Think CaterBack to Sign In

Privacy Policy

Last updated: June 20, 2026

This Privacy Policy explains how Think Cater ("Think Cater," "we," "us") collects, uses, shares, and protects information when you visit thinkcater.com or use the Think Cater catering-management platform (the "Service"). It applies to caterers and their team members who use the Service ("Customers") and to visitors of our website.

Roles. For information about our Customers and website visitors, Think Cater is the controller. For data a Customer uploads or enters about their own end customers (for example, names, delivery addresses, or contact details inside an order or menu document), the Customer is the controller and Think Cater acts as a processor / service provider handling that data on the Customer's behalf and under their instructions.

1. Information We Collect

  • Account & contact data — name, email, business name, role, and password (stored hashed).
  • Business & operational data — menus, recipes, dishes, ingredients, inventory, orders, shopping lists, delivery routes, and analytics you create or generate in the Service.
  • Uploaded documents — order and menu files you upload (PDF, images, spreadsheets, email text). These may contain personal information about your end customers (names, addresses, phone numbers). We process this only to provide the Service to you.
  • Payment data — billing is handled by Stripe. We do not see or store full card numbers; we receive limited billing metadata (e.g., plan, last4, status) from Stripe.
  • Usage & device data — log data, IP address, browser/device type, and product usage collected via cookies and analytics to operate and improve the Service.
  • Sales inquiries — if you submit a contact or demo request, the name, email, company, and message you provide.

2. How We Use Information & Legal Bases

We use information to:

  • provide, operate, secure, and improve the Service (performance of our contract with you; our legitimate interests);
  • process AI features such as order parsing, recipe/ingredient generation, and allergen flagging (contract; legitimate interests);
  • process payments and manage subscriptions (contract; legal obligation);
  • send transactional messages (account, security, order, billing) — these are required to use the Service;
  • send occasional product/lifecycle emails (our legitimate interests; you can unsubscribe at any time);
  • comply with law and enforce our Terms.

AI note. AI-generated content (recipes, costs, allergen tags) is decision support, not a substitute for professional judgment — especially for allergen and food-safety decisions, which you must independently verify.

3. Service Providers & Subprocessors

We share data with vetted providers strictly to run the Service. We do not sell personal information. Current subprocessors:

  • Supabase (via Lovable Cloud) — database, authentication, and file storage.
  • Stripe — payment processing and subscription billing.
  • Resend — transactional and lifecycle email delivery.
  • Lovable — application hosting and the AI gateway that powers our AI features.
  • Google — Fonts, Maps/Places (address autocomplete), and Tag Manager / Analytics.
  • Calendly — demo scheduling (only if you book a demo).

Each provider is bound by its own terms and data-protection commitments. We may update this list as the Service evolves; material changes will be reflected here.

4. Cookies & Analytics

We use strictly necessary cookies to keep you signed in and secure, and analytics cookies (Google) to understand and improve usage. You can control cookies through your browser settings; disabling some may affect functionality. Where required by law, we honor opt-out preference signals such as Global Privacy Control (GPC).

5. Data Retention

  • Account & business data — kept while your account is active and for up to 90 days after closure, unless a longer period is required by law.
  • Uploaded documents — retained while needed to provide the Service and then deleted or anonymized on a rolling basis.
  • Billing records — retained as required by tax and accounting law (typically up to 7 years).
  • Logs & analytics — retained for a limited period for security and product improvement.

6. Your Privacy Rights

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to opt out of the "sale" or "sharing" of personal information. Think Cater does not sell your personal information,and we do not share it for cross-context behavioral advertising.

California (CCPA/CPRA): rights to know, delete, correct, and to opt out of sale/sharing, with no discrimination for exercising them. EEA/UK (GDPR): rights of access, rectification, erasure, portability, restriction, and objection, and the right to lodge a complaint with a supervisory authority.

How to exercise your rights (DSAR). Email privacy@thinkcater.com with your request and the email address associated with your account. We will verify your identity and respond within the time required by law (generally 45 days under CCPA and 30 days under GDPR), and will tell you if we need an extension. If you are an end customer of one of our Customers (caterers), please contact that business directly, as they control that data; we will assist them as their processor. Account owners can also request deletion or an export of their account data through the same address.

7. Data Security

We use industry-standard safeguards including encryption in transit, row-level access controls scoped per business, hashed credentials, scoped API authorization, and least-privilege access. No method of transmission or storage is 100% secure, but we work to protect your information and to notify affected parties of incidents as required by law.

8. International Transfers

We and our providers may process data in the United States and other countries. Where personal data is transferred internationally, we rely on appropriate safeguards (such as standard contractual clauses) where required.

9. Children's Privacy

The Service is a business tool and is not directed to children under 16, and we do not knowingly collect their personal information.

10. Changes to This Policy

We may update this Policy from time to time. We will revise the "Last updated" date above and, for material changes, provide additional notice.

11. Contact

Questions or requests: privacy@thinkcater.com. Postal: Think Cater, 2200 Jerrold Ave, San Francisco, CA 94124.