Effective Date: April 3, 2026
Privacy Questions? support@sonomachef.com
■ Privacy at a Glance
| Personal data collected | None |
| Data sold or shared | Never |
| Advertising | None — no ads, no trackers |
| Analytics / telemetry | None |
| Third-party SDKs | None that collect data |
| Children’s data | Not collected |
| Data stored | Solely on your device |
| Applicable law | California CCPA/CPRA · GDPR · Apple guidelines |
Sonoma Chef is a read-only guide to food, wine, and farmstands in Sonoma County. Because the app does not collect, transmit, sell, or share any personal information, most traditional privacy obligations simply do not arise. This policy documents that commitment in full.
1. About This Policy
This Privacy Policy applies to the Sonoma Chef iOS mobile application (“App”, “we”, “us”, or “our”). It describes our data practices in compliance with:
- The California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), Cal. Civ. Code § 1798.100 et seq.
- The EU/UK General Data Protection Regulation (GDPR / UK GDPR).
- The Apple App Store Review Guidelines and iOS privacy framework, including App Tracking Transparency (ATT).
- All other applicable U.S. state and federal privacy laws.
By downloading or using the App, you acknowledge this policy. If you do not agree, please uninstall the App.
2. Information We Do Not Collect
Sonoma Chef is designed with privacy-by-default. We do not collect, store, process, transmit, sell, share, or otherwise use any personal information. Specifically, we do not collect:
2.1 Identity & Contact Data
- Names, email addresses, phone numbers, or postal addresses.
- Account credentials, usernames, or passwords (no accounts required).
2.2 Device & Technical Data
- Device identifiers (IDFA, IDFV, serial numbers, or MAC addresses).
- IP addresses or network information.
- Operating system version, device model, or hardware specifications.
- Crash reports or diagnostic data sent to us.
2.3 Location Data
- Precise or approximate GPS location.
- Wi-Fi or Bluetooth proximity data.
The App may display a map (using Apple Maps or similar system-provided components). Any location services invoked are handled entirely by iOS and Apple — we receive no location data from those interactions.
2.4 Behavioral & Usage Data
- Pages viewed, taps, scrolls, or other in-app interactions.
- Search queries entered within the App.
- Session duration, frequency of use, or retention metrics.
2.5 Financial Data
- Payment information of any kind. The App is a one-time purchase of $4.99 on the Apple App Store; all payment processing is handled exclusively by Apple and we receive no financial or billing data from that transaction.
2.6 Sensitive Personal Information
- Racial or ethnic origin, religious beliefs, health data, biometric data, sexual orientation, immigration status, or union membership.
3. Cookies, Tracking, and Advertising
The App does not use cookies, pixel tags, web beacons, fingerprinting, or any cross-app or cross-site tracking technologies. We do not serve advertisements, sponsored content, or affiliate promotions within the App. We do not integrate any advertising SDK (e.g., Google AdMob, Meta Audience Network) or marketing automation platform.
Because we do not engage in tracking, we do not display an App Tracking Transparency (ATT) prompt. No IDFA is requested or used.
4. Third-Party Services
The App does not embed third-party analytics SDKs (e.g., Firebase, Mixpanel, Amplitude), social-media SDKs, or crash-reporting tools that transmit data to external servers. Any links within the App to restaurant websites, winery pages, or farmstand listings open in your default browser. Those third-party websites have their own privacy policies; we are not responsible for their practices.
Apple’s standard iOS services (e.g., iCloud sync, Apple Maps) may be invoked by the operating system. Apple’s privacy practices are governed by Apple’s own Privacy Policy at https://www.apple.com/legal/privacy/.
5. Children’s Privacy
The App is not directed to children under 13 (U.S.) or under 16 (EU/EEA/UK). Because we collect no personal data from anyone, we cannot and do not knowingly collect data from minors. If you believe a minor has somehow provided personal information in connection with the App, please contact us and we will investigate promptly (although we do not anticipate this scenario given our zero-data model).
6. California Privacy Rights (CCPA / CPRA)
California residents have rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of the sale or sharing of personal information. Because Sonoma Chef collects no personal information, these rights have no practical application to our App. We do not sell, share, or disclose personal information to third parties for any purpose.
We do not discriminate against California residents who exercise their privacy rights. We will respond to any verifiable consumer request within the timeframes required by law.
6.1 Shine the Light
California Civil Code § 1798.83 (“Shine the Light”) permits California residents to request information about disclosure of personal information to third parties for direct marketing purposes. We do not disclose personal information to third parties for direct marketing.
7. GDPR Rights — EU, EEA, and United Kingdom
If you are located in the European Economic Area or the United Kingdom, the GDPR and UK GDPR grant you the following rights with respect to your personal data. Because we do not process any personal data, these rights are moot in practice; however, we acknowledge them and will respond to any request promptly.
- Article 15 — Right of AccessYou may request confirmation of whether we process your data (we do not) and a copy of any data held.
- Article 16 — Right to RectificationYou may request correction of inaccurate personal data.
- Article 17 — Right to Erasure (Right to be Forgotten)You may request deletion of your personal data.
- Article 18 — Right to RestrictionYou may request that we restrict processing of your personal data.
- Article 20 — Right to Data PortabilityYou may request your data in a structured, machine-readable format.
- Article 21 — Right to ObjectYou may object to processing based on legitimate interests or for direct marketing.
- Article 22 — Right against Automated Decision-MakingWe do not engage in automated decision-making or profiling.
Legal Basis for Processing: We have no legal basis to declare because we process no personal data. We do not rely on consent, contract, legitimate interest, or any other GDPR basis.
International Data Transfers: No personal data is transferred outside your jurisdiction because no personal data is collected.
Supervisory Authority: EU/EEA users have the right to lodge a complaint with their national data protection authority. UK users may contact the Information Commissioner’s Office (ICO) at https://ico.org.uk.
8. Data Security
The best data security is not collecting data in the first place. Because Sonoma Chef stores all content locally on your device and transmits nothing to our servers, the risk of a data breach affecting your personal information through our App is effectively zero. The App content (restaurant listings, winery information, farmstand details) is static editorial content and contains no user-specific data.
9. Data Retention
We retain no personal data because we collect none. App content is cached locally by iOS according to your device settings. Deleting the App removes all associated local data.
10. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the “Effective Date” at the top of this document and post the revised policy within the App. We encourage you to review this policy periodically. Continued use of the App after changes become effective constitutes acceptance of the revised policy.
11. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
| App | Sonoma: Food, Wine, Farmstands |
| support@sonomachef.com | |
| Region | Sonoma County, California, United States |
We will respond to all privacy-related inquiries within 30 days (or sooner as required by applicable law). For GDPR requests, the response period is 30 days from receipt of a verifiable request, extendable by a further two months for complex requests.
