Draft, 14 September 2026. Written for review by a solicitor before OnlyFood takes public money.

Privacy

What we know about you, why we need it, and how to get rid of it.

Last updated 14 September 2026

1. Who holds your data

[OnlyFood Ltd] of [registered address] is the controller of your personal data. Write to hello@onlyfood.me about anything on this page. [Solicitor: confirm whether a UK representative or a data protection officer is needed, and register with the ICO.]

We would rather hold less of this than more. There is no advertising here, so there is nothing to profile you for.

2. What we collect

  • Your account. E-mail address and a password Supabase stores as a hash. We never see the password.
  • Your profile. Display name, handle, short bio, avatar, time zone. For a creator, also the kitchen name, tagline, cover photo, chosen colour and cuisine tags. All of this is public by design — a kitchen has to be findable.
  • What you cook. Cook logs: which recipe, a rating, a note, a photo if you add one, and whether you chose to share it with the creator.
  • Questions. What you ask a creator, and their answer. The creator sees your display name and handle with it, never your e-mail address.
  • What you bought. Memberships, Recipe Passes, session bookings and the brief or dietary note you give a creator before a session, plus the amount, the currency and the date.
  • Payments. Handled by Stripe. We keep the Stripe identifiers and the amounts. We never see, receive or store your card number.
  • Link clicks. When you open a creator's shared recipe link we count the visit. Instead of your IP address we store a short hash of your browser's user-agent, your language setting and the day's date. It changes every day on purpose, so it counts people rather than page loads and cannot follow you from one day to the next. We do not store the IP address.
  • Product events. A small internal log of actions like "recipe published", used to see whether the product works. Nobody outside OnlyFood can read it.

We do not ask for your address, your date of birth, your phone number or anything about your health. Please do not put health information into a cook log or a session brief — write "no nuts" rather than a diagnosis.

3. Why, and on what legal basis

  • To give you what you paid for — your account, access to a kitchen, a booked session, a receipt. Basis: performance of our contract with you.
  • To pay creators and keep our books — the payments ledger and the fee. Basis: contract, and our legal obligation to keep accounting records.
  • To send service e-mails — a booking confirmation, an answered question, a failed payment, a membership ending. Basis: contract. These are the ones you cannot switch off, because they are the service.
  • To send optional e-mails — a new recipe from a kitchen you belong to, the Sunday drop. Basis: consent, and you can switch them off from your profile page at any time.
  • To give creators counts — visits, members, views. Basis: legitimate interests, which is why the visitor hash is daily and coarse rather than an identifier.
  • To keep the place safe — fraud, chargeback abuse, takedowns. Basis: legitimate interests, and legal obligation where a rights holder complains.

4. Who else sees it

Four companies, each doing one job. None of them is an advertiser, and we sell your data to nobody.

  • Stripe — payments, your card, creator payouts and identity checks. Stripe is the merchant of record and its own controller for card data.
  • Supabase — the database, your login and file storage. Hosted in the EU, in Frankfurt (eu-central-1).
  • Vercel — serves the website and keeps short-lived request logs.
  • Resend — sends our e-mails. It sees your e-mail address and the message.

Creators see the part described in section 9 of the creator agreement: your display name, your handle, your questions and what you bought from them. Never your e-mail address.

Some of these companies are in the United States and use the standard transfer protections. [Solicitor: confirm the transfer mechanism and the list of sub-processors before launch.]

5. How long we keep it

  • Your account and profile: while your account exists.
  • Cook logs, notes and questions: while your account exists, then deleted with it.
  • Payment records: six years, because tax law says so.
  • Link-click hashes and product events: 24 months, then deleted.
  • Backups: rolled off within 30 days of a deletion.

6. Your rights

You can ask for a copy of your data, ask us to correct it, ask us to delete it, object to what we do on legitimate interests, and withdraw consent to optional e-mails.

Most of it you can do yourself. Delete your account from your profile page, and switch e-mail notices off there too. For anything else, e-mail hello@onlyfood.me and we will answer within 30 days, free.

If we handle it badly you can complain to the Information Commissioner's Office at ico.org.uk, or to your own country's data protection authority.

7. Children

OnlyFood is for adults. You must be 18 or over to have an account, and we do not knowingly collect anything from a child. If you think a child has an account here, tell us and we will remove it.

8. Cookies

There are two, and neither one advertises to you. The list is on the cookies page.

9. Changes and contact

If we start collecting something new, or hand data to a company not listed above, we will change this page and e-mail you before it happens. Write to hello@onlyfood.me.