Effective: September 27, 2026 · v8
Privacy Policy
1. Introduction
Rouxbarb ApS ("Rouxbarb ApS," "we," "us," or "our") operates the Rouxbarb application and related services (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our Service.
Rouxbarb ApS is a company registered in Denmark, CVR no. 46028244, and acts as the data controller for personal data processed through the Service.
By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Service.
This version (v8) replaces v7 and, in addition to the changes described in Section 13, sets out in more detail how we handle Creator payout, tax, and compliance data (Sections 2.4, 5, 8 and 12).
2. Data We Collect
2.1 Information You Provide
-
Account information: name and email address when you create an account. Sign-in is handled via Apple, Google, or a one-time email sign-in link (passwordless) — we do not collect or store a password.
-
Profile information: handle, display name, profile photo, optional bio, and other optional details you choose to share.
-
User-generated content: recipes, Experiences, ratings, comments, photos, and shopping lists you create or upload.
-
Communications: messages you send to us through support channels or feedback forms.
-
Declared interests (optional): you may choose to tell us which kinds of food content you want to see more of by selecting interest tags in Settings → My Interests (for example, cuisines, meal types, or dietary styles). Providing interests is entirely optional, is never required to use the Service, and is collected only through that dedicated screen — we do not infer or auto-populate declared interests from your behaviour. Some interest tags may reveal, or be capable of suggesting, special categories of personal data — for example, religious or philosophical beliefs (such as Kosher, Halal, or Vegan) or health information (such as allergy-related or medically-associated diets). We collect and use such tags only with your explicit consent, which you give by selecting them on the My Interests screen after being informed of this use (Art. 9(2)(a) GDPR). We use declared interests for one purpose only: personalising the content shown to you. They are never used for advertising, for profiling beyond recipe ranking, in analytics segmentation exports, or disclosed to any third party for that party's own purposes. You can change or remove your declared interests at any time in Settings; removing a tag deletes it and immediately stops its use in personalisation.
2.2 Information Collected Automatically
-
Usage data: pages viewed, features used, search queries, recipes saved, and interaction patterns.
-
Personalisation data: to recommend content you are likely to enjoy, we derive a numerical representation of your engagement patterns (an "affinity profile") from the content you view, save, like, and cook from. This profile is a mathematical pattern used solely to measure similarity between content you have engaged with and other content on the Service; it is computed from your recent activity when your feed is generated and is not stored as a lasting record (see Section 8). It is not a set of labels or categories about you, and we do not use it to derive, record, or act on conclusions about your beliefs, health, or other special categories of personal data. See Section 3 for how this works and how to object.
-
Device information: device type, operating system, app version, language settings, and unique device identifiers.
-
Log data: IP address, access times, and crash reports.
-
Location data: we do not collect your device's GPS location, and the app does not request location permissions. A coarse, approximate location (such as country or region) may be derived from your IP address. When you tag a place on an Experience, we store the location of the place you select (for example, a restaurant) — not your own position.
2.3 Information from Third Parties
-
Social login providers: if you sign in using a third-party account (e.g., Google or Apple), we may receive your name, email address, and profile picture as permitted by your settings with that provider.
-
Merchants of Record: Apple (App Store) and, for the Android application, Google (Google Play) act as the merchant of record for in-app purchases. They provide us with transaction and settlement reporting for those purchases. We do not receive your payment card details from them.
2.4 Creator Payout, Tax and Compliance Data
If you take part in the Creator Program and are eligible to receive payouts, we additionally collect and hold:
-
Payout account details: the bank account to which settlements are made (for example IBAN, or local account and routing details), the account holder name, the account country, and the account holder's postal address (which our payout partners require in order to make a transfer).
-
Tax-reporting information: your legal name, tax residence, address and, if you provide it, your date of birth, which platform tax-reporting rules require us to hold; and, for businesses, a VAT or registration number.
-
Tax documentation: your taxpayer identification number and the kind of tax form it relates to (for example an EU tax identification number or, for US persons, an SSN, EIN or ITIN).
-
Compliance records: the records of the sanctions screening we carry out before each payout run, and the payout and earnings ledger.
Two deliberate limits apply to this category. First, we do not collect or store identity documents (such as scans of a passport or driving licence) and we never store biometric templates. If we ever require an identity check before a payout (see our Terms, Section 7.4(c)), it will be run by a verification provider and we will keep the result and a minimal extract, not the underlying documents. Second, the most sensitive elements, full bank account numbers and taxpayer identification numbers, are encrypted at rest in a separate vault in the EU (Google Cloud, Frankfurt) rather than in the application database, which holds only masked references to them (such as the last digits, the account country, and the holder name needed to operate payouts and screening). They pass through our application servers in the United States in memory only, on their way into the vault. The rest of the information described above (your legal name, postal address, date of birth, tax residence and any VAT or registration number) is stored in our primary application database in the United States (Google Cloud, Iowa), with access limited to authorised administrators; you can also see and change the postal address you entered with your bank details in the app. See Sections 7 and 12.
Sanctions-screening records are held for compliance purposes, are visible only to authorised administrators, and are not shown in the Creator dashboard.
3. How We Use Your Data
We process your personal data for the following purposes and legal bases under the GDPR:
| Purpose | Legal Basis |
|---|---|
| Providing and maintaining the Service | Performance of a contract (Art. 6(1)(b)) |
| Personalising recipe and content recommendations based on how you interact with the Service | Legitimate interest (Art. 6(1)(f)) — our interest in operating a useful, relevant discovery experience; you may object at any time (see Section 9) |
| Personalising recommendations based on interests you declare in Settings → My Interests | Consent (Art. 6(1)(a)); where a declared interest may reveal special categories of personal data (beliefs or health), your explicit consent (Art. 9(2)(a)) — withdrawable at any time by removing the interest or clearing your interests (see Section 9) |
| Communicating with you about your account or support requests | Performance of a contract (Art. 6(1)(b)) |
| Sending service (transactional) emails — account verification, sign-in links, security notices, purchase receipts, and payout notices | Performance of a contract (Art. 6(1)(b)) and, for certain records, legal obligation (Art. 6(1)(c)) — these emails are necessary to provide the Service and cannot be unsubscribed from |
| Sending lifecycle emails related to your use of the Service (for example, a welcome email or onboarding tips shortly after you join) | Legitimate interest (Art. 6(1)(f)) — our interest in helping you get started with the Service you signed up for; every lifecycle email contains an unsubscribe link and you can opt out at any time |
| Sending our email newsletter, promotional emails, and push notifications | Consent (Art. 6(1)(a)) — withdrawable at any time via the unsubscribe link in any email or the Newsletter toggle in Settings |
| Calculating Creator earnings and settling them to a Creator's payout account | Performance of a contract (Art. 6(1)(b)) — settlement of the Creator agreement in our Terms of Service |
| Checking that payout details are plausible and can receive payments (including asking our payout partner, when you enter them, whether it would accept them), confirming that changes to them come from you, and, where we require it, verifying the identity of a Creator we are paying | Legitimate interest (Art. 6(1)(f)) — our interest in paying the right person and preventing payout fraud; and performance of a contract (Art. 6(1)(b)) |
| Screening payees against applicable sanctions lists before each payout | Legal obligation (Art. 6(1)(c)) — EU restrictive-measures rules bind all EU entities and prohibit making funds available to designated persons |
| Collecting taxpayer information and reporting Creator earnings to tax authorities | Legal obligation (Art. 6(1)(c)) where a reporting regime applies to us; performance of a contract (Art. 6(1)(b)) where we collect the information in advance of a payout as a condition of settlement |
| Keeping accounting records of purchases, earnings and payouts | Legal obligation (Art. 6(1)(c)) — Danish Bookkeeping Act (Bogføringsloven) |
| Analyzing usage trends to improve the Service | Legitimate interest (Art. 6(1)(f)) |
| Detecting and preventing fraud or abuse, security monitoring, and audit logging | Legitimate interest (Art. 6(1)(f)) |
| Complying with other legal obligations | Legal obligation (Art. 6(1)(c)) |
Where we rely on your explicit consent to use declared interests that may reveal special categories of personal data, that consent is separate from your acceptance of our Terms of Service and from any other consent. It is given through the dedicated My Interests screen in Settings, is limited to the single purpose of personalising the content shown to you, and may be withdrawn as easily as it was given — remove a tag or clear your interests in Settings at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Accepting our Terms of Service does not constitute consent to this processing.
Emails we send. We send three kinds of email. Service (transactional) emails — such as sign-in links, account verification, security notices, purchase receipts, and payout notices — are necessary to operate the Service; because the Service cannot function without them, they cannot be unsubscribed from and are not affected by any marketing opt-out. Lifecycle emails — such as a welcome email or a small number of onboarding tips after you join — relate to your use of the Service; each one contains an unsubscribe link, and opting out stops all future lifecycle emails immediately. Newsletter and marketing emails are sent only with your consent; each one contains an unsubscribe link, and you can also opt out at any time using the Newsletter toggle in Settings. Opting out of lifecycle or marketing emails never affects service emails or your use of the Service.
How our recommender system works. When you use the Service, our recommender system suggests recipes and Experiences by comparing content: it converts each post into a numerical pattern, builds an affinity profile from the patterns of content you have engaged with (viewed, saved, liked, cooked from), and surfaces other content whose pattern is similar. Your personalised feed is regenerated regularly based on your recent activity. The most significant factors determining what you are shown are: (a) the similarity of a post to content you have recently engaged with; (b) the type and strength of your engagement (for example, cooking from a recipe weighs more than viewing it); (c) the recency and popularity of the post; and (d) if you have declared interests in Settings → My Interests, how well a post matches those interests. The behavioural part of the system matches content to content: it is not designed to identify, categorise, or record your religious or philosophical beliefs, health, or other special categories of personal data, and we do not query or analyse affinity profiles to draw such conclusions. As a safeguard, content categories whose inference could reveal such data (for example, religious dietary practices, belief-based diets, or allergy- and health-associated diets) are excluded from behavioural inference entirely: the system will never learn or score them from your viewing, saving, liking, or cooking activity. The only way such a category can influence your recommendations is if you explicitly declare it yourself in My Interests, with the consent described in Section 2.1.
You may object to this personalisation at any time, free of charge, by contacting us or using the feed-mode control in Settings (see Section 9). If you object, we stop generating personalised recommendations for you and discard any cached affinity data; you will see non-personalised content instead, and the Service remains fully usable.
Automated decision-making. We do not make decisions producing legal or similarly significant effects about you by automated means alone. Where a payout is automatically held, for example because a sanctions screening has flagged a potential match, a person reviews the hold before any final decision is taken, and you can contact us to have it reviewed.
4. Cookies and Similar Technologies
Rouxbarb is a native mobile application and does not use cookies. Our website at rouxbarb.com, which hosts these legal documents, does not set cookies either. We do not use analytics, advertising, or other tracking technologies.
5. Third-Party Service Providers
We share personal data with the categories of recipient set out below. Except where stated otherwise (in particular Apple and Google, which act as independent controllers for app-store purchases and sign-in, and the bank and payment providers that execute Creator payouts, which act as independent controllers), each acts as a processor on our behalf under a data processing agreement compliant with Article 28 of the GDPR. We maintain a register of our current processors and sub-processors; you can request the current list at privacy@rouxbarb.com.
| Category | Provider | What they process |
|---|---|---|
| Cloud infrastructure, database, authentication, AI processing, push notifications, AI language model, place search & bot detection | Google (GCP, Firebase, Vertex AI, Gemini, FCM, Google Places, reCAPTCHA Enterprise) | All user data, content, logs, identity tokens, usage behaviour, user photos, recipe text, voice transcripts, device tokens, conversational query text, place search queries, sign-up bot-detection signals |
| Error monitoring | Sentry | Crash reports, error diagnostics, device and app state, IP address, user IDs |
| In-app purchases & authentication | Apple (App Store IAP, Sign in with Apple) and, for the Android application, Google (Google Play Billing) | Transaction data, account identifiers, and (where you sign in with Apple or Google) your authentication identity token and name. In respect of app-store purchases and sign-in, Apple and Google act as independent data controllers for the data they collect and process for those purposes (including payment processing, billing, fraud prevention and authentication), under their own privacy policies, rather than as our processors. We are the controller only for the limited transaction and identity data they make available to us and which we then process in the Service |
| Payout validation and execution | Our payout partners: Revolut (our corporate bank) and Airwallex (a regulated payment institution) | The account holder's name, payout account details and postal address, and the payment instruction needed to settle a payout. When you enter or change your payout details, we also send the same details (without a payment) to the partner that will pay you, so that it can confirm it would accept them, and we may decline details it refuses. Revolut and Airwallex receive these details under their own terms and act as independent controllers for them, including for their own anti-money-laundering and sanctions obligations; they may process data outside the EU/EEA (see Section 7). Where your bank account is outside the EU/EEA, your bank receives the payment and your details in that country. End-User payment card data is never processed by them; all End-User purchases are handled by the applicable merchant of record |
| Former payout provider | Stripe | Stripe made Creator payouts for us until 25 September 2026. It continues to hold the data it received from Creators it paid, as an independent controller under its own terms, and receives no new Creator data from us |
| Voice AI — Kitchen Assistant (STT & TTS) | ElevenLabs | Voice input, synthesised voice output |
| Email delivery | Resend | Your email address and the content of account verification, sign-in link, notification, support, and lifecycle emails, and — where you have opted in — our email newsletter and other marketing emails |
| Operational alerting | Slack | The content of any bug report or support message you submit from the app |
Firebase is used solely for authentication and push notification delivery (FCM); we do not use the Firebase Analytics SDK. reCAPTCHA Enterprise runs only on our website for bot detection at sign-up and does not store or read information on your device.
Wake-word detection for the Kitchen Assistant ("Hey Rouxbarb") is performed entirely on your device using a local model. No audio is transmitted to Rouxbarb ApS, ElevenLabs, Google, or any other third party unless and until the wake word is detected on your device. Once activated, your spoken input is transmitted to ElevenLabs for transcription and to Google (Gemini) for generating a response, and the response is converted to speech by ElevenLabs and streamed back to your device.
These providers are contractually obligated to process your data only as instructed by us and in compliance with applicable data protection laws.
6. Data Sharing and Disclosure
We do not sell your personal data. Neither your declared interests nor your affinity profile is visible to other users, and neither is shared with any outside party for that party's own purposes; they are stored securely and used only to personalise the content shown to you. We may disclose personal data in the following circumstances:
-
With your consent: when you direct us to share information with a third party.
-
Service providers: as described in Section 5 above.
-
Tax authorities: where a platform tax-reporting regime applies to us, we report Creator identification details and annual earnings to the relevant tax authority, and we tell affected Creators what has been reported about them, as those regimes require (see Section 2.4 and our Terms of Service, Section 7.4(d)).
-
Sanctions and other legal screening: where a payee screening produces a confirmed match against an applicable sanctions list, we are required to act on it and may be required to report it to the competent authority.
-
Legal requirements: when required by law, regulation, legal process, or governmental request.
-
Business transfers: in connection with a merger, acquisition, or sale of assets, in which case you will be notified of any change in data controller.
-
Safety and rights: to protect the rights, property, or safety of Rouxbarb ApS, our users, or others.
7. International Data Transfers
Rouxbarb ApS is based in Denmark (EU/EEA). Some of our processors are located in the United States. Our starting principle is that sensitivity determines geography. For Creators this works as follows. Bank details and taxpayer identification numbers are encrypted at rest in an EU vault (Google Cloud, Frankfurt); they transit our application servers in the United States in memory only. Your legal name, address, date of birth and tax residence are stored in our primary database in the United States (Google Cloud, Iowa), under the EU–US Data Privacy Framework and the Standard Contractual Clauses described below. Our payout partners, Revolut and Airwallex, receive your name, bank details and address to validate and execute payouts, under their own terms and as independent controllers. Creators outside the EU are paid to banks in their own countries, which necessarily receive the payment and the details needed to credit it; sending your details to your own bank is necessary to perform our contract with you. For the remaining data, we rely on the following transfer mechanisms under Chapter V of the GDPR:
7.1 EU–US Data Privacy Framework. For transfers to Google (Google LLC), Sentry (Functional Software, Inc.), Slack (Salesforce, Inc. / Slack Technologies, LLC), ElevenLabs (US entity) and Resend, we rely on their certification under the EU–US Data Privacy Framework, which the European Commission has recognised as providing an adequate level of protection. Before relying on a provider's certification we verify that the correct legal entity is actively certified for the relevant category of data (non-HR data). Where a certification lapses or ceases to cover a transfer, we rely on the Standard Contractual Clauses described in Section 7.2 as a fallback.
7.2 Standard Contractual Clauses. As a fallback for any processor not covered by the Data Privacy Framework, we rely on the Standard Contractual Clauses adopted by the European Commission under Commission Implementing Decision (EU) 2021/914 of 4 June 2021, supported by a documented transfer impact assessment and, where appropriate, supplementary technical and organisational measures. Where the data of UK or Swiss users is in scope, the UK Addendum or the Swiss annex applies.
7.3 Apple and Google (independent controllers). In respect of app-store purchases and sign-in with Apple or Google, those companies act as independent data controllers and any international transfer of the data they control is governed by their own privacy policies and transfer mechanisms, not by controller-to-processor Standard Contractual Clauses entered into by us. The same applies to our payout partners, Revolut and Airwallex, for the Creator data they receive to validate and execute payouts, and to the bank that holds a Creator's account.
7.4 Continuity of safeguards. If any transfer mechanism on which we rely is invalidated, suspended, or otherwise ceases to be available, we will identify and implement an alternative lawful transfer mechanism to ensure your personal data continues to receive an adequate level of protection.
7.5 Creator payouts to banks outside the EEA. When we pay a Creator whose bank account is held outside the EEA (for example in the United Kingdom, the United States, Canada, Australia or New Zealand), the payout instruction carries the Creator's name, bank account details and postal address to that bank, because a bank transfer cannot be made without them. That transfer is necessary for the performance of our Creator agreement with you, and we rely on Article 49(1)(b) GDPR for it. Where the destination country benefits from a European Commission adequacy decision (for example the United Kingdom), we rely on that decision instead. The receiving bank and our payout partners act as independent controllers of the data they receive, as described in Section 7.3. We send nothing beyond what the transfer requires.
A copy of the applicable safeguards is available on request by contacting us at privacy@rouxbarb.com.
8. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. Where a legal obligation requires us to keep a record, deleting your account does not delete that record; the categories where this applies are listed below, so that our commitment to erasure is not stated more broadly than we can honour.
-
Account data: retained for the lifetime of your account. When you delete your account, your personal data is deleted immediately, except: (a) records we are required to retain by law — such as the accounting, tax, and screening records described below, which are separated from your active profile and retained; (b) a short period needed to purge data from routine backups; and (c) if you were a Creator, your Creator credit — your Creator name and profile image, as they appeared at the time of sale — on content you sold to End-Users. This credit is preserved as attribution on those End-Users' purchases, as a fixed record detached from any active profile, so that buyers keep access to the recipe they paid for by you. It is limited to content that was actually purchased or accessed under a subscription, we make no new use of it, and it is not a live or updatable profile. We retain it on the legal bases of: performing our contract with those buyers; your agreement to this under the Creator Program (Terms Section 7.9); the legitimate interests of buyers and of Rouxbarb ApS in the integrity of purchased content; and the establishment or exercise of legal claims. See Terms Sections 7.5 and 7.9.
-
Personalisation data: your behavioural affinity profile is not stored as a lasting record. It is recomputed from your recent activity each time your feed is generated and held only in a short-lived cache (approximately 30 minutes) before it expires; your generated recommendation feed is likewise held in a short-lived cache. The underlying interaction events are retained for the lifetime of your account and deleted when you delete your account.
-
Declared interests: retained until you remove them in Settings → My Interests (removal takes effect immediately) or delete your account, whichever comes first. Withdrawing consent for a declared interest deletes it; withdrawal does not affect the lawfulness of personalisation carried out before withdrawal.
-
Voice input and transcripts: voice input for the Kitchen Assistant is processed in real time and the resulting transcripts are not retained beyond the active session — they are purged when the session ends.
-
Usage and analytics data: retained in an aggregated or anonymized form for up to 26 months.
-
Communications: retained for up to 24 months after the inquiry is resolved.
-
Email preferences and consent records (newsletter, marketing, and lifecycle emails): your subscription status and the record of when and how you gave or withdrew consent are retained for as long as you hold a Rouxbarb account, to evidence consent and to keep honouring your preferences. When your account is deleted, these records are deleted with it. We retain only a minimal suppression entry (your email address and the fact that it must not be contacted) after account deletion, so that your opt-out continues to be honoured. Unsubscribing takes effect immediately for future sends, though you may occasionally receive a message that was already in transit.
-
Suppression list: we maintain a suppression list of email addresses that must not be contacted — addresses that have opted out, hard-bounced, generated a spam complaint, or been suppressed manually. Each entry contains only the email address and the reason it must not be contacted. Suppression entries are retained for as long as necessary to prevent unwanted contact, which in practice means they are not deleted, on the basis of our legitimate interest in honouring opt-outs and maintaining email deliverability (Art. 6(1)(f)) and, for opt-outs, our legal obligation to respect them (Art. 6(1)(c)). Because deleting a suppression entry would defeat its purpose — it exists to ensure we do not contact you — an erasure request does not extend to the suppression entry itself.
-
Accounting records (Creator transaction history, payout and earnings ledger, purchase settlement records): retained for 5 years from the end of the relevant financial year, as required by the Danish Bookkeeping Act (Bogføringsloven). For a Creator's records we count this as five years from 31 December of the year of your last payout or earning. This retention applies regardless of account deletion and overrides any shorter preference expressed by the Creator. If you delete your account while Creator Earnings are unsettled, your earnings stay attributed to you in our records so that we can settle them and report them (see our Terms, Section 15.2).
-
Creator payout account details held in the vault: retained while you are an active Creator (superseded versions are kept so that past payouts remain auditable). When you delete your account, the references held in the application database are deleted with it (or, if you have unsettled Creator Earnings, after the final payout run that settles them), and the vault records are scheduled for deletion at the end of the accounting retention period above (five years from 31 December of the year of your last payout or earning) and are deleted then.
-
The postal address you enter with your bank details: kept while you are a Creator (earlier versions are kept so we can show which address a past payout was sent to) and deleted when you delete your account, or, if you have unsettled Creator Earnings, after the final payout run that settles them.
-
Tax documentation and reporting records: retained after you delete your account for five years from 31 December of the year of your last payout or earning, or for longer where the platform tax-reporting regime under which they were collected requires it, and then deleted.
-
Sanctions-screening records: retained as evidence that we carried out the screening required of us. Because their purpose is to evidence a compliance step that has already taken place, these records survive deletion of the account they relate to and are kept for five years from 31 December of the year of the last payout they relate to, and then deleted; they are never visible to other users and are accessible only to authorised administrators.
9. Your Rights Under the GDPR
If you are in the EU/EEA, you have the following rights regarding your personal data:
-
Access: request a copy of the personal data we hold about you.
-
Rectification: request correction of inaccurate or incomplete data.
-
Erasure: request deletion of your data ("right to be forgotten"), subject to the limited exceptions in Section 8 — including records we must keep by law (accounting, tax, and sanctions-screening records), suppression entries (which exist to ensure we do not contact you), and, if you were a Creator, the retained Creator credit on content you have sold to End-Users.
-
Restriction: request that we limit how we process your data.
-
Data portability: receive your data in a structured, machine-readable format.
-
Objection: object to processing based on legitimate interest, including personalised recommendations (via the feed-mode control in Settings or by contacting us — if you object to personalisation, we stop generating personalised recommendations, discard any cached affinity data, and serve you non-personalised content), lifecycle emails (via the unsubscribe link in any lifecycle email), and to direct marketing.
-
Withdraw consent: withdraw consent at any time where processing is based on consent (for example, marketing communications (unsubscribe link in any email, or Profile > Settings > Account > Newsletter), or interests you have declared in Settings → My Interests — remove a tag or clear your interests there, and it is deleted and no longer used). Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Service (transactional) emails, such as sign-in links, security notices, and receipts, are necessary to provide the Service and are not affected by marketing opt-outs.
If you are a Creator, note that we cannot settle payouts without the payout and tax information described in Section 2.4, and that sanctions screening before each payout is a legal obligation we cannot disapply at your request. Objecting to, or withdrawing, that processing means we are unable to make payouts to you; it does not affect your other rights.
To exercise any of these rights, contact us at the address provided in Section 15. We will respond within one month of receipt of your request. That period may be extended by up to two further months where necessary, taking into account the complexity and number of requests, in which case we will inform you within one month of the reasons for the delay. You also have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet) or another relevant supervisory authority.
10. Your Rights Under the CCPA/CPRA (California Residents)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA/CPRA"), grants you additional rights, to the extent it applies to Rouxbarb ApS:
-
Right to know: you may request details about the categories and specific pieces of personal information we have collected about you, the sources of that information, our business purposes for collecting it, and the categories of third parties with whom we share it.
-
Right to delete: you may request that we delete the personal information we have collected from you, subject to certain exceptions.
-
Right to correct: you may request that we correct inaccurate personal information we hold about you.
-
Right to opt out of sale or sharing: Rouxbarb ApS does not sell or share personal information as those terms are defined under the CCPA/CPRA. If this changes, we will provide a "Do Not Sell or Share My Personal Information" link.
-
Right to limit use of sensitive personal information: you may request that we limit the use of any sensitive personal information to that necessary to provide the Service.
-
Right to non-discrimination: we will not discriminate against you for exercising any of your CCPA/CPRA rights.
To exercise these rights, contact us at the address provided in Section 15. We will verify your identity before processing your request and respond within 45 days.
Residents of other jurisdictions with comparable privacy legislation — including other US states, the United Kingdom, Canada, Australia, and New Zealand — may exercise equivalent rights available to them under their local law by contacting us at the same address; we apply the standards described in this policy to all users, regardless of where they live.
11. Children's Privacy
The Service is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16, we will take steps to delete that information promptly.
Where a user is aged 16 or 17, they may use the Service on the basis set out in our Terms of Service (which requires the consent of a parent or legal guardian). We process the personal data of users aged 16 and 17 on the same bases described in this Privacy Policy, apply data minimisation, and do not direct marketing specifically at them.
Creators who apply to receive payouts through the platform must be at least 18 years of age. By joining the Creator Program, Creators confirm that they meet this requirement. We may ask for proof of age or identity before settling a payout (see our Terms, Section 7.4(c)); where we use a specialist verification provider for this, we receive the result rather than the underlying identity documents. If you believe we may have collected data from a child under 16, please contact us.
12. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption in transit and at rest, access controls, audit logging, regular security review, and employee training. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Protection proportionate to sensitivity. We hold different kinds of data with different levels of protection:
-
Social and content data (your profile, recipes, comments, likes, follows, declared interests) is isolated per user in the database itself, with the visibility rules of the Service applied on top.
-
Operational data (email address, authentication identifiers, push tokens, device and build information, support tickets, consent records, purchase ledger) is additionally restricted to administrative access with role checks and append-only audit logging.
-
Creator bank details and taxpayer identification numbers are held in a separate, dedicated environment in the EU: an encrypted vault, in a separate cloud project from the application, in a single EU region (Frankfurt). Each record is encrypted with its own key under a customer-managed key hierarchy, decryption happens at a single controlled point in our systems, the vault database is not reachable from the public internet, and every access is recorded in an append-only audit log. The application database holds only masked references to these (for example the account country, the last digits, and the holder name), never a full account number or taxpayer identification number. Your tax-reporting details (legal name, address, date of birth, tax residence) and the postal address you enter with your bank details are held in the application database in the United States, with access limited to authorised administrators (and, for the postal address, to you).
Incident response. In the event of a personal data breach, we will notify the Danish Data Protection Agency (Datatilsynet) without undue delay and, where feasible, within 72 hours of becoming aware of it, in accordance with Article 33 of the GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in accordance with Article 34 of the GDPR. Where users in other jurisdictions are affected, we notify the relevant authority and affected users as required by the law applicable to them. We maintain internal incident runbooks so that these steps are carried out promptly.
13. Changes to This Privacy Policy
Where we make material changes to this policy — including changes to what data we collect, how we use it, or who we share it with — we will update the "Effective" date at the top of this policy and post the revised version at rouxbarb.com/legal/privacy. We may also post a notice on the Platform to draw your attention to significant changes.
Where a change affects processing that relies on your consent (for example, marketing communications, or your explicit consent to the use of declared interests), we will obtain your fresh consent before the change takes effect for that processing; continued use of the Service alone does not constitute acceptance of such changes. For changes that do not rely on your consent, your continued use of the Platform following the update constitutes your acceptance of the revised policy.
What changed in v8. This version describes in detail the payout, tax, and compliance data we process for Creators and the protections applied to it (Sections 2.4, 5, 12); states the legal bases for those activities, including sanctions screening and tax reporting (Section 3); sets out the retention periods that survive account deletion (Section 8); describes where Creator payout and tax data is stored and to whom it is disclosed (Sections 2.4, 7 and 12), including the postal address collected with bank details; and names our payout partners, Revolut and Airwallex, and our former payout provider, Stripe (Section 5). It does not change how we handle End-User data, declared interests, or personalised recommendations.
14. Beta Signup Privacy Notice
If you applied to join the Rouxbarb closed beta program, your signup data was collected and processed separately under our Beta Signup Privacy Notice, available at rouxbarb.com/legal/beta-privacy. That notice governs data collected during the beta application process only. This Privacy Policy applies once you become a registered user of the Platform, whether through beta conversion or direct signup at full launch. If you converted from a beta tester to a registered user, your data handling transitions to this Privacy Policy from the date your account was activated on the live Platform.
15. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:
Rouxbarb ApS | privacy@rouxbarb.com | rouxbarb.com
Vesterbrogade 74, 1620 København V, Denmark | CVR: 46028244
For complaints, you may also contact the Danish Data Protection Agency (Datatilsynet) at datatilsynet.dk.
← Back to home