DinnerSolved

Privacy Policy

DinnerSolved (Dinner Solved Limited) · Effective as of the date first accepted by you

Version 1.0

1. About This Policy

This Privacy Policy explains how Dinner Solved Limited ("DinnerSolved", "we", "us", or "our") collects, uses, discloses, and protects your personal information when you use the DinnerSolved platform (the "Service").

DinnerSolved is committed to protecting your privacy and complying with applicable Canadian privacy laws, including the Personal Information Protection and Electronic Documents Act ("PIPEDA") and the Canadian Anti-Spam Legislation ("CASL").

By using the Service, you consent to the collection, use, and disclosure of your personal information as described in this Policy.

2. What Personal Information We Collect

We collect personal information that you provide directly, information generated through your use of the Service, and information from third parties.

Information you provide directly

Contact details: your name, email address, phone number, and pickup or delivery address.

Account credentials: your password (stored in encrypted form).

Order and dietary information: your order history, meal preferences, food allergies, and dietary restrictions.

Payment information: your payment method details are collected and processed directly by Stripe, our payment processor. We do not store your full payment card number. We receive from Stripe a token representing your payment method, along with limited details such as the last four digits of your card and the card brand.

Communications: any messages, feedback, reviews, or support requests you send to us.

Information generated through your use of the Service

Technical and device information: your IP address, browser type, operating system, device identifier, and general geographic location.

Usage information: pages viewed, actions taken, features used, search terms, and time spent on the Service.

Cookies and similar technologies: session cookies, authentication cookies, and analytics cookies as described in Section 9.

Information from third parties

Payment processing information from Stripe, limited to what is described above.

Analytics providers may share aggregated information about how users interact with the Service.

3. Why We Collect Your Information

We collect and use your personal information for the following purposes:

To provide the Service, including creating and managing your account, processing orders, arranging pickup, and communicating with you about your orders;

To process payments through Stripe;

To share necessary order information with the kitchen preparing your meal (see Section 4);

To send transactional communications, such as order confirmations, receipts, and pickup reminders;

To provide customer support and respond to your inquiries;

To improve the Service, including analyzing usage patterns and troubleshooting issues;

To send marketing communications with your separate opt-in consent (which you may withdraw at any time);

To detect, prevent, and address fraud, security, and technical issues;

To comply with legal, regulatory, and tax obligations, including retention of transaction records for the period required by the Excise Tax Act (Canada) and other applicable law.

4. Who We Share Your Information With

We share your personal information only as described below. We do not sell your personal information to third parties, and we do not share it for third-party marketing purposes without your separate consent.

Kitchen partners

When you place an order, we share with the kitchen preparing your meal the information they need to fulfill your order, which typically includes your first name and last initial, order details (meal, quantity, any modifications), pickup code, and any allergen acknowledgments or dietary restrictions relevant to your order. We do not share your payment information, home address (beyond the pickup context), or general order history with kitchens.

Service providers

We use third-party service providers to help us operate the Service, subject to obligations of confidentiality and appropriate data protection. These include:

Stripe (payment processing);

Microsoft Azure (hosting and infrastructure);

Email delivery providers (transactional email);

Analytics providers (product analytics, where applicable);

Customer support tools.

Legal and regulatory disclosures

We may disclose your personal information if required to do so by law, subpoena, court order, or other legal process, or if we believe in good faith that disclosure is necessary to protect our rights, property, or safety, or the rights, property, or safety of others. This includes providing information to the Canada Revenue Agency in connection with tax matters.

Business transactions

If DinnerSolved is involved in a merger, acquisition, financing, or sale of assets, your personal information may be transferred to the successor or acquirer. In such a case, we will require the successor to honour the commitments in this Policy or provide you with notice and choice regarding your information.

5. Cross-Border Data Transfers

Some of our service providers process personal information outside of Canada, primarily in the United States. This includes Stripe (payment processing) and may include hosting or analytics providers. When your personal information is processed outside Canada, it is subject to the laws of the jurisdiction where it is processed and may be accessible to law enforcement or regulatory authorities in that jurisdiction under lawful process.

We take reasonable steps to ensure that service providers processing personal information outside Canada provide comparable levels of protection.

6. How Long We Keep Your Information

We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, or as required by law.

Account information: while your account is active. If you delete your account, we may retain certain information for tax and legal purposes as described below.

Order and transaction records: at least six (6) years, as required by the Excise Tax Act (Canada) for HST compliance.

Allergen acknowledgment records: at least seven (7) years, for legal and audit purposes.

Marketing consent records: for as long as your opt-in remains active, plus a reasonable period after withdrawal.

Support communications: for a reasonable period after the resolution of your inquiry.

You may request earlier deletion of specific information, subject to our legal retention obligations. See Section 7.

7. Your Privacy Rights

Under PIPEDA and other applicable law, you have the following rights regarding your personal information:

Access

You may request access to the personal information we hold about you. We will respond to your request within 30 days, or sooner if practicable. In limited circumstances (for example, where providing access would reveal personal information about another individual), we may be unable to provide certain information.

Correction

You may request that we correct inaccurate or incomplete personal information about you.

Withdrawal of consent

You may withdraw your consent to the collection, use, or disclosure of your personal information at any time, subject to legal and contractual restrictions and reasonable notice. Withdrawing consent may affect our ability to provide the Service to you.

Deletion

You may request that we delete your personal information. We will comply, subject to our legal retention obligations (for example, tax records).

Complaint

If you have a concern about how we handle your personal information, please contact our Privacy Officer at chris@dinnersolved.ca. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca or 1-800-282-1376.

8. How We Protect Your Information

We use reasonable administrative, technical, and physical safeguards to protect your personal information from loss, theft, unauthorized access, disclosure, copying, use, or modification. These include:

Encryption of data in transit using industry-standard TLS/HTTPS;

Encryption of sensitive data at rest;

Access controls limiting who at DinnerSolved can access personal information;

Payment information handled by Stripe, a PCI-DSS Level 1 certified processor, rather than stored by us;

Regular review of our security practices;

Employee and contractor confidentiality obligations.

No system is perfectly secure. If we become aware of a security breach that creates a real risk of significant harm to you, we will notify you and the Office of the Privacy Commissioner of Canada in accordance with applicable law.

9. Cookies and Similar Technologies

We use cookies and similar technologies to operate the Service, remember your preferences, and analyze how the Service is used.

Types of cookies we use

Strictly necessary cookies: required for the Service to function (for example, session and authentication cookies). These cannot be disabled.

Preference cookies: remember your settings and preferences.

Analytics cookies: help us understand how the Service is used so we can improve it. These are only used with your consent where required.

You can control cookies through your browser settings. Blocking or deleting certain cookies may affect the functionality of the Service.

10. Marketing Communications and CASL

DinnerSolved sends two types of email communications:

Transactional emails: order confirmations, receipts, pickup reminders, service updates, and other communications necessary to operate the Service and fulfill your orders. Consent to these is implied by your creation of an account and placement of orders.

Marketing emails: newsletters, promotional offers, information about new kitchens or features. We send marketing emails only with your separate opt-in consent.

You may withdraw consent to marketing emails at any time by clicking the unsubscribe link in any marketing email or by contacting us. Withdrawal of marketing consent does not affect our right to send you transactional emails necessary for your account and orders.

All electronic communications sent by DinnerSolved comply with the Canadian Anti-Spam Legislation (CASL), including identification of the sender, a valid contact method, and an unsubscribe mechanism where required.

11. Children's Privacy

The Service is intended for individuals 18 years of age and older. We do not knowingly collect personal information from anyone under 18. If you believe we have inadvertently collected personal information from a minor, please contact us and we will delete the information.

12. Third-Party Links

The Service may contain links to third-party websites (for example, links to a kitchen's own website or social media). This Policy does not apply to those third-party sites. We recommend you review the privacy policies of any third-party sites you visit.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. If we make material changes, we will notify you by email or through a notice in the Service before the changes become effective.

The date at the top of this Policy indicates when it was last updated.

14. Contact Us

If you have questions about this Policy, wish to exercise your privacy rights, or wish to file a complaint, please contact our Privacy Officer:

Privacy Officer

Dinner Solved Limited

Kitchener-Waterloo, Ontario

Email: chris@dinnersolved.ca

Website: dinnersolved.ca

If you are not satisfied with our response, you have the right to file a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca or 1-800-282-1376.