1Statutory Compliance Basis (UAE PDPL)
This Privacy Policy is established pursuant to UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection ("PDPL"). Cravo Technologies L.L.C. operates as the Data Controller and Processor for personal data collected through its customer web portal, restaurant dashboards, driver applications, and system administration consoles.
2Categories of Personal Data Collected
Cravo collects and processes specific personal and technical data categories necessary to deliver hyper-personalized food delivery and dietary management services:
| Data Category | Collected Attributes | Operational Purpose |
|---|---|---|
| Identity & Profile Data | First Name, Last Name, Email Address, Phone Number, Password Hash (bcrypt), User Role. | User registration, JWT authentication, role-based authorization, and account management. |
| Biometric & Health Telemetry | Daily step count, active calories burned, daily energy expenditure, FitnessConnected flag. | Calculate daily available calorie balance via Google Fit / Health Connect API (opt-in only). |
| Financial & Budget Data | Monthly budget limit (MonthlyBudget), cumulative monthly spend, Stripe payment tokens. | Enforce budget spending controls and execute secure payment processing via Stripe. |
| AI Interaction & Mood Data | Free-text mood prompts (MoodText), AI chat history (chatWithAI), food preferences. | Power AI meal recommendation engine and personalized discount generation algorithms. |
| Geospatial & Address Data | Delivery address text, GPS coordinates (lat/lng), real-time courier location updates. | Live order delivery tracking, route optimization via Google Maps API, and courier dispatch. |
| Technical & System Logs | IP address, browser/device parameters, stateless JWT access tokens, audit logs. | Ensure platform security, API token verification, fraud detection, and system health monitoring. |
3Lawful Purposes of Data Processing
Messages, photos and voice you send to the Cravo AI Assistant, plus your dietary parameters (diet, allergies, goals, order history), are processed over encrypted connections by our AI providers: Groq (chat, speech-to-text and photo recognition) and Google Gemini (voice and photo fallback). Your name, phone number and payment details are NEVER sent to AI providers or sold to third-party data brokers. Photos you send in the AI chat are stored with that conversation so you can see them again; archiving a chat hides them. While Cravo uses the providers' free API tiers, they may use submitted content to improve their services; Cravo will move to paid tiers, which exclude this, before commercial launch.
4Fitness API Integration & Granular Consent Controls
5Data Sharing & Third-Party Infrastructure Transfers
Cravo does NOT sell, rent, or monetize your personal data to third-party advertisers. Personal data is shared strictly with essential operational infrastructure providers:
6Data Storage, Security & Encryption Protocols
7User Data Rights Under UAE PDPL
8Children's Data Protection Policy
Cravo is strictly intended for use by individuals who are at least 18 years of age. We do not knowingly collect or solicit personal data from minors. If we discover that an individual under 18 has created an account without verified parental consent, we will immediately purge all associated account records.
9Policy Amendments & Contact
Cravo reserves the right to update this Privacy Policy at any time to reflect software updates, architectural changes, or statutory amendments. Continued platform access after updates constitutes acceptance of revised terms.