Privacy Policy

Last updated: 30 August 2026

The short version.

  • You do not need an account to use DinnerSwipe.
  • We use your location only to find restaurants near you. The people you are swiping with never see it.
  • Nobody you are swiping with sees your swipes — only a restaurant everyone liked.
  • Ads never use your location, dinner choices, who you are eating with, or restaurant data.
  • Anonymous sessions are deleted within 24 hours of ending.

This policy explains what DinnerSwipe collects when you use the DinnerSwipe mobile app or website, why we collect it, who we share it with, and the choices you have. It applies to both the app and this site.

1. Who we are

DinnerSwipe is operated by Hallows Group LLC, a Texas limited liability company ("Hallows Group", "we", "us"). For data protection purposes, Hallows Group LLC is the data controller for the information described in this policy.

Hallows Group LLC
5900 Balcones Drive #31966
Austin, TX 78731
United States
Privacy contact: privacy@dinner-swipe.app

DinnerSwipe is intended for users in the United States. We do not direct the service to, or market it in, the European Economic Area or the United Kingdom.

2. Using DinnerSwipe without an account

DinnerSwipe is anonymous by default. You can create a room, share it, swipe, and get a match without giving us a name, an email address, or a password. Creating an account is optional and only adds the features described in section 4.

3. What we collect when you use a session

Location

To show you restaurants that are actually nearby, we need a starting point. You give us one in one of two ways: by granting the app location permission (used only while you are using the app), or by typing an area or address yourself.

  • Your starting point is used to search for restaurants for that session.
  • We store it as a coordinate on the session record for as long as that session exists. We also derive a rounded version of it (to roughly one kilometre) as a cache key, so repeat searches in the same area do not re-query our restaurant providers.
  • The other person in your session never receives your coordinates. This is enforced in our database, not just in the app: the view the app reads from does not contain the location field at all.
  • The starting point is deleted with the session itself, when the whole session record is erased roughly 24 hours after the session ends. It is not retained afterwards and is never added to a profile. See the table in section 11.
  • If you type an address instead of using GPS, we send that text to a restaurant provider to resolve it (see section 8) and keep only the resolved coordinate and a short area label. We do not keep the text you typed.
  • We do not track your location in the background, and we do not build a location history.

Your swipes

We record which restaurants you liked or passed on, so we can tell when you and the other person have liked the same one.

  • You can only ever read your own swipes. This is enforced by database row-level security. The other participant cannot retrieve them, and neither can the app on their behalf.
  • The comparison happens on our server. The only result either of you sees is a mutual match.
  • Swipes are never used for advertising.

Session data

We store the room code, which mode you chose (eating out or ordering in), your filters, the deck of restaurants generated for the session, and its outcome.

Your filters can include dietary exclusions. Some of these — for example halal, kosher, or coeliac — can imply something about your religion or your health. Please see section 5, which explains how we treat them and where they go.

Technical and anti-abuse data

To stop people brute-forcing room codes and abusing our servers, we record a limited amount of technical data:

  • Your IP address is stored briefly against a rate-limiting counter when you exchange an anonymous session token. It is kept for up to 2 days and then deleted automatically. It is not linked to your swipes or your location.
  • Operational logs record events such as errors, provider call counts, and handoff clicks, along with a session or user reference. These are kept for 90 days. Coordinates, addresses, search terms, and access tokens are stripped before anything is written.
  • Our hosting provider, Cloudflare, keeps its own short-term request logs, which include IP addresses, as part of running the service.

Notifications

If you allow notifications, we collect an encrypted push token so we can tell you about a dinner update, such as a partner joining or a mutual match. This applies whether you use DinnerSwipe anonymously or with an account. Notification payloads do not contain a session ID.

  • We send the token to Expo only to deliver the notification.
  • For an anonymous user, the token is deleted when its anonymous identity is reaped after its sessions have ended (at the earliest after the 7-day anonymous-user retention window).
  • For an account holder, the token is deleted with the account; tokens reported invalid by the push provider are disabled sooner.

Your agreement to our terms

If you create an account, we record which version of our terms you accepted and when, against a reference for that account. Using DinnerSwipe anonymously does not create this record: the terms are shown to you as a notice where you start or join a dinner, and nothing about that is stored.

The reference is your DinnerSwipe user identifier, which is a random value. While you have an account it is linked to your email address. Once your account is deleted, that link is gone and the identifier is all that remains — we hold nothing that connects it back to you, and we will not try to.

We keep this record even after your other data goes — after you delete your account — because the limitation period for a contract claim runs for years. Deleting the only evidence of what was agreed would remove your proof as well as ours. What survives is the reference, the version, and the timestamp: nothing about your dinners, your location, or your swipes. We keep it for five years from the date you accepted, then delete it automatically.

4. What we collect if you create an account

An account is optional. If you create one, we additionally store:

  • Your email address and password. We send a confirmation link to the address you sign up with, and it must be confirmed before it is active on your account. Passwords are hashed by our authentication provider; we never see or store them in readable form.
  • Your saved preferences — default mode, search radius, price range, dietary exclusions, cuisine preferences, and whether to show only places that are open.
  • Your dinner history — the general area label (for example, a neighbourhood name), the outcome, and the name of the restaurant you matched on. This does not include coordinates and does not include your swipes.

4a. If you give us your email address on this website

The homepage has an optional field for sending you the app links. It is separate from an account — giving us an address here does not create one, and we do not connect it to any session, swipe, or location.

  • Your email address, and which page you entered it on.
  • An unsubscribe code, stored only as a one-way hash. The code itself exists only in the link at the bottom of our emails, so a copy of our records cannot be used to unsubscribe anyone.

We use it for one welcome message with the app links, and after that only to tell you about new features. We do not sell it, and we do not use it for advertising. Every message carries a one-click unsubscribe; you can also mail support@dinner-swipe.app and we will remove you by hand.

The field is protected by Cloudflare Turnstile, which checks that a person — not a script — is submitting it. Turnstile sees your IP address and basic browser signals for that check. It does not set an advertising cookie and does not track you across sites.

5. Dietary exclusions

Dietary exclusions deserve their own section, because they are the one filter that can reveal something sensitive about you.

  • They are stored on the session, and on your profile if you saved them as a default.
  • They are included in the search text we send to the restaurant provider (see section 8), because that is how the provider finds matching restaurants. The provider receives the exclusion words and a search area. It does not receive your identity, your device details, or your session ID.
  • They are never used for advertising, and are never shared with the person you are swiping with.
  • They are deleted with the session, or with your account if you saved them as a default.

If you would rather not have a dietary exclusion leave our servers, leave the field empty and filter the results yourself. You can clear saved exclusions at any time in Account & privacy.

6. Advertising

The mobile app shows ads through Google AdMob. To do this, Google may access advertising identifiers and device information from your device, subject to your consent and your device settings.

We do not give advertisers your DinnerSwipe data. Ads never use your location, your dinner choices, who you are swiping with, or the restaurants you were shown. Nothing from sections 3, 4, or 5 of this policy is shared with Google for advertising purposes.

You control ads in these ways:

  • In the app, open Account → Ad privacy choices to change your advertising consent at any time. Where your region requires a consent choice, Google's consent form appears before any personalised ads are shown.
  • On iOS, Settings → Privacy & Security → Tracking controls whether apps may request to track you.
  • On Android, Settings → Google → Ads lets you delete or reset your advertising ID and opt out of ad personalisation.

Under some privacy laws, showing personalised advertising counts as "sharing" personal information, even though no money changes hands. We do not sell your personal information. If you turn off personalised ads using the controls above, this sharing stops. You will still see ads; they will just be less relevant.

7. Crash and diagnostic data

We use Sentry to record crashes and errors in the mobile app so we can fix them. These reports include technical information such as the error, your app version, and your device type. They are configured to exclude coordinates, restaurant provider data, room codes, and your swipe history. Sentry processes this data in the European Union.

8. Restaurant information

Restaurant listings come from third-party providers — Yelp, Google Places, Foursquare, and OpenStreetMap, depending on the session.

  • These providers are called only from our servers, never from your device or browser. They do not receive your device details, your identity, or your session ID.
  • What they receive is a search area, a radius, and your filter terms — which include cuisine preferences and dietary exclusions (see section 5). If you typed an address rather than using GPS, they receive that text so it can be resolved to a location.
  • We cache the restaurant details they return for at most 24 hours.
  • Where we show reviews, the cached review text includes the reviewer's display name as published by the provider. That is other people's data, shown as the provider supplies it, and it is discarded within 24 hours.

9. Who we share data with

We do not sell your personal information. We share data only with the service providers we need to run DinnerSwipe:

Provider What they handle
Supabase Database, authentication, and server functions
Cloudflare Website and app hosting, delivery, request logs, and sending the email described in section 4a
Google AdMob Advertising in the mobile app (see section 6)
Sentry Crash and error reporting, mobile app only (EU-hosted)
Expo Push notification delivery and app updates
Yelp, Google Places, Foursquare, OpenStreetMap Restaurant listings (server-side only)
Apple, Google App distribution and, if you buy an upgrade, payment
Cloudflare Turnstile Checking that a person is submitting the website email field (section 4a)

Law enforcement and legal requests

We may preserve and disclose information where we believe in good faith that the law requires it, or that it is necessary to protect our rights, our users, or the public.

In practice we hold very little, and not for long. Most people use DinnerSwipe without an account, session data is erased about 24 hours after a session ends, and we never store the other participant's view of your activity. By the time a request reaches us, the data it asks about has usually already been deleted. We cannot recover it.

10. Why we are allowed to use your data

We think you should be able to see not just what we do with your data, but why we consider ourselves entitled to. We hold ourselves to this whether or not the law where you live requires it:

What we do Legal basis
Run a session, generate a deck, detect a match Performance of a contract — this is the service you asked for
Use your device location Consent — the device permission you grant, revocable at any time
Send push notifications Consent — the notification permission you grant, revocable at any time
Use dietary exclusions to search for restaurants Consent, where those exclusions reveal religion or health; otherwise performance of a contract
Personalised advertising Consent — collected through the in-app consent form
Non-personalised advertising Legitimate interests — funding a free service
Rate limiting, abuse prevention, security Legitimate interests — keeping the service and its users safe
Crash and error diagnostics Legitimate interests — keeping the service working
Account, saved preferences, dinner history Performance of a contract — the account features you opted into
Recording that you accepted our terms Legitimate interests — being able to show what was agreed, and when

Where we rely on consent, you can withdraw it at any time. Withdrawing consent does not make our earlier use of the data unlawful, and it may mean part of the service stops working — for example, without location permission you will need to type an area instead.

11. How long we keep things

Data Kept for
An email address you gave us on this website Until you unsubscribe, or 3 years with no contact from us — whichever comes first
The record that you unsubscribed 30 days, so an email already being sent cannot reach you, then deleted
A room waiting for someone to join 15 minutes, then it expires
An active session 1 hour, then it expires
A finished session, including its starting coordinate, swipes, deck, and match Erased about 24 hours after the session ends
Cached restaurant details and reviews At most 24 hours
IP address held for rate limiting Up to 2 days
Operational and error logs 90 days
Unused anonymous identities Deleted from 7 days, once they have no sessions left
Push notification tokens Until the token is invalidated or, for an account, the account is deleted; anonymous tokens are deleted with the anonymous identity
Restaurant reference IDs Kept, where provider terms allow. These identify restaurants, not people
Account details, preferences, and dinner history Until you delete your account
Record that you accepted our terms 5 years from the date you accepted. Kept after account deletion and after an anonymous identity is cleared — the reference, the version, and the time, and nothing else. See section 3

12. Your rights

Depending on where you live, you have some or all of the following rights over your personal information. Exercising them is free and will never cause us to treat you differently.

  • Access — ask what we hold about you and get a copy.
  • Rectification — have inaccurate information corrected.
  • Erasure — have your data deleted. See below; this one is self-serve.
  • Restriction — ask us to pause processing while a dispute is resolved.
  • Portability — receive your data in a machine-readable format.
  • Objection — object to processing based on legitimate interests, and to direct marketing at any time.
  • Withdraw consent — at any time, for anything we do on the basis of consent.
  • Complain — to your local data protection authority.

One exception, and only one. The record that you accepted our terms — the identifier, the version, and the time, described in section 3 — is not covered by erasure or objection. It is the evidence of an agreement between us, so deleting it on request would let either side remove the proof of what the other agreed to. Everything else we hold about you is covered, including everything the record is attached to. We keep it for five years and no longer, it is never used for anything else, and once your account or anonymous identity is gone it is no longer linked to you.

Deleting your data

You can delete your account and its data yourself, in the mobile app under Account & privacy, or on the web at app.dinner-swipe.app. Deletion is immediate and permanent. Full instructions, and exactly what is removed, are on our Delete your account page.

After deletion, a small number of operational log rows remain until their 90-day window ends, with the reference to you removed so they no longer identify you.

Everything else

  • Location: revoke the permission in your device settings at any time. You can still use DinnerSwipe by typing an area instead.
  • Notifications: turn them off in your device settings, or from Account in the app.
  • Ads: use the controls in section 6.
  • Access, portability, or anything else: email privacy@dinner-swipe.app from your account's email address. We handle these by hand rather than through a self-serve export, and we aim to respond within 30 days.

If you used DinnerSwipe anonymously, we usually have no way to identify which data was yours, so we may not be able to act on a request. Anonymous data is deleted automatically on the schedule in section 11.

We grant these rights to everyone who uses DinnerSwipe, wherever you live, rather than only where the law compels us. If you think we have got something wrong, tell us first — and if your country has a privacy regulator, you are free to complain to them as well.

13. Automated decision-making

We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you. Ranking restaurants in a deck is not such a decision, and there is no profiling behind it beyond the filters you chose.

14. If you live in a US state with privacy rights

Residents of California and other states with comprehensive privacy laws have rights to know, delete, correct, and obtain a copy of their personal information, and to opt out of sale, sharing for cross-context behavioural advertising, and certain profiling.

We do not sell personal information, and we have not done so. Personalised advertising may count as "sharing" under California law; you can turn it off with the controls in section 6. To make any other request, use the deletion controls above or email privacy@dinner-swipe.app. You may use an authorised agent, and you may appeal a refusal by replying to our response. We do not discriminate against anyone for exercising these rights.

The categories we collect are described in sections 3 to 5: identifiers, approximate and precise geolocation, commercial or preference information, internet activity, and — where your dietary exclusions imply it — information that may be treated as sensitive. We use them only for the purposes in section 10, and never to infer characteristics about you.

15. Children

DinnerSwipe is for adults 18 and older and is not directed to minors. We do not knowingly collect personal information from minors. To enforce this, the mobile app may ask for a date of birth on the device when no store-provided age signal is available. The date is not sent to us; we retain only a local confirmation that the device user is 18 or older. If you believe a minor has provided us with personal information, contact privacy@dinner-swipe.app and we will delete it.

16. Purchases

If we offer a paid ad-free upgrade, payment is handled entirely by the Apple App Store or Google Play. We never receive your card details. We receive only a record of whether your upgrade is active.

17. International transfers

We are based in the United States, and our service providers operate internationally, so your information may be processed outside your own country — including in the United States.

Where a provider processes your data outside the country you are in, we rely on the contractual safeguards in our agreement with them, including standard contractual clauses where those apply. You can ask us what safeguards cover a particular provider by emailing privacy@dinner-swipe.app.

18. Security

Access to your data is restricted at the database level rather than only in the app, so the privacy rules described above hold even if a client is modified. Push tokens are stored encrypted. Restaurant providers are called only from our servers, so API keys never reach your device. No system is perfectly secure, but we design for the principle that data we do not keep cannot leak.

19. Changes to this policy

If we make a material change, we will update the date at the top of this page and, where appropriate, tell you in the app.

20. Contact

Privacy questions and data requests: privacy@dinner-swipe.app
Everything else: support@dinner-swipe.app
Hallows Group LLC, 5900 Balcones Drive #31966, Austin, TX 78731, USA