Privacy Policy

Last updated: August 15, 2026.

Ponch is operated by UXsimple Inc. ("we", "us", or "our"), a company incorporated in Canada. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use the Ponch mobile application (the "App"), and describes the rights available to you depending on where you live.

By creating an account or using the App, you agree to the practices described in this policy.

1. Who We Are

For users in the European Economic Area (EEA) or United Kingdom, UXsimple Inc. acts as the data controller for personal information processed through the App.

2. Information We Collect

2.1 Account Information

We use Sign in with Apple for authentication. Depending on your choices at sign-in, we may receive:

  • Your Apple-generated unique user identifier

  • Your name (only if you choose to share it)

  • A real or Apple-relay email address (only if you choose to share it)

We never receive or store your Apple ID password.

2.2 Location Data

With your permission, we collect your device's approximate or precise location to:

  • Detect your current country for local dish discovery

  • Find restaurants and places near you serving a selected dish

  • Set a different location when you use travel mode, so you can browse and find places in a city you are not currently in

Location is collected only when you actively use the Find Nearby feature or on first launch to determine your country. We do not track your location continuously or in the background. You can revoke location permission at any time through your device settings.

If you use travel mode, we store the location you select so the app can keep showing results for that city across sessions. You can change or clear it at any time in the app.

2.3 Usage and Analytics Data

We use PostHog to understand how the app is used and to diagnose problems. This includes:

  • Features used and screens visited

  • Session duration and interaction patterns

  • Crash reports and error logs

  • Device type, operating system version, and app version

  • Session replays, described below

Session replays. We may record a sample of app sessions to see how people move through the app and where it fails. Not all sessions are recorded. Recordings capture screen interactions, not audio, camera, or anything outside the Ponch app.

Text you type, and the screens where you set dietary preferences and allergen filters, are masked in these recordings and are not visible to us in replay form. Session replays are not recorded for users in the European Economic Area or the United Kingdom.

This data is linked to your account identifier. We do not use it to build advertising profiles and we do not sell it.

2.4 User-Generated Content

If you submit a dish suggestion or send feedback through the App, we collect the content of that submission and associate it with your account identifier.

2.5 Preferences and App State

We store your saved dishes, hidden dishes, and appearance preferences (light or dark mode) so your experience stays consistent across sessions and devices.

Food preferences. During onboarding and in your profile settings, we collect the cuisines you enjoy, the cuisines you would rather skip, your dietary preference (for example vegetarian or vegan), and any allergen filters you set (for example dairy, gluten, or nuts). We use this only to order and filter what the app shows you. We do not use it for advertising and we do not share it with third parties for their own purposes.

Dietary and allergen information may reveal something about your health or beliefs, so we treat it as sensitive. We collect it only if you choose to provide it, you can change or remove it at any time in your profile, and the app works without it.

Referral source. During onboarding we ask how you heard about Ponch. We use this to understand which channels bring people to the app. It is not shared with third parties for their own purposes.

2.6 Notifications

With your permission, the app sends you notifications, for example when a Find Nearby search finishes while the app is in the background. These are generated and delivered on your device. No notification content is sent to our servers or to any third party. You can turn notifications off at any time in your device settings.

3. Legal Bases for Processing (EEA and UK Users)

If you are located in the EEA or UK, we process your personal data under the following legal bases as required by the General Data Protection Regulation (GDPR) and UK GDPR:

  • Account information (Sign in with Apple): Performance of a contract — necessary to provide your account and the core App experience.

  • Location data: Consent — we request explicit permission before accessing your location.

  • Usage and analytics data: Legitimate interests — to keep the app stable and improve how it works, balanced against your privacy rights. Session replays are not recorded for users in the EEA or UK.

  • User-generated content (submissions, feedback): Performance of a contract / Legitimate interests — to process your request and improve the service.

  • Saved dishes, hidden dishes, and app preferences: Performance of a contract — necessary to deliver the features you have chosen.

  • Cuisine preferences and referral source: Legitimate interests — to order what the app shows you and to understand how people find us.

Dietary preference and allergen filters: Consent — you choose whether to provide this, and we ask for it explicitly. Where this information reveals health or religious belief, we rely on your explicit consent under Article 9(2)(a) GDPR. You can withdraw it at any time by clearing these settings in your profile.

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

Where we rely on legitimate interests, you have the right to object (see Section 9).

4. How We Use Your Information

We use the information we collect to:

  • Authenticate you and maintain your account

  • Determine your location for dish discovery and nearby place search

  • Sync your saved dishes, hidden dishes, and preferences across sessions

  • Filter and order dishes according to your cuisine, dietary, and allergen preferences

  • Generate AI-refined search queries to find relevant places near you

  • Process dish suggestions and feedback you submit

  • Enforce usage limits and distinguish free from premium features

  • Diagnose bugs, monitor performance, and improve the App

  • Comply with legal obligations

We do not sell your personal information. We do not use your data to serve you third-party advertising.

5. How We Share Your Information

We do not sell, rent, or trade your personal information. We share data only in the following circumstances:

5.1 Service Providers

We work with third-party companies to operate the app. They are contractually restricted to using your data only to perform services on our behalf, and may not use it for their own purposes. Our main providers are:

  • PostHog — product analytics, crash reporting, and session replay.

  • RevenueCat — subscription management. RevenueCat receives your app user identifier and purchase history to determine which tier you are on. Payment details are handled by Apple and never reach us or RevenueCat.

  • Apple — Sign in with Apple and in-app purchase processing.

  • AI providers — used to turn the dish you select into a search query. We currently use Google (Gemini) and OpenAI, and we may change providers over time; this list is kept current. We send the dish, your approximate location, and, where relevant to the search, your dietary preference or allergen filters, so that results reflect what you can eat. We do not send your name, email, or account identifier. These providers do not supply place data and do not use your data to train their models.

  • Mapping and location providers — used to find places near you that serve the dish. We send only what the search needs: the query and your approximate location.

5.2 Apple

Sign in with Apple and any in-app purchases are processed by Apple and governed by Apple's Privacy Policy.

5.3 Legal Requirements

We may disclose your information if required to do so by law, regulation, court order, or lawful request from a government authority, or where we believe disclosure is necessary to protect the rights, property, or safety of UXsimple Inc., our users, or others.

5.4 Business Transfers

If UXsimple Inc. is involved in a merger, acquisition, financing, or sale of all or part of its assets, your information may be transferred as part of that transaction. We will notify you via the App or email before your information becomes subject to a materially different privacy policy.

6. International Data Transfers

UXsimple Inc. is based in Canada. Canada has been recognized by the European Commission as providing an adequate level of data protection for commercial organizations subject to PIPEDA, meaning transfers of your personal data from the EEA to Canada are permitted without additional safeguards.

For any transfers to other countries (for example, where our service providers are located), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission or equivalent mechanisms recognized under applicable law.

Our analytics and subscription providers process data in the US. Where that involves a transfer outside your country, we rely on the safeguards described above.

7. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the App's features.

Session replays are retained for 7 days and then deleted. Analytics events are retained for 12 months.

If you delete your account, we will delete or anonymize your personal data within 30 days, except where we are required to retain certain information for legal, tax, or regulatory purposes.

8. Your Rights — All Users

Regardless of where you live, you have the right to:

  • Access your data — request a copy of the personal information we hold about you

  • Correct your data — request correction of inaccurate or incomplete information

  • Delete your account — directly within the App via Profile → Delete Account, or by contacting us

  • Withdraw location consent — at any time via your device's location settings

To submit any request, contact us at legal@ponch.app. We will respond within 30 days.

9. Your Rights — EEA and UK Users (GDPR / UK GDPR)

In addition to the rights above, if you are located in the EEA or UK, you have the right to:

  • Erasure ("right to be forgotten") — request deletion of your personal data where there is no compelling reason for continued processing

  • Restriction of processing — request that we limit how we use your data in certain circumstances

  • Data portability — receive your personal data in a structured, machine-readable format and transmit it to another controller

  • Object to processing — object to processing based on legitimate interests or for direct marketing purposes

  • Not be subject to automated decision-making — we do not make decisions based solely on automated processing that produce legal or similarly significant effects on you

To exercise any of these rights, contact us at legal@ponch.app.

You also have the right to lodge a complaint with your local supervisory authority:

  • EEA: Your national data protection authority (e.g. CNIL in France, BfDI in Germany)

  • UK: The Information Commissioner's Office (ICO) at ico.org.uk

10. Your Rights — California Residents (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you additional rights.

We do not sell or share your personal information for cross-context behavioral advertising. You do not need to opt out because we do not engage in these practices.

You have the right to:

  • Know what personal information we collect, use, disclose, and retain, and for what purpose

  • Delete your personal information (subject to certain exceptions)

  • Correct inaccurate personal information

  • Opt out of sale or sharing — not applicable, as we do not sell or share personal information

  • Limit use of sensitive personal information — we use dietary, allergen, and location data only to provide the features you have asked for, never to infer characteristics about you. You can clear dietary and allergen settings in your profile and revoke location permission in your device settings at any time.

  • Non-discrimination — we will not discriminate against you for exercising your CCPA rights

To submit a verifiable consumer request, contact us at legal@ponch.app. We will respond within 45 days as required by law. You may designate an authorized agent to make requests on your behalf.

Categories of personal information collected in the preceding 12 months:

  • Identifiers (Apple user ID, email) - collected, not sold or shared.

  • Geolocation data - collected, not sold or shared.

  • Internet or network activity (usage analytics) - collected, not sold or shared.

  • Inferences drawn from usage data - collected, not sold or shared.

  • Sensitive personal information (dietary preference and allergen filters, which may indicate health status or religious belief; precise geolocation) - collected, not sold or shared.

11. Your Rights — Canadian Residents (PIPEDA / Quebec Law 25)

Your personal information is protected under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). If you are in Quebec, additional protections apply under Quebec's Act Respecting the Protection of Personal Information in the Private Sector (Law 25).

You have the right to:

  • Access the personal information we hold about you

  • Challenge the accuracy and completeness of your information and request correction

  • Withdraw consent to our collection or use of your information (subject to legal and contractual restrictions)

  • Lodge a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca

Quebec residents may also contact the Commission d'accès à l'information (CAI) at cai.quebec.ca.

12. Children's Privacy

Ponch is not directed at children under the age of 13 (or 16 in the EEA, where applicable local law sets this threshold). We do not knowingly collect personal information from children below the applicable age in their jurisdiction. If you believe a child has provided us with personal information without appropriate parental consent, please contact us at legal@ponch.app and we will promptly delete it.

13. Security

We implement reasonable and appropriate technical and organizational measures to protect your personal information against unauthorized access, disclosure, alteration, or destruction, including encrypted data transmission and access controls.

No method of electronic transmission or storage is completely secure. We cannot guarantee absolute security, but we are committed to protecting your data and will notify you of any breach as required by applicable law.

14. Third-Party Services

The App integrates with third-party services including mapping and location APIs. These services operate under their own privacy policies, which we encourage you to review. We are not responsible for the data practices of third parties.

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal obligations. When we make material changes, we will update the "Last updated" date at the top of this page and, where required by law, notify you through the App or by email.

Your continued use of the App after the effective date of any changes constitutes your acceptance of the revised policy.

16. Contact Us

For questions, concerns, or to exercise any of your rights under this policy:

UXsimple Inc. (operating as Ponch) Email: legal@ponch.app Website: https://ponch.app

We aim to respond to all inquiries within 30 days.

Ponch © 2026

Ponch © 2026

Ponch © 2026

Ponch © 2026