MADFRESH
OrderMeal PlansCateringAbout UsOur ImpactLaunch Party
Log InStart Order
Back to Home

Privacy Policy

Last updated: May 13, 2026

Mad Fresh Kitchen (“we,” “us,” or “our”) operates the website and mobile application at madfresh.app(the “Service”). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our Service, place orders, or otherwise interact with us.

By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this policy, please do not access the Service.

1. Information We Collect

Personal Information You Provide

When you create an account, place an order, or contact us, we may collect:

  • Full name
  • Email address
  • Phone number
  • Delivery address
  • Payment information (processed securely through Stripe — we do not store your full card number)
  • Order history and meal preferences
  • Dietary restrictions or allergy information you share
  • Account login credentials

Information Collected Automatically

When you access the Service, we may automatically collect:

  • Device information (browser type, operating system, device model)
  • IP address and approximate geographic location
  • Pages viewed, time spent, and navigation patterns
  • Referring URL and search terms
  • Cookies and similar tracking technologies

2. How We Use Your Information

We use the information we collect for the following purposes:

  • Order fulfillment: Processing, preparing, and delivering your meals
  • Account management: Creating and maintaining your account, managing subscriptions
  • Communications: Sending order confirmations, delivery updates, and customer support responses
  • Marketing: Sending promotional offers, menu updates, and newsletters (with your consent; you may opt out at any time)
  • Improvement: Analyzing usage patterns to improve our Service, menu, and user experience
  • Security & fraud prevention: Detecting and preventing fraudulent transactions or unauthorized access
  • Legal compliance: Meeting legal obligations and resolving disputes

3. Third-Party Services

We use trusted third-party service providers to operate the Service. These providers have access only to the information necessary to perform their functions and are obligated to protect your data:

Stripe — Payment Processing

Handles all payment transactions securely. Your credit card details are transmitted directly to Stripe and never touch our servers. Stripe is PCI DSS Level 1 certified. See Stripe's Privacy Policy.

Supabase — Authentication & Database

Provides secure user authentication and data storage. Your account credentials are encrypted and managed through Supabase's infrastructure. See Supabase's Privacy Policy.

Resend — Transactional Email

Delivers order confirmations, password resets, and other transactional emails. Resend processes your email address and name to deliver messages on our behalf. See Resend's Privacy Policy.

Vercel — Hosting & Infrastructure

Hosts and serves the Service. Vercel may collect standard web server logs including IP addresses and request data. See Vercel's Privacy Policy.

We do not sell, rent, or trade your personal information to third parties for their marketing purposes.

4. Cookies & Local Storage

We use cookies and browser local storage to:

  • Keep you signed in to your account
  • Remember your cart contents and preferences
  • Analyze site traffic and usage patterns
  • Improve the overall user experience

You can control cookies through your browser settings. Disabling cookies may affect the functionality of the Service.

5. Data Retention

We retain your personal information for as long as your account is active or as needed to provide you with the Service. We may also retain certain information as required by law, to resolve disputes, enforce our agreements, or for legitimate business purposes such as financial record-keeping.

Order history and transaction records are retained for a minimum of seven (7) years to comply with tax and accounting regulations. If you delete your account, we will remove your personal information within thirty (30) days, except where retention is required by law.

6. Data Security

We implement industry-standard security measures to protect your personal information, including encryption in transit (TLS/SSL), secure authentication, and access controls. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.

7. Your Rights & Choices

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request that we correct inaccurate or incomplete data
  • Deletion: Request that we delete your personal information, subject to legal retention requirements
  • Opt-out:Unsubscribe from marketing communications at any time by clicking the “unsubscribe” link in any email or contacting us directly
  • Data portability: Request your data in a commonly used, machine-readable format

To exercise any of these rights, please contact us at hello@madfresh.app. We will respond to your request within thirty (30) days.

8. California Privacy Rights (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with specific rights regarding your personal information, including the right to know what data we collect, the right to request deletion, and the right to opt out of the sale of personal information.

We do not sell your personal information. California residents may submit a verifiable consumer request to access or delete their personal data by emailing hello@madfresh.app. We will verify your identity before fulfilling any request and respond within forty-five (45) days.

9. Arizona Residents

Mad Fresh Kitchen is based in Tempe, Arizona. While Arizona does not currently have a comprehensive state privacy law equivalent to the CCPA, we are committed to providing all customers with transparency and control over their personal data regardless of their state of residence. Arizona residents may exercise the same rights described in Section 7 above.

10. Children's Privacy

The Service is not intended for individuals under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal information, we will take steps to delete such information promptly. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at hello@madfresh.app.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page and, for material changes, notify you via email or a prominent notice on the Service. Your continued use of the Service after any changes constitutes acceptance of the updated policy.

12. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us:

Mad Fresh Kitchen

Tempe, Arizona

Email: hello@madfresh.app

Website: madfresh.app