Who we are
FullFork (“FullFork”, “we”, “us”) operates the FullFork iOS app for diners (the “App”) and the restaurant dashboard at this website (the “Dashboard”). Together they are the “Service”. By using the Service you agree to this policy. If you do not agree, please do not use the Service. Questions go to fullforkapp@gmail.com.
What we collect
If you are a diner using the App
- Account details. Your email address, first and last name, and password (stored by Firebase Authentication, never by us in plain text). If you sign in with Google, we receive your name, email, and Google account identifier from Google.
- Birthdate. Asked for at signup and used to show only deals you are eligible for. It is stored on your profile and used for nothing else.
- Saved deals. The deals you bookmark, so they appear in your Saved tab.
- Location. With your permission, your device’s precise location while the App is open (never in the background). We use it to find deals near you, to sort them by driving distance, and to confirm you are at the restaurant when you open a deal or reveal a redemption code. See Location below for exactly what is kept.
- Deal activity. When you open a deal within a quarter mile of the restaurant, or reveal its redemption code within one mile, we record that event with the deal, the time, your location at that moment, your distance from the restaurant, your account identifier, and a device identifier (Apple’s vendor identifier, which is specific to FullFork and is not an advertising identifier).
- Push notification token. If you allow notifications, a device token so we can send them. We do not send marketing notifications today.
- Phone number. Only on older accounts that were created with one. New accounts do not provide a phone number.
The App may ask for photo-library access when you tap the profile picture. No photo is currently uploaded or stored by FullFork.
If you are a restaurant using the Dashboard
- Account and business details. Your name, work email, mobile number, password (Firebase Authentication), restaurant name, street address(es), opening hours, cuisines, and, if you enter it, a business license number.
- Content you publish. Deals, deal descriptions, redemption codes, deal photos, and your logo. Photos and logos are stored at publicly readable web addresses so the App can display them.
- Deal performance. Aggregate claim and redemption counts, estimated revenue and diner savings, and, per event, the deal, the time, and the diner’s distance from your restaurant. You never see a diner’s identity, contact details, or coordinates.
Collected automatically
- App diagnostics and usage (App only). The App uses Firebase Analytics and Firebase Crashlytics (Google). They collect device model, operating system version, app version, language, region, session and screen-view events, crash reports, and a Firebase app-instance identifier. We do not attach your name or email to these tools.
- Map telemetry (App only). Maps in the App are drawn by the Mapbox SDK, which may collect de-identified map-usage and device data under Mapbox’s own privacy policy.
- Server logs. Like every web service, our servers record requests, including IP address, time, the endpoint called, and, for nearby-deal searches, the coordinates the App sent. Logs are used for security and debugging and are kept for a limited period by our hosting provider.
The Dashboard website does not use analytics or advertising trackers.
How we use information
- To create and secure your account and sign you in.
- To show diners deals near them and let restaurants publish, schedule, and target deals to their locations.
- To verify a diner is at the restaurant before a deal counts as claimed or a code is revealed, and to prevent the same device from claiming a deal repeatedly (one claim per deal every 30 minutes).
- To give restaurants performance reporting that never identifies an individual diner.
- To send transactional email such as email verification and password resets.
- To find and fix crashes and bugs, and to understand which features are used.
- To respond to your support requests.
- To detect and prevent fraud, abuse, and security incidents, and to comply with law.
We do not sell your personal information, and we do not share it with third parties for their own advertising. We do not use your information for targeted advertising.
Location, in detail
- The App asks for “While Using” location only. You can decline; you can still browse deals, but they will not be sorted by distance and you will not be able to claim them.
- When you search for nearby deals, your coordinates are sent to our server to rank deals and, through Mapbox’s distance service, to estimate driving distance. They are not stored as part of that search.
- When you open a deal nearby or reveal a code, your coordinates at that moment are stored with the event so we can audit distance checks and prevent abuse. Restaurants see only the resulting distance (for example “0.09 mi away”), never your coordinates.
- Restaurant addresses are converted to map coordinates once, using Google’s Geocoding service, so the App can show distance to them.
Who we share information with
We use a small number of service providers that process data on our behalf:
| Provider | What it does | Data involved |
|---|---|---|
| Google Firebase / Google Cloud | Authentication, database, file storage, hosting, push notifications, app analytics, crash reporting | Everything described above |
| Google Maps Platform | Turns restaurant addresses into coordinates; address and business-name search in the Dashboard and App | Restaurant addresses and names; search text you type |
| Mapbox | Map display in the App; driving-distance estimates | Your coordinates during nearby-deal searches; SDK telemetry |
| Google Sign-In | Optional sign-in method | Your Google name, email, and account identifier |
We may also disclose information when required by law, to protect the rights and safety of FullFork, our users, or others, or as part of a merger, acquisition, or sale of assets (we would notify you before your information becomes subject to a different privacy policy).
Cookies and on-device storage
The Dashboard sets one first-party cookie that remembers whether the sidebar is collapsed, and stores your theme preference and your sign-in session in your browser’s local storage. Neither is used for tracking. The address search on the restaurant signup page loads Google’s Maps script, which may set Google cookies under Google’s policy. We do not respond to browser “Do Not Track” signals because there is no tracking to turn off.
Retention and deletion
- Diners: delete your account in the App under Profile → Account Settings → Delete Account. This removes your sign-in, profile, and saved deals, and anonymizes your deal activity: the event and its distance remain in restaurant statistics, but your account identifier, device identifier, and coordinates are removed from it.
- Restaurants: email fullforkapp@gmail.com from your account email to delete your account. Published deals and their statistics are deleted with it.
- Crash and analytics data held by Google is retained on Google’s standard schedule (Firebase Analytics: up to 14 months for user-level data). Server logs are kept for a limited period by our hosting provider.
Your choices and rights
- Access and correction. Diners can edit their name and birthdate in the App; restaurants can edit their business details in Dashboard settings. Email us for anything else.
- Location. Change or revoke the App’s location permission at any time in iOS Settings.
- Notifications. Turn them off in iOS Settings.
- Deletion. See above.
- Email. We only send transactional email (verification, password reset). There is no marketing list to unsubscribe from.
California residents. The California Consumer Privacy Act gives you the right to know what personal information we collect and how it is used and shared, to access it, to delete it, to correct it, and to not be discriminated against for exercising these rights. In the past twelve months we collected the categories listed under What we collect (identifiers, account and profile details, precise geolocation, commercial activity in the form of deal claims and redemptions, and device and usage information) from you and from your use of the Service, for the purposes listed under How we use information, and shared them only with the service providers listed above. We do not sell or “share” (as the CCPA defines it) personal information, and we do not use or disclose sensitive personal information for purposes other than providing the Service. To exercise any right, email fullforkapp@gmail.com from the address on your account, or have an authorized agent do so with your written permission; we will verify the request before acting on it.
Security
Data is stored with Google Firebase and protected by its access controls; only our server code can read deal-activity records, and restaurants can only read their own data. Passwords are handled by Firebase Authentication. No system is perfectly secure, so keep your password private and tell us at fullforkapp@gmail.com if you suspect your account has been accessed without permission.
Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has created an account, email fullforkapp@gmail.com and we will delete it.
Changes to this policy
We will update this page when our practices change and revise the date at the top. For material changes we will notify you in the App or by email before they take effect.
Contact
fullforkapp@gmail.com. Read our Accessibility Statement or visit Support.
