Privacy Policy
Effective Date: April 8, 2026
Welcome to Fond & Flame ("we," "us," or "our"). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you visit our website at fondflame.com (the "Site").
Your privacy matters. We are committed to protecting your privacy and being transparent about our data practices. By using the Site, you agree to the collection and use of information in accordance with this policy.
Quick Summary
- We use cookies and analytics to improve the Site
- We do not sell your personal information
- You can opt out of analytics tracking
- You have rights to access, correct, and delete your data
- We comply with GDPR, CCPA, and other privacy laws
Data Controller: Fond & Flame is the data controller responsible for your personal information. Contact: privacy@fondflame.com
1. Information We Collect
Information You Provide Directly
Account Information: If you create an account, we collect your email address and an encrypted password. Account creation is optional — you can browse all recipes without an account.
Communications: If you contact us via email, we collect your email address and message content.
User-Generated Content: If you post comments, reviews, or recipe requests, we collect the content you submit and the timestamp.
Information Collected Automatically
Usage Data: When you visit the Site, we automatically collect:
- Pages visited and time spent on each page
- Referring website (how you arrived at our Site)
- Browser type, operating system, and device type
- Date and time of visit
This data is collected through our internal analytics system (stored in Supabase) and is used to understand which recipes are popular and improve the Site experience.
Information from Third Parties
Affiliate Networks: When you click affiliate links and make purchases, we may receive confirmation that a purchase was made and the commission amount earned. We do not receive your personal information, payment details, or specific purchase history from affiliate networks (Amazon Associates, ShareASale, CJ Affiliate).
2. Cookies & Tracking Technologies
Cookies are small text files stored on your device when you visit a website. They help websites remember preferences and analyze traffic.
Types of Cookies We Use
- Essential Cookies: Required for the Site to function (login sessions, preferences). Cannot be disabled.
- Analytics Cookies: Help us understand how visitors use the Site. We use an internal analytics system that tracks page views and referrers. No third-party advertising cookies are used.
- Functional Cookies: Remember your preferences (meal plan settings, view preferences). Stored in your browser's localStorage.
We do not use advertising cookies or third-party tracking cookies for targeted advertising.
Managing Cookies
You can manage cookies through your browser settings. Disabling cookies may affect some Site features (saved preferences, login sessions). You can also enable "Do Not Track" in your browser — we honor Do Not Track signals.
3. How We Use Your Information
Legal Basis for Processing (GDPR)
We process your data based on:
- Consent: You have given consent for specific purposes (analytics, email communications)
- Legitimate Interests: Operating and improving the Site, provided your rights do not override these interests
- Legal Obligation: Complying with legal requirements
We Use Your Information To:
- Provide access to recipes, guides, and educational content
- Analyze Site usage to improve user experience
- Identify and fix technical issues
- Respond to your inquiries and support requests
- Send account-related notifications (password resets, security alerts)
- Track affiliate link clicks and conversions
- Comply with legal obligations
We Do NOT:
- Sell your personal information to third parties
- Use your data for targeted advertising
- Share your information with data brokers
- Send unsolicited marketing emails
4. How We Share Your Information
We share your information with the following service providers, solely for the purposes described:
- AWS Amplify: Hosts the Site and serves content
- Supabase: Stores recipe data and user accounts
- Amazon S3 / CloudFront: Stores and delivers images
- Resend: Sends transactional emails (meal plan delivery, password resets)
- Affiliate Networks (Amazon Associates, ShareASale, CJ Affiliate): Track affiliate link clicks and conversions. These networks do not receive your personal information from us.
We may also disclose your information if required by law, court order, or government request, or to protect our rights, property, or safety. If Fond & Flame is acquired or merged, your information may be transferred to the new owner with prior notice.
5. Data Retention
- Page view analytics: Retained for 90 days, then purged
- Account data: Retained until you delete your account or request deletion
- Comments and reviews: Retained indefinitely unless you request deletion
- Email communications: Retained for 2 years
- Affiliate click data: Retained for 90 days
You can request deletion of your personal data at any time by emailing privacy@fondflame.com. We will process deletion requests within 30 days.
6. Your Privacy Rights
GDPR Rights (European Users)
If you are in the European Economic Area, you have the right to:
- Access: Request a copy of the personal data we hold about you
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your personal data
- Restriction: Request limits on how we use your data
- Data Portability: Request a copy of your data in a machine-readable format
- Object: Object to processing based on legitimate interests
- Withdraw Consent: Withdraw consent at any time
- Lodge a Complaint: File a complaint with your local data protection authority
CCPA/CPRA Rights (California Users)
If you are a California resident, you have the right to:
- Know: Request disclosure of what personal information we collect and how it's used
- Delete: Request deletion of your personal information
- Opt-Out: Opt out of the sale or sharing of personal information (we do not sell or share personal information)
- Correct: Request correction of inaccurate information
- Non-Discrimination: You will not be discriminated against for exercising your rights
Other State Privacy Laws
If you are a resident of Virginia, Colorado, Connecticut, Utah, or other states with privacy laws, you may have similar rights. Contact privacy@fondflame.com to exercise your rights.
How to Exercise Your Rights: Email privacy@fondflame.com with your request. We will respond within 30 days (45 days for CCPA requests).
7. Data Security
We implement reasonable security measures to protect your personal information, including:
- Encryption: Data transmitted between your browser and our servers is encrypted using SSL/TLS
- Secure Hosting: Site is hosted on AWS Amplify with industry-standard security
- Access Controls: Limited access to personal data on a need-to-know basis
- Password Protection: User passwords are hashed and encrypted
Data Breach Notification: In the event of a data breach affecting your personal information, we will notify you and relevant authorities within 72 hours as required by GDPR, or as required by applicable law.
No method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
8. Children's Privacy
Fond & Flame is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact privacy@fondflame.com. We will delete the information within 30 days.
9. International Data Transfers
Your information may be transferred to and processed in the United States, where our servers and service providers are located. The United States may have different data protection laws than your country of residence.
When we transfer data outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission. By using the Site, you consent to the transfer of your information to the United States.
10. Third-Party Links
The Site contains links to external websites, including affiliate partner sites, YouTube videos, and reference materials. We are not responsible for the privacy practices or content of third-party websites. When you click a link to an external site, you are subject to that site's privacy policy.
11. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. When we make material changes, we will update the "Effective Date" at the top of this page and post a notice on the homepage. Your continued use of the Site after changes are posted constitutes acceptance of the updated policy.
12. Contact Information
Questions about this Privacy Policy or how we handle your personal information?
Email: privacy@fondflame.com
Website: fondflame.com
If you are in the EEA and wish to contact our Data Protection Officer, email privacy@fondflame.com with "DPO Inquiry" in the subject line.
If you are in the EEA and believe we have not addressed your privacy concerns, you have the right to lodge a complaint with your local data protection authority.
See also: Terms of Service