Privacy Policy

Last updated: July 27, 2026

Feedhood ("we", "us", "our") operates the Feedhood mobile app and website at feedhood.com, a technology platform connecting home cooks, restaurants, bakers, farmers ("feeders") with neighbours who want to buy their food ("buyers"), plus drivers who deliver orders. This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the rights you have over your data.

We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) in Canada and the BC Personal Information Protection Act (PIPA). If you are in the European Economic Area, UK, or California, additional rights apply (see "Your Rights" below).

1. Information we collect

Information you give us

  • Account info: email address, password (hashed via Supabase Auth, we never see your plaintext password).
  • Profile info: full name, phone number, profile photo (optional), default delivery address.
  • Order info: the items you order, delivery address, dietary preferences, optional booking details (party size, contact name/phone for dine-in).
  • Payment info: handled by Stripe. We store only the last 4 digits of your card and the Stripe customer ID. Card numbers, CVV, and expiry never touch our servers.
  • Feeder info (if you sell): business name, bio, food-safety certificate (PDF), Stripe Connect ID for payouts.
  • Driver info (if you deliver): driver's license + insurance documents, vehicle details, real-time GPS location while on an active delivery.
  • Communications: support emails, in-app messages, reviews you leave.

Information collected automatically

  • Device + app info: device type, OS version, app version, push notification token.
  • Usage data: screens viewed, features used, searches made, collected by Supabase + our own logs.
  • Crash + error diagnostics: when the app or website hits an error, a diagnostic report is sent to our error-monitoring provider. See Error monitoring for exactly what it contains.
  • Approximate location: to show feeders near you. We never track precise GPS unless you're an active driver on a delivery.

Information from third parties

  • Stripe, payment + Connect account status.
  • Google Maps + Places, geocoding addresses you enter.
  • Apple / Google, push notification delivery (no personal info shared with them by us, beyond what the OS exposes).

2. How we use your information

We use your data only for the following purposes:

  • To provide the Feedhood service: process orders, route deliveries, settle payouts, send notifications.
  • To keep the platform trustworthy: verify food-safety certificates, review feeder + driver applications.
  • To respond to customer support requests.
  • To prevent fraud and abuse (account takeover, payment fraud, fake reviews).
  • To improve the product (aggregated, anonymized analytics).
  • To send transactional emails (order confirmations, password resets). We do not send marketing emails unless you opt in.

We do not sell your personal information to anyone, and we do not use it for targeted advertising.

3. Who we share your information with

We share the minimum necessary data with:

  • Feeders + drivers involved in your order: the feeder sees your name, delivery address, order contents, and special instructions. The driver sees your name and delivery address while delivering. They do not see your email or full profile.
  • Stripe: for payment processing and feeder payouts. Stripe's privacy policy applies.
  • Supabase: our cloud infrastructure provider. Data is hosted in their Canada (Toronto) region where available.
  • Google Maps + Places: to geocode the address you enter. Google receives the address text only.
  • Resend: delivery of transactional email (order confirmations, password resets). Resend receives your email address and the message contents.
  • Sentry: error and crash monitoring, operated by Functional Software, Inc. (United States). Sentry receives a pseudonymous account identifier, technical error details, and device information. It does not receive your name, email, phone number, or delivery address. Data is processed in the United States under a data-processing agreement. See Error monitoring below.
  • Other service providers we engage from time to time, bound by confidentiality agreements.
  • Law enforcement when legally compelled (court order, subpoena). We will notify you unless prohibited by law.
  • Successor entities in case of merger, acquisition, or sale, your data is treated as protected under this policy by the acquirer.

4. How long we keep your data

Order + financial records: kept for at least 6 years to comply with the Canada Revenue Agency's record-keeping rules. Even if you delete your account, the order rows persist in anonymized form (your name becomes "Deleted user", PII is scrubbed).

Account profile, addresses, favorites, push tokens: deleted immediately when you request account deletion. See "Your Rights" below.

Driver GPS location: retained for 90 days after the delivery completes (for dispute resolution), then deleted.

Support tickets + reviews: retained for as long as your account is active, then 3 years after deletion.

5. How we protect your information

  • All traffic between your device and our servers uses TLS 1.2+.
  • Passwords are hashed by Supabase Auth using bcrypt.
  • Database access is gated by Row Level Security policies, buyers can't see other buyers' orders, feeders can't see other feeders' menus, etc.
  • Card numbers + CVV are never stored by us. Stripe (PCI-DSS Level 1 certified) handles all card data.
  • Sensitive documents (food-safety certificates, driver licenses) are stored in private Supabase Storage buckets accessible only via short-lived signed URLs.
  • Our team's access to your data is logged internally.

No internet service is 100% secure. We follow industry best practices but cannot guarantee absolute security.

6. Your rights

You have the right to:

  • Access the personal information we hold about you.
  • Correct inaccurate information in your profile (do this directly in the app).
  • Delete your account (Profile → Delete my account). PII is scrubbed immediately; financial records are retained anonymously.
  • Export your data in a portable format, email hello@feedhood.app.
  • Withdraw consent for any optional processing at any time.
  • Lodge a complaint with the Office of the Privacy Commissioner of Canada or the BC Privacy Commissioner.

If you are in the EU/UK or California, GDPR and CCPA give you additional rights (right to object, right to data portability, etc.). Email us to exercise any of these.

7. Dine-in and in-person meetings

Dine-in lets a buyer reserve a seat to eat in person at a feeder's place (a restaurant, or a home cook hosting guests). To make a booking work, we share what's needed between the two of you: the feeder receives the buyer's booking name, party size, and a contact phone for the reservation, and the buyer may see the feeder's address and contact details the feeder has chosen to publish.

A dine-in then happens in person and off the platform. Any information you exchange face-to-face, and anything that happens during the meeting, is outside Feedhood's systems and outside our control. We can't protect personal information you choose to share in person, and we are not responsible for in-person dine-in interactions. Please see the dine-in section of our Terms of Service for how responsibility works, and only share what you're comfortable sharing.

8. Children

Feedhood is not intended for users under 13. We do not knowingly collect personal information from children. If you believe a child has given us information, contact us and we'll delete it.

9. Cookies + tracking

Our mobile app does not use cookies. Our website uses session cookies for authentication and a small number of analytics cookies (e.g. to count page views). We do not use third-party advertising or cross-site tracking cookies.

10. Error monitoring and diagnostics

To find and fix crashes and bugs, we use Sentry, an error-monitoring service operated by Functional Software, Inc. in the United States. When something goes wrong in the app or on the website, Sentry receives a diagnostic report.

That report contains:

  • A pseudonymous account identifier (an internal random ID, not your email or name).
  • The technical error details: the error message and the code path that failed.
  • Device information: device model, OS version, and app version.

It does not receive your name, email address, phone number, delivery address, GPS coordinates, push token, payment details, IP address, or screenshots of your screen. We have turned off the default settings that would collect those, and we additionally instruct Sentry to scrub personal fields on their side.

The account identifier is random, but because we can match it to your account in our own database, we treat it as personal information. Sentry processes this data in the United States under a data-processing agreement, and does not use it for any purpose other than providing the service to us.

11. International transfers

We host data in Canada when possible. Some service providers (Stripe, Google, Sentry, Resend) process data in the US, your data is protected under their respective privacy frameworks and, where applicable, a data-processing agreement with us. While your information is outside Canada it may be accessible to foreign courts and law enforcement under the laws of that country.

12. Changes to this policy

If we make material changes, we'll notify you in-app and update the "Last updated" date above. Continued use of Feedhood after the effective date means you accept the revised policy.

13. Contact us

Privacy questions, data requests, or complaints: hello@feedhood.app

Feedhood, Vancouver, British Columbia, Canada