Pantry Play
Privacy Policy
Plain-language description of what Pantry Play stores, why, and what you can ask us to do about it.
Effective August 4, 2026
Who we are
Pantry Play ("Pantry Play," "we," "us," or "our") operates https://pantryplay.io and is the controller of the personal information described here.
Privacy questions and requests: hello@pantryplay.io. Billing questions: hello@pantryplay.io.
Information we collect and why
Almost everything below comes directly from you. Technical information is generated automatically when your browser talks to our servers, and subscription information comes back to us from our payment provider.
- Account information — your email address, display name and the authentication data needed to sign you in and reset your password. Used to create and operate your account. Legal basis: performance of our contract with you.
- Username and profile — your unique @username, username history (kept so a released handle rests before someone else can take it), avatar image, bio and your Public or Private profile setting. Used to identify you to other members and to run profile search. Legal basis: contract, and our legitimate interest in preventing impersonation.
- Content you create — recipes, Recipe Maps, recipe images, cookbooks, saved recipes and anything else you submit. Used to store, display and share that content according to the visibility you chose. Legal basis: contract.
- Social activity — who you follow and who follows you, and the resulting counts. Legal basis: contract.
- Subscription and billing information — your plan, subscription status, renewal and period dates, the customer and subscription identifiers issued by our payment provider, the billing events they send us, and the history of any billing support you ask for. Used to give you the Premium access you paid for, keep records and handle refunds. Legal basis: contract and our legal obligations (tax, accounting).
- Invite and promotional code use — which code you entered, when it was redeemed and what it granted. Used to apply the benefit and to prevent code abuse. Legal basis: contract and legitimate interest.
- Account-security events — email verification, password resets, email changes, sign-in attempts and similar events. Used to keep your account secure. Legal basis: legitimate interest in security, and legal obligation where applicable.
- Messages you send us — when you use the contact form we store your name, email address, the subject you chose, your message, whether you were signed in (and your account identifier if you were), and the time you sent it. We also store a one-way salted hash of your email address and of your IP address, used only to apply the form's anti-abuse limits — the raw IP address is not kept. Emails you send us directly and our replies are stored too. Used to answer you, apply anti-abuse limits and keep a record of the outcome. Legal basis: contract, and our legitimate interest in answering enquiries and preventing abuse of the form.
- Technical information — IP address, browser and device information, timestamps, request and error logs, and security logs generated by our hosting and backend platforms. Used to run the site, diagnose faults and detect abuse. Legal basis: legitimate interest in a secure, working service.
We do not sell your personal information, we do not share it for cross-context behavioural advertising, and we do not use it to build advertising profiles.
The contact form
The contact form is open to everyone, signed in or not. Your submission is saved to our database first, so your message is never lost if email delivery fails, and then two emails are sent through Resend: a notification to our own inbox and a confirmation to you. Resend acts as our processor for that delivery, and open and click tracking are disabled.
To stop automated abuse, the form limits how many messages can come from one network or one email address per hour. We do that by comparing salted one-way hashes rather than storing your raw IP address.
Please don't send passwords or full payment-card details through the form or by email.
Payment card information
Card and payment details are entered on the checkout of our payment provider, Paddle, who acts as merchant of record. Pantry Play never sees, receives or stores your card number. What comes back to us is your subscription status, plan, billing period dates and the identifiers we need to link a subscription to your account.
Cookies, local storage and analytics
Pantry Play uses only essential browser storage: the storage that keeps you signed in, and a short list of up to five recipe identifiers kept in your own browser so logged-out visitors can read five recipes before creating an account. That list stays on your device and clearing your browser storage removes it.
We do not run advertising cookies, advertising pixels, third-party analytics products or other non-essential tracking. Because there are no non-essential cookies, there is no cookie consent banner. If that ever changes, we will update this page and ask for consent where the law requires it.
Who we share information with
We share information only with the service providers needed to run Pantry Play, and only for that purpose. They act on our instructions under contract.
- Lovable — application hosting and delivery of the website, including server and security logs.
- Supabase — authentication, database and file storage. Your account, profile, recipes and images are stored there on our behalf.
- Paddle — merchant of record for Premium subscriptions: payment processing, invoicing, tax compliance, subscription management and refunds.
- Resend — delivery of contact-form emails: the notification sent to our own inbox and the confirmation sent back to you. Resend processes the name, email address, subject and message content needed to deliver those emails. Open tracking and click tracking are switched off.
- Email delivery — account emails (verification, password reset, email change confirmations) are sent through our backend platform's transactional email service. Pantry Play does not currently use a separate marketing email provider.
- Professional advisers (such as accountants or lawyers) and authorities, where we are legally required or it is necessary to establish or defend legal claims.
Product recommendations may link out to retailers. Once you follow a link, that retailer's own privacy practices apply.
What other people can see
Your email address is never shown to other members. Every profile starts Private, which shows only your display name, username and avatar. Making a profile Public, publishing a recipe or turning on a cookbook share link are deliberate actions you take, and each can be undone.
Content you deliberately publish — a public profile, a published recipe, a shared cookbook link — can be seen by other members and, for shared cookbook links, by visitors without an account.
International processing
Pantry Play is operated from the United States, and our hosting, database and payment providers process information in the United States and other countries where they operate. If you use Pantry Play from outside the United States, your information is transferred there. Where a transfer is made from the UK or EEA, our providers rely on recognised safeguards such as Standard Contractual Clauses or an applicable adequacy decision.
How long we keep information
- User content and ordinary account information: deleted or anonymised after a valid account-deletion request, subject to backups, technical limitations and the exceptions below.
- Username history: up to 90 days after a handle is released, so it can rest before being reused.
- Contact-form submissions and support or billing correspondence: retained only as long as reasonably necessary to answer the request, maintain appropriate business records, resolve disputes, prevent abuse and meet legal obligations.
- Anti-abuse hashes attached to contact-form submissions: kept with the submission and only ever used to enforce the form's rate limits.
- Technical, security and server logs: retained according to Pantry Play's operational and security needs and the applicable service provider's retention settings, then deleted or anonymised when no longer reasonably necessary, unless longer retention is legally required.
- Account, subscription, transaction, fraud-prevention and legal-compliance records: may be retained after account deletion when reasonably necessary for contractual, tax, accounting, dispute-resolution, security or legal obligations.
Deleting a recipe or cookbook removes it from Pantry Play immediately, though copies may persist briefly in routine encrypted backups before those backups age out.
Security
We use appropriate technical and organisational measures, including encryption in transit, access controls, and access rules enforced on the server rather than in your browser. No online service can guarantee perfect security, and we make no compliance certification claims. If a breach affects you and the law requires it, we will notify you.
Deleting your account
Email hello@pantryplay.io from the address on your account and ask us to delete it. We remove your profile, content and account data. Some records must stay behind afterwards: billing and tax records held by us and by Paddle, records needed to prevent fraud or abuse, and anything we are legally required to retain or need to defend a legal claim. Content you shared publicly may remain in other people's browser caches or in copies they made.
Your rights and how to use them
Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, restrict or object to certain processing, receive a portable copy, withdraw consent where we relied on it, and complain to your data protection authority. We do not discriminate against you for exercising these rights.
Send your request to hello@pantryplay.io. To protect your account we will verify it — usually by asking you to write from the email address on the account, and occasionally by asking you to confirm details only the account holder would know. We aim to respond within 30 days, or one month for UK/EEA requests, and will tell you if we need longer.
Children's privacy
Pantry Play is not intended for children under 13, which matches the minimum age in the Terms of Use, and we do not knowingly collect their information. If you believe a child has created an account, email hello@pantryplay.io and we will remove it.
Changes to this policy
We update this page as Pantry Play changes, and the effective date at the top always shows the current version. If a change is material, we will give notice in the app or by email to the address on your account before it takes effect.
See also the Terms of Use and the Refund Policy.