Privacy Policy

Download Privacy

This section is rendered from the same legal file users download.

COMPREHENSIVE PRIVACY POLICY

1. Introduction and Statutory Compliance
1.1 Privacy Commitment
Cravo ("We", "Us", "Our") respects your personal data privacy. This Privacy Policy details how we collect, store, process, transfer, and protect your personal data across our multi-sided web applications, backend API servers, and AI recommendation subsystems.

1.2 UAE PDPL Compliance
This Privacy Policy is constructed in strict compliance with UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (PDPL) and international data protection standards.

2. Data Categories Collected by Cravo
We collect and process the following categories of personal and technical data:
- Identity and Profile Data: First Name, Last Name, Email, Phone Number, Password Hash (bcrypt), Admin Status.
- Biometric and Health Telemetry: Daily step counts, active calories burned, daily energy expenditure, fitness connection status (FitnessConnected). Collected only upon user opt-in.
- Financial and Budget Data: Monthly food budget (MonthlyBudget), cart subtotals, monthly cumulative spend, payment transaction IDs, Stripe token strings. Raw card details are not stored.
- AI Interaction and Mood Data: Free-text mood prompts (MoodText), AI chat history (chatWithAI), food preferences, interaction logs, generated recommendations.
- Geospatial and Delivery Data: Delivery address text, GPS coordinates (latitude/longitude), active courier location updates, order delivery timestamps.
- Technical and System Logs: IP address, browser type, device type, stateless JWT access tokens, system performance logs.

3. How We Use Your Personal Data
Cravo processes personal data strictly for lawful operational purposes:
- Order Fulfillment: Communicating order items to Restaurant Partners and routing spatial delivery details to assigned Couriers.
- AI Hyper-Personalization: Analyzing food preferences, past order history, available daily calories, and budget limits to rank personalized dish options (COMP-AI-02).
- Fitness Telemetry Sync: Adjusting daily caloric allowances in real time based on active burn metrics pulled from authorized fitness APIs.
- Financial Controls: Enforcing user-configured monthly budget warnings prior to checkout.
- Platform Security and Governance: Authenticating JWT sessions, verifying user roles, preventing payment fraud, and facilitating administrative oversight (FR-24).

4. Data Sharing and Third-Party Integrations
Cravo does NOT sell, rent, or trade your personal data to third-party advertisers or data brokers. Data is shared strictly with essential service infrastructure providers:
- Restaurant Partners: Receive order item details, food preferences, and delivery notes necessary to prepare your meal.
- Delivery Couriers: Receive pickup/drop-off customer names, delivery address text, phone contact, and GPS coordinates during active fulfillment.
- Stripe API (Payment Processing): Receives payment tokens and transaction amounts to charge credit cards securely without storing raw card data on local servers.
- OpenAI API (AI Infrastructure): Receives anonymized/pseudonymized text prompts and candidate menu parameters to process natural language chat responses and AI dietary recommendations.
- Google Maps Platform API: Receives spatial coordinates to calculate delivery routes, distance metrics, and live courier tracking overlays.

5. Data Storage, Security, and Encryption
5.1 Database Infrastructure
All relational data is stored in centralized MySQL databases configured on cloud Virtual Private Servers (VPS).

5.2 Security Measures
- Transit Encryption: All data transmitted between web/mobile clients and the Express.js backend API gateway is encrypted using HTTPS / TLS 1.3 protocols.
- Password Security: Passwords are hashed using bcrypt prior to database storage (PasswordHash).
- Session Isolation: Authentication relies on signed JWT access tokens with strict expiration timeouts.
- Access Control: Administrative access is restricted to verified System Administrators (FR-23, FR-24).

6. User Rights and Data Control Options
In accordance with the UAE Personal Data Protection Law (PDPL), users possess the following rights:
- Right to Access and Export: You may request a copy of your personal data, order history (FR-19), and AI recommendation logs stored in our MySQL database.
- Right to Rectification: You may update your profile details, budget figures, and password at any time via your Profile Settings page (FR-03).
- Right to Revoke Fitness Consent: You may immediately disconnect fitness API synchronization (FitnessConnected = FALSE), halting all health telemetry ingestion.
- Right to Erasure ("Right to be Forgotten"): You may submit an account deletion request. Upon verification, Cravo will purge your personal identification records, subject to legal audit retention duties.

7. Children's Privacy
Cravo is not intended for use by children under the age of 18 without parental supervision. We do not knowingly collect or solicit personal data from minors. If we discover that a child under 18 has registered an account without parental consent, we will promptly delete the account and associated records.

8. Policy Amendments and Contact Information
Cravo reserves the right to update or modify this Privacy Policy and Terms of Service at any time. Material changes will be communicated via platform notifications or email alerts. Continued use of the platform after updates constitutes acceptance of the revised terms.

Cravo Platform Data Protection and Legal Contact
Email: [email protected] | [email protected]
Official Web Portal: https://cravonow.ae/legal