Back to Home
Z
ZapMeals
Compliance Center

Privacy Policy

Last Updated: June 18, 2026. Your privacy is paramount to us.

Welcome to ZapMeals (“we”, “our”, or “us”). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit and use our web application. We are committed to transparency regarding the data we collect to personalize your meal planning, process your subscription orders, and provide smart grocery shopping cart deep-links.

1. Information We Collect

To provide tailored meal schedules and track grocery budgets, we collect two categories of information:

  • Account Credentials: Email addresses and profiles generated through our secure authentication layer with Supabase.
  • User Planning Inputs: Preferred grocery stores (Kroger, Target, Walmart, Whole Foods, etc.), weekly financial budget sliders, kitchen equipment profiles, and health/dietary tags.
  • Kitchen & Meal Logs: Images uploaded for recipe matching or meal critiques via Chef Kai's Vision AI, active cook time settings, and streak metrics.

2. Billing and Payment Processing

For subscriptions (Premium and Family tiers) and ad campaign wallets for sponsors/brands, payments are processed directly via Stripe. ZapMeals does not collect, record, or store raw credit card numbers. Stripe manages payment data securely according to PCI-DSS rules, notifying our webhook endpoints of status updates to modify your account status in our Database.

3. How We Share Information

We do not sell your personal data. We only share information with partners necessary to perform key functions:

  • Supabase: For cloud hosting, metadata databases, and user session tokens.
  • Google Gemini AI: For processing image uploads, recipe swapping options, and providing coaching guidelines.
  • Instacart: When you elect to transfer ingredients, standard query values are deep-linked to compile the digital cart.

4. Data Protection & Security

All backend endpoints, including Gemini proxy connectors, employ industry-standard encryption protocols. API credentials stored in our database (e.g., brand integration tokens) are encrypted at the application level using AES-256-GCM keys.

5. Cookies and Your Rights

We use functional session cookies to verify log-ins and preserve store configurations locally. You can manage or block cookies through our consent popup or browser controls. You hold the right to review, update, or request deletion of your account records by contacting support.