receive in the app | Generated by us | To tell you about follows, kudos, kitchen changes and events | Contract; you can mute in settings |
We do not collect precise location, contacts, health data or advertising identifiers, and we do not sell personal data. Your food choices may hint at religion or health; we do not infer or process such categories, and we ask you not to add them to free-text fields.
2. Where your data is stored
Your data is stored in the European Union (Amazon Web Services, Ireland) by our hosting provider Supabase. Photos are stored in the same region and are only reachable through short-lived links generated for signed-in users. If you use DinDin from outside the EU, your data still lives in the EU.
3. Who we share it with
We share personal data only with processors that help us run the Service, each under a data-processing agreement:
- Supabase, Inc. — database, authentication, file storage and serverless functions (EU hosting).
- Apple Inc. — App Store purchases and subscription management; Apple’s own privacy policy applies to your Apple ID.
- Google LLC — sign-in with Google (we receive your email and a stable account identifier; we do not receive your Google password or contacts).
- RevenueCat, Inc. — subscription status processing between Apple and our servers.
- Cloudflare, Inc. — hosting and protection for dindin.recipes.
Other users see your nickname, avatar, cooked dishes and photos if they follow you or share a kitchen with you. We disclose data to authorities only when legally required.
4. Analytics and marketing
At launch DinDin uses no third-party analytics or advertising SDKs. If we add product analytics later we will ask for your consent in the app first, and this section will be updated.
5. How long we keep data
- Account, profile and activity data: for as long as your account exists.
- Notifications: 90 days, then deleted.
- Quiz searches: 12 months, then deleted.
- Server and security logs: up to 30 days.
- Purchase records: 7 years after the transaction, in pseudonymised form, to meet accounting obligations.
When you delete your account, everything in the first three categories is deleted immediately, including your photos; kitchens you created are handed to another member or deleted if you were the only one.
6. Your rights
Under the GDPR (and similar laws elsewhere) you can:
- Access and export your data: Settings → Export my data gives you a JSON file with everything we hold about you.
- Correct it: edit your nickname, avatar and home cuisine in the app.
- Delete it: Settings → Delete account removes your account and data as described above.
- Object to or restrict processing based on legitimate interest, and withdraw any consent you gave.
- Complain to a supervisory authority; in the EU that is the data-protection authority of your country.
For anything the app cannot do, email [email protected]; we answer within 30 days.
7. Security
All traffic is encrypted in transit; data is encrypted at rest by our hosting provider. Access to your rows in our database is enforced per user at the database level (row-level security), and only a small number of administrators can access production systems, with multi-factor authentication. If a breach affects your data we will inform you and the supervisory authority as the law requires.
8. Children
DinDin is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has created an account, contact [email protected] and we will delete it.
9. Changes
We will post changes here and, for material changes, notify you in the app. The effective date at the top tells you which version applies.
10. Contact
DinDin, 77 Lower Camden Street, Saint Kevin’s, Dublin, D02 XE80 — [email protected]