Privacy Policy
Last updated: August 11, 2026
Theme Park Food Reviews (“the app,” “we,” “us”) is a digital record keeper for rating and remembering food across theme parks. This policy explains what we collect, how we use it, and the choices you have. Questions? Email foodiesupport@themeparkfoodreviews.com.
Information we collect
- Account details — your email address, a password (stored securely in hashed form by our authentication provider), and the display name you choose.
- Google sign-in (optional) — if you sign in with Google, we receive your name, email address, and profile picture, as authorized by you on Google’s consent screen.
- Profile & content — an optional avatar image you upload, and the content you create: reviews (ratings, written notes, dish tags, and photos), which dishes each photo shows when you link them, the groups you create or join, and who invited you.
- Review photos & photo details — when you add a photo to a review, we store the image and which menu items you associate it with (so we can improve food matching over time). When the file includes them, we privately retain capture time, a broad camera family (for example “Apple iPhone”), and location only if the photo was taken inside a supported public park or resort boundary. Exact in-park coordinates never appear on your public photo, expire after 24 months, and are discarded when the photo is outside those boundaries. Many phones strip this information; if it isn’t in the file, we cannot collect it. These review-photo details are separate from Photo Inbox organization and are not controlled by the Inbox opt-out below.
- Photo Inbox — photos you explicitly select for later reviews are stored privately as compressed copies. By default we use location and date details already in the photo file to organize imports: coordinates are checked on your device, and we retain only the supported park match and capture date — not exact coordinates or unselected photos. When you later attach an Inbox photo to a review, we may copy that capture date and park match onto the private review-photo record (still without exact GPS from the Inbox). You can opt out under Profile → Privacy & Disclosures. That opt-out does not change details already stored with published review photos.
- Cookies and preferences — essential login cookies and small first-party preference cookies remember choices such as your resort and optional advertising-measurement preference. If you affirmatively allow Meta measurement on the Founding Foodies campaign page, Meta Pixel may set or read the
_fbpadvertising identifier, and our site may set the_fbcclick identifier for Meta after a Meta ad click. We do not load Meta code, set those Meta cookies, or make Meta requests before you allow it. - Optional beta usage data — Founding Foodies can choose to share a limited set of named app events, such as opening a major feature, starting or completing a review, safe validation/failure codes, and opening or submitting feedback. We attach a stable account identifier, app version, sanitized screen path, and coarse device/network details. We do not send review or feedback text, search terms, email, display name, photo contents, storage links, or precise location. Session replay is a separate choice; form inputs are masked and images, video, and canvas content are blocked.
- Optional Founding Foodies ad measurement — only after you choose “Allow optional measurement,” the browser and our server may send Meta one of three events: viewing the campaign page, opening its application, or successfully submitting it. Each event includes an opaque event ID, event time, the canonical campaign-page URL, and website as the action source. Meta may also receive your IP address, browser user agent, and the
_fbpor_fbcidentifiers when present. Meta Pixel may transmit ordinary technical browser details such as page title, referrer, screen, and viewport. We do not send Meta your name, email (even hashed), application answers, exact or broad visit timing, eligibility or qualification, review content, referral codes, free text, Supabase or PostHog account IDs, or our stored UTM/source fields. We do not use Meta advanced matching. - Notification delivery data — if you enable push, we privately store a browser delivery endpoint, encryption keys, and a coarse platform label. We also record provider acceptance, notification opens, and daily-mission views, CTA opens, and acknowledgments so we can test reliability. Beta admins see channel status and participation, but not endpoints or encryption keys.
How we use your information
- To provide the app — your account, reviews, groups, badges, and notifications.
- To improve food identification and search — photo–dish associations you confirm, plus private review-photo details when present, help match photos to park foods and eateries over time. Aggregated location learning only uses coarse park cells after enough distinct contributors, and never shows your exact spot publicly.
- To send transactional and beta communications you choose: signup confirmation, sign-in (magic) links, password resets, daily beta missions, progress summaries, and important account notices by inbox, email, or push.
- To keep the service secure and prevent abuse.
- If you opt in, to understand feature usage, find friction in the review/photo flow, and connect a feedback report to the privacy-filtered session that led to it.
- If you separately allow Founding Foodies advertising measurement, to count completed recruiting applications, understand which Meta ads are effective, and let Meta optimize delivery toward likely applicants. Supabase, not Meta, remains the authoritative record of submitted or qualified applicants.
We do not sell your personal information. We do not use application answers, qualification, reviews, or account details for advertising. The optional Meta data described above is used only to measure and optimize the Founding Foodies recruitment campaign.
Who processes your data
We rely on a few trusted providers that process data on our behalf:
- Supabase — database, authentication, and image storage.
- Vercel — application hosting.
- Resend — delivery of the transactional emails above.
- Google — only if you choose “Sign in with Google.”
- Browser push providers — Apple, Google, Mozilla, or Microsoft, depending on the browser or device where you enable push.
- PostHog — optional product analytics and privacy-masked session replay for opted-in beta testers.
- Meta — optional Founding Foodies recruiting-ad measurement, only after the separate choice on that campaign page.
What other people can see
You control the visibility of each review — Public, Groups (visible only to members of groups you share with), or Private (only you). Your display name and avatar appear alongside reviews you share. We share your information with others only according to these settings, with the processors listed above, or where required by law.
Your choices
- Edit your profile, your reviews, and each review’s visibility at any time.
- Choose push and beta email categories, disable push on one or every device, or turn off beta email under Profile → Notifications.
- Remove private Photo Inbox items at any time before creating a review.
- Opt out of using photo location/date details under Profile → Privacy & Disclosures. That only affects Photo Inbox organization, not review photos you already submitted.
- Turn beta usage events and session replay on or off independently under Profile, Privacy & Disclosures. Session replay requires usage events to be on.
- On the Founding Foodies campaign page, allow or decline optional Meta measurement without affecting the application. Use the page’s Advertising choices control later to change your choice. Withdrawing stops future Meta events and removes the Meta cookies our site can access; it does not automatically erase events Meta already received. This choice is separate from optional PostHog beta product analytics.
- Delete your content (reviews, photos, lists, inbox) or delete your entire account under Profile → Privacy & Disclosures, with confirmation steps. You can also email foodiesupport@themeparkfoodreviews.com for help.
Advertising-measurement retention and deletion
We keep the minimum first-party Meta measurement audit record for 90 days: the consent receipt, event name and opaque event ID, delivery status and timestamps, and—only for a successfully submitted application—an internal link to that applicant so duplicate completion events are prevented. We do not store IP addresses, user agents, Meta cookie values, page-query parameters, or form answers in that audit record. Expired records are deleted automatically. Meta keeps information it receives under its own policies and controls. You may use Advertising choices to stop future sharing or email foodiesupport@themeparkfoodreviews.com to request help with deletion.
Children
The app is not directed to children under 13, and we do not knowingly collect their information. If you believe a child has provided us data, contact us and we will remove it.
Security
We use industry-standard measures to protect your data, including encrypted connections and access controls. No method of transmission or storage is 100% secure, so we cannot guarantee absolute security.
Changes to this policy
We may update this policy from time to time. The “Last updated” date above reflects the latest version, and significant changes will be reflected here.
Contact
Questions about this policy or your data? Email foodiesupport@themeparkfoodreviews.com.
Theme Park Food Reviews is an independent fan project and is not affiliated with, endorsed by, or sponsored by The Walt Disney Company or its affiliates. Park and restaurant names are used for identification only.