Legal
Privacy policy
What Digital Kitchen collects from customers and Kitchens, who can see it, how allergy information is treated, how long things are kept, and what survives a deletion request.
# Privacy policy
**Version 1.0-pilot · controlled pilot**
Written and approved by the founder of Digital Kitchen Marketplace for a small
invitation-only pilot. Not reviewed by a lawyer, and it does not claim to have
been. It makes no claim of legal compliance, government approval or professional
certification.
Everything below was checked against the database schema and the row-level
security policies that enforce it. It describes what the software actually
collects — not what a policy template would guess.
---
## What we collect
### If you order food
**Account.** Your email address, and a display name if you give one.
**Orders.** What you ordered, from which Kitchen, when, for how much, and the
fulfilment details needed to hand the food over.
**Household dietary profiles.** Allergies and dietary requirements you choose to
save. The schema holds no diagnosis, no medication, no health-card number, and no
unnecessary information about children.
**Settlement.** Whether a payment was reported, when, whether a person verified
it, and any reference recorded. **Card details are never collected**, because no
card is ever charged by this service.
**Support and safety.** Messages in a support case, and any food-safety incident
record.
**Reviews.** What you write, if you write one.
**Security and activity.** Sign-in and authentication activity handled by our
authentication provider, and audit records of privileged actions taken about your
account.
### If you run a Kitchen
**Contact and identity.** Your name, contact email and phone, and the
identification or business-registration documents you submit.
**Business information.** Legal name, operating name, how your business is set up,
your operating address, municipality, province and postal code, your public-health
region where you give one, and business identifiers where applicable.
**Tax information.** Whether you are registered for GST/HST and, where you supply
it, your registration number. Supplying a number is not required to complete
onboarding.
**Compliance documents.** Food handler certificates, permits and licences,
public-health documentation, insurance documentation, and other supporting
documents, along with their review status and expiry dates.
**Agreement acceptances.** Which version of the Kitchen/Seller Agreement you
accepted, when, and which signed-in account accepted it. We do **not** record an
IP address or a device fingerprint with an acceptance.
**Operator review information.** Notes a reviewer records about your application,
and the review states of your identity, documents and reporting review.
**Orders and activity.** The orders placed with you and how they were fulfilled.
We do not collect categories of data that are not listed here.
## Who can see what
Access is enforced by the database, not by the interface. The rules below are
row-level security policies — a screen cannot show what a policy withholds.
- **You** see your own orders, your own profiles, your own settlement status.
- **A Kitchen** sees the orders placed with it, and for each order only the
immutable snapshot attached to it. A Kitchen is never joined back to your live
household profile, and never sees an order placed with another Kitchen.
- **Operators** see what their platform role admits and no more. Allergy detail is
need-to-know operational data: content and finance roles do not receive it.
- **Nobody** sees a raw credential, a customer address outside the order it
belongs to, an access token, a handoff code, or a private Kitchen location.
A Kitchen's tax number and the operator notes about it are not visible to other
Kitchens or to customers. The public profile of a Kitchen carries its names, its
municipality and province, its operation type, and whether identity and documents
have been reviewed — and nothing else.
## Allergy and dietary information
We treat this as **sensitive**, with the care health information warrants. We are
not asserting a legal classification, because nobody qualified has made one; we
are telling you how it is handled, which is the part that affects you.
**We use it for:** preparing your order safely, communicating it to the Kitchen
cooking that order, investigating a support or safety matter, and aggregate
operational safety metrics where the data has been properly de-identified.
**We never use it for:** advertising, promotional targeting, profiling unrelated
to your order, or sale to anyone.
The Kitchen receives it only as the frozen snapshot attached to its own order, and
under the Kitchen/Seller Agreement may use it only to prepare that order safely.
## Seller identity, business and tax information
We collect this where it is reasonably needed to operate the marketplace, verify
sellers, meet legal and regulatory obligations, meet tax and reporting
obligations, prevent fraud and protect security, and keep proper records.
Two things this does **not** mean:
- We are **not** saying that every Kitchen is a reportable seller. Recording that
somebody reviewed a Kitchen's information is not a determination that the
Kitchen is reportable to any authority.
- We do **not** automatically submit anything to the Canada Revenue Agency. No
such functionality exists in this software.
## Invitations
An invitation stores the email address it was issued to and a hash of a token. The
token itself is never stored, never shown after creation, and never returned by
any query — an invitation is proven by the email address matching.
## Exports
The settlement export carries the order number, Kitchen, status, amount and
timestamps. It carries no name, email address, delivery address, allergy
information, or customer-typed payment reference.
## Marketing
Marketing is separate and optional.
**Nothing is pre-checked.** You are not opted in by default, and declining
marketing does not prevent you creating an account, ordering, or running a
Kitchen.
Service messages about an order you placed — that it was accepted, that it is
ready — are not marketing, and you receive those because you ordered.
Where we send a commercial message, it will identify us and give you a way to
unsubscribe.
## How long we keep things
We do not publish a fixed number of days, because no automatic deletion schedule
is implemented and publishing one would be a promise nothing keeps.
What we can tell you is the principle we follow. Personal information is kept
while your account is open, and afterwards only for as long as reasonably required
for:
- completing and evidencing transactions
- handling disputes and complaints
- fraud prevention and security
- legal obligations
- tax and reporting obligations
- audit records of privileged actions
- agreement acceptance history
Personal information that is not needed for one of those should not be kept
indefinitely.
## Your requests
A privacy request centre handles export, correction and deletion requests. Each
request is identity-verified, delivered privately, limited to an allowlisted
inventory of records, and audited.
**Deletion is reviewed, not automatic.** We are not going to promise that every
record about you disappears on request, because some records cannot lawfully or
sensibly be destroyed. Records likely to survive a deletion request include:
- transaction and settlement records
- food-safety incident and recall records
- audit records of privileged actions
- agreement acceptances, which are the evidence of what somebody agreed to
- anything we are required to keep by law
Where a record survives, we still remove personal information from it that is not
needed for the reason it survives.
## Who else is involved
**Supabase** hosts the database, authentication and file storage.
**Netlify** hosts and serves the application.
**Resend** delivers outbound email. Email bodies contain secure order links, and
every logging path redacts anything token-shaped before it is written.
**No analytics, advertising or tracking service is used, and no third-party script
runs in your browser.**
## Security
Passwords are handled by the authentication provider and never seen by this
application. Private files are stored in private buckets and reached only through
short-lived links.
Uploaded documents are structurally validated. **Structural validation is not
malware scanning**, and we do not describe it as such anywhere.
## Changes
We may publish a new version of this policy. Published versions are never edited
or deleted, and a change applies from its publication date.
## Contact
Digital Kitchen Marketplace is the marketplace operated by Digital Kitchen Marketplace.
400 Mississauga Valley Blvd, Mississauga, Ontario, L5A 3N6, Canada
Telephone: +1 416-358-2594
- General and order support: support@digitalkitchenmarketplace.com
- Policy and contract questions: legal@digitalkitchenmarketplace.com
- Privacy and data requests: privacy@digitalkitchenmarketplace.com
---
## What this policy deliberately does not claim
- That a lawyer wrote or reviewed it
- Any fixed retention period, because none is implemented
- That data is deleted on request, because deletion is reviewed
- That allergy data has been legally classified
- That any Kitchen is a reportable seller
- That anything is submitted to a tax authority automatically
- That uploads are scanned for malware
- Any claim about processing location beyond naming the providers