Last Updated: May 14, 2026
Please select your country to view the applicable Privacy Policy for your region.
Welcome to CookWoW ("we," "our," "us"), operated by CookWoW. We are committed to protecting your privacy in accordance with the Saudi Arabia Personal Data Protection Law (PDPL). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website (cookwow.fun), mobile application, and related services (collectively, the "Platform"). By using the Platform, you consent to the data practices described in this policy.
We collect the following categories of personal data when you use our Platform:
We collect location data that you voluntarily provide, such as delivery addresses for meal orders and farm product purchases, restaurant locations entered by chefs, and farm locations entered by farmers. We do not automatically track your GPS location or share your precise location with other users. Location data displayed on public profiles (such as restaurant maps) is entered manually by the profile owner.
If you enable biometric login (fingerprint or Face ID) on our mobile app, authentication is performed entirely on your device using the device's secure enclave. We never receive, transmit, or store your biometric data. We only store a flag indicating that biometric login is enabled for your account.
We use the following tracking technologies:
• Firebase Analytics — for app performance monitoring and user behavior analysis • Google Analytics (G-4SVL3CK89C) — for website traffic analysis and conversion tracking • Google reCAPTCHA — for bot protection and fraud prevention • TikTok Pixel — for advertising conversion tracking • Meta (Facebook) Pixel — for advertising conversion tracking • Snapchat Pixel — for advertising conversion tracking • Session cookies — for authentication (14-day expiry, HTTP-only, secure) • localStorage — for user preferences (language, theme, country selection)
These technologies help us understand how users interact with our Platform, measure the effectiveness of our marketing, and improve the user experience. You can disable cookies in your browser settings, but this may affect Platform functionality.
We use collected information for the following purposes:
Under the Saudi Arabia Personal Data Protection Law (PDPL), we process your personal data based on the following legal grounds:
• Consent: You provide consent when creating an account, opting into WhatsApp notifications, or enabling push notifications. • Contractual necessity: Processing is necessary to fulfill our Terms of Service, process transactions, and deliver services you have requested. • Legitimate interest: We have a legitimate interest in preventing fraud, improving our Platform, and ensuring security. • Legal obligation: We may process data to comply with applicable Saudi laws, including tax reporting and financial regulations.
We may share your information in the following circumstances:
We use the following third-party services that process your data on our behalf:
• Firebase (Google Cloud) — Authentication, database, file storage, hosting, push notifications, analytics • Tap Payments — Credit/debit card payment processing (PCI DSS compliant) • PayPal — Alternative payment processing • Google Analytics — Website analytics • Google reCAPTCHA — Bot protection • TikTok for Business — Advertising pixel and conversion API • Meta (Facebook) — Advertising pixel and conversion API • Snapchat — Advertising pixel and conversion API • Amazon Web Services (AWS) — Live streaming infrastructure (IVS) • Stream (GetStream.io) — Live chat during streams • Vercel / Google Cloud Run — Application hosting
Each processor is contractually obligated to handle your data securely and only for the purposes specified.
Your data may be processed in countries outside Saudi Arabia, including the United States (Firebase, AWS, Stream), Ireland (Meta), and Singapore (TikTok). These transfers are necessary to operate our global Platform. We ensure appropriate safeguards are in place, including standard contractual clauses and processor agreements that meet PDPL requirements.
We retain your personal data for the following periods:
• Account data: As long as your account is active, plus 30 days after deletion request to allow recovery. • Transaction records: 7 years from the transaction date (required for tax and financial regulations). • User-generated content: Until you delete it or your account is deleted. Publicly shared content may persist in other users' caches temporarily. • Analytics data: 26 months (Google Analytics default retention period). • Push notification tokens: Until you uninstall the app or revoke notification permission. • Chat messages: As long as both conversation participants have active accounts. • Audit logs (admin actions): 3 years. • Failed payment attempts: 90 days.
After the retention period, data is permanently deleted or anonymized.
We retain wallet ledger records (top-ups, spends, refunds, invoices, receipts) for the period required by applicable tax and accounting law in the Kingdom of Saudi Arabia (currently five years from the end of the relevant tax period). These records persist after account closure to satisfy regulatory obligations, and we may retain additional records longer where required by law or where reasonably necessary to resolve disputes.
We implement industry-standard security measures to protect your data:
• All data transmitted between your device and our servers is encrypted using TLS/HTTPS. • Sensitive data (contact information, financial details) is stored in isolated Firestore subcollections with strict access rules. • Authentication uses Firebase Auth with support for multi-factor authentication (MFA). • Payment processing is handled by PCI DSS-compliant processors (Tap, PayPal) — we never store full card numbers. • Admin access is protected by role-based access control. • Webhook endpoints verify cryptographic signatures before processing. • Rate limiting is applied to sensitive endpoints to prevent abuse.
Despite these measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
Under the Saudi Arabia PDPL, you have the following rights:
• Right of Access: You can request a copy of your personal data by contacting us. • Right to Rectification: You can update your profile information at any time through your account settings. • Right to Erasure: You can request deletion of your account and associated data through Profile → Settings → Delete Account. Deletion is processed within 30 days. • Right to Restrict Processing: You can opt out of WhatsApp notifications, push notifications, and growth engine nudges in your settings. • Right to Data Portability: You can request an export of your data by contacting us at info@cookwow.fun. • Right to Object: You can object to processing based on legitimate interests by contacting us. • Right to Withdraw Consent: You can withdraw consent for optional data processing at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at info@cookwow.fun. We will respond within 30 days.
The Platform is not intended for children under 13 years of age. We do not knowingly collect personal data from children under 13. If we discover that a child under 13 has provided us with personal data, we will promptly delete that information. If you believe a child under 13 has provided us with personal data, please contact us at info@cookwow.fun.
Our mobile app (available on Google Play and Apple App Store) operates as a wrapper around our web platform (cookwow.fun). The app may request the following device permissions:
• Camera: For uploading profile photos, food content, and live streaming. • Microphone: For live streaming audio. • Photos/Media: For selecting images and videos to upload. • Notifications: For push notifications about orders, messages, and platform activity. iOS uses Apple Push Notification service (APNs) via Firebase Cloud Messaging; Android uses Firebase Cloud Messaging (FCM) directly. • Biometric sensors: For optional biometric login (Face ID/fingerprint). Biometric authentication is performed on-device by Apple/Android — we never receive your biometric data. • App Tracking Transparency (iOS only): iOS may show a prompt asking your permission to track activity across other companies' apps and websites. We do not currently track you across other companies' apps or websites and we do not request IDFA — accept or deny, the app's behavior is unchanged.
You can manage these permissions in your device settings at any time. Denying permissions may limit certain app features.
When you make an in-app purchase or subscription inside our iOS app, the purchase is processed by Apple In-App Purchase. On the web (cookwow.fun) and inside the Android app, purchases are processed by Tap Payments — see the Financial Information row in Section 1 for details. The iOS in-app purchase data we receive and store relates to two product types:
• Wallet top-ups (one-time consumables, e.g. cookwow_wallet_topup_sar_19_99) — credit you add to your CookWoW Wallet. • Wallet auto-top-up subscriptions (e.g. cookwow_wallet_sub_sar_9_99) — recurring monthly credit added to your wallet.
We store the following per Apple transaction, solely to grant the corresponding wallet credit, prevent fraud, and reconcile billing:
• Original transaction ID and per-purchase transaction ID issued by Apple. These identifiers are tied to your Apple ID, not to your CookWoW account directly. • Product identifier (the specific wallet product purchased) and Apple price tier. • Purchase environment (Sandbox or Production) — used to keep test purchases segregated from real ones. • Receipt / signed JWS payload that Apple issues to prove the purchase. We send this to Apple's App Store Server API to verify authenticity and renewal status. • For subscriptions: status events received via Apple App Store Server Notifications V2 (ASSN V2) — e.g., DID_RENEW, DID_FAIL_TO_RENEW, EXPIRED, REFUND, REVOKE. We use these events to extend or revoke wallet auto-top-up; we do not store the underlying credit-card data, which stays with Apple.
We do not receive your full Apple ID email, your payment instrument, or any device identifier beyond the transaction record. Apple's own privacy policy governs the data Apple collects from you when you transact in the App Store.
Legacy creator subscriptions: Some users have a legacy direct chef subscription that was purchased on an earlier version of the iOS app (product IDs starting with cookwow_subv*). For those legacy subscriptions, we receive the same set of transaction data described above and use it to maintain their access; new iOS purchases use the wallet products instead.
Apple App Privacy: A summary of the data we collect through the iOS app is also published on our App Store listing under "App Privacy." These summaries describe the same practices as this Privacy Policy in the format required by Apple.
On the web we use Google AdSense to display contextual ads in specific surfaces (e.g., the Meal Orders map and Restaurants page). On the iOS and Android apps we use Google AdMob to display the same placements where applicable.
• Identifier for Advertisers (IDFA, iOS) — We do not request IDFA via ATT and AdMob is configured to serve only non-personalized ads on iOS unless you explicitly opt in via the App Tracking Transparency prompt. If you tap "Ask App Not to Track," no IDFA is shared and ads remain non-personalized. • Android Advertising ID (AAID) — AdMob may use this identifier if you have not opted out of ad personalization in Google's Android settings. You can reset or opt out from your device's ad settings. • Frequency capping and contextual targeting are performed locally on-device by AdMob using non-personal signals (device type, app category, country). • We do not sell your personal data to AdMob or AdSense. AdMob and AdSense are Google products; Google's own privacy policy at policies.google.com/privacy describes how Google processes ad signals. • In-app analytics — We use Firebase Analytics in the mobile app for app-performance monitoring (crash counts, screen loads, login funnel). Firebase Analytics does not use IDFA on iOS without ATT consent.
You can request account deletion at any time through Profile → Settings → Delete Account, or by contacting us at info@cookwow.fun. Upon deletion:
• Your profile, content, and personal data will be removed within 30 days. • Transaction records will be retained for 7 years as required by financial regulations. • Content you shared publicly (comments, posts) may be anonymized rather than deleted to maintain conversation integrity. • Active subscriptions will be cancelled. • Pending payouts will be processed before account closure. • This action is irreversible after the 30-day recovery period.
CookWoW Wallet on account deletion: any remaining wallet balance is forfeited on account closure — wallet credit is held on your behalf to spend on the Platform and is not refundable as cash. If you wish to use up your wallet credit before closing the account, do so before requesting deletion. The wallet ledger (top-ups, spends, refunds) is retained as part of the 7-year financial-records retention period above; it is not deleted on account closure because tax and accounting law requires us to keep it.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on the Platform with a new "Last Updated" date, and for significant changes, by sending an email notification. Your continued use of the Platform after changes constitutes acceptance of the updated policy.
If you have questions or comments about this Privacy Policy, or wish to exercise your data protection rights, please contact us at: info@cookwow.fun