Privacy & Cookie Policy
Last updated: May 4, 2026
1. Who We Are
Cook For Me ("we", "us", "our") operates the cookforme.com platform. This policy explains how we collect, use, and protect your personal data, and how we use cookies. Contact us at privacy@cookforme.com with any questions.
2. Data We Collect
We collect the following categories of personal data:
- Account data: name, email address, password (hashed), and role (customer or chef).
- Profile data: chef bio, cuisine type, profile photo, service areas, and pricing.
- Booking data: booking dates, service type, messages, and payment information (processed by Stripe — we never store full card details).
- Location data: approximate location derived from your IP address for showing nearby chefs. We do not track GPS location without explicit permission.
- Usage data: pages visited, features used, and interaction patterns — only if you consent to analytics (see Section 6).
- Communications: messages sent through the platform between chefs and customers.
3. How We Use Your Data
- To provide, operate, and improve the platform
- To process bookings and facilitate payments
- To send booking confirmations, updates, and service notifications
- To verify chef compliance and prevent fraud
- To respond to customer support requests
- To analyse usage trends and improve user experience (with consent)
- To comply with legal obligations
4. Legal Basis for Processing
We process your data under the following legal bases:
- Contract: to fulfil bookings you make
- Legitimate interests: security, fraud prevention, service improvement
- Consent: analytics tracking and marketing emails
- Legal obligation: tax records, compliance audits
5. Data Sharing
We do not sell your personal data. We share data only with:
- Stripe:for secure payment processing. Stripe's privacy policy governs their use of your payment data.
- Railway / Vercel: our infrastructure providers hosting the platform.
- Chefs on the platform: your name and booking details are shared with the chef you book.
- Law enforcement: if required by applicable law or valid legal process.
6. Cookies & Tracking
Essential Cookies
These are required for the platform to function. They include your authentication session token and security tokens. You cannot opt out of these while using the Service.
| Cookie | Purpose | Duration |
|---|---|---|
| access_token | Keeps you logged in | 1 hour |
| refresh_token | Silent re-authentication | 7 days |
Analytics Cookies (Optional)
With your consent, we use first-party analytics to understand how the platform is used. We do not use Google Analytics or any third-party tracking pixels.
| Storage key | Purpose | Duration |
|---|---|---|
| analytics_consent | Records your analytics preference | Persistent |
| analytics_events | Queued event data sent to our server | Session |
You can change your analytics preference at any time using the controls below.
7. Data Retention
We retain your account data for as long as your account is active, and for up to 3 years after closure for legal and tax compliance purposes. Booking records are retained for 7 years as required by US tax law. Analytics event data is retained for 2 years.
8. Your Rights
Depending on your location, you may have the following rights:
- Access: request a copy of the data we hold about you
- Correction: request correction of inaccurate data
- Deletion: request deletion of your account and data
- Portability: receive your data in a machine-readable format
- Opt-out: withdraw consent for analytics at any time
- CCPA (California): opt out of the sale of personal information (we do not sell data)
To exercise any of these rights, email privacy@cookforme.com. We will respond within 30 days.
9. Security
We use industry-standard security measures including TLS encryption in transit, hashed passwords (bcrypt), JWT tokens with short expiry, and access-controlled infrastructure. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security.
10. Children
The Service is not directed at children under 18. We do not knowingly collect personal data from anyone under 18. If we become aware that a child under 18 has provided us personal data, we will delete it promptly.
11. Changes to This Policy
We may update this policy periodically. We will notify you by email or in-app notification before material changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.
12. Contact
For privacy inquiries, contact our privacy team at privacy@cookforme.com.