Legal
Privacy Policy
Last updated: 15 July 2026
This Privacy Policy explains how ChefID (“ChefID”, “we”, “us”) collects, uses, stores, and protects personal data of users and data subjects of the website chefid.io (also reachable at chefid.ru) and the ChefID mobile app (together, the “Service”).
We process personal data in accordance with applicable law, including Federal Law No. 152-FZ of 27 July 2006 “On Personal Data” of the Russian Federation and, where they apply to you, the EU General Data Protection Regulation (“GDPR”) and California privacy law. By using the Service or submitting information to us, you consent to the processing of your personal data as described in this Policy.
1. Operator
The operator (data controller) of your personal data is ChefID, which operates chefid.io. For any question about this Policy or to exercise your rights, contact us at privacy@chefid.ru.
Full operator registration details are available on request at privacy@chefid.ru.
Details of our representative in the European Union may be requested at privacy@chefid.ru.
2. What data we collect
We collect only what the Service needs:
- Account data — your email address, display name, and password (stored only as a cryptographic hash, never in plain text).
- Content you contribute — information you add about chefs, restaurants, bars, tenures, and related professional records, including text and images, plus reviews, feed posts, comments, and direct messages you send through the Service.
- Identity documents — only when you claim a profile, and only to verify your identity (see “Identity verification and passport data” below).
- Technical data — IP address, browser type, and privacy-friendly, aggregate analytics (page views). We do not use advertising or cross-site tracking.
- Mobile app data — a push-notification token if you enable notifications, and your device location if you grant permission (see “The ChefID mobile app” below).
3. The ChefID mobile app
The mobile app contains no advertising, no analytics SDKs, and no crash-reporting SDKs, and it does not read or collect device identifiers such as the advertising ID.
Location: if you grant the location permission, your coordinates are used to centre the map, show distances, and order “near me” results. Coordinates are sent to our servers only as short-lived query parameters for those features and are never stored or used to build a location history.
Photos and videos: the app uses the system photo picker, so it can access only the items you explicitly choose. Location metadata (EXIF GPS) is stripped from images before upload.
Push notifications: if you enable them, a device token is registered with us and with Google’s Firebase Cloud Messaging to deliver notifications. The token identifies the device installation, not your identity, and is deleted when you sign out or delete your account.
4. Identity verification and passport data
When you claim a ChefID profile, we may ask you to submit an identity document (for example, a passport page) for the sole purpose of confirming that you are the person you claim to be.
Passport and identity-document data are used only to evaluate and confirm your identity. As soon as the verification decision is made — whether successful or not — the submitted document is discarded and is not retained. We do not build or keep a database of passport data.
We retain only the fact and outcome of verification (for example, “identity verified on <date>”). We never store the document image, the passport number, or other document details.
Providing an identity document is voluntary. Without it we cannot grant verified or claimed status, but you may still use the rest of the Service.
5. Purposes of processing
We process personal data to:
- operate the Service and maintain the public professional record;
- create and secure your account;
- verify identity for profile claims;
- moderate contributions and prevent abuse;
- comply with our legal obligations.
6. Legal basis
We process personal data on the following legal bases: your consent (which you may withdraw at any time); the necessity to perform our agreement with you (the Terms of Use) — for example operating your account, delivering messages you send, and publishing contributions you submit; our legitimate interest in maintaining a public professional record and keeping the Service secure; and compliance with legal obligations.
Public professional information (name, workplaces, roles, accolades) about chefs, bars, and restaurants is processed as part of a publicly significant professional record. Data subjects may request correction or removal as described below.
7. Where your data is processed and international transfers
Our servers and databases are located in the Russian Federation. In accordance with 152-FZ, the personal data of citizens of the Russian Federation is recorded, systematized, accumulated, stored, and processed using databases located within the Russian Federation.
If you use the Service from the European Economic Area, the United Kingdom, or another jurisdiction with data-transfer rules, this means your personal data is transferred to and processed in a country that has not received an adequacy decision from your jurisdiction. We take the protection measures described in this Policy regardless of where data is processed (encryption in transit, encrypted storage of sensitive material, strict access controls), and we rely on your explicit, informed consent to the transfer, given when you create an account or submit data after reading this Policy. You may withdraw that consent at any time by deleting your account.
We apply organizational and technical measures to protect personal data against unauthorized access, alteration, disclosure, or destruction.
8. Retention
Account data is kept while your account is active and for as long as necessary for the purposes above, or as required by law.
Identity documents are not retained (see “Identity verification and passport data”).
Direct messages are kept until you delete them or your account; push-notification device tokens are deleted when you sign out or delete your account.
When you delete your account, your personal data is erased or irreversibly anonymized: your profile is scrubbed, your private data (collections, messages, notifications, devices) is deleted, and content that must remain for the integrity of the public record (for example published contributions) is kept without any link to your identity. See the “Account deletion” page for the full description.
9. Disclosure and third-party services
We do not sell personal data, and we do not share it with third parties for advertising. We may disclose data only where required by law or to protect our rights. Public professional records are, by design, publicly viewable.
The Service relies on a small number of third-party processors:
- Google Firebase Cloud Messaging — delivers push notifications to the mobile app; receives the device push token.
- OpenFreeMap — serves the map tiles shown in the mobile app; like any web server, it receives your IP address when tiles load.
- We host our own CAPTCHA (mCaptcha) and media storage; those requests do not leave our infrastructure.
10. Your rights
Whatever law applies to you, you can exercise the core rights directly in the Service: download a copy of your data (Dashboard → Account → Download my data), delete your account and associated data (in the app: Profile → Delete account; on the web: Dashboard → Account), and correct your account details at any time. For anything else, contact us at privacy@chefid.ru.
Under 152-FZ (Russian Federation), you have the right to:
- obtain information about the processing of your personal data;
- request rectification, blocking, or deletion of data that is incomplete, outdated, inaccurate, or unlawfully processed;
- withdraw your consent to processing;
- appeal to the authorized body for the protection of data subjects’ rights (Roskomnadzor) or to a court.
11. Your rights under the GDPR (EEA and UK users)
If the GDPR or UK GDPR applies to you, you additionally have the right to:
- access the personal data we hold about you and receive a copy of it (Art. 15);
- receive the data you provided in a structured, commonly used, machine-readable format — data portability (Art. 20; the “Download my data” export satisfies this);
- have inaccurate data rectified (Art. 16) and, in the circumstances set out in Art. 17, have data erased;
- restrict or object to processing based on legitimate interests (Arts. 18 and 21);
- withdraw consent at any time, without affecting the lawfulness of processing before withdrawal (Art. 7(3));
- lodge a complaint with the supervisory authority in your EU member state or with the UK Information Commissioner’s Office.
12. California privacy rights
If you are a California resident, the California Online Privacy Protection Act (CalOPPA) and, where its thresholds are met, the California Consumer Privacy Act as amended by the CPRA give you rights over your personal information.
The categories of personal information we collect are listed in “What data we collect” above: identifiers (email address, display name, IP address), user-generated content, ephemeral geolocation (mobile app, with your permission), and a push-notification device token. We collect them for the purposes listed in “Purposes of processing”.
We do not sell personal information, we do not share it for cross-context behavioral advertising, and we have not done either in the preceding 12 months. We use no advertising networks and no cross-site tracking.
You have the right to know what personal information we hold about you (use “Download my data”), the right to delete it (use account deletion), and the right to correct it. We do not discriminate against you for exercising these rights.
Do Not Track: our Service does not track visitors across third-party websites, so it behaves the same whether or not your browser sends a “Do Not Track” signal.
13. Children
The Service is not directed to children under 13, and we do not knowingly collect personal data from children under 13 (or under the higher minimum age that applies in your country, such as 16 in parts of the European Union). If you believe a child has provided us personal data, contact privacy@chefid.ru and we will delete it.
14. Cookies and analytics
We use strictly necessary cookies for authentication, and privacy-friendly, aggregate analytics that do not profile individuals. Because these cookies are strictly necessary for the Service to function, they do not require a consent banner; we set no advertising or third-party cookies.
15. Changes to this Policy
We may update this Policy from time to time. The “Last updated” date reflects the latest revision; material changes will be indicated on this page.
16. Contact
Questions about this Policy or requests to exercise your rights: privacy@chefid.ru. We respond within the timeframes required by applicable law.