Privacy Policy
Effective 11 September 2026
This policy explains how the FoodieTom application collects, uses and protects your personal data, in compliance with the General Data Protection Regulation (GDPR) and the French Data Protection Act.
1. Data controller
The data controller is TWILL CONSULTING, a French limited liability company (SARL), 142 rue de Rivoli, 75001 Paris, France (Paris Trade and Companies Register 992 404 962).
For any question regarding your data: contact@foodietom.com.
2. Data we collect
- Account data — email address, password (stored encrypted, never in plain text), username, preferred language. If you choose Sign in with Apple, Apple passes us an account identifier, your email address (or a relay address if you hide yours) and, on first sign-in only, the name you agree to share. That name stays on your device: it is neither sent to our servers nor stored, and only prompts you to choose your username.
- Device location — if you allow it: used on your device to sort dishes near you. It is not sent to our servers. When you search for a place or view the map, it centres the search and the map, which Apple Maps provides (see section 4).
- Contributions — recommended dishes, accompanying sentences and reports that you publish within the Application.
- Push notifications — if you enable them: a notification token (APNs) and a device identifier (identifierForVendor), required to send you notifications.
- Minimal technical data — authentication and session data essential to operating the service.
FoodieTom uses no advertising trackers and never sells any data. This website is static and sets no cookies.
3. Purposes and legal bases
- Providing the service (account creation, publishing and displaying contributions) — basis: performance of the contract formed by the Terms.
- Sending notifications about activity that concerns you — basis: your consent, which can be withdrawn at any time in your device settings.
- Moderating and securing the community (preventing abuse, spam and unlawful content) — basis: the legitimate interest of the publisher and the community.
4. Recipients and processors
Your data is never sold. As part of providing the service, it is processed by the following providers — processors acting on our behalf, or independent controllers bound by their own privacy policy (Apple for Sign in with Apple and Maps):
- Supabase Inc. — hosting of the database and the authentication service, within the European Union (see section 6).
- Apple Inc. — delivery of push notifications via the APNs service, mapping features (Apple Maps) when you search for a place or view the map, and identity provider if you choose Sign in with Apple.
5. Your contributions and their visibility
Your username and your contributions are visible to other members, by the very nature of the service. If you delete your account, your recommendations may remain displayed anonymously, dissociated from your identity, in order to preserve the coherence of the dishes revealed.
6. Hosting and location
The Application's data is hosted within the European Union, by Supabase Inc. on Amazon Web Services infrastructure located in France (Paris region, eu-west-3). The delivery of push notifications, the mapping features and Sign in with Apple rely on the services of Apple Inc., whose servers may be located outside the European Union, notably in the United States: these exchanges, limited to the data strictly necessary, are safeguarded by Apple's certification under the EU–US Data Privacy Framework, in accordance with Article 45 of the GDPR.
7. Retention period
- Account and associated data — kept for as long as the account is active. Account deletion is immediate and permanent.
- Contributions — anonymised and kept after account deletion (see section 5).
- Notification tokens — deleted as soon as they become invalid or when you disable notifications.
- Technical logs — kept for 30 days by our hosting provider (diagnostics and security), then deleted automatically.
- Infrastructure backups — kept for 7 days by our hosting provider, then overwritten automatically.
8. Security
Exchanges between the Application and our servers are encrypted (HTTPS/TLS). Data is protected at rest by our host, and authentication tokens are stored securely in your device's keychain. Passwords are never stored in plain text.
9. Your rights
In accordance with the GDPR, you have the rights of access, rectification, erasure, restriction, objection and portability of your data.
- Export your data and delete your account — directly from the Profile screen of the Application.
- To exercise any other right, write to contact@foodietom.com. We respond within one month.
10. Minors
The Application is restricted to adults. We do not knowingly collect data relating to minors.
11. Complaints
If you consider that your rights are not being respected, you may lodge a complaint with the French data protection authority (CNIL): www.cnil.fr.
12. Changes to this policy
This policy may change. The applicable version is the one in force when you use the Application; its date appears at the top of this document.