Privacy Policy
Last updated: August 31, 2026
1. Data Controller and Contact Details
This Privacy Policy explains how Secret Recipe Vault (“we”, “us”, or “our”) collects, uses, and protects personal data when you visit and use our digital recipe platform.
Data Controller: Secret Recipe Vault
Postal Address: Office 4182, 58 Peregrine Road, Hainault, Ilford, IG6 3SZ, United Kingdom
Support & Privacy Inquiries: vaultsecretrecipe@gmail.com
2. Personal Data We Collect
We only collect personal data that is strictly necessary to provide access to our digital recipe vault, manage your account, and securely process transactions:
- Account Identification Data: Your name, email address, password hash (for direct email registrations), and assigned internal user ID.
- Billing and Payment Data: Subscription status, purchase date, plan tier, transaction IDs, and currency. Note: All payment card details are collected and processed directly by our PCI-DSS compliant payment providers (Stripe and PayPal). We never store full credit or debit card numbers, expiration dates, or CVV security codes on our servers.
- Usage and Technical Data: IP address, browser type and version, operating system, saved recipes/bookmarks, timestamps, and page interaction data.
- Customer Communications: Records of inquiries, emails, or support requests sent to our support inbox.
3. Google OAuth and Authentication Services
When you choose to register or sign in to Secret Recipe Vault using Google Sign-In (OAuth 2.0), we request the following specific scopes:
openidhttps://www.googleapis.com/auth/userinfo.emailhttps://www.googleapis.com/auth/userinfo.profile
Data Received from Google: Your verified email address, full name, Google account ID, and profile photo URL.
How Google User Data is Used: We use this information solely to verify your identity, create or authenticate your Secret Recipe Vault member account, display your name in your account dashboard, and grant access to recipe content and bookmarks.
Data Protection Guarantee: We strictly adhere to the Google API Services User Data Policy. We do not sell, rent, trade, or transfer Google OAuth user data to third parties or data brokers. Google user data is never used for serving advertisements, market research, or training machine learning models.
4. Lawful Bases for Processing under UK GDPR
Under the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018, we process your personal data under the following legal bases:
- Contractual Necessity: To provide access to the digital recipe library, manage your subscription, process payments, and authenticate your login.
- Legitimate Interests: To maintain platform security, prevent fraudulent abuse or scraping, troubleshoot technical errors, and optimize website performance.
- Legal Obligation: To maintain financial, tax, and accounting records in compliance with applicable statutory requirements.
- Consent: For optional non-essential communications where you have explicitly opted in. You may withdraw consent at any time.
5. Third-Party Data Processors
We engage reliable third-party service providers (subprocessors) to support our technical and commercial operations:
- Payment Processing: Stripe, Inc. and PayPal (Europe) S.à r.l. et Cie, S.C.A. (handling encrypted checkout, subscription billing, and refunds).
- Cloud Infrastructure & Hosting: Google Cloud Platform (Google LLC) and Cloudflare, Inc. (providing server hosting, edge caching, and DDoS mitigation).
- Database & Authentication Management: Supabase, Inc. (providing secure PostgreSQL database storage and session token verification).
- Transactional Email: Transactional email service providers for delivery of purchase receipts, password reset links, and critical account notices.
6. International Data Transfers
Some of our third-party infrastructure providers operate servers located outside the United Kingdom and European Economic Area (EEA), primarily in the United States. Whenever personal data is transferred internationally, we ensure that appropriate safeguards are in place, including UK International Data Transfer Agreements (IDTAs), UK Addendums to EU Standard Contractual Clauses (SCCs), and Data Privacy Framework certifications where applicable.
7. Data Retention Schedule
We retain personal information only for as long as necessary to fulfill the purposes outlined in this policy:
- Active Accounts: Retained for the duration of your active subscription and account status.
- Deleted Accounts: Upon receiving an account deletion request, user profiles and personal identifiers are permanently removed or anonymized within 30 days.
- Financial & Billing Records: Retained for up to 6 years following the end of the relevant financial year to satisfy statutory accounting and tax compliance.
- Server & Security Logs: Retained for a maximum of 90 days for diagnostic and security auditing purposes.
8. Your Legal Rights (UK GDPR & CCPA/CPRA)
Depending on your location, you hold specific statutory privacy rights regarding your personal information:
Under UK GDPR and EU GDPR:
- Right of Access: Obtain confirmation of whether we process your data and request a copy.
- Right to Rectification: Request correction of inaccurate or incomplete personal records.
- Right to Erasure (“Right to be Forgotten”): Request deletion of your personal data where statutory grounds exist.
- Right to Restriction of Processing: Request temporary restriction of data processing.
- Right to Data Portability: Receive your data in a structured, machine-readable format.
- Right to Object: Object to processing based on legitimate interests or direct marketing.
Under California Consumer Privacy Act (CCPA/CPRA):
California residents have the right to know what personal information is collected, request deletion, and not be discriminated against for exercising privacy rights. We confirm that we do not sell or share personal information with data brokers or advertisers.
To exercise any of these rights, please email us at vaultsecretrecipe@gmail.com. We will respond within one month (or within statutory timeframes).
9. Cookies and Local Storage
We use strictly necessary first-party cookies and session tokens to keep you securely signed in to your account and maintain your session state across page views. We do not deploy third-party tracking or behavioral profiling cookies. You can configure your browser to refuse all cookies; however, disabling strictly necessary cookies will prevent login and recipe access functionality.
10. How to Complain to the Supervisory Authority
If you believe your data has been handled improperly, you have the right to lodge a complaint with your relevant supervisory authority, including the UK Information Commissioner's Office (ICO):
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Website: https://ico.org.uk | Tel: 0303 123 1113
11. Changes to This Privacy Policy
We may revise this Privacy Policy periodically to reflect legal, regulatory, or technical changes. Any updates will be posted on this page with an updated “Last updated” timestamp. For material modifications, we will notify registered members via email or prominent website notification prior to the change taking effect.