1Overview and scope
1.1 Who we are
Plaum Inc. ("Plaum," "we," "us," or "our") operates a two-sided food discovery platform for diners and restaurants. On the diner side, Plaum helps people discover dishes, restaurants, and recommendations from creators, friends, and their city. On the restaurant side, Plaum provides tools across the mobile app and the restaurant-only Plaum Web App for menus, ordering, reservations, customer support, staff operations, managed websites, analytics, and related workflows.
1.2 What this policy covers
This policy applies to personal information processed through:
- The Plaum mobile app for consumer and restaurant users
- The restaurant-only Plaum Web App, including dashboards, kitchen tools, reservations workflows, support tools, and admin features
- Plaum Managed Websites, public restaurant pages, Plaum-hosted subdomains, and custom domains published through Plaum
- The Plaum website, waitlist, and legal pages
- Support, feedback, email, and other communications with Plaum
- Backend systems, APIs, data stores, analytics, and infrastructure that power these services
1.3 Your relationship with Plaum
For most of the data practices described here, Plaum acts as the data controller or business responsible for deciding why and how information is used. Our cloud, payment, analytics, email, and infrastructure vendors generally act as service providers, processors, or sub-processors on our behalf, subject to contract and applicable law.
1.4 By using Plaum
By using Plaum, you acknowledge that you have read this Privacy Policy and understand how your information is handled. If you do not agree, do not use Plaum.
2Information we collect
2.1 Account, identity, and profile information
When you create or manage a Plaum account, we may collect:
- Email address
- Password hash and authentication metadata if you sign up directly with Plaum
- Google or Apple sign-in identifiers if you use those login methods
- First name, last name, username, display name, bio, and avatar
- Account type, such as diner, restaurant, or both
- Email verification, password reset, and account recovery activity
- Profile visibility or notification settings you choose in the app
2.2 Taste, onboarding, and personalization information
To personalize discovery, Plaum may collect information you provide during onboarding or later in settings, including:
- Preferred cuisines
- Dietary tags or restrictions
- Quiz answers and food personality responses
- Whether to include drinks in suggestions
- Saved dishes, saved restaurants, follows, likes, comments, and other preference signals
- Palate Twin, missions, badges, shared boards, and similar participation history where those features are used
2.3 Restaurant business, Plaum Web App, and operations information
If you use Plaum for a restaurant, whether through the mobile app or the Plaum Web App, Plaum may collect business and operational information such as:
- Restaurant name, address, contact details, website, hours, cuisine, and profile information
- Menu items, dish names, pricing, modifiers, add-ons, tags, descriptions, and availability settings
- Claim or verification details, including contact name, optional phone number, and optional business proof
- Order settings, dine-in QR settings, payment options, tips settings, and reservation settings
- Reservation rules such as seating windows, deposits, cancellation policies, party limits, and blackout dates
- Staff invites, staff account details, roles, permissions, linked restaurant access, and admin actions
- Kitchen-board activity such as order claims, order status changes, chat or edit activity, cancellation reasons, queue state, and operational event history
- Reservation actions such as approval, decline, no-show handling, table assignment, and reservation-message history
- Support workspace activity, support chat history, ticket escalations, and related case notes
- Plaum Managed Websites configuration such as theme choices, visible sections, copy, media, draft and publish state, subdomain selection, custom-domain configuration, and verification status
- Restaurant-side notification, audio alert, dashboard layout, and similar operational preferences stored for product functionality
- Analytics summaries, reporting views, and other product-usage records tied to the restaurant account
- POS connection status and sync data if the restaurant enables integrations such as Square or Toast
- Restaurant-authored posts, portfolio content, and other discovery-facing materials
2.4 Content, messages, support, and feedback
When you interact socially or contact us, Plaum may collect:
- Photos, videos, captions, restaurant tags, dish tags, and visibility settings for posts
- Comments, replies, likes, saves, follows, shares, reports, and blocks
- Direct messages, message attachments, and shared content links
- Support tickets, support chat messages, screenshots, attachments, and dispute materials
- Feedback submissions about a place, dish, order, or data accuracy
2.5 Orders, reservations, payments, and transaction records
When you place an order, manage an order, or make a reservation, Plaum may collect:
- Cart contents, modifiers, quantity, special instructions, and fulfillment method
- Order status history, order chat, order edit proposals, cancellation events, reviews, and tips
- Guest order identifiers or guest reservation details when those flows are used without a full account, including public restaurant websites published through Plaum
- Reservation details such as party size, reservation time, special requests, deposit acknowledgements, cancellation data, or no-show disputes
- Saved payment method tokens, Stripe customer references, payment intent references, subscription references, and payout status information
- Billing and reconciliation records needed for accounting, fraud prevention, taxes, disputes, and support
2.6 Location, device permissions, and media access
Plaum may request or receive the following device-level data and permissions:
- Foreground location: to show nearby discovery, maps, restaurant distance, local search, and location-aware Plaum AI suggestions
- Camera access: for QR scanning and, if you choose, capturing content to post
- Photo library access: for selecting and uploading profile or post media
- Microphone or speech recognition access: if you choose to use voice-based Plaum AI interactions or supported voice tools
- Push notification token: to deliver order, social, restaurant, and account notifications
- Browser notification permission: if you enable supported restaurant web alerts, browser notifications, or related web-push features
Plaum uses these permissions only for Plaum features you enable or actively use. You can also control most of these permissions at the operating-system level.
As of July 20, 2026, Plaum does not use background location permissions, geofencing, or visit-tracking features. If that changes in the future, Plaum will update this policy before using that data.
2.7 Technical, analytics, and diagnostic information
Plaum automatically collects certain technical information to operate, secure, and improve the service, including:
- Device type, operating system, app version, locale, and session data
- Approximate IP-based network information and security logs
- Feature usage events, page or screen views, interaction events, purchase-history signals, and aggregated analytics, including data collected through Firebase Analytics
- Crash reports, error logs, performance diagnostics, and user-linked reliability data, including data collected through Firebase Crashlytics on mobile and Sentry on the Plaum Web App when configured
- Notification preferences and token registration activity
- Browser-notification state, service-worker or install-state data, and web-push subscription metadata where those web features are enabled
- Browser, session, and device-state information used by the Plaum Web App for sign-in persistence, security, dashboard state, and feature continuity
Plaum tries to keep analytics proportional to the product need. Plaum uses analytics, user IDs, product-interaction records, transaction-related signals, and diagnostics for app functionality, personalization, reliability, and service improvement rather than third-party ad-tech profiling.
2.8 Plaum AI interaction data
If you use Plaum AI, Plaum may process text prompts, voice-to-text transcripts, AI responses, timestamps, and related context needed to answer your request. Depending on the task, that context may include your taste preferences, approximate or precise location context, restaurant or dish references, current cart context, or recent activity relevant to the request.
Plaum may store limited Plaum AI conversation memory inside your account so the feature can carry context across turns. Plaum also logs actions you ask Plaum AI to perform, such as adding an item to your cart or navigating you to a restaurant or dish.
2.9 Information from third parties and integrations
Plaum may also receive information from:
- Google or Apple when you use their sign-in products
- Restaurants or restaurant staff who manage listings, menus, hours, and service settings
- POS systems enabled by a restaurant, such as Square or Toast
- Payment providers such as Stripe, including payment success or failure, customer references, and connected-account status
3How we use information
Plaum uses personal information for the following business and operational purposes:
3.1 To provide Plaum's core services
- Create and secure accounts
- Show discovery feeds, restaurant profiles, menus, maps, and dish pages
- Publish posts, comments, messages, and restaurant content
- Process orders, reservations, refunds, tips, support cases, and payouts
- Operate restaurant dashboards, kitchen tools, ordering flows, reservation tools, support workspaces, managed websites, and analytics
3.2 To personalize the Plaum experience
- Rank feeds and recommendations
- Match users with relevant dishes, places, or people
- Power Plaum AI suggestions and actions
- Highlight local, timely, or personally relevant restaurants and dishes
3.3 To keep the platform safe and reliable
- Detect spam, fraud, abuse, account misuse, or harmful content
- Investigate reports, disputes, and suspicious transactions
- Moderate content and protect the security of Plaum users, restaurants, and systems
- Debug crashes, monitor performance, and improve service stability
3.4 To communicate with you
- Send transactional messages such as verification emails, password resets, receipts, reservation updates, order updates, or support responses
- Send product notices, legal updates, and security alerts
- Send marketing or launch communications where allowed by law and where your settings or consent support them
3.5 To comply with law and platform obligations
- Maintain accounting, tax, and audit records
- Respond to legal requests and enforce our terms
- Support accessibility, privacy, and consumer-protection obligations
3.6 Automated systems and human review
Plaum uses automated systems to help rank content, recommend restaurants or dishes, match users, moderate content, and detect fraud or misuse. These systems support the product experience, but Plaum may also use human review for support, moderation, legal compliance, fraud investigations, safety escalations, and product quality checks.
3.7 Legal bases for EEA, UK, and similar jurisdictions
Where GDPR, UK GDPR, or similar laws apply, Plaum generally relies on one or more of the following legal bases:
- Contract: to create accounts, provide discovery features, process orders and reservations, operate the Plaum Web App, and deliver support you request
- Legitimate interests: to secure Plaum, prevent fraud, improve the product, analyze usage, moderate content, and keep restaurant operations running reliably
- Consent: for permissions such as location, camera, microphone, certain notifications, and marketing where consent is required by law
- Legal obligation: to keep records, respond to valid legal requests, comply with tax and accounting rules, and meet consumer-protection or privacy obligations
4How we share information
4.1 Information visible inside Plaum
Some information is meant to be visible to other users or restaurants depending on the feature and your settings. For example:
- Your username, profile, avatar, and public posts may be visible to other Plaum users
- Restaurant pages, menus, restaurant-authored posts, and operating details may be visible to diners
- Restaurant public websites, subdomains, custom domains, menu pages, reservation entry points, and similar managed-website content may be visible to the public
- Order and reservation details are shared with the restaurant involved in that order or reservation
- Messages and shared-board activity are visible to the participants in those features
4.2 Service providers, processors, and integrations
Plaum may disclose personal information to vendors and infrastructure providers that help us run the service.
| Provider | Purpose | Examples of data involved |
|---|---|---|
| Stripe | Payment processing, saved payment method support, subscriptions, and restaurant payouts | Payment references, customer IDs, connected-account status, transaction amounts, and payout metadata |
| Supabase | Authentication and application data infrastructure | Account credentials, user profile data, relational records, and session-related application data |
| Amazon Web Services (AWS) | Infrastructure, media storage and delivery, AI processing, and content-processing support | Uploaded media, AI requests and responses, app infrastructure logs, and related service metadata |
| Neo4j | Graph relationships, recommendation logic, and matching features | Relationship and discovery graph data tied to users, restaurants, dishes, and interactions |
| Google Firebase Analytics and Firebase Crashlytics | Mobile analytics, app measurement, crash diagnostics, and reliability monitoring | App usage events, screen views, crash reports, device-level diagnostics, performance signals, and notification-related metadata |
| Sentry | Web-app error monitoring, request-error capture, and performance diagnostics for the Plaum Web App and related public web flows when enabled | Error reports, request metadata, stack traces, route context, and related technical diagnostics |
| Google and Apple | Sign-in, device-level services, maps, speech, and operating-system features where used | OAuth identifiers, device permission flows, speech transcripts handled by the device platform, and maps-related context |
| Resend | Transactional email delivery | Email address, message metadata, and email content necessary to deliver account and service emails |
| Square or Toast | Restaurant POS sync when enabled by a restaurant | Menu, order, inventory, or operational sync data determined by the restaurant's integration settings |
4.3 Legal, safety, and business disclosures
Plaum may also disclose information:
- To comply with a valid legal request, court order, subpoena, or regulatory obligation
- To protect the rights, safety, property, users, staff, or systems of Plaum or others
- As part of a merger, financing, acquisition, restructuring, or asset sale, subject to appropriate confidentiality and legal safeguards
4.4 No sale of personal information
Plaum does not sell personal information as that term is commonly used in privacy laws. Plaum also does not share personal information for cross-context behavioral advertising.
5Data retention
5.1 General retention approach
Plaum keeps personal information only for as long as it is reasonably needed for the purposes described in this policy, including service delivery, account management, safety, support, legal compliance, fraud prevention, tax and accounting records, and dispute resolution.
5.2 Account deletion and the 30-day grace period
If you request account deletion, Plaum may place your account into a deletion workflow that includes a 30-day grace period. During that window, Plaum may retain enough information to allow cancellation of the request, to prevent fraud, and to finish pending obligations. Where Plaum offers an immediate deletion option for eligible data, you may choose that option instead.
After the applicable deletion period ends, Plaum deletes or de-identifies personal information unless we are required or permitted to keep certain records longer for legal, accounting, security, or dispute reasons.
5.3 Transaction, reservation, and support records
Order records, reservation records, payout records, refunds, disputes, charge issues, support records, Plaum Web App operational logs, and related communications may be retained longer than ordinary profile data because they can be needed for tax, financial reporting, fraud prevention, consumer protection, legal compliance, or ongoing support.
5.4 Plaum AI history
Plaum AI uses limited conversation memory to make the feature useful across nearby interactions. Plaum may prune older Plaum AI memory and keep only a limited recent history in active use. You may also clear Plaum AI history from the product controls when that control is available to you.
5.5 Backups and system logs
Backup copies and infrastructure logs may persist for a limited period after live records are deleted. Plaum keeps these copies only for continuity, recovery, security, and audit purposes and then rotates or deletes them in the ordinary course.
6Your rights and choices
6.1 In-app and device controls
You can control many privacy settings directly through Plaum or your device, including:
- Profile edits, avatar changes, and certain visibility settings
- Notification preferences
- Location permission settings at the device level
- Plaum AI history clearing where that feature is available
- Some Plaum Web App or browser preferences such as theme, session continuity, or dashboard layout controls
- Content deletion for posts, comments, or messages you control
6.2 Access, correction, deletion, portability, and objection
Depending on where you live, you may have rights to request access to your personal information, ask for correction of inaccurate information, request deletion, request a portable copy, restrict certain processing, or object to certain uses.
6.3 Rights for EEA, UK, and similar jurisdictions
Where GDPR, UK GDPR, or similar laws apply, you may have rights such as:
- Access
- Rectification
- Erasure
- Restriction of processing
- Data portability
- Objection to certain processing
- Withdrawal of consent for consent-based processing
- Complaint to your local supervisory authority
6.4 Rights for California residents
Where the California Consumer Privacy Act or California Privacy Rights Act applies, California residents may have rights to:
- Know what categories of personal information Plaum collects, uses, discloses, or retains
- Request deletion of personal information, subject to legal exceptions
- Request correction of inaccurate personal information
- Request a portable copy of certain information
- Request information about sensitive personal information and, where applicable, request limits on certain uses of it
- Opt out of sale or sharing if a business engages in those activities
- Not be discriminated against for exercising privacy rights
Plaum does not sell personal information and does not share personal information for cross-context behavioral advertising as those concepts are commonly used in California privacy law.
6.5 Rights for Canadian users
Where PIPEDA or similar Canadian privacy laws apply, you may request access to personal information Plaum holds about you, ask for corrections, and withdraw consent for certain uses where consent is the legal basis and no overriding legal restriction applies.
6.6 Email and communication choices
You may unsubscribe from marketing emails using the unsubscribe link in the message. Plaum will still send transactional or service-critical messages when needed for your account, orders, reservations, security, or legal compliance. Plaum intends marketing communications to respect applicable anti-spam rules, including CAN-SPAM and CASL.
6.7 How to exercise your rights
Email admin@plaum.co with enough detail for us to understand your request and verify your identity.
If you are invoking a region-specific right, it helps to use a subject line such as GDPR Request, CCPA Request, or PIPEDA Request.
Plaum may ask for identity verification before fulfilling a request. Plaum will respond within the time required by applicable law, which may be around 30 days in some jurisdictions and up to 45 days in others depending on the request and local law.
7International transfers
Plaum is based in Ontario, Canada, and Plaum's infrastructure and service providers may process information in Canada, the United States, or other countries where Plaum or its providers operate.
When information is transferred across borders, Plaum relies on lawful transfer mechanisms appropriate to the jurisdiction and the transfer, such as contractual safeguards, data-processing agreements, and where relevant, Standard Contractual Clauses or similar protections.
8Children's privacy
Plaum is a general-audience service designed for users age 13 and older. Plaum is not intended for children under 13, and Plaum does not knowingly collect personal information from children under 13. If Plaum learns that a child under 13 has provided personal information without appropriate permission, Plaum will take steps to delete that information.
Users between 13 and 17 should use Plaum only with any consent required by their parent, guardian, or local law.
9Security
Plaum uses technical, organizational, and contractual safeguards designed to protect personal information, including:
- Encryption in transit for communications between apps, browsers, and Plaum services
- Role-based access controls and internal access limitations
- Secure token or credential storage patterns appropriate to the platform
- Cloud security controls, logging, monitoring, and incident investigation
- Payment separation so raw card credentials are handled by payment providers instead of Plaum systems
No service can guarantee perfect security. If Plaum becomes aware of a reportable security incident, Plaum will investigate and provide notices required by applicable law, including applicable regulator or user notification timelines.
10Cookies and similar tools
10.1 Mobile app
The Plaum mobile app generally does not use browser cookies. Instead, it may use secure local storage, app session state, analytics SDKs, cached data, and notification tokens needed to run the product.
10.2 Website and restaurant web tools
Plaum's website and restaurant web experiences may use cookies, local storage, session storage, service workers, and similar technologies for sign-in, security, session continuity, locale preferences, dashboard state, builder continuity, install prompts, performance, browser notifications, and basic analytics. These tools may remember things like auth state, invite flow state, theme or layout choices, notification dismissals, install-banner state, and other settings needed to make the Plaum Web App work reliably. Plaum does not currently describe the site as relying on third-party ad-tech cookies.
11Changes to this policy
Plaum may update this Privacy Policy as the product changes, as laws evolve, or as Plaum's data practices mature. When Plaum makes a material update, Plaum will revise the date at the top of this page and may also provide additional notice inside the app, by email, or through another reasonable channel when required by law.
12Contact information
For privacy questions, access requests, deletion requests, or other data concerns, contact Plaum at admin@plaum.co.
Plaum Inc.
Ontario, Canada