CONSUMER PRIVACY & DATA PROTECTION (UAE PDPL)

Privacy Policy

Cravo Technologies L.L.C. is dedicated to protecting your personal data privacy and ensuring transparent data governance across cravonow.ae in strict compliance with UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (PDPL).

Statutory Standard: UAE PDPL (Decree No. 45/2021)
Data Controller: Cravo Technologies L.L.C.
Effective: August 4, 2026
Download Official PDF (31.2 KB)

1Statutory Compliance Basis (UAE PDPL)

This Privacy Policy is established pursuant to UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection ("PDPL"). Cravo Technologies L.L.C. operates as the Data Controller and Processor for personal data collected through its customer web portal, restaurant dashboards, driver applications, and system administration consoles.

2Categories of Personal Data Collected

Cravo collects and processes specific personal and technical data categories necessary to deliver hyper-personalized food delivery and dietary management services:

Data CategoryCollected AttributesOperational Purpose
Identity & Profile DataFirst Name, Last Name, Email Address, Phone Number, Password Hash (bcrypt), User Role.User registration, JWT authentication, role-based authorization, and account management.
Biometric & Health TelemetryDaily step count, active calories burned, daily energy expenditure, FitnessConnected flag.Calculate daily available calorie balance via Google Fit / Health Connect API (opt-in only).
Financial & Budget DataMonthly budget limit (MonthlyBudget), cumulative monthly spend, Stripe payment tokens.Enforce budget spending controls and execute secure payment processing via Stripe.
AI Interaction & Mood DataFree-text mood prompts (MoodText), AI chat history (chatWithAI), food preferences.Power AI meal recommendation engine and personalized discount generation algorithms.
Geospatial & Address DataDelivery address text, GPS coordinates (lat/lng), real-time courier location updates.Live order delivery tracking, route optimization via Google Maps API, and courier dispatch.
Technical & System LogsIP address, browser/device parameters, stateless JWT access tokens, audit logs.Ensure platform security, API token verification, fraud detection, and system health monitoring.

3Lawful Purposes of Data Processing

Order Fulfillment & Dispatch: Transmitting order selections to Restaurant Partners and routing spatial delivery coordinates to assigned Delivery Couriers.
AI Hyper-Personalization: Analyzing culinary preferences, historical purchases, remaining daily calories, and monthly budget limits to generate tailored meal options.
Health Metric Synchronization: Dynamically adjusting daily caloric allowances in real time based on fitness burn metrics pulled from authorized fitness frameworks.
Financial Management & Budget Tracking: Enforcing user-configured spending warnings prior to checkout.
Security & Governance: Authenticating JWT sessions, preventing fraudulent payment transactions, and facilitating system monitoring.
AI DATA PROTECTION

Messages, photos and voice you send to the Cravo AI Assistant, plus your dietary parameters (diet, allergies, goals, order history), are processed over encrypted connections by our AI providers: Groq (chat, speech-to-text and photo recognition) and Google Gemini (voice and photo fallback). Your name, phone number and payment details are NEVER sent to AI providers or sold to third-party data brokers. Photos you send in the AI chat are stored with that conversation so you can see them again; archiving a chat hides them. While Cravo uses the providers' free API tiers, they may use submitted content to improve their services; Cravo will move to paid tiers, which exclude this, before commercial launch.

4Fitness API Integration & Granular Consent Controls

4.1 Opt-in Framework: Health and fitness telemetry synchronization (Google Fit / Apple Health) operates strictly on an opt-in basis (FitnessConnected == TRUE). The system will never access health metrics without explicit user consent.
4.2 Immediate Revocation: Users maintain the right to disconnect fitness API integration at any time through Profile Settings by setting FitnessConnected = FALSE. Disconnection immediately halts all health data ingestion.

5Data Sharing & Third-Party Infrastructure Transfers

Cravo does NOT sell, rent, or monetize your personal data to third-party advertisers. Personal data is shared strictly with essential operational infrastructure providers:

Restaurant Partners: Receive item details, food preference tags, and dietary notes necessary to prepare your meal.
Delivery Couriers: Receive pickup/drop-off customer names, delivery address text, phone contact, and GPS coordinates during active dispatches.
Stripe API Gateway: Receives tokenized payment details to charge credit cards securely without exposing raw card numbers to local servers.
Groq & Google Gemini APIs (AI Infrastructure): Receive pseudonymized messages, food photos, voice clips and candidate menu data to produce recommendations, speech and transcripts.
Google Maps Platform API: Receives spatial coordinates to calculate delivery routes, distance metrics, and live map tracking overlays.

6Data Storage, Security & Encryption Protocols

6.1 Centralized Cloud Infrastructure: All relational platform data is stored in centralized relational databases hosted on secured cloud Virtual Private Servers (VPS).
6.2 Transit Encryption: All data transmitted between clients and backend APIs is encrypted using HTTPS / TLS 1.3 protocols.
6.3 Password Cryptography: Passwords are hashed using bcrypt with strong salt factors prior to storage.
6.4 Session Security: Authentication relies on signed, stateless JWT access tokens with strict expiration timeouts.

7User Data Rights Under UAE PDPL

Right to Access & Export: You have the right to request a digital copy of all personal records, order histories, and AI recommendation logs stored in our database.
Right to Rectification: You may update profile details, budget constraints, and account credentials at any time via Profile Settings.
Right to Revoke Consent: You may revoke permission for fitness telemetry processing at any time.
Right to Erasure: You may request full account deletion. Upon verification, Cravo will purge your personal identification records, subject to statutory accounting and legal audit retention obligations.

8Children's Data Protection Policy

Cravo is strictly intended for use by individuals who are at least 18 years of age. We do not knowingly collect or solicit personal data from minors. If we discover that an individual under 18 has created an account without verified parental consent, we will immediately purge all associated account records.

9Policy Amendments & Contact

Cravo reserves the right to update this Privacy Policy at any time to reflect software updates, architectural changes, or statutory amendments. Continued platform access after updates constitutes acceptance of revised terms.

Have questions regarding your personal data privacy?Contact our Data Protection Officer at [email protected] or visit Contact Support.
Download PDF