Peace Love Dishes, Inc. • Zero data sold. Ever. • Last Updated: March 1, 2026
Your data belongs to you. We don't track you. We don't sell your information. We don't monetize your family's data.
IMPORTANT: This Privacy Policy explains how Peace Love Dishes Inc., a Delaware corporation ("Company", "we", "us", "our"), collects, uses, discloses, and protects your information when you use the PeaceLoveDishes Service. Please read this Privacy Policy carefully. By using the Service, you agree to the collection and use of information in accordance with this policy.
Effective Date: March 1, 2026
At PeaceLoveDishes, privacy is not a feature—it's our foundation. We built this platform specifically to give families control over their data and escape the surveillance economy of big tech companies. This Privacy Policy explains our commitment to protecting your privacy and how we handle your information.
Our Core Privacy Principles:
The data controller responsible for your personal data is:
Company Name: Peace Love Dishes Inc.
Legal Form: Delaware Corporation
Address: 14205 N Mo Pac Expy Ste 570, PMB 387691, Austin, Texas 78728-6529, United States
Email: privacy@peacelovedishes.com
Phone: 512-650-8975
Website: https://peacelovedishes.com
For privacy-related inquiries, GDPR requests, or data protection concerns, you may contact our Data Protection Officer:
Email: privacy@peacelovedishes.com
Subject Line: "Data Protection Inquiry" or "GDPR Request"
For users in the European Economic Area (EEA), United Kingdom, or Switzerland, we will appoint an EU representative if required under GDPR Article 27. Until such time, please direct all inquiries to the contact information above.
When you create an account, we collect:
Password Security: We require passwords to be at least 17 characters long. Passwords are hashed using bcrypt with appropriate cost factors. We never store passwords in plain text and cannot recover your password if forgotten.
The Service allows you to upload, create, and store various types of data across 27+ modules. This includes, but is not limited to:
Your Control: You control what data you upload and store. We do not require you to provide any specific data beyond account creation information. You may choose not to use certain modules or features.
We collect minimal usage information necessary to provide and improve the Service:
No Behavioral Tracking: We do not track your browsing behavior, mouse movements, keystrokes, or other behavioral data. We do not use analytics tools that identify individual users or track you across sessions.
When you access the Service, we automatically collect certain technical information:
This technical information is used for security, fraud prevention, and service delivery. We do not use IP addresses to track your location or build profiles about you.
When you subscribe, payment information is collected and processed by third-party payment processors. We do not store your complete credit card information. Payment processors may collect:
Payment processing is subject to the privacy policies of our payment processors. We do not have access to your complete payment information.
To be clear, we do NOT collect:
We use your information solely to provide, maintain, and improve the Service:
We use your email address to:
No Marketing Emails: We do not send marketing emails, promotional messages, or newsletters unless you explicitly opt in. We do not share your email address with third parties for marketing purposes.
We may use anonymized, aggregated data to improve the Service:
Anonymization: Any data used for service improvement is anonymized and aggregated so it cannot identify you or your family. We never use your personal data for these purposes.
We may use or disclose your information when required by law, court order, or legal process, including:
We do NOT use your information for:
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data based on the following lawful bases under the General Data Protection Regulation (GDPR):
Processing is necessary to perform our contract with you (the Terms of Service) and provide the Service you requested:
We obtain your explicit consent for specific processing activities:
Withdrawal of Consent: You may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
Processing is necessary for our legitimate interests or the legitimate interests of third parties, where not overridden by your rights:
Balancing Test: We have conducted a balancing test and determined that our legitimate interests do not override your fundamental rights and freedoms.
Processing is necessary to comply with legal obligations:
Processing may be necessary to protect vital interests of you or another person:
We process special category data (sensitive personal data) under GDPR Article 9, including:
Where we process your data based on legitimate interests, you have the right to object to such processing. Contact privacy@peacelovedishes.com to exercise this right.
We do not sell your data. We do not rent, trade, or otherwise monetize your personal information. Your data is not for sale.
We share your information only in the following limited circumstances:
We may share information with third-party service providers who perform services on our behalf:
These service providers are contractually obligated to protect your information and use it only for the specific services they provide. They are not permitted to use your information for their own purposes.
We may disclose your information if required by law, court order, or legal process, including:
We will notify you of any legal requests for your data unless prohibited by law or court order.
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you of any such transfer and your information will continue to be protected under this Privacy Policy.
We do NOT share your information with:
We implement comprehensive security measures designed to protect your data:
We implement security practices designed to meet enterprise-grade standards. However, no security system is perfect, and we cannot guarantee absolute security. You acknowledge that you use the Service at your own risk.
Important: We are not SOC 2 compliant, and we do not claim SOC 2 compliance. We implement security measures designed to protect your data, but we do not maintain SOC 2 certification.
You also play a role in protecting your data:
In the event of a security breach that may affect your data, we will:
Notification will be provided in accordance with applicable law. However, we are not liable for security breaches that occur despite our security measures.
Your data is stored on secure servers located in the United States. Specific storage locations:
We do not transfer your data outside the United States except as necessary for service provision (e.g., AWS S3 may use data centers in various locations, but all are within AWS's secure infrastructure).
Active Accounts: We retain your data while your account is active and you are using the Service.
After Cancellation: After you cancel your account, we retain your data for 30 days to allow you to export it. After 30 days, we may delete your account and all associated data in accordance with our data retention policies.
Backup Retention: Backups may be retained for a longer period for disaster recovery purposes, but they are encrypted and not accessible except for recovery purposes.
Legal Requirements: We may retain certain information longer if required by law or for legal purposes.
You may delete your data at any time through the Service's delete features. When you delete data:
Permanent Deletion: Complete permanent deletion may take up to 90 days due to backup systems. We cannot recover data after permanent deletion.
Regardless of your location, we respect your privacy rights. All users have the following rights:
You have the right to:
You have the right to:
To exercise your privacy rights:
We will not discriminate against you for exercising your privacy rights. You will not receive different pricing, service levels, or quality based on exercising your rights.
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have specific rights under the General Data Protection Regulation (GDPR) and equivalent laws.
You have the right to obtain confirmation of whether we process your personal data and, if so, to access your personal data along with information about:
How to Exercise: Email privacy@peacelovedishes.com with "GDPR Access Request" in the subject line. We will respond within 30 days with a copy of your personal data.
You have the right to obtain rectification of inaccurate personal data and to have incomplete personal data completed.
How to Exercise: Update your information directly in your account settings or contact privacy@peacelovedishes.com.
You have the right to obtain erasure of your personal data in the following circumstances:
Exceptions: We may retain data where required by law, for the establishment, exercise, or defense of legal claims, or for other legitimate purposes under GDPR Article 17(3).
How to Exercise: Email privacy@peacelovedishes.com with "GDPR Erasure Request" in the subject line.
You have the right to obtain restriction of processing in the following circumstances:
How to Exercise: Email privacy@peacelovedishes.com with "GDPR Restriction Request" in the subject line.
You have the right to receive your personal data in a structured, commonly used, machine-readable format (JSON, CSV, or XML) and have the right to transmit that data to another controller.
This right applies when:
How to Exercise: Use the data export feature in your account settings or email privacy@peacelovedishes.com with "GDPR Portability Request" in the subject line.
You have the right to object to processing of your personal data where:
How to Exercise: Email privacy@peacelovedishes.com with "GDPR Objection" in the subject line. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
Where processing is based on your consent, you have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
How to Exercise: Email privacy@peacelovedishes.com or adjust your settings in the Service.
You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of alleged infringement if you believe our processing violates GDPR.
Supervisory Authorities: You can find your local supervisory authority at https://edpb.europa.eu.
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you.
Our Practice: We do not engage in automated decision-making or profiling that produces legal effects or similarly significantly affects you.
We will respond to GDPR requests within 30 days. For complex requests, we may extend this period by two months and will inform you of the extension and reasons.
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) grant you specific rights regarding your personal information.
In the preceding 12 months, we have collected the following categories of personal information as defined by the CCPA:
We collect and use personal information for the following business purposes:
You have the right to request disclosure of:
How to Exercise: Email privacy@peacelovedishes.com with "CCPA Right to Know Request" in the subject line or call 512-650-8975.
You have the right to request deletion of personal information we collected from you, subject to certain exceptions.
Exceptions: We may retain information when necessary to:
How to Exercise: Email privacy@peacelovedishes.com with "CCPA Deletion Request" in the subject line or call 512-650-8975.
You have the right to request correction of inaccurate personal information.
How to Exercise: Update information in your account settings or email privacy@peacelovedishes.com with "CCPA Correction Request" in the subject line.
WE DO NOT SELL PERSONAL INFORMATION. We do not sell or share personal information to third parties for monetary or other valuable consideration. We have not sold personal information in the preceding 12 months.
No Opt-Out Required: Since we do not sell personal information, there is no need to opt out.
You have the right to limit our use of sensitive personal information. However, we only use sensitive personal information (health data, financial data) for purposes allowed without the right to limit:
You have the right not to receive discriminatory treatment for exercising your CCPA rights. We will not:
You may designate an authorized agent to make requests on your behalf. The authorized agent must provide:
We may require you to verify your identity directly or confirm the authorization.
To verify your identity for CCPA requests, we may request:
For requests to know specific pieces of information, we may require additional verification.
We will respond to verifiable CCPA requests within 45 days. If we need more time (up to 90 days total), we will inform you of the extension and reason.
California's "Shine the Light" law (Cal. Civ. Code § 1798.83) permits California residents to request information about disclosure of personal information to third parties for direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.
The Service is intended for users who are at least 18 years of age. Users under 18 may use the Service only with the involvement and consent of a parent or legal guardian.
Children Under 13: We comply with the Children's Online Privacy Protection Act (COPPA). We do not knowingly collect personal information from children under 13 years of age without verifiable parental consent.
Our Service is designed for families, including children. We comply with the Children's Online Privacy Protection Act (COPPA):
If you wish to create an account for a child under 13, you must:
How to Provide Consent: Contact us at privacy@peacelovedishes.com with "Parental Consent for Child Account" in the subject line. We will verify your identity as the parent or legal guardian before activating the child's account.
For children under 13 with parental consent, we may collect:
Minimal Collection: We do not collect more information from children than is reasonably necessary to provide the Service. We do not condition a child's participation on disclosure of more personal information than is reasonably necessary.
Information collected from children under 13 is used only for:
No Marketing: We do not use children's information for advertising, marketing, or building behavioral profiles.
We do not disclose personal information collected from children under 13 to third parties, except:
Parents and legal guardians have the right to:
How to Exercise: Contact us at privacy@peacelovedishes.com with "COPPA Rights Request" in the subject line. We will verify your identity as the parent or legal guardian before processing the request.
Parents who create family accounts:
If we discover that we have collected personal information from a child under 13 without verifiable parental consent, we will delete that information as quickly as possible.
If you believe we have collected information from a child under 13 without parental consent, please contact us immediately at privacy@peacelovedishes.com with "Unauthorized Child Data Collection" in the subject line, and we will delete such information.
PeaceLoveDishes is designed for family use. One subscription account ("Primary Account") may cover multiple family members. The Primary Account holder controls:
When you invite family members, they may have access to shared data according to permissions you set. This may include:
Your Control: You control what is shared. You can change sharing permissions at any time. We do not monitor or control data sharing between family members—this is your responsibility.
Some data remains private to individual users:
Privacy Respect: We respect the privacy of individual family members. Private data is not accessible to other family members unless explicitly shared.
When you invite family members, you are responsible for:
HIPAA Compliant Health Records Module: Our Health Records module is HIPAA compliant and designed to meet HIPAA requirements for Protected Health Information (PHI). We implement comprehensive HIPAA security measures to protect health data.
HIPAA Security Measures: The Health Records module complies with HIPAA requirements including:
BAAs Available: We can provide Business Associate Agreements (BAAs) for covered entities who require them. If you are a HIPAA-covered entity (healthcare provider, health plan, or healthcare clearinghouse) and need a BAA, please contact us at privacy@peacelovedishes.com to request one.
BAA Terms: Our BAAs include standard HIPAA provisions regarding the use and disclosure of PHI, security measures, breach notification, and compliance with HIPAA requirements.
While we provide HIPAA-compliant infrastructure for health data, you are responsible for:
Health data stored in the Health Records module receives enhanced security measures:
HIPAA Compliance: These security measures are implemented in accordance with HIPAA requirements and constitute HIPAA compliance for the Health Records module.
Note: HIPAA compliance applies specifically to the Health Records module. Other modules (recipes, photos, etc.) are not designed for HIPAA compliance. If you need to store health information, use the Health Records module which is HIPAA compliant.
Your data is stored on servers located in the United States. If you are located outside the United States, you consent to the transfer of your data to the United States for processing and storage.
If you access the Service from outside the United States, your data will be transferred to, stored, and processed in the United States. The United States may have data protection laws that differ from those in your country.
For data transfers from the EEA, UK, or Switzerland to the United States, we implement appropriate safeguards to protect your personal data in accordance with GDPR Chapter V:
We use the following third-party service providers that may process your data:
All third-party processors are contractually obligated to implement appropriate security measures and comply with applicable data protection laws, including GDPR.
You have the right to:
To request information about international data transfers or copies of safeguards, contact privacy@peacelovedishes.com with "International Transfer Information Request" in the subject line.
For transfers from the UK, we use the UK International Data Transfer Agreement (IDTA) or UK Addendum to EU SCCs. For transfers from Switzerland, we comply with Swiss data protection law and use Swiss-approved Standard Contractual Clauses.
We use essential cookies and similar technologies necessary for the Service to function:
These cookies are essential and cannot be disabled. They do not track you across websites.
We do NOT use:
You can control cookies through your browser settings. However, disabling essential cookies may prevent the Service from functioning properly.
Our session cookies expire when you log out or after 30 minutes of inactivity. Security tokens expire after their designated validity period.
The Service integrates with third-party services necessary for operation:
These service providers are contractually obligated to protect your information. However, their privacy policies also apply to data they process.
We do NOT use:
The Service may contain links to third-party websites. We are not responsible for the privacy practices of these websites. We encourage you to read the privacy policies of any third-party websites you visit.
We do not engage in automated decision-making or profiling that produces legal effects or similarly significantly affects you.
No Profiling: We do not create profiles about you for marketing, advertising, or behavioral targeting purposes.
Automated processing is used only for essential service functionality:
These automated processes do not make decisions that produce legal effects or similarly significantly affect you.
Some web browsers and devices permit you to broadcast a preference that you not be "tracked" online. At this time, there is no industry consensus on what constitutes a "Do Not Track" signal.
Our Practice: Since we do not track you for advertising or behavioral profiling purposes, Do Not Track signals do not affect our practices. We do not track you across websites or use tracking technologies for advertising regardless of your Do Not Track settings.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other reasons. We will notify you of material changes by:
Material changes to this Privacy Policy will take effect 30 days after notice. Your continued use of the Service after changes become effective constitutes acceptance of the updated Privacy Policy.
We recommend reviewing this Privacy Policy periodically. The "Last Updated" date indicates when this policy was last revised.
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
General Privacy Inquiries: privacy@peacelovedishes.com
GDPR Requests: privacy@peacelovedishes.com
(Subject: "GDPR Request")
CCPA Requests: privacy@peacelovedishes.com
(Subject: "CCPA Request") or call 512-650-8975
COPPA/Parental Requests: privacy@peacelovedishes.com
(Subject: "COPPA Request")
Data Protection Officer: privacy@peacelovedishes.com
Website: https://peacelovedishes.com
Mailing Address:
Peace Love Dishes Inc.
14205 N Mo Pac Expy Ste 570
PMB 387691
Austin, Texas 78728-6529
United States
We will respond to privacy inquiries within 30 days. For urgent security concerns, please mark your email as "URGENT" in the subject line.
This Privacy Policy is written in English. Any translation is provided for convenience only. In the event of conflict between the English version and any translation, the English version shall prevail.
If you believe we have violated your privacy rights or applicable data protection laws, you have the right to lodge a complaint with us and with the appropriate supervisory authority.
Please contact us first at privacy@peacelovedishes.com with "Privacy Complaint" in the subject line. We will investigate and respond to your complaint promptly.
European Users: If you are in the EEA, UK, or Switzerland, you have the right to lodge a complaint with your local supervisory authority:
California Users: California residents may file complaints with the California Attorney General at https://oag.ca.gov.
We take privacy concerns seriously and encourage you to contact us directly so we can address your concerns promptly. We are committed to resolving complaints in accordance with applicable law.
This Privacy Policy is incorporated into and subject to our Terms of Service. Please review our Terms of Service for additional information about your use of the Service.
This Privacy Policy does not create rights enforceable by third parties or require disclosure of any personal information relating to users of the Service.
If any provision of this Privacy Policy is found to be unenforceable or invalid, that provision shall be limited or eliminated to the minimum extent necessary, and the remaining provisions shall remain in full force and effect.
By using the PeaceLoveDishes Service, you acknowledge that you have read, understood, and agree to this Privacy Policy.
Peace Love Dishes Inc. (Delaware Corporation)
Last Updated: March 1, 2026