Privacy Policy
This Privacy Policy explains how Peace Love Dishes, Inc. collects, uses, discloses, and protects your information when you use PeaceLoveDishes. Privacy is our foundation — we built this platform to give you control of your data and escape the surveillance economy. By using the Service, you agree to the practices described here.
1. Overview and Our Commitment to Privacy
At PeaceLoveDishes, privacy is not a feature—it's our foundation. We built this platform specifically to give families control over their data and escape the surveillance economy of big tech companies. This Privacy Policy explains our commitment to protecting your privacy and how we handle your information.
Our Core Privacy Principles:
2. Data Controller Information
The data controller responsible for your personal data is:
For privacy-related inquiries, GDPR requests, or data protection concerns, you may contact our Data Protection Officer:
For users in the European Economic Area (EEA), United Kingdom, or Switzerland, we will appoint an EU representative if required under GDPR Article 27. Until such time, please direct all inquiries to the contact information above.
3. Information We Collect
When you create an account, we collect:
The Service allows you to upload, create, and store various types of data across 27+ modules. This includes, but is not limited to:
Personal and Family Information Family member names, dates of birth, contact information Family tree and genealogy information Personal notes, journals, and thoughts Contact directory information Financial Information Bank account numbers and routing numbers (encrypted)
Credit card information (encrypted)
Accounting transactions and financial records Investment information and portfolio data Tax documents and financial statements Estate planning documents Credit reports and credit management information Health Information Medical records and health history Medication lists and schedules Appointment records and medical provider information Lab results and test reports Immunization records Insurance information Legal Information Legal case information and documents Court dates and deadlines Legal correspondence Wills, trusts, and estate documents Media and Content Photos and videos (stored in AWS S3)
Recipe photos and cookbooks Documents and files Other Information Passwords and secure notes (encrypted)
Vehicle information and maintenance records Property and home management information Task lists and project information Calendar events and appointments Shopping lists Travel plans and itineraries Pet health and care information And other data you choose to store in the Service
We collect minimal usage information necessary to provide and improve the Service:
When you access the Service, we automatically collect certain technical information:
When you subscribe, payment information is collected and processed by third-party payment processors. We do not store your complete credit card information. Payment processors may collect:
Credit card number (last 4 digits only stored for identification)
Billing address Payment method information Payment processing is subject to the privacy policies of our payment processors. We do not have access to your complete payment information.
To be clear, we do NOT collect:
Your browsing history outside our Service Information from other websites you visit Location data (except IP address for security)
Biometric information Social media information Information from data brokers Advertising identifiers Information for marketing purposes
4. How We Use Your Information
We use your information solely to provide, maintain, and improve the Service:
We use your email address to:
Send important service notifications (security alerts, account changes)
Send billing and subscription information Respond to your support requests Notify you of service updates or changes Send security alerts (e.g., login from new device)
We may use anonymized, aggregated data to improve the Service:
Understanding which features are most used (anonymized)
Identifying technical issues and bugs Improving performance and reliability Developing new features
We may use or disclose your information when required by law, court order, or legal process, including:
Responding to valid legal requests (subpoenas, court orders)
Complying with applicable laws and regulations Protecting our rights and property Preventing fraud or security threats Protecting the safety of users or the public
We do NOT use your information for:
Advertising or marketing to you Building profiles about you for third parties Selling to data brokers Tracking you across websites Creating marketing lists Sharing with social media companies Any purpose other than providing the Service
5. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data based on the following lawful bases under the General Data Protection Regulation (GDPR):
5.2.1 Contract Performance (GDPR Article 6(1)(b))
Processing is necessary to perform our contract with you (the Terms of Service) and provide the Service you requested:
Creating and managing your account Providing access to the Service and its modules Storing and processing your data Processing subscription payments Providing customer support 5.2.2 Consent (GDPR Article 6(1)(a))
We obtain your explicit consent for specific processing activities:
Storing sensitive personal data (health information, financial data)
Sending marketing communications (if you opt in)
Processing children's data (parental consent for children under 13)
We process special category data (sensitive personal data) under GDPR Article 9, including:
Where we process your data based on legitimate interests, you have the right to object to such processing. Contact
6. Data Sharing and Disclosure
We do not sell your data. We do not rent, trade, or otherwise monetize your personal information. Your data is not for sale.
We share your information only in the following limited circumstances: 6.2.1 Service Providers We may share information with third-party service providers who perform services on our behalf:
We do NOT share your information with:
Data brokers or data aggregators Advertising networks Social media companies Marketing companies Analytics companies (except anonymized usage data)
Third parties for their own purposes
7. Data Security
Our Security Measures We implement comprehensive security measures designed to protect your data:
We implement security practices designed to meet enterprise-grade standards. However, no security system is perfect, and we cannot guarantee absolute security. You acknowledge that you use the Service at your own risk.
You also play a role in protecting your data:
Use a strong, unique password (minimum 17 characters)
Do not share your account credentials Log out when using shared devices Notify us immediately of any unauthorized access Keep your email account secure (used for password resets)
In the event of a security breach that may affect your data, we will:
Investigate the breach immediately Notify affected users as soon as reasonably possible Notify relevant authorities if required by law Take steps to prevent further breaches Notification will be provided in accordance with applicable law. However, we are not liable for security breaches that occur despite our security measures.
8. Data Storage and Retention
Your data is stored on secure servers located in the United States. Specific storage locations:
You may delete your data at any time through the Service's delete features. When you delete data:
It is marked for deletion in our systems It is removed from active access It may remain in backups until backup rotation It is permanently deleted according to our deletion schedule
9. Your Privacy Rights
Regardless of your location, we respect your privacy rights. All users have the following rights:
You have the right to:
You have the right to:
To exercise your privacy rights:
Use the Service's built-in features (export, delete, etc.)
We will respond within 30 days (GDPR) or 45 days (CCPA)
We will not discriminate against you for exercising your privacy rights. You will not receive different pricing, service levels, or quality based on exercising your rights.
10. GDPR Rights (European Users)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have specific rights under the General Data Protection Regulation (GDPR) and equivalent laws.
You have the right to obtain confirmation of whether we process your personal data and, if so, to access your personal data along with information about:
The purposes of processing The categories of personal data concerned The recipients or categories of recipients to whom data has been disclosed The envisaged period of data retention Your rights regarding your data The right to lodge a complaint with a supervisory authority The source of data (if not collected from you) respond within 30 days with a copy of your personal data.
You have the right to obtain rectification of inaccurate personal data and to have incomplete personal data completed.
You have the right to obtain erasure of your personal data in the following circumstances:
The personal data is no longer necessary for the purposes for which it was collected You withdraw consent and there is no other legal basis for processing You object to processing and there are no overriding legitimate grounds The personal data has been unlawfully processed Erasure is required to comply with a legal obligation
You have the right to obtain restriction of processing in the following circumstances:
You contest the accuracy of personal data (during verification)
Processing is unlawful but you oppose erasure We no longer need the data but you need it for legal claims You have objected to processing (pending verification of legitimate grounds)
You have the right to receive your personal data in a structured, commonly used, machine-readable format (JSON, CSV, or XML) and have the right to transmit that data to another controller.
This right applies when:
Processing is based on consent or contract Processing is carried out by automated means "GDPR Portability Request" in the subject line.
You have the right to object to processing of your personal data where:
Processing is based on legitimate interests (Article 6(1)(f))
Processing is for direct marketing purposes (we do not engage in direct marketing)
Processing is for scientific/historical research or statistical purposes processing unless we can demonstrate compelling legitimate grounds that override your interests.
Where processing is based on your consent, you have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of alleged infringement if you believe our processing violates GDPR.
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you.
We will respond to GDPR requests within 30 days. For complex requests, we may extend this period by two months and will inform you of the extension and reasons.
11. CCPA Rights (California Residents)
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) grant you specific rights regarding your personal information.
In the preceding 12 months, we have collected the following categories of personal information as defined by the CCPA:
We collect and use personal information for the following business purposes:
Providing and maintaining the Service Processing transactions and subscriptions Customer support and communication Security, fraud prevention, and legal compliance Service improvement (using anonymized, aggregated data)
You have the right to request disclosure of:
Categories of personal information collected Categories of sources from which information was collected Business or commercial purposes for collecting or selling information Categories of third parties with whom we share information Specific pieces of personal information collected about you 512-650-8975.
You have the right to request deletion of personal information we collected from you, subject to certain exceptions.
You have the right to request correction of inaccurate personal information.
Correction Request" in the subject line.
WE DO NOT SELL PERSONAL INFORMATION. We do not sell or share personal information to third parties for monetary or other valuable consideration. We have not sold personal information in the preceding 12 months.
You have the right to limit our use of sensitive personal information. However, we only use sensitive personal information (health data, financial data) for purposes allowed without the right to limit:
Performing services you reasonably expect (providing the Service)
Security and integrity purposes Short-term, transient use
You have the right not to receive discriminatory treatment for exercising your CCPA rights. We will not:
Deny goods or services Charge different prices or rates Provide different quality of goods or services Suggest you will receive different prices or quality
You may designate an authorized agent to make requests on your behalf. The authorized agent must provide:
Written authorization signed by you Proof of their identity We may require you to verify your identity directly or confirm the authorization.
To verify your identity for CCPA requests, we may request:
Email address associated with your account Account username Additional information to match our records For requests to know specific pieces of information, we may require additional verification.
We will respond to verifiable CCPA requests within 45 days. If we need more time (up to 90 days total), we will inform you of the extension and reason.
California's "Shine the Light" law (Cal. Civ. Code § 1798.83) permits California residents to request information about disclosure of personal information to third parties for direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.
12. Children's Privacy (COPPA)
The Service is intended for users who are at least 18 years of age. Users under 18 may use the Service only with the involvement and consent of a parent or legal guardian.
Our Service is designed for families, including children. We comply with the Children's Online Privacy Protection Act (COPPA):
We do not knowingly collect personal information from children under 13 without parental consent Parents control family member accounts and data Parents can review, modify, or delete their children's information We do not use children's information for advertising or marketing
If you wish to create an account for a child under 13, you must:
Be the parent or legal guardian of the child Provide verifiable parental consent before the child can use the Service Review and agree to this Privacy Policy on behalf of the child Take responsibility for all activities under the child's account Monitor the child's use of the Service the subject line. We will verify your identity as the parent or legal guardian before activating the child's account.
For children under 13 with parental consent, we may collect:
Name and age Parent/guardian contact information Content created or uploaded by the child within the family account
Information collected from children under 13 is used only for:
Providing the Service to the child Communicating with parents about the child's account Protecting the security and integrity of the Service Complying with legal obligations
We do not disclose personal information collected from children under 13 to third parties, except:
To the extent necessary to provide the Service (e.g., secure data storage with AWS)
To protect the security or integrity of the Service As required by law or to respond to legal process To protect the rights, property, or safety of Peace Love Dishes Inc., our users, or the public
Parents and legal guardians have the right to:
Parents who create family accounts:
Control what data children can access Control what data children can create or upload Can review all children's activities Can remove children's access at any time
If we discover that we have collected personal information from a child under 13 without verifiable parental consent, we will delete that information as quickly as possible.
If you believe we have collected information from a child under 13 without parental consent, please contact us will delete such information.
13. Family Account Data Sharing
PeaceLoveDishes is designed for family use. One subscription account ("Primary Account") may cover multiple family members. The Primary Account holder controls:
Which family members have access What data is shared with family members What permissions each family member has
When you invite family members, they may have access to shared data according to permissions you set. This may include:
Shared recipes and cookbooks Shared calendar events Shared photos and videos Family health records (if you choose to share)
Family financial information (if you choose to share)
Other data you designate as shared
Some data remains private to individual users:
Personal journals (unless shared)
Private passwords in Passwords Personal tasks and notes Individual user settings
When you invite family members, you are responsible for:
Ensuring family members understand privacy settings Managing what data is shared Ensuring family members comply with the Terms of Service and this Privacy Policy Removing access when family members should no longer have access
14. Health Information and HIPAA
While we provide HIPAA-compliant infrastructure for health data, you are responsible for:
Ensuring you have proper authorization to store health information in the Service Complying with all applicable health privacy laws beyond HIPAA (state laws, etc.)
Obtaining necessary consents from individuals whose health information you store Using the Health Records module in accordance with HIPAA requirements Requesting a BAA if you are a covered entity and require one
Health data stored in the Health Records module receives enhanced security measures:
HIPAA-compliant encryption at rest and in transit HIPAA-compliant access controls and authentication Complete audit logging of all health data activities Secure storage in HIPAA-compliant data centers Encrypted backups with HIPAA-compliant retention policies User ownership verification and permission systems
15. International Data Transfers
Your data is stored on servers located in the United States. If you are located outside the United States, you consent to the transfer of your data to the United States for processing and storage.
If you access the Service from outside the United States, your data will be transferred to, stored, and processed in the United States. The United States may have data protection laws that differ from those in your country.
For data transfers from the EEA, UK, or Switzerland to the United States, we implement appropriate safeguards to protect your personal data in accordance with GDPR Chapter V:
We use the following third-party service providers that may process your data:
You have the right to:
Obtain information about international data transfers Request a copy of the safeguards in place (e.g., Standard Contractual Clauses)
Object to data transfers in certain circumstances To request information about international data transfers or copies of safeguards, contact
For transfers from the UK, we use the UK International Data Transfer Agreement (IDTA) or UK Addendum to EU SCCs. For transfers from Switzerland, we comply with Swiss data protection law and use Swiss-approved Standard Contractual Clauses.
16. Cookies and Tracking Technologies
We use essential cookies and similar technologies necessary for the Service to function:
We do NOT use:
Advertising cookies Analytics cookies that identify users Social media tracking pixels Third-party tracking cookies Any cookies for advertising or marketing purposes
You can control cookies through your browser settings. However, disabling essential cookies may prevent the Service from functioning properly.
Our session cookies expire when you log out or after 30 minutes of inactivity. Security tokens expire after their designated validity period.
17. Third-Party Services
The Service integrates with third-party services necessary for operation:
We do NOT use:
Google Analytics or similar tracking services Facebook Pixel or social media tracking Advertising networks Data brokers Marketing automation tools Any service that tracks users for advertising
The Service may contain links to third-party websites. We are not responsible for the privacy practices of these websites.
We encourage you to read the privacy policies of any third-party websites you visit.
18. Automated Decision-Making
We do not engage in automated decision-making or profiling that produces legal effects or similarly significantly affects you.
Automated processing is used only for essential service functionality:
Authentication and access control Data storage and retrieval Security monitoring and fraud prevention These automated processes do not make decisions that produce legal effects or similarly significantly affect you.
19. Do Not Track Signals
Some web browsers and devices permit you to broadcast a preference that you not be "tracked" online. At this time, there is no industry consensus on what constitutes a "Do Not Track" signal.
20. Changes to Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other reasons. We will notify you of material changes by:
Email to the address associated with your account Prominent notice in the Service Updating the "Last Updated" date at the top of this policy
Material changes to this Privacy Policy will take effect 30 days after notice. Your continued use of the Service after changes become effective constitutes acceptance of the updated Privacy Policy.
We recommend reviewing this Privacy Policy periodically. The "Last Updated" date indicates when this policy was last revised.
21. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
Mailing Address:
Peace Love Dishes Inc. 14205 N Mo Pac Expy Ste 570 PMB 387691 Austin, Texas 78728-6529 United States
We will respond to privacy inquiries within 30 days. For urgent security concerns, please mark your email as "URGENT" in the subject line.
This Privacy Policy is written in English. Any translation is provided for convenience only. In the event of conflict between the English version and any translation, the English version shall prevail.
22. Complaints and Supervisory Authority
If you believe we have violated your privacy rights or applicable data protection laws, you have the right to lodge a complaint with us and with the appropriate supervisory authority.
and respond to your complaint promptly.
We take privacy concerns seriously and encourage you to contact us directly so we can address your concerns promptly.
We are committed to resolving complaints in accordance with applicable law.
23. Additional Information
This Privacy Policy is incorporated into and subject to our Terms of Service. Please review our Terms of Service for additional information about your use of the Service.
This Privacy Policy does not create rights enforceable by third parties or require disclosure of any personal information relating to users of the Service.
If any provision of this Privacy Policy is found to be unenforceable or invalid, that provision shall be limited or eliminated to the minimum extent necessary, and the remaining provisions shall remain in full force and effect.
By using the PeaceLoveDishes Service, you acknowledge that you have read, understood, and agree to this Privacy Policy.
Peace Love Dishes Inc. (Delaware Corporation)