Privacy Policy
Effective date: 5th of August 2026
Introduction
PRANA KITCHEN PROJECT, LLC (“Company,” “we,” “us,” or “our”) operates the Prana Kitchen mobile application and related services (collectively, the “App” or the “Services”), which allow users in and around Miami, Florida to browse menus, place food orders, redeem promotions, and communicate with our customer support team.
By downloading, accessing, or using the App, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the App.
Scope
This Privacy Policy applies to personal information we collect through:
- the App (iOS and Android versions);
- our website, to the extent it links to or supports the App;
- customer support interactions conducted by phone, email, or in-app chat; and
- offline interactions directly connected to the App, such as in-restaurant pickup of an App order.
This Policy does not apply to third-party websites, applications, or services that we do not own or control, even if accessed through a link in the App. It also does not apply to information collected by our restaurant locations outside the context of the App (e.g., a paper comment card), which may be governed by separate notices.
Information We Collect
We collect the categories of personal information described in the table below, which include, in summary:
| Category of Personal Data | Examples of Data Collected | Purpose of Processing |
|---|---|---|
| Identification data | Full name, date of birth (if collected for age-restricted promotions) | Account creation |
| Contact information | Email, phone number, delivery/billing address | Order & reservation confirmations, customer service |
| Account credentials | Username, hashed/salted password, social-login tokens | Authentication, account security |
| Order history | Items ordered, order value, timestamps | Fulfillment, personalization, product improvement |
| Payment information | Cardholder name, billing address, last 4 digits/card type, transaction ID | Payment processing, fraud prevention, refunds |
| Device information | Device type/model, OS/version, app version, language | App functionality, diagnostics, security, analytics |
| IP address | IP address, approximate geolocation from IP, ISP | Security, fraud prevention, localization, analytics |
| Cookies and similar technologies | Session/persistent cookies, SDK identifiers, local storage | Session management, analytics |
| Geolocation | Precise or approximate device location (only when enabled) | To identify delivery address |
| Marketing preferences | Opt-in/opt-out status, communication preferences, campaign engagement | Sending promotions, measuring effectiveness, honoring opt-outs |
| Customer support communications | Chat transcripts, support emails, call notes | Resolving inquiries/complaints |
| User-generated content | Reviews, ratings, photos submitted with reviews, comments | Displaying feedback, service improvement, moderation |
| Analytics data | Navigation paths, feature usage, session duration, screen views (typically pseudonymized) | Product improvement, usage measurement |
| Crash logs | Stack traces, device state at crash, OS/app version | Diagnosing and fixing software defects |
| Fraud prevention information | Transaction risk scores, device fingerprinting signals, velocity flags, chargeback history | Preventing fraudulent orders/payments, account takeover prevention, chargeback defense |
We do not knowingly collect government identification numbers, biometric identifiers, or precise health information through the App. If this changes, we will update this Policy and, where required, obtain your consent beforehand.
How We Collect Information
We collect information:
- Directly from you, when you create an account, place an order, make a reservation, enter a promo code, contact customer support, submit a review, or otherwise interact with the App.
- Automatically, through your use of the App, via cookies, software development kits (“SDKs”), and similar technologies, including device information, IP address, analytics, and crash data.
- From third parties, such as our payment processor (limited transaction confirmation data, not full card numbers); social login providers, if you register using a third-party account (e.g., Sign in with Apple/Google), which may share your name and email per your permissions; delivery or logistics partners, regarding order fulfillment status; and analytics, crash-reporting, and advertising technology partners, as described in this Privacy Policy.
Legal Bases for Processing (Where Applicable)
| Category of Personal Data | Legal Basis | Mandatory / Optional |
|---|---|---|
| Identification data | Contract performance; legitimate interest; consent (optional fields) | Mandatory for accounts ; optional otherwise |
| Contact information | Contract performance; consent (marketing); legitimate interest | Mandatory for accounts/orders/reservations; marketing optional |
| Account credentials | Contract performance | Mandatory for registered accounts |
| Order history | Contract performance; legitimate interest | Mandatory to complete an order |
| Payment information | Contract performance; legal obligation (fraud/AML where applicable) | Mandatory to complete a paid transaction |
| Device information | Legitimate interest; consent where required | Automatic; advertising identifiers optional/consent-based |
| IP address | Legitimate interest | Automatic; inherent to network use |
| Cookies and similar technologies | Consent (non-essential); legitimate interest (necessary) | Necessary cookies mandatory; analytics/advertising optional |
| Geolocation | Consent | Optional — disabled unless permission granted |
| Marketing preferences | Consent | Optional |
| Customer support communications | Contract performance; legitimate interest | Mandatory only if support is initiated by the user |
| User-generated content | Consent; legitimate interest | Optional |
| Analytics data | Legitimate interest; consent where required | Automatic; limitable via device-level tracking controls |
| Crash logs | Legitimate interest | Automatic upon crash |
| Fraud prevention information | Legitimate interest; legal obligation (payment-network contexts) | Automatic in connection with transactions |
- Contract performance: processing necessary to create your account, fulfill an order or reservation, or provide customer support you requested.
- Consent: processing based on your affirmative opt-in, such as marketing communications, geolocation access, or optional profile fields; you may withdraw consent at any time (see Section 20).
- Legitimate business interests: processing for fraud prevention, security, analytics, and service improvement, conducted in a manner that does not override your privacy interests.
- Legal obligation: processing necessary to comply with tax, accounting, or payment-network requirements.
Cookies and Tracking Technologies
Our use of cookies is deliberately limited. We do not set our own session, authentication, or shopping-cart cookies. The categories below describe, precisely, what is set, by whom, and when.
Strictly Necessary (No Consent Required)
Login and cart: Our backend API is stateless. Authentication is handled through a JSON Web Token (“JWT”) sent in the HTTP Authorization header, not through a cookie. Your login token and the contents of your cart are stored locally on your device or browser, in localStorage/sessionStorage, and are never set by us as cookies.
Payments (Stripe): At checkout, our payment processor, Stripe, sets its own cookies directly on its domain for fraud detection and payment security purposes. These cookies are strictly necessary to process your payment safely and are governed by Stripe’s own privacy policy.
Preferences (Functional)
Your selected pickup location and your most recently used delivery address are stored locally in your browser’s local Storage, not in a cookie, and are used only to pre-fill the App the next time you visit. You may clear this information at any time by clearing your browser’s site data.
Analytics (Consent-Based, Off by Default)
Analytics tools are disabled by default. No analytics script loads and no analytics identifier is set until you affirmatively accept analytics through our consent banner (recorded as a prana.consent.analytics preference). Before you provide consent, no analytics data of the kind described below is collected.
Once you have consented, we use:
- First-party identifiers: used to associate usage events sent directly to our own backend (POST /public/events). No third-party cookies are involved in this first-party analytics.
- Google Analytics only where a measurement ID is configured for the relevant property and only after you have consented; consent signal defaults to “denied” until you opt in.
- PostHog: session recording are disabled, and PostHog operates on an opt-out-by-default basis consistent with your consent choice.
You may withdraw analytics consent at any time by adjusting your cookie preferences, which will stop future analytics collection going forward.
Third-Party Cookies Set on Third-Party Domains
Certain embedded third-party services set cookies directly on their own domains, outside our control, when you use the corresponding feature.
What We Do Not Use
We do not use advertising-network cookies, cross-site or cross-app tracking cookies, or mobile advertising identifiers for third-party tracking purposes. We do not use cookies or similar technologies to sell personal information, and we do not permit any of the providers listed above to use data collected via these technologies for their own advertising purposes.
You may control non-essential cookies and analytics through our consent banner or cookie preference tool, and through your browser settings. Blocking or clearing strictly necessary items may prevent core App features such as login, cart persistence, or checkout from functioning correctly.
Push Notifications
If you enable push notifications, we may send you order status updates, reservation reminders, loyalty program updates, and promotional offers. You may disable push notifications at any time through your device’s operating system settings without affecting your ability to use the App generally, though you may miss time-sensitive order or reservation updates.
Location Services
Geolocation is an optional feature. We only access your device’s precise or approximate location if you grant permission through your device’s operating system. You may revoke this permission at any time in your device settings, and doing so will not prevent you from using the core ordering and reservation features of the App, though location-based recommendations will no longer be available.
Payments
Payments made through the App are processed by one or more third-party, PCI-DSS-compliant payment processors (“Payment Processor(s)”). When you enter payment card information:
- Full card numbers, CVV codes, and similar sensitive payment data are transmitted directly to and stored by the Payment Processor, not by Prana Kitchen Project LLC;
- We receive only limited transaction metadata from the Payment Processor, such as a transaction ID, the last four digits of your card, card type, and authorization/decline status, which we use for order confirmation, receipts, refunds, and fraud prevention;
- Your use of the Payment Processor’s services is also subject to that Payment Processor’s own privacy policy and terms, which we encourage you to review; and
- The Company is not responsible for the independent privacy or security practices of the Payment Processor, although we select processors that maintain industry-standard security certifications.
Sharing of Personal Information
We do not sell your personal information for money. We may share personal information as follows:
With Service Providers who process data on our behalf and under contractual confidentiality and security obligations, such as our payment processor, cloud hosting provider, analytics and crash-reporting vendors, customer support platform, email/SMS/push notification vendors, and delivery/logistics partners.
With restaurant staff and point-of-sale systems to the extent necessary to prepare and fulfill your order.
For legal reasons, where we believe disclosure is necessary to (i) comply with a law, regulation, subpoena, or governmental request; (ii) enforce our Terms of Service; (iii) protect the rights, property, or safety of the Company, our users, or the public; or (iv) detect, prevent, or address fraud or security issues.
With your consent, for any other purpose we disclose to you at the time of collection.
International Transfers
Our Services are intended for users located in the United States, and our servers and service providers are assumed to be based in the United States ъ. If any service provider processes data outside the United States, we require contractual safeguards consistent with applicable law. If you access the App from outside the United States, you understand that your information will be transferred to and processed in the United States, where privacy laws may differ from those of your home jurisdiction.
Data Retention
We retain personal information only for as long as reasonably necessary to fulfill the purposes described in this Policy.
| Category of Personal Data | Retention Period |
|---|---|
| Identification data | Account duration + 7 years after closure |
| Contact information | Account duration + 3–7 years (tax/accounting) |
| Account credentials | Account duration + 90 days post-deletion (security logs) |
| Order history | 3–7 years (tax/accounting); anonymized data may be retained longer |
| Payment information | Transaction metadata: 7 years; full card data retained solely by processor |
| Device information | 24 months (crash/analytics), then aggregated |
| IP address | 12 months identifiable, then anonymized/deleted |
| Cookies and similar technologies | Session to 12 months, per cookie table |
| Geolocation | Session only, unless a saved address is created |
| Marketing preferences | Until opt-out + 24 months (suppression compliance) |
| Customer support communications | 2 years after ticket closure |
| User-generated content | Until deleted by user or account closure; moderation records 1 year |
| Analytics data | 24 months, then aggregated |
| Crash logs | 12 months |
| Fraud prevention information | 3–7 years, consistent with payment-network/tax requirements |
Where we no longer have a legitimate business or legal need to retain personal information in identifiable form, we will delete it, de-identify it, or aggregate it.
Data Security
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, or destruction, consistent with requirement that businesses maintain reasonable security measures. These safeguards include, as applicable: encryption of data in transit (e.g., TLS), access controls limiting employee access on a need-to-know basis, and contractual security obligations imposed on our service providers.
No method of transmission or storage is completely secure. In the event of a data breach affecting personal information, we will notify affected individuals and applicable regulators in accordance with applicable legislation.
Consumer Privacy Rights
Florida Residents
Under the Florida Digital Bill of Rights (applicable to certain “controllers” meeting statutory thresholds) and, more broadly, as a matter of Company policy extended to all Florida users, you may have the right to:
- confirm whether we are processing your personal information and access that information;
- correct inaccuracies in your personal information;
- request deletion of personal information you have provided or that we hold about you;
- obtain a portable copy of your personal information in a usable format;
- opt out of the processing of your personal information for purposes of (i) targeted advertising, (ii) the sale of personal information, or (iii) profiling in furtherance of decisions that produce legal or similarly significant effects, to the extent such processing occurs; and
- not be discriminated against for exercising these rights.
To exercise these rights, contact us using the details in Policy. We will verify your identity before processing your request, generally using information already associated with your account (e.g., matching email address).
California Residents (CCPA/CPRA), If Applicable to Our Business
If, and to the extent, the CCPA/CPRA applies to our business, California residents have the right to:
- know/access the categories and specific pieces of personal information we have collected, used, disclosed, or sold/shared about them in the preceding 12 months;
- delete personal information we have collected from them, subject to certain exceptions;
- correct inaccurate personal information;
- opt out of the “sale” or “sharing” of personal information;
- limit the use of sensitive personal information, to the extent we process any sensitive personal information as defined by the CPRA; and
- non-discrimination for exercising any of these rights.
California residents (or their authorized agents) may submit a request using the contact details in Policy. We will verify the request consistent with CCPA/CPRA regulations before responding, and will respond within the statutory timeframe (generally 45 days, extendable by an additional 45 days when reasonably necessary).
We have not sold personal information for monetary consideration in the preceding 12 months. To the precautionary extent any sharing for cross-context behavioral advertising is deemed a “share” under CPRA, you may opt out via the “Do Not Sell or Share My Personal Information” mechanism, or by enabling applicable device-level tracking controls (e.g., declining ATT on iOS).
Marketing Communications
We may send you promotional emails, SMS/text messages, and push notifications about offers, new menu items, and loyalty rewards where you have opted in. You may opt out at any time.
Opting out of marketing communications will not affect transactional messages necessary to service your orders (e.g., order confirmations, receipts).
Children’s Privacy
The App is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13 in a manner inconsistent with COPPA. If we later introduce features directed to children, or if we obtain actual knowledge that a child under 13 has provided personal information without verifiable parental consent, we will take steps to delete such information promptly and, where appropriate, update this Policy to describe any child-directed practices and parental consent mechanisms. If you believe a child under 13 has provided us with personal information, please contact us using the details inPolicy so we can investigate and take appropriate action.
Third-Party Services
The App may contain links to, or integrations with, third-party websites, social media platforms, mapping services, or other applications that we do not own or control. This Privacy Policy does not apply to those third-party services, and we encourage you to review their respective privacy policies before providing any personal information to them.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. If we make material changes, we will notify you by posting a notice within the App, updating the “Last Updated” date above, and, where required by law, seeking your consent before applying such changes to previously collected information. We encourage you to review this Policy periodically.
Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, including to exercise any privacy rights described above, please contact us at:
Company Name: PRANA KITCHEN PROJECT LLC
Business address: 12864 BISCAYNE BLVD 2129 MIAMI, FL 33181
Identification Number: 41-4926992
Email: info@prana.kitchen