Skip to content

Legal

Privacy Policy

Last updated: 3 June 2026

MAKAN APP LTD (“we”, “us”, “our”) operates the Makan mobile application (the “App”), the website at makanofficial.com (the “Site”), and the early-access waitlist (together, the “Services”). This Privacy Policy explains how we collect, use, store, and protect personal data when you use the Services.

We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who We Are

Data controller: MAKAN APP LTD

Registered address: 86–90 Paul Street, London, EC2A 4NE, United Kingdom

Contact email: support@makanofficial.com

MAKAN APP LTD is responsible for determining how and why personal data is processed under this Privacy Policy. We have not appointed a Data Protection Officer, as we are not required to; data-protection queries can be sent to the contact email above.

2. Personal Data We Collect

2.1 Account data (App)

  • Name or display name (if provided)
  • Email address
  • Username and unique user identifier
  • Account status
  • Account creation and activity timestamps

2.2 Meal content and social data (App)

Depending on how you use the App, we process:

  • Meal photos you upload
  • Captions or notes added to meals
  • Restaurant or location tags applied to meals
  • Audience settings selected for each post (just me, friends-only, or public)
  • Friend relationships and friend requests (Makan uses mutual friendships)
  • Likes, craves, and comments

2.3 Technical, usage, and security data (App and Site)

  • Device and app information required to operate the Services, such as device type, operating system, and app version
  • Usage and analytics events (for example, which screens are opened and which features are used), collected to understand and improve the Services
  • Approximate location derived from your IP address, used for aggregate analytics
  • Security, abuse-prevention, and diagnostic logs used to protect users and the Services

2.4 Location data (App)

With your permission, the App accesses your device's location to show you nearby places and calculate distances to restaurants. You can grant or revoke this permission at any time in your device settings. If you decline, location-based discovery features are limited, but the rest of the App works normally. We use your location to provide these features at the time you use them and do not build a history of your movements.

2.5 Waitlist and enquiry data (Site)

If you join the early-access waitlist or contact us through the Site, we process the name and email address you submit, and a timestamp, so we can send you a beta invitation (delivered via TestFlight) and respond to you.

We do not intentionally collect special category personal data. However, user-generated content may reveal sensitive information. You should avoid uploading personal data you do not wish to be processed.

3. How We Use Personal Data

We use personal data to:

  • Create and manage user accounts
  • Provide core App functionality, including saving meals and displaying feeds according to your selected audience settings
  • Operate the friend graph, including friend requests and mutual friendships
  • Synchronise content across your devices
  • Show nearby places and calculate distances, using your device location where you have granted permission
  • Operate the waitlist and send beta invitations
  • Maintain security, prevent abuse, and protect the integrity of the Services
  • Respond to support enquiries
  • Understand usage and improve the reliability, performance, and design of the Services

We do not sell personal data, we do not use personal data for third-party advertising, and we do not use AI to generate, infer, or analyse the content of your meals.

4. Lawful Bases for Processing

Under UK GDPR, we rely on the following lawful bases.

4.1 Contract

Processing is necessary to provide the App and its core features once you create an account.

4.2 Legitimate interests

Processing is necessary for internal operations such as security, abuse prevention, understanding usage, and improving the reliability of the Services. We balance these interests against your rights and expectations.

4.3 Consent

We rely on your consent when you join the waitlist or submit an enquiry, and for any optional analytics technologies that require consent. You can withdraw consent at any time by contacting us or unsubscribing.

5. Sharing and Visibility Controls

The App supports different visibility settings. What other users can see depends on the choices you make.

  • Public posts are visible to other users and may appear in discovery features within the App
  • Friends-only posts are visible only to your mutual friends
  • Private posts are visible only to you within your personal meal diary

If you change the audience of a post or delete it, the change is applied within the App. Copies may remain temporarily in device caches or system backups for limited periods, as described in the retention section.

6. Service Providers (Processors)

We use the following providers to operate the Services. Each processes personal data on our behalf under contractual terms that require appropriate security and confidentiality.

  • Google LLC (Firebase)— the App's backend. We use Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, and Firebase Analytics to store and synchronise account and meal data, operate core features, and understand usage.
  • Vercel Inc. — hosting for the Site, and Vercel Web Analytics, which measures aggregate Site usage.
  • Google LLC (Google Sheets) — secure storage of waitlist and enquiry submissions.
  • Resend — delivery of transactional emails, such as your beta invitation.
  • Apple Inc. — distribution of the App through TestFlight and the App Store.

We do not use third-party advertising SDKs or cross-app tracking technologies. If we introduce additional processors, we will update this Privacy Policy before those changes take effect.

7. Cookies and Similar Technologies

The Site uses Vercel Web Analytics, which is privacy-friendly and cookieless: it identifies visits using a hash that resets daily and cannot track you across days or across other websites. It stores no information on your device and collects no personal identifiers, so it does not require a consent banner.

The App uses Firebase Analytics, which relies on device identifiers to measure how features are used. Because this stores and accesses information on your device, we ask for your consent within the App before enabling non-essential analytics, and you can change your choice at any time in the App's settings. We never use these technologies for advertising or cross-app tracking.

8. International Data Transfers

Some of our providers — including Google, Vercel, Resend, and Apple — process personal data outside the United Kingdom, including in the United States.

Where international transfers occur, we rely on appropriate safeguards recognised under UK law, such as the UK International Data Transfer Agreement or Addendum, the UK extension to the EU Standard Contractual Clauses, or transfers to providers certified under an applicable data protection framework. You can request more information about these safeguards using the contact details above.

9. Security

We apply technical and organisational measures designed to protect personal data, including encryption in transit, access controls, and server-side security rules.

No system is completely secure, but we take reasonable steps to protect data against unauthorised access, loss, or misuse. If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the Information Commissioner's Office, and affected users where required, within the timeframes set by law.

10. Data Retention

We retain personal data only for as long as necessary for the purposes described in this Privacy Policy.

10.1 Active accounts

Account data and meal content are retained while an account remains active.

10.2 Deleted accounts

When an account is deleted, personal data is deleted or anonymised within 30 days, unless a longer retention period is required by law or necessary for security purposes such as preventing abuse.

10.3 Waitlist data

Waitlist and enquiry data is retained until you ask us to remove it, or until it is no longer needed for the purpose it was submitted for.

10.4 Backups and security logs

  • Backups may retain data for up to 35 days as part of system resilience and recovery processes
  • Security and abuse-prevention logs may be retained for up to 180 days

11. Your Rights

Under UK GDPR, you have the right to:

  • Access your personal data
  • Request correction of inaccurate data
  • Request deletion of personal data
  • Request restriction of processing in certain circumstances
  • Request data portability where applicable
  • Object to processing in certain circumstances
  • Withdraw consent where we rely on it

You can delete your account at any time from within the App, which begins the deletion process described above. To exercise any other right, contact us at support@makanofficial.com. We may request information to verify your identity, and we handle requests within the time limits required by law.

You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.

12. Children

You must be at least 13 to create an account. Because a service like ours may be accessed by people under 18, we follow the UK Age Appropriate Design Code (the Children's Code). In practice this means:

  • Privacy-protective defaults — new posts default to friends-only, not public
  • Location access is off by default and only used, with permission, at the moment you use a location feature
  • We collect the minimum data needed and do not profile users or use data for targeted advertising
  • We do not use manipulative design or nudges to push you to share more than you intend

If we become aware that personal data has been collected from a child under 13, we will take steps to delete that data. If you believe a child has provided us with personal data, please contact us.

13. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal or similarly significant effects, and we do not use AI to generate or interpret your meal content.

14. Changes to This Policy

We may update this Privacy Policy from time to time.

The updated version will be published with a revised “Last updated” date. Where the change is significant, we will take reasonable steps to notify you, for example within the App or by email.