[{"data":1,"prerenderedAt":10},["ShallowReactive",2],{"legal:privacy":3},{"slug":4,"title":5,"dateLabel":6,"effectiveDate":7,"description":8,"html":9},"privacy","Privacy Policy","Effective date","5th of August 2026","How Prana Kitchen Project LLC collects, uses, shares and retains personal information in the Prana app and related services.","\u003Ch2 id=\"introduction\">Introduction\u003C\u002Fh2>\n\u003Cp>PRANA KITCHEN PROJECT, LLC (“Company,” “we,” “us,” or “our”) operates the Prana Kitchen mobile application and related services (collectively, the “App” or the “Services”), which allow users in and around Miami, Florida to browse menus, place food orders, redeem promotions, and communicate with our customer support team.\u003C\u002Fp>\n\u003Cp>By downloading, accessing, or using the App, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the App.\u003C\u002Fp>\n\u003Ch2 id=\"scope\">Scope\u003C\u002Fh2>\n\u003Cp>This Privacy Policy applies to personal information we collect through:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>the App (iOS and Android versions);\u003C\u002Fli>\n\u003Cli>our website, to the extent it links to or supports the App;\u003C\u002Fli>\n\u003Cli>customer support interactions conducted by phone, email, or in-app chat; and\u003C\u002Fli>\n\u003Cli>offline interactions directly connected to the App, such as in-restaurant pickup of an App order.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>This Policy does not apply to third-party websites, applications, or services that we do not own or control, even if accessed through a link in the App. It also does not apply to information collected by our restaurant locations outside the context of the App (e.g., a paper comment card), which may be governed by separate notices.\u003C\u002Fp>\n\u003Ch2 id=\"information-we-collect\">Information We Collect\u003C\u002Fh2>\n\u003Cp>We collect the categories of personal information described in the table below, which include, in summary:\u003C\u002Fp>\n\u003Cdiv class=\"table-wrap\">\n\u003Ctable>\n\u003Cthead>\n\u003Ctr>\n\u003Cth>Category of Personal Data\u003C\u002Fth>\n\u003Cth>Examples of Data Collected\u003C\u002Fth>\n\u003Cth>Purpose of Processing\u003C\u002Fth>\n\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\n\u003Ctr>\n\u003Ctd>Identification data\u003C\u002Ftd>\n\u003Ctd>Full name, date of birth (if collected for age-restricted promotions)\u003C\u002Ftd>\n\u003Ctd>Account creation\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Contact information\u003C\u002Ftd>\n\u003Ctd>Email, phone number, delivery\u002Fbilling address\u003C\u002Ftd>\n\u003Ctd>Order &amp; reservation confirmations, customer service\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Account credentials\u003C\u002Ftd>\n\u003Ctd>Username, hashed\u002Fsalted password, social-login tokens\u003C\u002Ftd>\n\u003Ctd>Authentication, account security\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Order history\u003C\u002Ftd>\n\u003Ctd>Items ordered, order value, timestamps\u003C\u002Ftd>\n\u003Ctd>Fulfillment, personalization, product improvement\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Payment information\u003C\u002Ftd>\n\u003Ctd>Cardholder name, billing address, last 4 digits\u002Fcard type, transaction ID\u003C\u002Ftd>\n\u003Ctd>Payment processing, fraud prevention, refunds\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Device information\u003C\u002Ftd>\n\u003Ctd>Device type\u002Fmodel, OS\u002Fversion, app version, language\u003C\u002Ftd>\n\u003Ctd>App functionality, diagnostics, security, analytics\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>IP address\u003C\u002Ftd>\n\u003Ctd>IP address, approximate geolocation from IP, ISP\u003C\u002Ftd>\n\u003Ctd>Security, fraud prevention, localization, analytics\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Cookies and similar technologies\u003C\u002Ftd>\n\u003Ctd>Session\u002Fpersistent cookies, SDK identifiers, local storage\u003C\u002Ftd>\n\u003Ctd>Session management, analytics\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Geolocation\u003C\u002Ftd>\n\u003Ctd>Precise or approximate device location (only when enabled)\u003C\u002Ftd>\n\u003Ctd>To identify delivery address\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Marketing preferences\u003C\u002Ftd>\n\u003Ctd>Opt-in\u002Fopt-out status, communication preferences, campaign engagement\u003C\u002Ftd>\n\u003Ctd>Sending promotions, measuring effectiveness, honoring opt-outs\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Customer support communications\u003C\u002Ftd>\n\u003Ctd>Chat transcripts, support emails, call notes\u003C\u002Ftd>\n\u003Ctd>Resolving inquiries\u002Fcomplaints\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>User-generated content\u003C\u002Ftd>\n\u003Ctd>Reviews, ratings, photos submitted with reviews, comments\u003C\u002Ftd>\n\u003Ctd>Displaying feedback, service improvement, moderation\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Analytics data\u003C\u002Ftd>\n\u003Ctd>Navigation paths, feature usage, session duration, screen views (typically pseudonymized)\u003C\u002Ftd>\n\u003Ctd>Product improvement, usage measurement\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Crash logs\u003C\u002Ftd>\n\u003Ctd>Stack traces, device state at crash, OS\u002Fapp version\u003C\u002Ftd>\n\u003Ctd>Diagnosing and fixing software defects\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Fraud prevention information\u003C\u002Ftd>\n\u003Ctd>Transaction risk scores, device fingerprinting signals, velocity flags, chargeback history\u003C\u002Ftd>\n\u003Ctd>Preventing fraudulent orders\u002Fpayments, account takeover prevention, chargeback defense\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003C\u002Ftbody>\n\u003C\u002Ftable>\n\u003C\u002Fdiv>\n\u003Cp>We do not knowingly collect government identification numbers, biometric identifiers, or precise health information through the App. If this changes, we will update this Policy and, where required, obtain your consent beforehand.\u003C\u002Fp>\n\u003Ch2 id=\"how-we-collect-information\">How We Collect Information\u003C\u002Fh2>\n\u003Cp>We collect information:\u003C\u002Fp>\n\u003Col>\n\u003Cli>Directly from you, when you create an account, place an order, make a reservation, enter a promo code, contact customer support, submit a review, or otherwise interact with the App.\u003C\u002Fli>\n\u003Cli>Automatically, through your use of the App, via cookies, software development kits (“SDKs”), and similar technologies, including device information, IP address, analytics, and crash data.\u003C\u002Fli>\n\u003Cli>From third parties, such as our payment processor (limited transaction confirmation data, not full card numbers); social login providers, if you register using a third-party account (e.g., Sign in with Apple\u002FGoogle), which may share your name and email per your permissions; delivery or logistics partners, regarding order fulfillment status; and analytics, crash-reporting, and advertising technology partners, as described in this Privacy Policy.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch2 id=\"legal-bases-for-processing\">Legal Bases for Processing (Where Applicable)\u003C\u002Fh2>\n\u003Cdiv class=\"table-wrap\">\n\u003Ctable>\n\u003Cthead>\n\u003Ctr>\n\u003Cth>Category of Personal Data\u003C\u002Fth>\n\u003Cth>Legal Basis\u003C\u002Fth>\n\u003Cth>Mandatory \u002F Optional\u003C\u002Fth>\n\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\n\u003Ctr>\n\u003Ctd>Identification data\u003C\u002Ftd>\n\u003Ctd>Contract performance; legitimate interest; consent (optional fields)\u003C\u002Ftd>\n\u003Ctd>Mandatory for accounts ; optional otherwise\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Contact information\u003C\u002Ftd>\n\u003Ctd>Contract performance; consent (marketing); legitimate interest\u003C\u002Ftd>\n\u003Ctd>Mandatory for accounts\u002Forders\u002Freservations; marketing optional\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Account credentials\u003C\u002Ftd>\n\u003Ctd>Contract performance\u003C\u002Ftd>\n\u003Ctd>Mandatory for registered accounts\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Order history\u003C\u002Ftd>\n\u003Ctd>Contract performance; legitimate interest\u003C\u002Ftd>\n\u003Ctd>Mandatory to complete an order\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Payment information\u003C\u002Ftd>\n\u003Ctd>Contract performance; legal obligation (fraud\u002FAML where applicable)\u003C\u002Ftd>\n\u003Ctd>Mandatory to complete a paid transaction\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Device information\u003C\u002Ftd>\n\u003Ctd>Legitimate interest; consent where required\u003C\u002Ftd>\n\u003Ctd>Automatic; advertising identifiers optional\u002Fconsent-based\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>IP address\u003C\u002Ftd>\n\u003Ctd>Legitimate interest\u003C\u002Ftd>\n\u003Ctd>Automatic; inherent to network use\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Cookies and similar technologies\u003C\u002Ftd>\n\u003Ctd>Consent (non-essential); legitimate interest (necessary)\u003C\u002Ftd>\n\u003Ctd>Necessary cookies mandatory; analytics\u002Fadvertising optional\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Geolocation\u003C\u002Ftd>\n\u003Ctd>Consent\u003C\u002Ftd>\n\u003Ctd>Optional — disabled unless permission granted\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Marketing preferences\u003C\u002Ftd>\n\u003Ctd>Consent\u003C\u002Ftd>\n\u003Ctd>Optional\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Customer support communications\u003C\u002Ftd>\n\u003Ctd>Contract performance; legitimate interest\u003C\u002Ftd>\n\u003Ctd>Mandatory only if support is initiated by the user\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>User-generated content\u003C\u002Ftd>\n\u003Ctd>Consent; legitimate interest\u003C\u002Ftd>\n\u003Ctd>Optional\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Analytics data\u003C\u002Ftd>\n\u003Ctd>Legitimate interest; consent where required\u003C\u002Ftd>\n\u003Ctd>Automatic; limitable via device-level tracking controls\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Crash logs\u003C\u002Ftd>\n\u003Ctd>Legitimate interest\u003C\u002Ftd>\n\u003Ctd>Automatic upon crash\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Fraud prevention information\u003C\u002Ftd>\n\u003Ctd>Legitimate interest; legal obligation (payment-network contexts)\u003C\u002Ftd>\n\u003Ctd>Automatic in connection with transactions\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003C\u002Ftbody>\n\u003C\u002Ftable>\n\u003C\u002Fdiv>\n\u003Cul>\n\u003Cli>Contract performance: processing necessary to create your account, fulfill an order or reservation, or provide customer support you requested.\u003C\u002Fli>\n\u003Cli>Consent: processing based on your affirmative opt-in, such as marketing communications, geolocation access, or optional profile fields; you may withdraw consent at any time (see Section 20).\u003C\u002Fli>\n\u003Cli>Legitimate business interests: processing for fraud prevention, security, analytics, and service improvement, conducted in a manner that does not override your privacy interests.\u003C\u002Fli>\n\u003Cli>Legal obligation: processing necessary to comply with tax, accounting, or payment-network requirements.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2 id=\"cookies-and-tracking-technologies\">Cookies and Tracking Technologies\u003C\u002Fh2>\n\u003Cp>Our use of cookies is deliberately limited. We do not set our own session, authentication, or shopping-cart cookies. The categories below describe, precisely, what is set, by whom, and when.\u003C\u002Fp>\n\u003Ch2 id=\"strictly-necessary\">Strictly Necessary (No Consent Required)\u003C\u002Fh2>\n\u003Cp>\u003Cstrong>Login and cart:\u003C\u002Fstrong> Our backend API is stateless. Authentication is handled through a JSON Web Token (“JWT”) sent in the HTTP Authorization header, not through a cookie. Your login token and the contents of your cart are stored locally on your device or browser, in localStorage\u002FsessionStorage, and are never set by us as cookies.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Payments (Stripe):\u003C\u002Fstrong> At checkout, our payment processor, Stripe, sets its own cookies directly on its domain for fraud detection and payment security purposes. These cookies are strictly necessary to process your payment safely and are governed by Stripe’s own privacy policy.\u003C\u002Fp>\n\u003Ch2 id=\"preferences-functional\">Preferences (Functional)\u003C\u002Fh2>\n\u003Cp>Your selected pickup location and your most recently used delivery address are stored locally in your browser’s local Storage, not in a cookie, and are used only to pre-fill the App the next time you visit. You may clear this information at any time by clearing your browser’s site data.\u003C\u002Fp>\n\u003Ch2 id=\"analytics-consent-based\">Analytics (Consent-Based, Off by Default)\u003C\u002Fh2>\n\u003Cp>Analytics tools are disabled by default. No analytics script loads and no analytics identifier is set until you affirmatively accept analytics through our consent banner (recorded as a prana.consent.analytics preference). Before you provide consent, no analytics data of the kind described below is collected.\u003C\u002Fp>\n\u003Cp>Once you have consented, we use:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>First-party identifiers: used to associate usage events sent directly to our own backend (POST \u002Fpublic\u002Fevents). No third-party cookies are involved in this first-party analytics.\u003C\u002Fli>\n\u003Cli>Google Analytics only where a measurement ID is configured for the relevant property and only after you have consented; consent signal defaults to “denied” until you opt in.\u003C\u002Fli>\n\u003Cli>PostHog: session recording are disabled, and PostHog operates on an opt-out-by-default basis consistent with your consent choice.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>You may withdraw analytics consent at any time by adjusting your cookie preferences, which will stop future analytics collection going forward.\u003C\u002Fp>\n\u003Ch2 id=\"third-party-cookies\">Third-Party Cookies Set on Third-Party Domains\u003C\u002Fh2>\n\u003Cp>Certain embedded third-party services set cookies directly on their own domains, outside our control, when you use the corresponding feature.\u003C\u002Fp>\n\u003Ch2 id=\"what-we-do-not-use\">What We Do Not Use\u003C\u002Fh2>\n\u003Cp>We do not use advertising-network cookies, cross-site or cross-app tracking cookies, or mobile advertising identifiers for third-party tracking purposes. We do not use cookies or similar technologies to sell personal information, and we do not permit any of the providers listed above to use data collected via these technologies for their own advertising purposes.\u003C\u002Fp>\n\u003Cp>You may control non-essential cookies and analytics through our consent banner or cookie preference tool, and through your browser settings. Blocking or clearing strictly necessary items may prevent core App features such as login, cart persistence, or checkout from functioning correctly.\u003C\u002Fp>\n\u003Ch2 id=\"push-notifications\">Push Notifications\u003C\u002Fh2>\n\u003Cp>If you enable push notifications, we may send you order status updates, reservation reminders, loyalty program updates, and promotional offers. You may disable push notifications at any time through your device’s operating system settings without affecting your ability to use the App generally, though you may miss time-sensitive order or reservation updates.\u003C\u002Fp>\n\u003Ch2 id=\"location-services\">Location Services\u003C\u002Fh2>\n\u003Cp>Geolocation is an optional feature. We only access your device’s precise or approximate location if you grant permission through your device’s operating system. You may revoke this permission at any time in your device settings, and doing so will not prevent you from using the core ordering and reservation features of the App, though location-based recommendations will no longer be available.\u003C\u002Fp>\n\u003Ch2 id=\"payments\">Payments\u003C\u002Fh2>\n\u003Cp>Payments made through the App are processed by one or more third-party, PCI-DSS-compliant payment processors (“Payment Processor(s)”). When you enter payment card information:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Full card numbers, CVV codes, and similar sensitive payment data are transmitted directly to and stored by the Payment Processor, not by Prana Kitchen Project LLC;\u003C\u002Fli>\n\u003Cli>We receive only limited transaction metadata from the Payment Processor, such as a transaction ID, the last four digits of your card, card type, and authorization\u002Fdecline status, which we use for order confirmation, receipts, refunds, and fraud prevention;\u003C\u002Fli>\n\u003Cli>Your use of the Payment Processor’s services is also subject to that Payment Processor’s own privacy policy and terms, which we encourage you to review; and\u003C\u002Fli>\n\u003Cli>The Company is not responsible for the independent privacy or security practices of the Payment Processor, although we select processors that maintain industry-standard security certifications.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2 id=\"sharing-of-personal-information\">Sharing of Personal Information\u003C\u002Fh2>\n\u003Cp>We do not sell your personal information for money. We may share personal information as follows:\u003C\u002Fp>\n\u003Cp>\u003Cstrong>With Service Providers\u003C\u002Fstrong> who process data on our behalf and under contractual confidentiality and security obligations, such as our payment processor, cloud hosting provider, analytics and crash-reporting vendors, customer support platform, email\u002FSMS\u002Fpush notification vendors, and delivery\u002Flogistics partners.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>With restaurant staff and point-of-sale systems\u003C\u002Fstrong> to the extent necessary to prepare and fulfill your order.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>For legal reasons,\u003C\u002Fstrong> where we believe disclosure is necessary to (i) comply with a law, regulation, subpoena, or governmental request; (ii) enforce our Terms of Service; (iii) protect the rights, property, or safety of the Company, our users, or the public; or (iv) detect, prevent, or address fraud or security issues.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>With your consent,\u003C\u002Fstrong> for any other purpose we disclose to you at the time of collection.\u003C\u002Fp>\n\u003Ch2 id=\"international-transfers\">International Transfers\u003C\u002Fh2>\n\u003Cp>Our Services are intended for users located in the United States, and our servers and service providers are assumed to be based in the United States ъ. If any service provider processes data outside the United States, we require contractual safeguards consistent with applicable law. If you access the App from outside the United States, you understand that your information will be transferred to and processed in the United States, where privacy laws may differ from those of your home jurisdiction.\u003C\u002Fp>\n\u003Ch2 id=\"data-retention\">Data Retention\u003C\u002Fh2>\n\u003Cp>We retain personal information only for as long as reasonably necessary to fulfill the purposes described in this Policy.\u003C\u002Fp>\n\u003Cdiv class=\"table-wrap\">\n\u003Ctable>\n\u003Cthead>\n\u003Ctr>\n\u003Cth>Category of Personal Data\u003C\u002Fth>\n\u003Cth>Retention Period\u003C\u002Fth>\n\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\n\u003Ctr>\n\u003Ctd>Identification data\u003C\u002Ftd>\n\u003Ctd>Account duration + 7 years after closure\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Contact information\u003C\u002Ftd>\n\u003Ctd>Account duration + 3–7 years (tax\u002Faccounting)\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Account credentials\u003C\u002Ftd>\n\u003Ctd>Account duration + 90 days post-deletion (security logs)\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Order history\u003C\u002Ftd>\n\u003Ctd>3–7 years (tax\u002Faccounting); anonymized data may be retained longer\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Payment information\u003C\u002Ftd>\n\u003Ctd>Transaction metadata: 7 years; full card data retained solely by processor\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Device information\u003C\u002Ftd>\n\u003Ctd>24 months (crash\u002Fanalytics), then aggregated\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>IP address\u003C\u002Ftd>\n\u003Ctd>12 months identifiable, then anonymized\u002Fdeleted\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Cookies and similar technologies\u003C\u002Ftd>\n\u003Ctd>Session to 12 months, per cookie table\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Geolocation\u003C\u002Ftd>\n\u003Ctd>Session only, unless a saved address is created\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Marketing preferences\u003C\u002Ftd>\n\u003Ctd>Until opt-out + 24 months (suppression compliance)\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Customer support communications\u003C\u002Ftd>\n\u003Ctd>2 years after ticket closure\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>User-generated content\u003C\u002Ftd>\n\u003Ctd>Until deleted by user or account closure; moderation records 1 year\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Analytics data\u003C\u002Ftd>\n\u003Ctd>24 months, then aggregated\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Crash logs\u003C\u002Ftd>\n\u003Ctd>12 months\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Fraud prevention information\u003C\u002Ftd>\n\u003Ctd>3–7 years, consistent with payment-network\u002Ftax requirements\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003C\u002Ftbody>\n\u003C\u002Ftable>\n\u003C\u002Fdiv>\n\u003Cp>Where we no longer have a legitimate business or legal need to retain personal information in identifiable form, we will delete it, de-identify it, or aggregate it.\u003C\u002Fp>\n\u003Ch2 id=\"data-security\">Data Security\u003C\u002Fh2>\n\u003Cp>We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, or destruction, consistent with requirement that businesses maintain reasonable security measures. These safeguards include, as applicable: encryption of data in transit (e.g., TLS), access controls limiting employee access on a need-to-know basis, and contractual security obligations imposed on our service providers.\u003C\u002Fp>\n\u003Cp>No method of transmission or storage is completely secure. In the event of a data breach affecting personal information, we will notify affected individuals and applicable regulators in accordance with applicable legislation.\u003C\u002Fp>\n\u003Ch2 id=\"consumer-privacy-rights\">Consumer Privacy Rights\u003C\u002Fh2>\n\u003Ch3 id=\"florida-residents\">Florida Residents\u003C\u002Fh3>\n\u003Cp>Under the Florida Digital Bill of Rights (applicable to certain “controllers” meeting statutory thresholds) and, more broadly, as a matter of Company policy extended to all Florida users, you may have the right to:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>confirm whether we are processing your personal information and access that information;\u003C\u002Fli>\n\u003Cli>correct inaccuracies in your personal information;\u003C\u002Fli>\n\u003Cli>request deletion of personal information you have provided or that we hold about you;\u003C\u002Fli>\n\u003Cli>obtain a portable copy of your personal information in a usable format;\u003C\u002Fli>\n\u003Cli>opt out of the processing of your personal information for purposes of (i) targeted advertising, (ii) the sale of personal information, or (iii) profiling in furtherance of decisions that produce legal or similarly significant effects, to the extent such processing occurs; and\u003C\u002Fli>\n\u003Cli>not be discriminated against for exercising these rights.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>To exercise these rights, contact us using the details in Policy. We will verify your identity before processing your request, generally using information already associated with your account (e.g., matching email address).\u003C\u002Fp>\n\u003Ch3 id=\"california-residents\">California Residents (CCPA\u002FCPRA), If Applicable to Our Business\u003C\u002Fh3>\n\u003Cp>If, and to the extent, the CCPA\u002FCPRA applies to our business, California residents have the right to:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>know\u002Faccess the categories and specific pieces of personal information we have collected, used, disclosed, or sold\u002Fshared about them in the preceding 12 months;\u003C\u002Fli>\n\u003Cli>delete personal information we have collected from them, subject to certain exceptions;\u003C\u002Fli>\n\u003Cli>correct inaccurate personal information;\u003C\u002Fli>\n\u003Cli>opt out of the “sale” or “sharing” of personal information;\u003C\u002Fli>\n\u003Cli>limit the use of sensitive personal information, to the extent we process any sensitive personal information as defined by the CPRA; and\u003C\u002Fli>\n\u003Cli>non-discrimination for exercising any of these rights.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>California residents (or their authorized agents) may submit a request using the contact details in Policy. We will verify the request consistent with CCPA\u002FCPRA regulations before responding, and will respond within the statutory timeframe (generally 45 days, extendable by an additional 45 days when reasonably necessary).\u003C\u002Fp>\n\u003Cp>We have not sold personal information for monetary consideration in the preceding 12 months. To the precautionary extent any sharing for cross-context behavioral advertising is deemed a “share” under CPRA, you may opt out via the “Do Not Sell or Share My Personal Information” mechanism, or by enabling applicable device-level tracking controls (e.g., declining ATT on iOS).\u003C\u002Fp>\n\u003Ch2 id=\"marketing-communications\">Marketing Communications\u003C\u002Fh2>\n\u003Cp>We may send you promotional emails, SMS\u002Ftext messages, and push notifications about offers, new menu items, and loyalty rewards where you have opted in. You may opt out at any time.\u003C\u002Fp>\n\u003Cp>Opting out of marketing communications will not affect transactional messages necessary to service your orders (e.g., order confirmations, receipts).\u003C\u002Fp>\n\u003Ch2 id=\"childrens-privacy\">Children’s Privacy\u003C\u002Fh2>\n\u003Cp>The App is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13 in a manner inconsistent with COPPA. If we later introduce features directed to children, or if we obtain actual knowledge that a child under 13 has provided personal information without verifiable parental consent, we will take steps to delete such information promptly and, where appropriate, update this Policy to describe any child-directed practices and parental consent mechanisms. If you believe a child under 13 has provided us with personal information, please contact us using the details inPolicy so we can investigate and take appropriate action.\u003C\u002Fp>\n\u003Ch2 id=\"third-party-services\">Third-Party Services\u003C\u002Fh2>\n\u003Cp>The App may contain links to, or integrations with, third-party websites, social media platforms, mapping services, or other applications that we do not own or control. This Privacy Policy does not apply to those third-party services, and we encourage you to review their respective privacy policies before providing any personal information to them.\u003C\u002Fp>\n\u003Ch2 id=\"changes-to-this-privacy-policy\">Changes to This Privacy Policy\u003C\u002Fh2>\n\u003Cp>We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. If we make material changes, we will notify you by posting a notice within the App, updating the “Last Updated” date above, and, where required by law, seeking your consent before applying such changes to previously collected information. We encourage you to review this Policy periodically.\u003C\u002Fp>\n\u003Ch2 id=\"contact-information\">Contact Information\u003C\u002Fh2>\n\u003Cp>If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, including to exercise any privacy rights described above, please contact us at:\u003C\u002Fp>\n\u003Cp>Company Name: PRANA KITCHEN PROJECT LLC\u003C\u002Fp>\n\u003Cp>Business address: 12864 BISCAYNE BLVD 2129 MIAMI, FL 33181\u003C\u002Fp>\n\u003Cp>Identification Number: 41-4926992\u003C\u002Fp>\n\u003Cp>Email: \u003Ca href=\"mailto:info@prana.kitchen\">info@prana.kitchen\u003C\u002Fa>\u003C\u002Fp>\n",1791464170358]