1. Data we collect
We may collect account details such as username and email, profile and chef-service information, recipes and media you publish, request details, messages needed to deliver the service, reviews, cookie preferences, device data, technical logs and verification status data.
2. Chef verification
Chef verification may require identity, country and liveness information. Where a managed verification provider is used, Culinaro stores only the verification status and provider reference needed to protect the marketplace. If manual review is used, uploaded documents, selfie files and OCR text are restricted to authorised staff and removed after the configured retention period.
3. How we use data
We use data to operate Culinaro, display public content, connect clients and chefs, deliver messages and requests, manage reviews, provide support, secure accounts, prevent abuse, improve the product and meet legal obligations.
4. Legal basis
We process data to perform the service contract, with consent where required, to comply with legal duties and for legitimate interests such as security, fraud prevention, product reliability, marketplace trust and dispute handling.
5. Sharing
We do not sell personal data. Public profile, recipe and review content may be visible to other users and search engines. Request and message details are shared with the relevant client or chef. We may disclose data where required by law.
6. Processors and transfers
We use processors for hosting, email, storage, analytics, AI-assisted content processing, verification and operational support. If data is transferred outside the EU/EEA, we rely on appropriate safeguards such as contractual protections or other lawful transfer mechanisms.
7. Storage and retention
We keep data only as long as needed for the stated purposes, account management, security, legal compliance or dispute handling. Verification files and OCR raw text are treated as high-risk data and are deleted or anonymised after review according to the configured retention policy.
8. Your rights
You can request access, correction, deletion, restriction, portability or objection where applicable by contacting us. Registered users can also manage or delete their account from Settings where the feature is available. We aim to respond to data protection requests within the legal deadline.
9. Security
We use access control, private storage for verification files, HTTPS, role-based admin access and operational safeguards designed to protect personal data. No online service can guarantee absolute security.
10. Supervisory authority
You may contact us first at the email above. You also have the right to lodge a complaint with the competent data protection supervisory authority.