CribGourmet

Your private claim page

Opening the kitchen page CribGourmet prepared for you. Your invitation is being checked securely.

Checking invitation…

CribGourmet

CribGourmet Privacy Policy

Last updated August 25, 2026 · Version 2026-08-25-v4

Crib Gourmet LLC operates CribGourmet, a directory and communication service that helps people discover independent cooks and contact them directly. We collect the information needed to run accounts, publish cook pages, support direct buyer-to-cook order requests and conversations, deliver requested notifications, prevent abuse, and operate the service. We do not sell personal information or share it for cross-context behavioral advertising.

Account export, privacy choices, and the secure signed-in deletion path are explained at Privacy choices & account deletion.

Account, device, and content information

Clerk manages sign-in and may provide a verified name, email address, phone number, and account identifier. CribGourmet stores the linked identifier and available verified identity details. We do not receive or store your Clerk password.

If you enable notifications in an installed iOS or Android app, we receive the APNs or Firebase Cloud Messaging device token, device platform, selected app language, and a random device-unlink proof. The token is linked to the signed-in account and encrypted at rest; the unlink proof is stored only as a hash. We do not use push tokens for advertising or cross-app tracking.

Cook pages can include public business information, menus, prices, photos, availability, service areas, approximate map locations, pickup spots, and contact or payment links. We also store saved cooks and carts, reviews and review photos, reports, notification preferences, support requests, and product activity such as page views, link taps, menu opens, onboarding, publishing, and sharing. Signed-in onboarding, publishing, and sharing activity may be linked to the account; ordinary visitor engagement uses a hashed visitor or browser-session identifier rather than an account identifier. Engagement records may also include a bounded referring-source category and platform category, such as Instagram, QR, web, iOS, or Android, but not the full referring URL or a raw device identifier.

We record basic technical and engagement information and privacy-light hashed network fingerprints for counting, security, fraud prevention, rate limiting, and legal-acceptance evidence. We do not intentionally retain raw IP addresses in CribGourmet application records, although hosting, security, authentication, and other infrastructure providers may process ordinary IP address, device, and request-log information when providing their services.

Private messages and order requests

A customer-to-cook conversation can include the customer's verified name and contact method, message text, message images, chosen menu items and quantities, item options and modification notes, requested date or time, fulfillment choice, delivery inquiry, and a drop-off address or cross streets when the customer requests delivery. CribGourmet shares that information with the selected cook and authorized kitchen managers so they can respond to the request.

Private message bodies, private message images, customer contact fields, order-request details, and drop-off addresses are encrypted at rest in CribGourmet's application database. Notification previews and routine operational alerts do not include private message content or the drop-off address.

Location and map information

If you choose a nearby or distance feature, your browser or installed app may ask for location permission while the service is in use. CribGourmet requests lower-accuracy location, but the operating system may return precise coordinates if you allow precise access. The coordinates are kept in storage on that device for nearby sorting until you clear that storage or replace the location.

Most distance sorting happens on the device. For an immediate nearby-food-drop lookup, the coordinates are also sent to CribGourmet's server as request parameters, used to return results within the selected radius, and not intentionally written to an account profile, food-drop record, or application database. We do not request background location or use these coordinates for advertising.

For cook listings, we may convert a city, neighborhood, service area, or cook-saved pickup spot into map coordinates and make the resulting listing or active pickup location available through the directory. Cooks should not publish a private home address unless they intend it to be public. Map, tile, and geocoding providers receive ordinary network and request information, and may receive the map area or place query needed to provide the requested map.

Direct transactions and subscription information

CribGourmet is a directory and communication service, not the seller of a cook's food. A customer's cart or order request is a message to the independent cook, not a completed marketplace order. CribGourmet does not accept or dispatch food orders, process buyer-to-cook payments, or store customer card or bank details. Buyers and cooks arrange acceptance, payment, pickup or delivery, refunds, disputes, and food-safety questions directly.

On supported web surfaces, Clerk processes CribGourmet Premium subscription checkout and provides subscription status so we can manage entitlement. Native-app purchase controls are not offered unless the applicable store billing path is implemented and approved.

How we use information

We use information to authenticate and secure accounts; operate, search, and personalize the directory; publish and manage cook pages; deliver private messages, order requests, email, and requested device notifications; provide account export and deletion; show cooks first-party engagement insights; measure which cook-shared links and drops bring visitors back to the service; moderate content; provide support; and prevent fraud, spam, and account abuse.

Cookies and browser storage

Clerk uses cookies or browser storage to maintain authentication. CribGourmet also stores language and workspace preferences, unfinished cook-page drafts, saved carts, recently viewed cooks, optional device coordinates, onboarding state, random first-party visitor and browser-session identifiers, the referring-source category for the current session, notification-unlink information, and historical guest-conversation access tokens on your device. Clearing browser or app data may reset engagement attribution and may remove drafts, preferences, cart state, nearby results, or access to a historical guest conversation.

Service providers

Service providers may process information on our behalf, including Clerk for authentication, account details, sessions, and supported web billing; Render for hosting and databases; Cloudflare for DNS, security, bot protection, caching, and object delivery when configured; AWS for moderation of submitted images and cook-requested menu translation; Resend for transactional email and delivery events; Apple Push Notification service and Firebase Cloud Messaging for device notifications; and Slack for restricted operational alerts when configured.

Map resources may be supplied by CribGourmet or providers using OpenFreeMap, OpenMapTiles, OpenStreetMap, and related geocoding data. These providers process information under their contracts and privacy practices. The final mobile release may also include Apple, Google, Capacitor, and other platform components whose privacy manifests and processing must be reviewed with the final archive before store submission.

When we disclose information

We disclose information to service providers as needed to perform the functions described above; to other users when you publish content or send them a message; at your direction; to investigate safety, fraud, ownership, or legal issues; to comply with lawful process; or in connection with a financing, merger, acquisition, reorganization, or sale of all or part of the business, subject to applicable law.

We do not sell personal information or share it for cross-context behavioral advertising. We do not disclose private message content to the public, although the sender and recipient can access their conversation and we may access or preserve information when reasonably necessary for support, security, abuse prevention, or legal compliance.

Public information and third-party links

Cook pages, public contact details, active pickup locations, and published reviews are visible to anyone. Links to cooks' social profiles, messaging services, websites, and payment methods lead to independent third parties with their own privacy practices. CribGourmet does not control information you choose to send or pay through those outside services.

Retention and account deletion

We generally retain account and content information while the account or relevant feature remains active and as reasonably needed to provide the service, maintain security and business records, resolve disputes, and meet legal obligations. An active native push registration remains until it is unregistered during logout, disabled as stale or invalid, transferred to another signed-in account on that device, or deleted with the account. Device-only coordinates remain until you clear or replace them; coordinates sent for an immediate nearby lookup are not intentionally persisted in the application database.

A successful signed-in account deletion permanently removes the active CribGourmet account, linked Clerk identity, profile and contact details, saved data, customer conversations and order requests, reviews, notifications, native push registrations, support requests, and any cook page the account owns with its associated content and inbox. Active paid or trial subscription items managed by Clerk are ended before the identity is deleted. Messages sent as a manager of somebody else's kitchen may remain as part of that kitchen's business conversation, but the deleted manager's account link and staff display name are removed.

We retain a minimized legal-acceptance record containing the document type, version, integrity hash, acceptance action, language, and time, detached under a one-way deletion marker. Its network fingerprint and device/browser description are cleared, and it does not retain the deleted profile's name, email, phone, messages, or push token. We retain that record only as long as reasonably needed for legal, fraud-prevention, and dispute purposes and do not currently promise a fixed deletion date. Restricted provider backups or security logs may retain copies temporarily until normal rotation, or longer when law, safety, or an active dispute requires preservation.

Your choices and privacy rights

You can update your profile and public cook page, remove saved cooks and carts, change email and activity-notification preferences, deny or revoke device location and notification permissions, clear device-only storage, export account data, or permanently delete your account from Account Settings. Instructions and the secure signed-in deletion link are available at /account-deletion.

Depending on where you live, you may also have rights to request access, correction, deletion, or a copy of personal information and to appeal certain privacy-request decisions. We may verify your identity before completing a request. To make a privacy request or ask for help when you cannot sign in, email hello@cribgourmet.com. Do not email a password, device token, or other secret.

Children and security

CribGourmet is not directed to children under 13. We use reasonable technical and organizational safeguards, but no transmission or storage system can be guaranteed completely secure.

Contact

Questions or privacy requests for Crib Gourmet LLC may be sent to hello@cribgourmet.com.