CrunchCall lets you tell friends you're heading to lunch and see who's already out. This policy explains what we collect, why, who can see it, and your rights. We've kept it short and plain.
Who we are
CrunchCall is run by Hasan Shahzad, an individual based in the United Kingdom, who is the "data controller" for your information. Contact: hello@crunchcall.app.
What we collect
- Account: your email address (to send sign-in codes), your name, username and role, and the workplace you choose (for example, a hospital).
- Friends: who you're friends with, friend requests, people you block, your private categories (like "Work"), and your alert settings for each friend.
- Lunch statuses: when you put out a CrunchCall or say you're at lunch, we store the place you pick (like "Mess"), the table you joined, an optional spot (like "window seats") and the time.
- Waves: who waved at whom, and when.
- Settings: who can see you, invisible mode, notification preferences, and whether your name shows at friends' tables.
- Notifications: if you allow them, a token that lets us send alerts to your phone.
- Reports: if you report someone, who reported whom, the reason and when.
We do not collect your GPS location, contacts, photos, health information or advertising identifiers. CrunchCall has no ads and no tracking, and we never sell your data.
Why we use it
- To run the app for you (our contract with you): signing you in, showing your lunch to the friends you choose, friends, waves and alerts.
- To keep people safe (our legitimate interests): rate limits, blocking, and reviewing reports of harassment or fake accounts.
- Phone notifications are only sent if you allow them, and you can turn them off at any time in the app or in your phone's settings.
Who can see what
- Anyone signed in can find you only by searching your exact username (at least 3 letters), and sees your name, username and role.
- Your lunch status is only shown to friends you allow ("Everyone", "Specific people" or "Categories"), and never while you're invisible or to anyone you've blocked.
- If you leave "Show my name at friends' tables" on, people who aren't your friends may see your name when you sit with their friends, never your status or times. You can turn this off in Profile.
- Your categories, settings and reports are private to you.
Who processes it for us
We use a few trusted services to run CrunchCall. They only handle your data on our instructions:
- Supabase: database and sign-in (servers in Ireland).
- Resend: sends sign-in code emails.
- Expo and Apple: deliver phone notifications, and Apple distributes the app.
- Cloudflare: hosts our domain and forwards emails sent to hello@crunchcall.app.
Some of these providers may process data outside the UK. Where they do, they use legal safeguards such as the UK's International Data Transfer Addendum or Standard Contractual Clauses.
How long we keep it
- Lunch statuses end automatically after 30, 60 or 90 minutes (you choose), and are replaced each time you go out again.
- Waves are deleted after 24 hours.
- Everything else is kept while you have an account. When you delete your account, your profile, friends, categories, settings, lunch statuses and waves are deleted straight away.
- Reports are kept for safety reasons, but your name is removed from reports you made once you delete your account.
Your rights
Under UK data protection law, you can ask to access, correct, delete or move your data, and object to or restrict how we use it. You can edit your profile and delete your account at any time in Profile → Delete account. For anything else, email hello@crunchcall.app, and we'll reply within one month.
If you're unhappy with how we've handled your data, you can complain to the Information Commissioner's Office at ico.org.uk.
Age
CrunchCall is for people aged 16 and over.
Changes
If we change this policy in a meaningful way, we'll update the date above and tell you in the app.