Privacy Policy
Last updated: January 9, 2026
1. Introduction
Welcome to FoodPic.ai ("we," "our," or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our services.
We comply with the General Data Protection Regulation (GDPR) and other applicable data protection laws in the European Union and the Netherlands.
2. Information We Collect
2.1 Personal Information
When you register for an account or use our services, we may collect:
- Name and email address
- Business name and website URL
- Payment information (processed securely via Stripe)
- Account preferences and settings
2.2 Uploaded Content
We process images you upload to generate AI-enhanced food photography. Original images are stored temporarily for processing and deleted according to our retention policy.
2.3 Automatically Collected Information
- Device information and browser type
- IP address and approximate location
- Usage data and interaction with our services
- Cookies and similar tracking technologies
3. How We Use Your Information
We use your information for the following purposes:
- Service Delivery: To provide and maintain our AI food photography services
- Account Management: To create and manage your account
- Payment Processing: To process transactions and manage subscriptions
- Communication: To send service updates, support responses, and marketing (with consent)
- Improvement: To analyze usage patterns and improve our services
- Legal Compliance: To comply with legal obligations and protect our rights
4. Legal Basis for Processing (GDPR)
Under GDPR, we process your personal data based on the following legal grounds:
- Contract: Processing necessary to fulfill our service agreement with you
- Consent: For marketing communications and optional cookies
- Legitimate Interest: To improve our services and prevent fraud
- Legal Obligation: To comply with applicable laws
5. Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your experience:
5.1 Necessary Cookies
Essential for website functionality, authentication, and security. These cannot be disabled.
5.2 Analytics Cookies
Help us understand how visitors interact with our website. We use privacy-friendly analytics.
5.3 Marketing Cookies
Used with your consent to deliver relevant advertisements and measure campaign effectiveness.
You can manage your cookie preferences at any time through our cookie consent banner.
6. Data Sharing and Third Parties
We may share your information with:
- Service Providers: Cloud hosting (Supabase), payment processing (Stripe), AI processing services
- Analytics Partners: Privacy-friendly analytics services (with consent)
- Legal Authorities: When required by law or to protect our rights
We do not sell your personal information to third parties.
7. Data Retention
- Account Data: Retained while your account is active and for 30 days after deletion
- Generated Images: Stored for as long as your account is active
- Original Uploads: Deleted within 24 hours after processing
- Transaction Records: Retained for 7 years for legal and tax purposes
8. Your Rights (GDPR)
Under GDPR, you have the following rights:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data ("right to be forgotten")
- Restriction: Limit how we process your data
- Portability: Receive your data in a portable format
- Objection: Object to certain processing activities
- Withdraw Consent: Withdraw consent at any time
To exercise these rights, contact us at support@foodpic.ai
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including encryption, secure servers, access controls, and regular security assessments. However, no method of transmission over the Internet is 100% secure.
10. International Data Transfers
Your data may be processed by our service providers in countries outside the EEA. We ensure appropriate safeguards are in place, such as Standard Contractual Clauses, to protect your data in accordance with GDPR requirements.
11. Children's Privacy
Our services are not intended for individuals under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. We encourage you to review this policy periodically.
13. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:
You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) if you believe your rights have been violated.