Back

Privacy Policy

Last updated: September 5, 2026

This policy explains what Suppah Social LLC (“Suppah Social,” “we,” “us”) collects when you use suppahsocial.com and the Suppah Social iOS and Android apps (together, the “Service”), how we use and share it, and the choices you have. It works together with our Terms of Service. Suppah Social is a private, invite-only dining community for people 18 and older, currently operating in the United States.

The short version: we collect what we need to verify members, keep the community safe, and run dinners and payments. We never sell your personal information and we do not share it with advertisers. You can see, export, or delete your data, and you control most of what other members can see about you.

1. Information We Collect

Information you give us

  • Account and contact details: name, email address, phone number, password, and the role you join as (guest, host, or chef).
  • Profile: photo, bio, gender (optional), neighborhood, city, state, and ZIP code.
  • Dining preferences: dietary preferences, food allergens, pet allergies, and taste preferences you share so chefs and hosts can plan around them.
  • Addresses: a host’s dining-space address, a guest’s home address if you book a private dinner at your home, and a chef’s service area and tax address for payouts.
  • Photos and content you post: profile and space photos, event photos, posts and comments, reviews and ratings, dining-passport notes, and messages you send in event chats, booking threads, proposals, and meal-prep conversations.
  • Chef and host credentials: food-safety certifications, business licenses, insurance documents, and hosting details you upload for review.
  • Chef business records: expense receipts and menu, dish, and pricing information you enter in your kitchen tools.
  • Friends you invite: if you invite someone to a dinner or refer a friend, we collect the name and email address or phone number you provide for that person and use it only to send the invitation. On mobile you can pick a contact from your address book; only the contact you select is shared with us, never your full contact list.
  • Communications: messages you send to support and replies to our text messages.

Identity verification and safety screening

  • Government ID and selfie: verification is performed by Stripe Identity, which scans your ID and compares it to a selfie. Stripe processes your ID images and facial geometry under its own privacy policy. We do not store your ID images. We receive and keep your verified legal name, date of birth, the result (verified or not), and a reference ID for the verification session.
  • Registry screening: we send your name and date of birth to Offenders.io to check the national sex offender registry. We keep only the check reference, the result (pass or fail), a risk level, and the date. No detailed registry information is retained.
  • Agreement records: when you accept the Terms of Service, guest waiver, or host agreement we record the version, date, your IP address, and your browser or device type.

Payment information

Payments, payouts, and payment-method storage are handled by Stripe. We never store card numbers or bank account details. We keep Stripe customer and account identifiers, transaction and booking records, refund and payout records, and, for chefs and hosts, the status of your Stripe Connect onboarding.

Information collected automatically

  • Usage and device data: pages and screens you view, buttons you tap, events you open, device type, operating system, browser, app version, language, approximate location derived from your IP address, and timestamps such as your last login.
  • Session replays: our analytics provider (PostHog) can record how you move through the app to help us find bugs and confusing screens. Anything you type is masked in these recordings.
  • Performance and crash data: page-speed metrics and error reports.
  • Push notification tokens: a device token if you turn on push notifications in the mobile apps.
  • Cookies and similar technologies: see section 7.

Location

We do not collect precise GPS location from your device, and the apps do not request location permission. Location information comes from what you enter: the state you sign up from, your neighborhood, and any addresses you provide. We convert addresses to map coordinates so events can be shown on a map to the people entitled to see them.

Device permissions in the mobile apps

  • Camera and photos: only when you choose to take or upload a photo (profile, posts, space listings, receipts, and credential documents).
  • Contacts: only when you choose to pick a friend to invite. We receive the selected contact, not your address book.
  • Calendar (write-only): only if you ask us to add a confirmed dinner to your calendar.
  • Notifications: only if you enable them.

You can revoke any of these permissions at any time in your device settings.

2. How We Use Your Information

  • Verify your identity, confirm you are at least 18, and decide on membership applications
  • Screen members for safety and enforce our community rules, including the strike policy
  • Run the Service: list and discover events, sell tickets, arrange private dinners and meal prep, and pay chefs and hosts
  • Share event logistics with the right people at the right time (for example, revealing a host’s address to confirmed ticket holders 72 hours before the dinner)
  • Let chefs and hosts plan around your dietary needs and allergens
  • Send transactional emails, texts, and push notifications: confirmations, reminders, receipts, login codes, booking updates, and safety notices
  • Send marketing texts about new events only if you separately opt in, and community emails you can unsubscribe from
  • Personalize recommendations and chef matching based on your dining history and preferences (you can turn personalization off in Privacy Settings)
  • Review chef credentials and receipts. We use AI tools to read uploaded certifications and receipts and extract details such as names, dates, and totals. A person on our team makes the final decision on every credential.
  • Understand how the Service is used, fix bugs, and improve features
  • Prevent fraud, abuse, duplicate accounts, and unauthorized access
  • Comply with tax, accounting, and other legal obligations, and resolve disputes

We do not use your information for automated decisions that have legal effects on you without human review, and we do not use it for targeted advertising.

3. How We Share Your Information

With other members

Suppah Social is a community, so some information is visible to the members you dine with. By default:

  • Chefs hosting an event you attend see your name, photo, dietary preferences and allergens, and may see your dining history, ratings, and notes they have written about past dinners with you.
  • Hosts see the first names and membership IDs of attending guests, and whether you have been to their space before.
  • Fellow guests at the same dinner see your name and photo, and may see your neighborhood and member-since date. After a dinner, tablemates can see each other in “table alumni” features.
  • Chef profiles are public on our website, including the chef’s name, photo, bio, certifications status, reviews, and past events.
  • Reviews you write are shown to the chef or host and may be displayed publicly with your first name unless you choose to review anonymously.

You control most of this in Settings → Privacy, where you can hide your name, photo, neighborhood, and member-since date from alumni, limit what chefs and hosts see, review anonymously, and opt out of alumni and “seen before” features. Host addresses are never publicly listed and are shared only with the assigned chef and confirmed ticket holders for that event.

With service providers

We share information with companies that process it on our behalf, under contracts that limit their use to providing services to us:

  • Supabase — database, authentication, and file storage
  • Vercel — web hosting and aggregated site-performance analytics
  • Stripe — payments, payouts (Stripe Connect), saved payment methods, and identity verification (Stripe Identity)
  • Offenders.io — sex offender registry screening
  • Twilio — text-message delivery and phone-number login codes
  • Resend — email delivery
  • PostHog — product analytics and session replay
  • Anthropic — AI reading of uploaded credentials and receipts. Under our agreement, your content is not used to train their models.
  • Apple and Google — Sign in with Apple, Sign in with Google, and push-notification delivery (Apple Push Notification service and Firebase Cloud Messaging)
  • OpenStreetMap (Nominatim) and CARTO — converting addresses to map coordinates and displaying map tiles
  • Google Cloud and Amazon Web Services — rendering marketing content; these do not receive member personal information

Other sharing

  • Safety and legal: to comply with law, respond to lawful requests, enforce our Terms, or protect the rights, property, and safety of members, the public, or Suppah Social. For example, we may share information with law enforcement about a safety incident at a dinner.
  • Business transfers: if Suppah Social is involved in a merger, acquisition, or sale of assets, your information may transfer as part of that deal, subject to this policy.
  • With your direction: for example, when you share a dining-passport link or forward an event invite.

What we never do

We never sell your personal information, and we do not share it with third parties for their own marketing or for targeted advertising. There are no advertising networks or ad-tracking SDKs in the Service. We do not share your mobile opt-in information or phone number with anyone for marketing purposes.

4. Your Choices and How to Opt Out

  • Member visibility: adjust what chefs, hosts, and other guests can see in Settings → Privacy.
  • Marketing texts: reply STOP to any message, or uncheck marketing texts in your profile. Transactional texts (confirmations, login codes, booking updates) continue while you have an account with a phone number on file.
  • Emails: use the unsubscribe link in any non-essential email or manage notifications in Settings. We still send emails required to run your account, such as receipts and booking changes.
  • Push notifications: turn them off in your device settings at any time.
  • Personalization: turn off personalized recommendations, milestone messages, and chef-network emails in Privacy Settings.
  • Analytics: our website honors the “Do Not Track” browser setting, and analytics are not used for advertising.
  • Camera, photos, contacts, and calendar: revoke access in your device settings.
  • Your dining history: export it as a spreadsheet, reset your saved preferences, or delete your passport entries, reviews, and preferences from Privacy Settings.
  • Delete your account: from the app (Settings → Delete account) or by following the steps at suppahsocial.com/delete-account.

5. Your Privacy Rights

Wherever you live, you can ask us to:

  • Confirm whether we process your personal information and give you access to it
  • Correct inaccurate information
  • Delete your account and personal information
  • Provide a portable copy of the information you gave us
  • Opt out of marketing communications and personalization

To exercise these rights, use the tools in the app or email support@suppahsocial.com from the address on your account. We will verify the request, respond within 45 days, and never treat you differently for exercising your rights. If we deny a request, you may appeal by replying to our response; we will explain the outcome of the appeal in writing. You may authorize an agent to make a request on your behalf if they can show your written permission.

Residents of California, Rhode Island, Massachusetts, and other U.S. states with privacy laws: the rights above apply to you. We do not sell personal information, do not share it for cross-context behavioral advertising, do not use it for profiling that produces legal or similarly significant effects without human involvement, and have not done so in the preceding 12 months. The categories of information we collect, our purposes, and the recipients are described in sections 1 through 3. We collect the sensitive categories of government ID, date of birth, and biometric verification results only to verify identity and screen for safety, as described above.

Outside the United States: the Service is offered only in the United States and is not directed to residents of the European Economic Area, the United Kingdom, or other regions. If you contact us from abroad, your information will be processed in the United States.

6. Text Messaging (SMS)

When you provide your mobile number, Suppah Social sends transactional text messages such as ticket confirmations, login codes, booking updates, and event reminders. If you separately opt in to marketing texts, we also send occasional messages about new events from chefs you follow. Message frequency varies. Message and data rates may apply. Reply STOP to any message to unsubscribe, or HELP for help. Consent to marketing texts is not a condition of membership.

We do not share or sell your mobile opt-in information or phone number with third parties or affiliates for their own marketing purposes. Text messaging originator opt-in data and consent are not shared with any third parties except subcontractors acting on our behalf (our messaging provider, Twilio) solely to deliver the messages you requested.

7. Cookies and Similar Technologies

We use a small number of cookies and similar technologies:

  • Essential: cookies that keep you signed in and protect against forgery. The Service does not work without them.
  • Analytics: PostHog stores an identifier in a cookie or local storage so we can understand usage and replay sessions for debugging. We honor Do Not Track on the website.
  • Preferences: local storage for things like dismissed banners.

We do not use advertising cookies or third-party tracking pixels. You can clear or block cookies in your browser, but you will need to sign in again.

8. Data Retention

We keep your information while your account is active. When you delete your account we remove your profile, contact details, photos, preferences, addresses, messages, posts, reviews, and device tokens, within 14 days. We retain:

  • Transaction, booking, and payout records for seven years for tax and accounting compliance
  • Identity-verification records held by Stripe under Stripe’s own retention policy
  • Limited safety records where necessary to enforce a membership decision, prevent a removed member from re-registering, investigate an incident, or defend legal claims
  • Aggregated or anonymized analytics that no longer identify you

Dining-history entries you delete from Privacy Settings are removed immediately. Shared records such as a chef’s count of events with you are kept in aggregate form.

9. Security

We protect your information with encryption in transit, database-level access controls that limit each member to their own data, restricted administrative access, and third-party providers that are independently audited (Stripe is PCI DSS Level 1 certified). Passwords are checked against known breach lists at signup. No system is perfectly secure; if we learn of a breach affecting your information we will notify you as required by law.

10. Age Requirement

Suppah Social is only for adults 18 and older, and every member’s age is confirmed through identity verification. We do not knowingly collect information from anyone under 18. If you believe a minor has provided us information, contact us and we will delete it.

11. Changes to This Policy

We may update this policy as the Service changes. We will post the new version here with a new “Last updated” date and, for material changes, notify you by email or in the app before they take effect.

12. Contact

Privacy questions, requests, or concerns: support@suppahsocial.com. Legal notices: legal@suppahsocial.com.

Suppah Social LLC
Rhode Island, United States