Privacy Policy
Last updated: September 17, 2026
This Privacy Policy explains how Profound AI Solutions LLC (“AskFoodie.AI”, “we”, “us”) collects, uses, and shares information when you use our websites, dashboard, mobile apps, QR-code and tap-tag experiences, loyalty programs, and related services (the “Service”).
1. Information We Collect
Diners. You can browse a restaurant’s menu and deals without an account. To collect rewards you sign in, and we then hold:
- Account details — your email address, and the name and profile picture your sign-in provider gives us if you use Google. There is no password: we send a one-time code to your email, or you use Google.
- Visit history — which restaurant you visited and when, recorded when you tap its card or give a code to its staff. This is the record the whole loyalty program is built on.
- Loyalty data — punches, points, membership tier, rewards you hold and have used, and prize-draw entries.
- Uploaded bills — where a restaurant allows it, you can photograph a bill so your points match what you spent. We do not keep the photograph. We extract the bill number, date, total, and currency, store those, and store a fingerprint (a hash) of the image so the same bill cannot be submitted twice. The image itself is discarded after it is read.
- Preferences and delivery data — which restaurants you follow, the notification level you chose, your time zone (so an email or push arrives at a sensible local hour), and, if you turn on alerts, a push subscription for your browser or device.
Restaurant owners, managers, and staff. Account details (name, email — again, no password), restaurant details (name, address, hours, time zone, country), menu and ingredient data, uploaded images, team membership and roles, and billing status. Payment card details are collected and processed by Stripe, our payment processor — we do not store card numbers.
Everyone. Basic technical data needed to operate and secure the Service, such as IP address, browser type, and request logs, plus essential cookies to maintain sessions. On our marketing site we may use analytics (Google Analytics) to understand site usage; we do not use advertising trackers.
2. How We Use Information
We use the information we collect to:
- Operate loyalty programs — record visits, count points, work out your tier, issue and track rewards, run prize draws
- Publish restaurant menus and deals
- Send the messages described in Section 3
- Process subscription payments
- Secure the Service and prevent abuse, including rate limiting and detecting visits or bills that were not genuine
- Improve the Service
3. Messages We Send You
Diners. If you follow a restaurant, you choose the level: no messages, a weekly email, or notifications. Regardless of that choice we may email you about your own account — a reward about to expire, points about to decrease, or a prize you have won — because those are about something you hold rather than something a restaurant wants to advertise. Every marketing email has an unsubscribe link, and unsubscribing stops all marketing email from us while leaving your rewards and points untouched. You can turn notifications off in your browser or device settings at any time.
Restaurants. We email account holders about the Service — billing, security, and transactional notices — and a weekly summary. These are not marketing and continue while the account is open.
4. AI Processing
Two things are sent to third-party AI model providers (currently Google’s Gemini models):
- Menu photographs a restaurant uploads, to extract menu items.
- Bill photographs a diner uploads, to read the bill number, date, and total.
AI providers process this data under their own terms. We do not keep either image once it has been read — for bills, only the extracted values and an image fingerprint are stored (Section 1). Please do not upload images containing personal information you do not want processed this way; a bill photograph should show the bill, not other documents.
5. Who We Share Information With
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We share information only with:
- The restaurant you visit. Its staff see your name when you check in at the counter, when you use a reward, and on a bill you upload to them, together with your visit and loyalty history at that restaurant. They do not see your activity at any other restaurant. Restaurants are given aggregate counts of their members — how many, and how many at each tier — not a list of who they are, and we do not give restaurants a way to export or message a membership list.
- Service providers (processors) who help us run the Service: Google (AI models, analytics), Stripe (payments), Neon (database hosting), Cloudflare (storage and delivery of uploaded images), and email providers (Resend / Amazon SES). Each is bound to use the data only to provide its service to us.
- Legal and safety — when required by law, legal process, or to protect the rights, safety, or property of AskFoodie.AI, our users, or the public.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.
6. Data Retention
Restaurant account and menu data is retained while the account is active and for a reasonable period afterward.
Diner visit and loyalty records are kept as a running history — visits, points, and rewards are added to rather than overwritten, because a points balance is worked out from the whole history and a reward has to be traceable to the visit that earned it. Closing your account removes your access to it; tell us at privacy@askfoodie.ai and we will delete or anonymize your records, subject to what we must keep by law or to settle a dispute.
Uploaded bill images are not retained at all — see Section 4. Prize-draw records (entries, winners, and the result of a draw) are kept as the audit trail for that draw.
We retain data as needed to comply with legal obligations, resolve disputes, and enforce agreements, then delete or anonymize it.
7. Security
We use appropriate technical and organizational measures to protect personal data, including encryption in transit, hashed one-time sign-in codes, role-based access for restaurant teams, and least-privilege access to production systems. No system is completely secure. Because we sign you in with a code sent to your email rather than a password, the security of your email account is the security of your AskFoodie.AI account — protect it accordingly.
8. International Data Transfers
We operate from the United States and serve restaurants in India, the United States, and elsewhere. Your information may be transferred to and processed in countries other than your own, including the United States, which may have different data-protection laws than your country. We take steps designed to ensure personal data receives adequate protection wherever processed.
9. Your Rights — India (DPDP Act, 2023)
If you are in India, we process your personal data on the basis of your consent (given when you create an account or record a visit) and for legitimate uses permitted by the Digital Personal Data Protection Act, 2023. You have the right to access a summary of your personal data, correct or erase it, nominate a person to exercise your rights, and withdraw consent (which stops processing that relied on it, without affecting prior processing). To exercise these rights, or to raise a grievance, contact privacy@askfoodie.ai — we will respond within the timelines required by law. If unsatisfied, you may complain to the Data Protection Board of India.
10. Your Rights — United States
Depending on your state (for example under the CCPA/CPRA in California), you may have the right to know what personal information we collect, access it, correct it, delete it, and to non-discrimination for exercising these rights. We do not sell or share personal information as those terms are defined in the CCPA, and we do not use or disclose sensitive personal information for purposes requiring a right to limit. To exercise your rights, email privacy@askfoodie.ai; we will verify your request and respond within the time required by law. You may use an authorized agent where the law allows.
11. Children
The Service is not directed at children, and we do not knowingly collect personal data from children under 13 (or under the age where parental consent is required in your jurisdiction, such as under 18 in India without verifiable parental consent). Prize draws are open only to entrants aged 18 or over. If you believe a child has provided us personal data, contact us at privacy@askfoodie.ai and we will delete it.
12. Changes to This Policy
We may update this Policy from time to time. We will post the updated version with a new “Last updated” date and, for material changes, notify account holders by email or through the Service.
13. Contact
Privacy questions, requests, or grievances: privacy@askfoodie.ai.
