GrubSwipe

Privacy Policy

Last updated 25 September 2026

GrubSwipe (“we”, “us”) helps you decide where to eat in Singapore. This policy explains what personal data we collect, why, and the choices you have. We handle personal data in line with Singapore’s Personal Data Protection Act 2012 (PDPA).

What we collect

If you use GrubSwipe without an account, we don’t ask who you are. We process:

  • Your quiz answers and search location. If you choose “near me”, your browser shares your approximate coordinates, only after you allow it. We use them to find nearby places for that search and don’t store them against you.
  • Your IP address. We use it briefly to rate-limit requests and protect the service from abuse.

If you sign in, we also store:

  • Your email address, used to send sign-in codes and identify your account.
  • Places you save, collections you create, and your past quiz sessions (including the search location you used), so you can come back to them.
  • Feedback you send us, along with your browser’s user-agent to help us reproduce bugs.
  • Your plan (Free or Plus) and, if you subscribe, a Stripe customer reference.

Payments. Card details go straight to Stripe. We never see or store your full card number.

How we use it

  • To run the app: search for places, rank your matches, and keep your saves and history.
  • To sign you in and manage your subscription.
  • To prevent abuse and keep the service reliable.
  • To understand usage in aggregate and improve the product.
  • To reply to feedback you send us.

We don’t sell your personal data, and we don’t use it for advertising.

Analytics

We use Vercel Web Analytics to count page views and a handful of in-app events (for example, “finished the quiz”). It doesn’t use cookies and doesn’t build a profile of you. It reports aggregate counts, not individuals.

Cookies and browser storage

We use only what’s strictly needed to run the app. If you sign in, we set a login cookie to keep you signed in. We also keep a few items in your browser’s local storage, such as your guest search count, which places you’ve already been shown, and dismissed prompts, so the app works smoothly. We don’t use advertising or tracking cookies, so there’s nothing to opt in or out of. If you install GrubSwipe as an app, it caches public pages for offline use. It doesn’t cache your account pages.

Who we share it with

We use trusted service providers, each only for the job below:

  • Supabase — account sign-in and database.
  • Stripe — subscription payments.
  • Google Maps Platform (Places API) — restaurant search and photos. Our server sends the search location and preferences. Your IP address and account aren’t sent.
  • Vercel — hosting and aggregate analytics.
  • Upstash — short-lived rate-limit counters.
  • Our email delivery provider — to send sign-in codes.

Some of these providers store data outside Singapore. Where they do, we rely on their contractual commitments to protect it to a standard comparable to the PDPA. We may also disclose data if the law requires it.

How long we keep it

We keep account data (email, saves, collections, history and feedback) while your account exists. When you delete your account, we delete it all. Rate-limit counters expire within a day. Stripe keeps payment records for as long as financial regulations require.

Your choices and rights

  • You can use GrubSwipe without an account, and without sharing your location. Just pick an area instead.
  • You can ask to see, correct or delete the personal data we hold about you, or withdraw your consent to our using it.
  • To delete your account and everything attached to it, email us from the address you signed in with.

Email hello@grubswipe.app and we’ll respond within 30 days.

Children

GrubSwipe isn’t directed at children under 13, and we don’t knowingly collect their personal data.

Changes

If we change this policy, we’ll update the date at the top. If a change is significant, we’ll tell signed-in users in the app or by email.

Contact

Questions or requests about your data: hello@grubswipe.app.