Plaum logo Plaum Join the waitlist

Privacy Policy

This Privacy Policy explains what information Plaum collects, why we collect it, how we use it, when we share it, how long we keep it, and what choices you have. It applies to the Plaum mobile app, restaurant tools, waitlist and marketing pages, support channels, and related backend services.

Effective date: July 21, 2026 Last updated: July 21, 2026 Contact: admin@plaum.co
Short version

Plaum is a food discovery platform. To run it, we use account details, taste and onboarding information, content you choose to post, order and reservation data, restaurant business information, foreground location permissions you choose to enable, and technical diagnostics including Firebase Analytics and Firebase Crashlytics. As of July 20, 2026, Plaum does not use background geofencing or visit-tracking features. Plaum does not store raw card numbers on its own servers, and Plaum does not sell personal information.

Contents
1. Overview and scope 2. Information we collect 3. How we use information 4. How we share information 5. Data retention 6. Your rights and choices 7. International transfers 8. Children's privacy 9. Security 10. Cookies and similar tools 11. Changes to this policy 12. Contact information

1Overview and scope

1.1 Who we are

Plaum Inc. ("Plaum," "we," "us," or "our") operates a two-sided food discovery platform for diners and restaurants. On the diner side, Plaum helps people discover dishes, restaurants, and recommendations from creators, friends, and their city. On the restaurant side, Plaum provides tools for menus, discovery, ordering, reservations, analytics, and operational workflows.

1.2 What this policy covers

This policy applies to personal information processed through:

  • The Plaum mobile app for consumer and restaurant users
  • Restaurant web tools, dashboards, and operational interfaces made available by Plaum
  • The Plaum website, waitlist, and legal pages
  • Support, feedback, email, and other communications with Plaum
  • Backend systems, APIs, data stores, analytics, and infrastructure that power these services

1.3 Your relationship with Plaum

For most of the data practices described here, Plaum acts as the data controller or business responsible for deciding why and how information is used. Our cloud, payment, analytics, email, and infrastructure vendors generally act as service providers, processors, or sub-processors on our behalf, subject to contract and applicable law.

1.4 By using Plaum

By using Plaum, you acknowledge that you have read this Privacy Policy and understand how your information is handled. If you do not agree, do not use Plaum.

2Information we collect

2.1 Account, identity, and profile information

When you create or manage a Plaum account, we may collect:

  • Email address
  • Password hash and authentication metadata if you sign up directly with Plaum
  • Google or Apple sign-in identifiers if you use those login methods
  • First name, last name, username, display name, bio, and avatar
  • Account type, such as diner, restaurant, or both
  • Email verification, password reset, and account recovery activity
  • Profile visibility or notification settings you choose in the app

2.2 Taste, onboarding, and personalization information

To personalize discovery, Plaum may collect information you provide during onboarding or later in settings, including:

  • Preferred cuisines
  • Dietary tags or restrictions
  • Quiz answers and food personality responses
  • Whether to include drinks in suggestions
  • Saved dishes, saved restaurants, follows, likes, comments, and other preference signals
  • Palate Twin, missions, badges, shared boards, and similar participation history where those features are used

2.3 Restaurant business and operations information

If you use Plaum for a restaurant, Plaum may collect business and operational information such as:

  • Restaurant name, address, contact details, website, hours, cuisine, and profile information
  • Menu items, dish names, pricing, modifiers, add-ons, tags, descriptions, and availability settings
  • Claim or verification details, including contact name, optional phone number, and optional business proof
  • Order settings, dine-in QR settings, payment options, tips settings, and reservation settings
  • Reservation rules such as seating windows, deposits, cancellation policies, party limits, and blackout dates
  • Staff roles, account permissions, analytics summaries, and operational event history
  • POS connection status and sync data if the restaurant enables integrations such as Square or Toast
  • Restaurant-authored posts, portfolio content, and other discovery-facing materials

2.4 Content, messages, support, and feedback

When you interact socially or contact us, Plaum may collect:

  • Photos, videos, captions, restaurant tags, dish tags, and visibility settings for posts
  • Comments, replies, likes, saves, follows, shares, reports, and blocks
  • Direct messages, message attachments, and shared content links
  • Support tickets, support chat messages, screenshots, attachments, and dispute materials
  • Feedback submissions about a place, dish, order, or data accuracy

2.5 Orders, reservations, payments, and transaction records

When you place an order, manage an order, or make a reservation, Plaum may collect:

  • Cart contents, modifiers, quantity, special instructions, and fulfillment method
  • Order status history, order chat, order edit proposals, cancellation events, reviews, and tips
  • Guest order identifiers or guest reservation details when those flows are used without a full account
  • Reservation details such as party size, reservation time, special requests, deposit acknowledgements, cancellation data, or no-show disputes
  • Saved payment method tokens, Stripe customer references, payment intent references, subscription references, and payout status information
  • Billing and reconciliation records needed for accounting, fraud prevention, taxes, disputes, and support
Important: Plaum does not store raw credit card numbers, debit card numbers, or bank account numbers on Plaum's own servers. Payment credentials are handled by Stripe or by the payment provider a restaurant uses outside Plaum.

2.6 Location, device permissions, and media access

Plaum may request or receive the following device-level data and permissions:

  • Foreground location: to show nearby discovery, maps, restaurant distance, local search, and location-aware Plaum AI suggestions
  • Camera access: for QR scanning and, if you choose, capturing content to post
  • Photo library access: for selecting and uploading profile or post media
  • Microphone or speech recognition access: if you choose to use voice-based Plaum AI interactions or supported voice tools
  • Push notification token: to deliver order, social, restaurant, and account notifications

Plaum uses these permissions only for Plaum features you enable or actively use. You can also control most of these permissions at the operating-system level.

As of July 20, 2026, Plaum does not use background location permissions, geofencing, or visit-tracking features. If that changes in the future, Plaum will update this policy before using that data.

2.7 Technical, analytics, and diagnostic information

Plaum automatically collects certain technical information to operate, secure, and improve the service, including:

  • Device type, operating system, app version, locale, and session data
  • Approximate IP-based network information and security logs
  • Feature usage events, page or screen views, interaction events, and aggregated analytics, including data collected through Firebase Analytics
  • Crash reports, error logs, and performance diagnostics, including data collected through Firebase Crashlytics
  • Notification preferences and token registration activity

Plaum tries to keep analytics proportional to the product need. For example, the mobile analytics layer is designed around product usage, reliability, and diagnostics rather than ad-tech profiling.

2.8 Plaum AI interaction data

If you use Plaum AI, Plaum may process text prompts, voice-to-text transcripts, AI responses, timestamps, and related context needed to answer your request. Depending on the task, that context may include your taste preferences, approximate or precise location context, restaurant or dish references, current cart context, or recent activity relevant to the request.

Plaum may store limited Plaum AI conversation memory inside your account so the feature can carry context across turns. Plaum also logs actions you ask Plaum AI to perform, such as adding an item to your cart or navigating you to a restaurant or dish.

2.9 Information from third parties and integrations

Plaum may also receive information from:

  • Google or Apple when you use their sign-in products
  • Restaurants or restaurant staff who manage listings, menus, hours, and service settings
  • POS systems enabled by a restaurant, such as Square or Toast
  • Payment providers such as Stripe, including payment success or failure, customer references, and connected-account status

3How we use information

Plaum uses personal information for the following business and operational purposes:

3.1 To provide Plaum's core services

  • Create and secure accounts
  • Show discovery feeds, restaurant profiles, menus, maps, and dish pages
  • Publish posts, comments, messages, and restaurant content
  • Process orders, reservations, refunds, tips, support cases, and payouts
  • Operate restaurant dashboards, ordering flows, reservation tools, and analytics

3.2 To personalize the Plaum experience

  • Rank feeds and recommendations
  • Match users with relevant dishes, places, or people
  • Power Plaum AI suggestions and actions
  • Highlight local, timely, or personally relevant restaurants and dishes

3.3 To keep the platform safe and reliable

  • Detect spam, fraud, abuse, account misuse, or harmful content
  • Investigate reports, disputes, and suspicious transactions
  • Moderate content and protect the security of Plaum users, restaurants, and systems
  • Debug crashes, monitor performance, and improve service stability

3.4 To communicate with you

  • Send transactional messages such as verification emails, password resets, receipts, reservation updates, order updates, or support responses
  • Send product notices, legal updates, and security alerts
  • Send marketing or launch communications where allowed by law and where your settings or consent support them

3.5 To comply with law and platform obligations

  • Maintain accounting, tax, and audit records
  • Respond to legal requests and enforce our terms
  • Support accessibility, privacy, and consumer-protection obligations

3.6 Automated systems and human review

Plaum uses automated systems to help rank content, recommend restaurants or dishes, match users, moderate content, and detect fraud or misuse. These systems support the product experience, but Plaum may also use human review for support, moderation, legal compliance, fraud investigations, safety escalations, and product quality checks.

4How we share information

4.1 Information visible inside Plaum

Some information is meant to be visible to other users or restaurants depending on the feature and your settings. For example:

  • Your username, profile, avatar, and public posts may be visible to other Plaum users
  • Restaurant pages, menus, restaurant-authored posts, and operating details may be visible to diners
  • Order and reservation details are shared with the restaurant involved in that order or reservation
  • Messages and shared-board activity are visible to the participants in those features

4.2 Service providers, processors, and integrations

Plaum may disclose personal information to vendors and infrastructure providers that help us run the service.

Provider Purpose Examples of data involved
Stripe Payment processing, saved payment method support, subscriptions, and restaurant payouts Payment references, customer IDs, connected-account status, transaction amounts, and payout metadata
Supabase Authentication and application data infrastructure Account credentials, user profile data, relational records, and session-related application data
Amazon Web Services (AWS) Infrastructure, media storage and delivery, AI processing, and content-processing support Uploaded media, AI requests and responses, app infrastructure logs, and related service metadata
Neo4j Graph relationships, recommendation logic, and matching features Relationship and discovery graph data tied to users, restaurants, dishes, and interactions
Google Firebase Analytics and Firebase Crashlytics Mobile analytics, app measurement, crash diagnostics, and reliability monitoring App usage events, screen views, crash reports, device-level diagnostics, performance signals, and notification-related metadata
Google and Apple Sign-in, device-level services, maps, speech, and operating-system features where used OAuth identifiers, device permission flows, speech transcripts handled by the device platform, and maps-related context
Resend Transactional email delivery Email address, message metadata, and email content necessary to deliver account and service emails
Square or Toast Restaurant POS sync when enabled by a restaurant Menu, order, inventory, or operational sync data determined by the restaurant's integration settings

4.3 Legal, safety, and business disclosures

Plaum may also disclose information:

  • To comply with a valid legal request, court order, subpoena, or regulatory obligation
  • To protect the rights, safety, property, users, staff, or systems of Plaum or others
  • As part of a merger, financing, acquisition, restructuring, or asset sale, subject to appropriate confidentiality and legal safeguards

4.4 No sale of personal information

Plaum does not sell personal information as that term is commonly used in privacy laws. Plaum also does not share precise location data with third parties for cross-context behavioral advertising.

5Data retention

5.1 General retention approach

Plaum keeps personal information only for as long as it is reasonably needed for the purposes described in this policy, including service delivery, account management, safety, support, legal compliance, fraud prevention, tax and accounting records, and dispute resolution.

5.2 Account deletion and the 30-day grace period

If you request account deletion, Plaum may place your account into a deletion workflow that includes a 30-day grace period. During that window, Plaum may retain enough information to allow cancellation of the request, to prevent fraud, and to finish pending obligations. Where Plaum offers an immediate deletion option for eligible data, you may choose that option instead.

After the applicable deletion period ends, Plaum deletes or de-identifies personal information unless we are required or permitted to keep certain records longer for legal, accounting, security, or dispute reasons.

5.3 Transaction, reservation, and support records

Order records, reservation records, payout records, refunds, disputes, charge issues, support records, and related communications may be retained longer than ordinary profile data because they can be needed for tax, financial reporting, fraud prevention, consumer protection, legal compliance, or ongoing support.

5.4 Plaum AI history

Plaum AI uses limited conversation memory to make the feature useful across nearby interactions. Plaum may prune older Plaum AI memory and keep only a limited recent history in active use. You may also clear Plaum AI history from the product controls when that control is available to you.

5.5 Backups and system logs

Backup copies and infrastructure logs may persist for a limited period after live records are deleted. Plaum keeps these copies only for continuity, recovery, security, and audit purposes and then rotates or deletes them in the ordinary course.

6Your rights and choices

6.1 In-app and device controls

You can control many privacy settings directly through Plaum or your device, including:

  • Profile edits, avatar changes, and certain visibility settings
  • Notification preferences
  • Location permission settings at the device level
  • Optional visit tracking settings where that feature is available
  • Plaum AI history clearing where that feature is available
  • Content deletion for posts, comments, or messages you control

6.2 Access, correction, deletion, portability, and objection

Depending on where you live, you may have rights to request access to your personal information, ask for correction of inaccurate information, request deletion, request a portable copy, restrict certain processing, or object to certain uses.

6.3 Rights for EEA, UK, and similar jurisdictions

Where GDPR, UK GDPR, or similar laws apply, you may have rights such as:

  • Access
  • Rectification
  • Erasure
  • Restriction of processing
  • Data portability
  • Objection to certain processing
  • Withdrawal of consent for consent-based processing
  • Complaint to your local supervisory authority

6.4 Rights for California residents

Where the California Consumer Privacy Act or California Privacy Rights Act applies, California residents may have rights to:

  • Know what categories of personal information Plaum collects, uses, discloses, or retains
  • Request deletion of personal information, subject to legal exceptions
  • Request correction of inaccurate personal information
  • Request a portable copy of certain information
  • Not be discriminated against for exercising privacy rights

Plaum does not sell personal information and does not use precise location for cross-context behavioral advertising.

6.5 Rights for Canadian users

Where PIPEDA or similar Canadian privacy laws apply, you may request access to personal information Plaum holds about you, ask for corrections, and withdraw consent for certain uses where consent is the legal basis and no overriding legal restriction applies.

6.6 Email and communication choices

You may unsubscribe from marketing emails using the unsubscribe link in the message. Plaum will still send transactional or service-critical messages when needed for your account, orders, reservations, security, or legal compliance. Plaum intends marketing communications to respect applicable anti-spam rules, including CAN-SPAM and CASL.

6.7 How to exercise your rights

Email admin@plaum.co with enough detail for us to understand your request and verify your identity. If you are invoking a region-specific right, it helps to use a subject line such as GDPR Request, CCPA Request, or PIPEDA Request.

Plaum may ask for identity verification before fulfilling a request. Plaum will respond within the time required by applicable law, which may be around 30 days in some jurisdictions and up to 45 days in others depending on the request and local law.

7International transfers

Plaum is based in Ontario, Canada, and Plaum's infrastructure and service providers may process information in Canada, the United States, or other countries where Plaum or its providers operate.

When information is transferred across borders, Plaum relies on lawful transfer mechanisms appropriate to the jurisdiction and the transfer, such as contractual safeguards, data-processing agreements, and where relevant, Standard Contractual Clauses or similar protections.

8Children's privacy

Plaum is not intended for children under 13. Plaum does not knowingly collect personal information from children under 13. If Plaum learns that a child under 13 has provided personal information without appropriate permission, Plaum will take steps to delete that information.

Users between 13 and 17 should use Plaum only with any consent required by their parent, guardian, or local law.

9Security

Plaum uses technical, organizational, and contractual safeguards designed to protect personal information, including:

  • Encryption in transit for communications between apps, browsers, and Plaum services
  • Role-based access controls and internal access limitations
  • Secure token or credential storage patterns appropriate to the platform
  • Cloud security controls, logging, monitoring, and incident investigation
  • Payment separation so raw card credentials are handled by payment providers instead of Plaum systems

No service can guarantee perfect security. If Plaum becomes aware of a reportable security incident, Plaum will investigate and provide notices required by applicable law, including applicable regulator or user notification timelines.

10Cookies and similar tools

10.1 Mobile app

The Plaum mobile app generally does not use browser cookies. Instead, it may use secure local storage, app session state, analytics SDKs, cached data, and notification tokens needed to run the product.

10.2 Website and restaurant web tools

Plaum's website and restaurant web experiences may use cookies, local storage, session storage, or similar technologies for sign-in, security, session continuity, performance, and basic analytics. Plaum does not currently describe the site as relying on third-party ad-tech cookies.

11Changes to this policy

Plaum may update this Privacy Policy as the product changes, as laws evolve, or as Plaum's data practices mature. When Plaum makes a material update, Plaum will revise the date at the top of this page and may also provide additional notice inside the app, by email, or through another reasonable channel when required by law.

12Contact information

For privacy questions, access requests, deletion requests, or other data concerns, contact Plaum at admin@plaum.co.

Plaum Inc.
Ontario, Canada

Plaum logo Plaum
Home Story Privacy Policy Terms of Service
© 2026 Plaum Inc. All rights reserved. Food discovery for diners and restaurants