Legal

Privacy Policy

We value your privacy. This policy explains what data we collect, how we use it, and the choices you have regarding your personal information.

Last updated: May 2026

1. Introduction

Food Trail (“we”, “us”, or “our”) is a restaurant and eatery discovery platform based in Rwanda. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our website at foodtrail.rw (the “Platform”).

By registering an account or using any feature of the Platform, you agree to the practices described in this policy. If you do not agree, please do not create an account or submit any personal information through the Platform.


2. Information We Collect

We collect the following categories of information:

Account Information

First name and last name

Email address

Password (stored in encrypted/hashed form — never stored as plain text)

Timestamp of when you accepted our Terms & Conditions and Privacy Policy

Profile Information (optional)

Phone number (if provided)

Profile avatar / photo (if uploaded)

User-Generated Content

Review text (written by you about eateries)

Review photos (images you upload with reviews)

Star ratings and recommendation preferences

Reactions you give to other users' reviews (e.g., helpful, thanks, love)

Contact Form Submissions

When you use our contact form, we collect your name, email address, and message content. These are delivered to our team via email and are not permanently stored in our database.

Technical Data

Session authentication cookies (httpOnly, Secure) used to keep you logged in

IP address and request metadata collected by our infrastructure provider (Supabase)


3. How We Use Your Information

To create and manage your account and authenticate your identity

To allow you to write reviews, upload photos, and interact with other users' content

To display your public profile information (first name, last initial, avatar) alongside your reviews

To respond to messages submitted through our contact form

To maintain the security and integrity of the Platform

To comply with legal obligations


4. What's Publicly Visible

When you post a review, certain information becomes visible to all visitors of the Platform — including people who are not logged in:

Your review text and photos

Your star rating and recommendation preference

Your first name and last name initial (e.g., "Junior H.")

Your avatar/profile photo (if you have set one)

Your total number of reviews

Your full last name, email address, phone number, and reaction history are never shown publicly.


5. Third-Party Services

Food Trail uses the following third-party services. By using the Platform, you acknowledge that your data may be processed by these providers in accordance with their own privacy policies.

Supabase

Database storage, user authentication, and file storage (profile photos, review photos). Supabase hosts our data and infrastructure. Visit supabase.com for their privacy policy.

Google Places API

Used server-side to validate eatery location URLs. No personal user data is sent to Google through this integration.

Anthropic / Claude AI

Used server-side to generate eatery descriptions from structured listing data. No personal user data is included in these requests.

Gmail / Resend

Used to deliver contact form messages to our team. Your name and email address are included in these emails.


6. Cookies

We use a single type of cookie on Food Trail:

Session Authentication Cookie

An httpOnly, Secure cookie is set when you log in. It stores your session token and is required to keep you authenticated while you browse the Platform. This cookie is automatically removed when you log out or when your session expires.

We do not use tracking cookies, advertising cookies, or third-party analytics cookies. We do not track your browsing behavior across other websites.


7. Data Storage & Security

All data is stored on Supabase-hosted infrastructure with industry-standard security measures

Passwords are never stored in plain text — they are encrypted using strong hashing algorithms managed by Supabase Auth

Database tables are protected by Row-Level Security (RLS) policies, ensuring users can only access data they are authorized to view or modify

Session cookies are marked httpOnly and Secure, preventing access from client-side JavaScript and requiring HTTPS

File uploads (photos) are stored in access-controlled Supabase Storage buckets


8. Data Retention

We retain your personal data for as long as your account is active or as needed to provide you with the Platform's services.

Account data (name, email, profile) is retained until you request account deletion

Reviews and photos you have posted are retained as part of the Platform's content unless you delete them or request their removal

Contact form submissions are delivered by email and are not stored permanently in our database

Session cookies expire automatically upon logout or session timeout


9. Your Rights

You have the following rights regarding your personal data:

Access — You may request a copy of the personal data we hold about you

Correction — You may update your name, phone number, and avatar at any time from your profile settings

Deletion — You may request deletion of your account and associated personal data

Portability — You may request your data in a readable format

To exercise any of these rights, please contact us at contact.foodtrail@gmail.com or use our Contact page. We will respond within a reasonable timeframe.


10. Deleting Your Data

You have the right to request the permanent deletion of your account and all personal data associated with it. Upon deletion, your profile, account credentials, reviews, photos, and any other data linked to your identity will be irreversibly removed from our systems.

To request deletion, please contact us at contact.foodtrail@gmail.com or use our Contact page. We will process your request and confirm deletion within a reasonable timeframe.

Coming soon: In a future update, you will be able to delete your own account directly from your profile settings page within the Platform, without needing to contact us.


11. Children's Privacy

Food Trail is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us immediately at contact.foodtrail@gmail.com and we will take steps to remove that information.


12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date at the top of this page. We encourage you to review this policy periodically. Continued use of the Platform after any changes constitutes your acceptance of the updated policy.


13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please reach out to us at contact.foodtrail@gmail.com or visit our Contact page.