C
Cravr
Get the App

Privacy Policy

Cravr Pte. Ltd. ("Cravr", "we", "our", "us") operates the Cravr mobile application, related websites, and services (collectively, the "Services"). This Privacy Policy explains what personal data we collect, how and why we use it, who we share it with, and the choices and rights available to you. It is drafted to comply with the Singapore Personal Data Protection Act 2012 ("PDPA") and, where applicable to you, the EU/UK General Data Protection Regulation ("GDPR") and other data protection laws.

By creating an account, downloading, or otherwise using the Services, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of your personal data as described here. If you do not agree, please do not use the Services. Where consent is the legal basis for a specific type of processing (for example, precise location or marketing messages), we will ask for that consent separately and you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

1. Data Controller

Cravr Pte. Ltd.
Registered in Singapore
Data Protection Officer contact details are provided at the bottom of this page.

2. Information We Collect

We collect the following categories of personal data. We collect only what is necessary to operate the Services described in this Policy — we do not seek to collect biometric, health, financial account, or other sensitive data categories beyond what is described below.

2.1 Information You Provide Directly

  • Account information: name, email address, phone number, date of birth, username, password, profile photo
  • Profile details: bio, cuisine preferences, dietary preferences (e.g. halal), city/country, is-private setting
  • User content: reviews, ratings, photos, captions, comments, posts, check-ins, and messages you send to other users or restaurants
  • Social graph: who you follow, who follows you, and the group plans you create or join (including the names/emails of people you invite)
  • Restaurant/business information: for claimed or business accounts, restaurant name, address, contact details, opening hours, menu and deal content, team member invitations
  • Wallet and transaction information: top-up amounts, points balance, transaction history, and currency preference. Full card numbers are processed by our payment processor and are never stored on our servers
  • Communications: support tickets, incident reports, moderation reports, and any correspondence with us

2.2 Information We Collect Automatically

  • Device information: device model, operating system and version, unique device and advertising identifiers, app version, language and locale settings
  • Log data: IP address, access times, crash logs, and diagnostic/performance data
  • Location data: with your permission, precise or approximate GPS location, used to power nearby discovery, distance-to-restaurant display, and map features
  • Usage data: screens viewed, swipe/vote/save actions, search queries, feature usage, session length, and interaction patterns, used to personalise your feed and improve the Services
  • Push notification tokens: a device token (via Expo/Apple/Google push services) used solely to deliver notifications to your device — we do not use this token for advertising purposes
  • Biometric login: if you enable Face ID, Touch ID, or fingerprint unlock, this is processed entirely on your device by its operating system. Cravr never receives, stores, or has access to your biometric data itself — only an encrypted session token is stored to let your device unlock the app

2.3 Information from Third Parties

  • Social/OAuth sign-in providers (Apple, Google, or similar): the name, email, and profile picture you authorise them to share with us
  • Restaurant data: publicly available business information (name, address, hours) sourced from public listings, which business owners can claim and correct
  • Referral and invite information: if another user invites you to a group plan or refers you to Cravr, we receive the contact details they provided to make that invitation

3. How We Use Your Information

We use your personal data for the following purposes:

  • Providing, operating, maintaining, and improving the Services, including new features as they are released
  • Personalising your discovery feed, search results, and recommendations based on your preferences, location, and past activity
  • Operating social features: follows, posts, comments, likes, group plan voting, and messaging
  • Processing wallet top-ups, points, badges, and other rewards-program activity
  • Sending service, transactional, and (with your consent, where required) marketing notifications and messages
  • Facilitating communication between users, and between users and restaurants/businesses
  • Detecting, investigating, and preventing fraud, abuse, security incidents, and violations of our Terms of Service
  • Moderating content, responding to reports, and enforcing community guidelines
  • Complying with legal, tax, and regulatory obligations under Singapore law and other applicable laws
  • Conducting internal analytics, testing, and research to understand usage patterns and improve app performance, stability, and user experience
  • Aggregating and anonymising data for statistical, product-development, and business-intelligence purposes

4. Legal Basis for Processing (GDPR)

For users in the European Economic Area or United Kingdom, we process your data under the following legal bases:

  • Contract: processing necessary to create your account and provide the Services you request
  • Legitimate interests: improving and securing our Services, preventing fraud and abuse, and internal analytics — balanced against your rights and interests
  • Consent: precise location access, marketing communications, biometric-login enablement, and other optional features
  • Legal obligation: compliance with applicable tax, accounting, and regulatory requirements

5. Cookies, SDKs, and Similar Technologies

The Cravr mobile app does not use browser cookies, but it does use comparable device-level technologies: local storage, mobile analytics SDKs, crash-reporting SDKs, and push-notification identifiers. Our web pages (including this one) may use essential cookies required for the site to function.

We do not currently run third-party advertising or ad-retargeting networks within the app. If this changes, we will update this Policy and, where required by law, obtain your prior consent. You can limit certain tracking through your device's privacy settings (for example, "Limit Ad Tracking" / "App Tracking Transparency" on iOS, or ad personalisation settings on Android). Disabling analytics or crash-reporting technologies may affect our ability to diagnose issues affecting your experience, but will not prevent you from using core features of the app.

6. Push Notifications

With your permission, we send push notifications for things like new messages, group plan invites and votes, follows, likes, deal alerts, and account activity. You can disable push notifications at any time through your device settings, or manage specific notification categories from within the app. Disabling notifications will not affect your ability to use the Services, though you may miss time-sensitive updates (such as a group plan's voting deadline).

7. Sharing Your Information

We do not sell your personal data, and we do not share it with third parties for their own independent marketing purposes. We share information in the following circumstances:

  • Other users: your public profile, posts, reviews, and any content you choose to make public are visible to other users. Content visibility is affected by your privacy settings (e.g. private-account toggle)
  • Restaurants/businesses: when you message, check in at, or interact with a restaurant listing, relevant interaction details are shared with that business
  • Group plan members: when you join or are invited to a group plan, your profile, vote, and participation are visible to other members of that plan
  • Service providers and sub-processors acting on our behalf, including authentication (Supabase), file/media storage (Cloudflare R2), push notification delivery (Expo/Apple/Google), and payment processing — each is bound by a data processing agreement limiting their use of your data to providing services to us
  • Legal and safety purposes: to comply with a legal obligation, respond to lawful requests from public authorities, enforce our Terms of Service, or protect the rights, property, or safety of Cravr, our users, or the public
  • Business transfers: if Cravr is involved in a merger, acquisition, financing, or sale of assets, your data may be transferred as part of that transaction. We will notify you of any such transfer and any change in how your data is handled

8. Rewards, Wallet, and Promotional Features

Cravr may offer a points system, wallet balance, badges, and promotional features such as scratch cards or prize draws (where available in your region and permitted by local law). Participation is entirely optional. Points, badges, and other in-app rewards have no cash value, are non-transferable, and cannot be redeemed for cash except where we explicitly state otherwise. We may modify, suspend, or discontinue any rewards feature at any time. We collect activity data related to these features (such as which promotions you engage with) to detect fraud, prevent abuse, and evaluate the effectiveness of the program. Any game of chance we offer, if any, is provided for entertainment purposes and is subject to additional terms, eligibility rules, and applicable law at the time it is offered.

9. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Services. Specific retention practices include:

  • Account, profile, and content data: retained until you delete your account, plus a limited grace period to allow account recovery
  • Deleted accounts: your profile and posts are soft-deleted immediately and hidden from other users; underlying records are permanently deleted or irreversibly anonymised within 30 days, except where retention is required below
  • Messages and group plan data: retained while the relevant conversation or plan exists, or until all participants have left/deleted it
  • Financial and transaction records (wallet top-ups, points transactions): retained for at least 7 years to meet Singapore IRAS record-keeping requirements
  • Security, fraud, and moderation records: retained for as long as necessary to investigate and prevent abuse, even after account deletion
  • Aggregated/anonymised analytics data, which can no longer identify you, may be retained indefinitely

You may request deletion of your account at any time through Profile → Settings → Delete Account, or by contacting us using the details at the bottom of this page.

10. Location Data

We request access to your device's location to show you nearby restaurants and enable distance-based discovery, search, and map features. Location access is optional — you can use Cravr without it, but discovery accuracy will be reduced. You can grant, restrict (e.g. "While Using the App"), or revoke location permission at any time in your device settings. We do not share your precise real-time location with restaurants or other users; group plan members and restaurants only see information you explicitly choose to share (e.g. a check-in).

11. Security

We implement technical and organisational security measures designed to protect your personal data, including:

  • TLS/HTTPS encryption for all data in transit
  • Encryption of sensitive data at rest
  • Role-based access controls restricting staff access to personal data on a need-to-know basis
  • Secure authentication via industry-standard JWT tokens, with biometric unlock processed entirely on-device
  • Periodic review of our security practices as the Services evolve

No method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security. If you believe your account has been compromised, contact us immediately using the details at the bottom of this page and change your password.

12. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: request a copy of the personal data we hold about you
  • Correction: request correction of inaccurate or incomplete data (many fields can be edited directly in-app under Profile → Settings)
  • Deletion: request deletion of your personal data ("right to be forgotten"), subject to the retention exceptions in Section 9
  • Portability: receive your data in a structured, commonly-used, machine-readable format
  • Objection: object to processing based on our legitimate interests
  • Restriction: request that we restrict processing of your data in certain circumstances
  • Withdraw consent: withdraw consent at any time where processing is based on consent, without affecting past lawful processing

To exercise any of these rights, contact our Data Protection Officer using the details at the bottom of this page. We will verify your identity and respond within the timeframe required by applicable law (generally within 30 days under the PDPA). If you choose not to provide certain personal data, or later withdraw consent, you may be unable to access certain features of the Services. You also have the right to lodge a complaint with the Singapore Personal Data Protection Commission (PDPC) at pdpc.gov.sg, or with your local supervisory authority if you are in the EEA/UK.

13. Children's Privacy

Our Services are not directed to children under 13, and we do not knowingly collect personal data from children under 13. Users between 13 and 18 should have parental or guardian consent to use the Services, consistent with our Terms of Service. If we become aware that a child under 13 has provided us personal data, we will delete it promptly. A parent or guardian who believes their child has provided us personal data should contact us using the details at the bottom of this page.

14. International Transfers

Your data may be processed and stored in Singapore or other countries where our service providers operate (for example, cloud infrastructure and push-notification providers). Where we transfer personal data outside of the jurisdiction in which it was collected, we take steps to ensure it receives an adequate level of protection, including entering into Standard Contractual Clauses or equivalent safeguards approved by the relevant regulator where required.

15. Third-Party Services and Links

The Services may contain links to, or integrations with, third-party websites, restaurant booking systems, payment processors, or social media platforms. We are not responsible for the privacy practices, content, or security of those third parties, and this Policy does not apply to them. We encourage you to review the privacy policy of any third-party service before providing it with personal data.

16. Do Not Track

Some browsers offer a "Do Not Track" signal. Because there is no common industry standard for how to respond to such signals, our web properties do not currently respond differently based on a "Do Not Track" signal.

17. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes to our practices or for legal, operational, or regulatory reasons. We will notify you of material changes through the App, by email, or by updating the "Last Updated" date at the bottom of this page. Your continued use of the Services after changes take effect constitutes your acknowledgement of the revised Policy.

18. Contact Us

For privacy-related enquiries, including requests to our Data Protection Officer, contact us at:

Cravr Pte. Ltd.

Email: support [at] cravrapp [dot] com

Last Updated: 11 July 2026
© 2026 Cravr Pte. Ltd.. All rights reserved.