Website privacy and cookies policy
Last updated 12 July 2026
This policy explains what we do with personal data about you — as a visitor to this website, as someone who contacts us, or as a customer. If anything here is unclear, write to dpo@tasteradar.ai and a person will answer you.
Who we are
TasteRadar is operated by Roving Rock Pte Ltd (UEN 201204989G), a company incorporated in Singapore. In this policy, “we” and “TasteRadar” mean Roving Rock Pte Ltd, and we are the controller of the personal data described below.
Our Data Protection Officer is Shalabh Pandey. You can reach the DPO at dpo@tasteradar.ai about anything in this policy, including any request to access, correct or delete your data.
The data we collect about you
Personal data means information from which a living individual can be identified. It does not include data where the identity has been removed. We collect the following:
| What | Why, and on what basis | How long we keep it |
|---|---|---|
| Enquiry data — your name, work email, company, job title, phone number, markets of interest, and what you tell us about your use case, when you submit the Request Access form | To assess and respond to your request. Our basis is the request you made of us, and our legitimate interest in replying to it. | Up to 24 months from your last contact with us, unless you ask us to delete it sooner |
| Account data — name, email, company, and the markets your subscription covers | To operate your account, authenticate you, and control what your seat can see. Necessary to perform our contract with you. | For the life of the account, then 12 months, then deleted |
| Transaction data — billing and invoice records | To bill you, and to meet the record-keeping obligations Singapore law places on us. | As long as the law requires us to retain accounting records |
| Marketing preference — whether you asked to hear from us | To send you market insights and product updates. Our basis is your consent, and we only have it if you actively ticked the box. | Until you unsubscribe |
| Technical data — your IP address, browser and device type, approximate location, and the pages you viewed | To keep the site secure and working, to tell humans apart from bots, and — see Cookies and analytics — to understand which of our content is worth writing. Our basis is our legitimate interest in running and improving the site, and your consent where we ask for it. | Aggregated. We do not build a profile of you as an individual. |
We do not collect special-category data — no health, biometric, financial account, or government identification data — and we ask you not to send it to us.
Publicly available information
TasteRadar analyses publicly available information about food, drink and restaurants in order to identify trends. That material occasionally contains personal data — for example, a name written inside the text of a public restaurant review.
We are not interested in who people are. We do not seek to identify individuals, we do not build profiles of them, and we do not index or search our data by any person’s identity. What we extract is the substance: the dish, the flavour, the sentiment, the price, the outlet.
If you believe information about you sits in TasteRadar and you want it removed, email dpo@tasteradar.ai with enough detail for us to find it, and we will delete it.
Disclosures of your personal data
We do not sell your personal data, and we do not share it so that anyone else can advertise to you. We share it only with:
- Service providers acting as processors, who provide hosting, database, email delivery, security and IT services to us. These include, but are not limited to, Supabase, Vercel, Resend and Cloudflare. They act only on our instructions and are bound to protect your data.
- Professional advisers — lawyers, accountants, auditors and insurers — where they need it to advise us.
- Regulators and authorities, where the law requires us to disclose it, or where we need to establish or defend a legal claim.
- An acquirer, if we sell, merge or transfer part of our business. If that happens, we will tell you before your data changes hands.
A current list of the processors we use is available to enterprise customers on request, and is set out in our data processing agreement.
International transfers
We are based in Singapore and your account data is stored in Singapore. Some of our service providers operate in the United States and elsewhere, so your data is transferred there. Where personal data protected by UK or EU law is transferred out of those regions, we rely on the Standard Contractual Clauses in our agreements with those providers.
Cookies and analytics
Strictly necessary — no consent needed
When you sign in, a cookie keeps you signed in; without it the product cannot work. Our bot check may set a short-lived token to confirm you are not a machine. These are essential, and we set them without asking, as we are permitted to.
Analytics
We use a privacy-preserving web analytics service to count page views and see where visitors came from, so we know which of our writing is worth doing more of. It tells us that forty people read a page. It does not tell us who they were. It sets no cookies, does not follow you to other websites, and does not build an advertising profile of you.
What we do not do
We set no advertising cookies and no tracking cookies. We run no advertising pixels and no session recording, and we do not follow you across other websites. Because we place nothing non-essential on your device, there is no consent banner to click here — there is nothing to consent to.
If that changes, this policy changes first, and we will ask you before anything new runs.
Your rights
Wherever you live, you can ask us to show you the personal data we hold about you, correct it if it is wrong, or delete it. If you are in the EU or UK, you can also ask us to export it, restrict how we use it, or object to our using it. If you are in California or a comparable US state, you can ask what we have collected and ask us to delete it — and note that we do not sell or share personal data as those laws define it.
To exercise any of these, email dpo@tasteradar.ai. We will reply within 30 days. We will not charge you and we will not make it difficult.
You can unsubscribe from marketing email at any time using the link in the email, or by writing to us. We only send it if you asked for it.
How we protect your data
Data is encrypted in transit and at rest. Access to production systems is restricted and protected by multi-factor authentication. Customer data is isolated at the database level, so one customer’s seat cannot read another’s. Our forms are protected against automated abuse.
No system is perfectly secure, and we do not claim otherwise. If you are evaluating TasteRadar and need the detail of how we run security, write to us and we will walk you through it.
If something goes wrong
If a data breach occurs that is likely to cause you significant harm, we will notify you, and we will notify Singapore’s Personal Data Protection Commission within the timeframe the law requires. Enterprise customers’ rights are set out in their data processing agreement.
Children
TasteRadar is a business product and is not intended for anyone under 18. We do not knowingly collect data about children. If we learn that we have, we delete it.
Changes to this policy
If we change this policy materially — a new category of data, a new purpose, a new kind of tracking — we will update the date at the top and, for account holders, tell you by email. We will not quietly broaden what we do with your data.
Complaints
Come to us first — dpo@tasteradar.ai — and we will try to put it right. If you are not satisfied, you can complain to Singapore’s Personal Data Protection Commission, or, if you are in the EU or UK, to your local data protection authority.
Contact
Roving Rock Pte Ltd (UEN 201204989G), Singapore
Data Protection Officer: Shalabh Pandey — dpo@tasteradar.ai
General enquiries: hi@tasteradar.ai