Privacy Policy
Privacy policy preparation page for Chinese Food at Home, covering controller details, local MVP data, future analytics, ads, community features, and GDPR rights.
Controller and Contact
Chinese Food at Home is currently documented as a personal website owned by a private individual, not a company. Public contact email candidate: esseninnb@gmail.com.
The owner's legal name, postal address, hosting provider, and production privacy details must be completed before public launch if legally required.
Current Data Use
The default production-oriented static build keeps browser-local registration, login, rating, and comment widgets disabled until a real backend is ready.
The ingredient matcher runs in the browser using the ingredients typed by the visitor. The current matcher does not send ingredients to an AI API.
The current static build does not intentionally collect special-category personal data and does not perform automated decision-making or profiling.
Hosting
Hosting is currently documented as a provider or server in South Korea. Hosting providers may process standard server logs such as IP address, request path, browser user agent, and timestamp for security and operations.
For visitors in the European Economic Area, use of a server or provider outside the EEA should be reviewed before launch. South Korea has an EU adequacy framework for many transfers, but the actual hosting provider and safeguards still need confirmation.
Legal Bases Under GDPR
Where GDPR applies, account and community functions may rely on contract necessity when they are needed to provide the requested service.
Security logging, abuse prevention, and basic operations may rely on legitimate interests where those interests are not overridden by visitor rights.
Analytics cookies, personalized advertising, remarketing, and non-essential Google tags should rely on consent where required, especially for visitors in the EEA, UK, and Switzerland.
Contact emails are processed to respond to the request and keep necessary records.
Analytics and Advertising
Google Analytics, Google AdSense, conversion tracking, and remarketing are not active in the current build.
If Google Analytics 4 or AdSense is added later, this policy must be updated before launch to explain cookies, consent choices, ads personalization, and data processing.
Remarketing and paid Google Ads conversion tracking are deferred until paid campaigns are intentionally planned.
Future Community Features
Future production community features are planned to use Supabase for real accounts, ratings, and comments. The first authentication methods should be email/password, Google, and GitHub.
Phone and SMS login are out of scope for the early phase to avoid extra usage costs.
Before real community launch, publish moderation rules, retention rules, account deletion instructions, and processor/subprocessor information.
Retention
Current localStorage data remains in the visitor's browser until the visitor clears browser storage or the app overwrites it.
Future production account, rating, and comment retention periods must be defined before launch. Server log retention should be configured with the hosting provider and documented here.
Your Rights
Where GDPR applies, you may have rights to access, rectification, erasure, restriction, portability, objection, and withdrawal of consent.
You may also have the right to lodge a complaint with a competent data protection supervisory authority.
To request privacy help, email esseninnb@gmail.com. The final production site should identify the competent supervisory authority after the owner's jurisdiction is confirmed.
Contact
For privacy questions, email esseninnb@gmail.com.