Privacy Policy
FoodLoot Ventures
Effective Date: 27 February 2026
Last
Updated: 27 February 2026
1. Introduction
Welcome to FoodLoot. This Privacy Policy explains how FoodLoot Ventures ("FoodLoot", "we", "us",
or "our") collects, uses, stores, and protects your personal information when you use the FoodLoot mobile
application and website (collectively, the "Platform").
By creating an account or using FoodLoot, you agree to the collection and use of your information as described in
this Privacy Policy. If you do not agree, please do not use our Platform.
This policy applies to all users of the FoodLoot Platform, including customers, vendors, and administrators.
2. Who We Are
FoodLoot Ventures operates the FoodLoot food rescue platform, connecting vendors with surplus
food to customers seeking discounted meals. We are based in Karachi, Pakistan.
For questions about this Privacy Policy, contact us at:
Email: foodloot@foodlootpk.com
3. Information We Collect
3.1 Information You Provide Directly
All Users:
- Full name
- Email address
- Password (encrypted — we never store it in plain text)
- Phone number (optional)
- Date of birth and gender (optional, for profile personalisation)
- Profile photo (if uploaded)
Customers:
- Order history and preferences
- Payment information (card number, billing details — processed and stored securely by our third-party payment
processor; we do not store raw card data)
- Deal ratings and reviews you submit
- Vendors you follow
Vendors:
- Business/brand name and legal business name
- Business description and food categories
- Business contact details (phone, address)
- Business location (address and GPS coordinates)
- Operating hours and weekly schedule
- Business logo
- Banking or payment receiving details (for vendor payouts, where applicable)
- Deal listings (title, description, prices, quantities, pickup windows)
3.2 Information Collected Automatically
When you use our Platform, we automatically collect:
- Device information — device model, operating system, unique device identifiers
- Usage data — screens viewed, features used, tap interactions, session duration
- Location data — approximate location (with your permission) used to show nearby deals and
calculate distances; we do not continuously track your location
- Push notification token — a unique identifier generated by Expo to deliver push notifications
to your device
- IP address and connection data — collected by our infrastructure provider for security and
debugging
- App performance and crash data — to help us identify and fix bugs
3.3 Information from Third Parties
- Apple Sign-In — if you choose to sign in with Apple, we receive your name and email address
from Apple. Apple may provide a private relay email address.
- Payment Processor — we receive confirmation and status updates (e.g., payment successful,
failed) from our payment processor. We do not receive or store your full card number.
4. How We Use Your Information
We use your personal information to:
| Purpose |
Details |
| Provide our service |
Create and manage your account, process orders and reservations, verify collections via QR code |
| Process payments |
Handle in-app payments for orders securely through our payment processor |
| Send notifications |
Push notifications about order status changes, new deals from vendors you follow, and platform updates
|
| Send transactional emails |
Order confirmations, collection receipts, welcome emails, vendor approval/rejection notices |
| Personalise your experience |
Show nearby deals based on your location, surface vendors you follow, remember preferences |
| Communicate with you |
Respond to support queries and feedback |
| Operate vendor tools |
Provide vendors with order management, QR verification, inventory and revenue tracking |
| Admin and moderation |
Review vendor applications, monitor platform activity, investigate reports |
| Safety and security |
Detect fraud, prevent abuse, protect users and the platform |
| Legal compliance |
Meet our obligations under applicable Pakistani law |
| Improve the platform |
Analyse usage patterns (in aggregate) to improve features and fix bugs |
We will not use your data for purposes incompatible with those listed above without notifying you first.
5. Legal Basis for Processing
We process your personal data on the following bases:
- Contract performance — processing necessary to provide the service you requested (e.g.,
processing your order, operating your vendor account)
- Legitimate interests — operating a secure platform, preventing fraud, improving our service,
communicating about orders and features
- Consent — push notifications and optional data (you can withdraw consent at any time in your
device or app settings)
- Legal obligation — where we are required by Pakistani law to retain or disclose data
6. Sharing Your Information
We do not sell your personal data. We share your information only in the following circumstances:
6.1 With Vendors (for Customers)
When you place an order, we share your name, order details, and QR code with the relevant vendor so they can prepare
and verify your collection.
6.2 With Customers (for Vendors)
Vendor business name, logo, location, description, deal listings, and operating hours are visible to all customers
on the Platform.
6.3 With Service Providers
We use trusted third-party providers to operate the Platform:
| Provider |
Purpose |
Data Shared |
| Supabase |
Database, authentication, file storage |
All user and operational data (hosted securely) |
| Expo |
Push notification delivery |
Device push token, notification content |
| Resend |
Transactional email delivery |
Name, email address, order/account details |
| Apple |
Sign-in authentication |
Email address, name |
| Payment Processor |
In-app payment processing |
Payment details (PCI-DSS compliant) |
All service providers are bound by contractual obligations to protect your data and use it only for the purpose we
specify.
6.4 For Legal Reasons
We may disclose your information if required to do so by law or in response to a valid request from a government
authority (e.g., court order, law enforcement agency) in Pakistan or another relevant jurisdiction.
6.5 Business Transfer
If FoodLoot Ventures is acquired, merged, or transfers its assets to another entity, your personal data may be
transferred as part of that transaction. We will notify you beforehand where legally required.
7. Data Storage and Security
7.1 Where Your Data Is Stored
Your data is stored on servers operated by
Supabase, which uses secure cloud infrastructure. Data
may be stored in data centres outside Pakistan. By using our Platform, you consent to this transfer.
7.2 Security Measures
We implement appropriate technical and organisational measures to protect your data, including:
- Encrypted data transmission (HTTPS/TLS)
- Encrypted passwords (never stored in plain text)
- Row-level security policies restricting database access
- Secure, access-controlled admin functions
- PCI-DSS compliant payment processing (via our payment processor)
No system is 100% secure. If you suspect unauthorised access to your account, contact us immediately at
foodloot@foodlootpk.com.
7.3 Data Retention
We retain your data for as long as your account is active or as needed to provide our service. Specific retention
periods:
| Data Type |
Retention Period |
| Account profile |
Until account deletion or request for erasure |
| Order history |
3 years (for dispute resolution and legal compliance) |
| Payment records |
5 years (financial record-keeping obligations) |
| Ratings and reviews |
Duration of account; may be anonymised and retained after deletion |
| Push tokens |
Until you sign out, uninstall the app, or revoke permission |
| Vendor applications (rejected) |
1 year from rejection date |
After the applicable retention period, we delete or anonymise your data.
8. Your Rights
You have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you
- Correction — request that we correct inaccurate or incomplete data
- Deletion — request that we delete your personal data (subject to legal retention obligations)
- Withdraw consent — for any processing based on consent (e.g., push notifications), you can
withdraw at any time via your app or device settings
- Portability — request your data in a structured, machine-readable format
- Objection — object to processing based on our legitimate interests
To exercise any of these rights, email us at foodloot@foodlootpk.com. We will respond within 30
days. We may need to verify your identity before fulfilling a request.
Account Deletion
You can delete your account directly from the FoodLoot app (Profile → Delete Account). This permanently removes your
personal data, subject to data we are legally required to retain.
9. Push Notifications and Communications
Push Notifications
We send push notifications for:
- Order status updates (e.g., "Your order is ready for collection")
- New deals from vendors you follow
- Platform announcements
You can disable push notifications at any time in your device settings or in the FoodLoot notification settings.
Disabling notifications does not affect your ability to use the Platform.
Emails
We send transactional emails for:
- Welcome and account confirmation
- Order confirmations and receipts
- Vendor approval or rejection notices
We do not send marketing emails without your explicit consent.
10. Children's Privacy
FoodLoot is not directed at children under the age of 13. We do not knowingly collect personal
data from children under 13. If you believe a child under 13 has provided us with personal data, please contact us
at foodloot@foodlootpk.com and we will delete it promptly.
Users aged 13 to 17 may create an account and browse the Platform only with the consent and
supervision of a parent or legal guardian. Users under 18 may not place orders or make payments through the
Platform — payment functionality is restricted to users aged 18 and over.
11. Third-Party Links
Our Platform may contain links to third-party websites or services. This Privacy Policy does not apply to those
third-party services. We are not responsible for the privacy practices of external sites and encourage you to
review their privacy policies.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will:
- Update the "Last Updated" date at the top of this policy
- Notify you via the app or email for material changes
Continued use of the Platform after changes are published constitutes your acceptance of the updated policy.
13. Governing Law
This Privacy Policy is governed by the laws of the Islamic Republic of Pakistan, including the
Personal Data Protection Act and the Electronic Transactions Ordinance 2002. Any disputes arising under this
policy shall be subject to the jurisdiction of the courts of Karachi, Pakistan.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please
contact:
FoodLoot Ventures
Karachi, Pakistan
Email: foodloot@foodlootpk.com
*This Privacy Policy was last updated on 27 February 2026.*