Local operation and optional online services
KitchenAct primarily works with data stored on the device. KitchenAct Account, KitchenAct Cloud, KitchenStaff, notifications, direct purchases and Partnership requests use online services only when the relevant feature is used.
Data processed and transfers from the device
- Local user-entered or generated data, including recipes, ingredients, menus, suppliers, processed invoices, notes, prices, costs, settings and operational records
- Data and preferences stored on the device; invoice images and text are processed for the available OCR features.
- Backups and exports chosen by the user; encrypted online backup; KitchenStaff data and content required for shared workspaces.
- No sharing for marketing, behavioural advertising or profiling; online transfers are limited to requested functions, security and authorised optional contributions
- Exported, printed, shared or externally saved files are processed by the selected destination and must be deleted separately
Purchases made through app stores remain managed by the relevant store. For subscriptions purchased directly from the website, PayPal handles payment and KitchenAct retains only the technical data needed to verify the subscription and entitlement. If you choose, Credential Manager can save credentials with your selected password manager. KitchenStaff notifications use Firebase Cloud Messaging and Firebase Installations.
External services and notifications
We do not sell personal data and do not use behavioural advertising or profiling. External services, including PayPal for direct payments, are used only for the functions described in this policy.
Retention and coordinated deletion
Local data stays on the device until you delete it or remove the app. Online data linked to KitchenAct Account, Cloud and KitchenStaff is retained according to service use and the applicable retention rules. Web deletion does not remove local copies already stored on devices.
Data security
KitchenAct Cloud backups are encrypted before HTTPS upload. The Account service handles email address, verification, sessions, authorised devices, plan and technical security data; passwords are not stored in plain text. KitchenStaff must process the operational data required for access, synchronisation, roles and notifications. Communications use HTTPS and access to economic data depends on authorised roles.
KitchenAct Account, Cloud, KitchenStaff and notifications
KitchenAct Cloud uses the KitchenAct Account. Cloud backups are stored encrypted and linked to the Account with the information needed to operate and protect the service. KitchenStaff links the Staff invite code to the Account where applicable. Notifications remain optional and are delivered through Google Firebase services.
Optional contributions improving supplier recognition
With separate consent, you can submit business supplier data or corrections that help improve supplier recognition in KitchenAct. Invoices, images, prices, quantities, private notes and credentials are not sent through this flow. Contributions are reviewed before acceptance and consent can be withdrawn.
Direct payments and Partnership requests
If you purchase a subscription directly from the website, KitchenAct processes first and last name, language and country for the Account profile; for direct purchases it also processes customer type and, only when needed, billing data such as legal name, address, tax ID or VAT ID. To keep VAT, taxable amount and B2B/B2C treatment consistent, KitchenAct may validate an EU VAT ID through the European Commission VIES service and stores the technical validation result, tax country, VAT rate, taxable amount, VAT amount and total in the payment’s fiscal record. KitchenAct also processes technical PayPal subscription identifiers, plan, status, payment/renewal dates and the version of the terms you accepted; complete payment-method details remain with PayPal. If you submit a Partnership request, we process the company and contact data entered in the form, your message, language and evidence of privacy consent to assess and manage the request.
Account and online-data deletion
KitchenAct Account and online data can be deleted from the Account area after signing in. Before confirmation, KitchenAct shows the affected Cloud data, devices and KitchenStaff links. An active direct PayPal subscription must be cancelled or resolved before final Account deletion. Ordinary profile data is deleted with the Account; billing snapshots and fiscal documents already linked to payments may be retained separately where required for administrative, tax or legal obligations; store subscriptions remain managed separately by the original store.
Controller, purposes, legal bases and contacts
Data controller: Luca Cocco. Privacy: privacy@professionalrecipemanager.com. Support: support@professionalrecipemanager.com. Data is processed to provide requested features, protect the service, manage KitchenAct Account, Cloud and KitchenStaff, verify direct subscriptions, manage Partnership requests, send optional notifications, receive authorised supplier contributions and provide support. We do not perform behavioural marketing or profiling.
Technical providers, recipients and transfers
Hosting is provided by OVH. Some Android features use Google services, including notifications, document scanning, text recognition, purchases and credential management. Direct website subscriptions use PayPal as the payment provider. KitchenStaff data is visible to other members only according to workspace, role and permissions. Public pages do not use advertising cookies or KitchenAct-managed analytics.
Rights, requests and updates
Subject to applicable law, you may request access, correction, deletion, restriction, objection or portability, and withdraw consent where applicable. For online data, use the Data deletion page or write to privacy@professionalrecipemanager.com.