私隱政策
Privacy Policy
更新日期:2026 年 9 月 7 日 · Last updated: 7 September 2026
1.我哋係邊個
Who we are
飯腳 FoodFoot(foodfoot.app)係一個香港餐廳配對 web app:開枱、SHARE LINK 俾飯腳、各自 SWIPE、開估睇夾中邊間。呢份政策講明我哋收集咩資料、點用、存喺邊,同你有咩權利。
私隱相關查詢,請 email:aidonkey.work@gmail.com。
FoodFoot (飯腳, foodfoot.app) is a Hong Kong restaurant-matching web app: open a table, share the LINK with your dining partners, everyone swipes on their own phone, then reveal which restaurants you all liked. This policy explains what we collect, how we use it, where it is stored and what rights you have. Privacy enquiries: aidonkey.work@gmail.com.
2.我哋收集咩資料
What we collect
2.1 玩家(開枱/SWIPE)Players
玩飯腳唔使登記、唔使登入,我哋唔會問你攞姓名、電話或者 email。開枱同 SWIPE 會產生以下資料:
- 枱資料:枱號(5 位隨機代碼)、副牌入面嘅餐廳、你揀嘅篩選條件(地區、菜式、價位、幾多人、係咪一人枱)、開枱時間、邊啲玩家 SWIPE 完。
- SWIPE 記錄:每張牌你舉腳定踢走,連同枱號同你嘅玩家代碼。
- 玩家代碼:第一次入枱時由你嘅瀏覽器隨機生成(例如 p3k9x2a7;開枱嗰個固定係 a),淨係用嚟分開同一張枱入面唔同人嘅 SWIPE,唔會連結到你係邊個。
- 使用事件:撳分享/下載分享圖、開邀請 LINK、催飯腳等動作,連同枱號、動物人格代號、圖鑑集牌數同事件種類。入面冇個人資料。
- 動物飯腳圖鑑:你解鎖過邊幾隻動物,只存喺你部機嘅瀏覽器,唔會上載。
注意:任何人只要有張枱嘅 LINK,就可以睇到嗰張枱嘅開估結果(邊間夾中、幾多人舉腳)。請只 SHARE 俾你嘅飯腳。
No sign-up or login is needed and we never ask for your name, phone number or email. Opening a table and swiping generates: table data (a random 5-character table code, the restaurants dealt, the filters you chose — area, cuisine, price level, party size, solo or not — creation time, and which players have finished); swipe records (like or pass for each card, with the table code and your player code); a player code generated randomly in your browser on first visit (for example p3k9x2a7; the person who opens the table is always a), used only to tell players at the same table apart and not linked to your identity; usage events (share, download, invite LINK opened, nudge sent) with the table code, animal persona key, collection count and event type — no personal data; and your animal collection, kept only in your browser.
Note: anyone with a table’s LINK can view that table’s reveal (which restaurants matched and how many liked each). Share it only with your dining partners.
2.2 店主(/partner 登記)Restaurant owners
店主自助登記時,我哋收集:餐廳名、地區、菜式大類、人均價位、招牌菜、一句介紹、食物相(1 至 4 張)、餐廳 IG(可選)、聯絡人稱呼、WhatsApp 號碼、email(可選)、想搞咩(可選),同兩個同意選項(同意收集資料;願意接收推廣資訊)。
- 會公開:餐廳名、地區、菜式、價位、招牌菜、一句介紹、餐廳 IG、食物相——即時出現喺牌池俾玩家 SWIPE。
- 唔會公開:聯絡人稱呼、WhatsApp、email、想搞咩、推廣同意——只用於上架同合作聯絡;資料庫嘅存取規則令匿名訪客讀唔到呢啲欄位。
- 第一頁撳「下一步」嗰刻,餐廳名、聯絡人稱呼同 WhatsApp 會先記錄一次(就算你之後冇填完第二頁),等我哋跟得返。
- 食物相會上載到我哋嘅雲端儲存,以公開網址顯示喺卡面。
When an owner registers we collect: restaurant name, area, cuisine category, price level, signature dish, one-line intro, food photos (1 to 4), restaurant IG (optional), contact name, WhatsApp number, email (optional), what you want to do (optional), and two consent choices (consent to data collection; opt-in to marketing). Public: restaurant name, area, cuisine, price level, dish, intro, IG and photos appear in the deck immediately. Not public: contact name, WhatsApp, email, goal and marketing consent are used only to contact you about listing and partnerships; database access rules prevent anonymous visitors from reading these fields. When you press “Next” on step one, the restaurant name, contact name and WhatsApp are recorded once (even if you do not finish step two) so we can follow up. Photos are uploaded to our cloud storage and shown on the card via a public URL.
2.3 意見/報錯Feedback
首頁「意見 · 報錯」表格會收集:主題(可選)、內容、你自願留低嘅聯絡方式(IG/WhatsApp/email,可選),同你交表嗰刻所在嘅頁面路徑。請唔好喺內容留身份證、銀行等敏感資料。
The feedback form collects: subject (optional), message, any contact you choose to leave (IG / WhatsApp / email, optional), and the page path you were on when you submitted. Please do not include sensitive data such as ID or bank details.
2.4 Threads 授權用戶Threads-authorised user
Threads 搜索係營運者嘅內部工具,一般玩家同店主唔會、亦唔需要連接 Threads。如果你用「用 Threads 登入」授權咗,我哋點處理你嘅資料見第 8 節。
Threads search is an internal operator tool; players and owners never connect Threads. If you have authorised us via “Log in with Threads”, section 8 explains how your data is handled.
3.點用
How we use it
- 玩家資料:行個配對流程(等齊人、開估);計每間餐廳跨枱嘅真實舉腳累積數(卡面嘅腳仔);統計開枱數、完成率、分享數等營運指標。
- 店主資料:上架;就上架同 FOODIE 試食企劃聯絡你。只有你剔咗「願意接收推廣資訊」,我哋先會 send 推廣企劃資訊俾你,可隨時取消;冇剔就唔會收到推廣訊息。
- 意見資料:跟進你嘅問題;你留低聯絡方式我哋先會覆你。
- 我哋唔會出售你嘅資料,亦唔會用嚟做個人化廣告。
Player data runs the matching flow (waiting for everyone, reveal), builds each restaurant’s real cumulative like count shown on cards, and gives us operating metrics (tables opened, completion rate, shares). Owner data lists your restaurant and lets us contact you about listing and FOODIE tasting campaigns; marketing messages are sent only if you ticked the marketing opt-in, and you can withdraw at any time. Feedback is used to follow up on your issue and reply if you left a contact. We do not sell your data or use it for personalised advertising.
4.資料存喺邊、邊個處理
Where data lives and who processes it
- Supabase
- 資料庫同相片儲存。枱、SWIPE、使用事件、店主登記、意見全部存喺度。Database and photo storage for tables, swipes, events, owner registrations and feedback.
- Vercel
- 網站寄存同 Web Analytics(頁面瀏覽統計:路徑、來源、裝置類型等)。Hosting and Web Analytics (page views: path, referrer, device type).
- Telegram
- 有新店主登記、店主留 lead、或者有人交意見時,資料庫會經我哋伺服器即時 send 一條通知去營運者嘅 Telegram,內容包括該筆登記/意見嘅文字欄位(店主嘅 WhatsApp、email 都會喺入面;相片唔會)。When an owner registers, leaves a lead, or someone submits feedback, our server sends the text fields of that record (not photos) to the operator’s Telegram as a notification.
- Google Fonts
- 字體由 Google 伺服器派送,你嘅瀏覽器會直接向 Google 請求字體檔。Fonts are served by Google; your browser requests the font files directly from Google.
- Meta(Threads API)
- 只涉及用「用 Threads 登入」授權咗嘅用戶,見第 8 節。Applies only to users who logged in with Threads; see section 8.
外部連結:卡面同分區頁會 LINK 去餐廳官方 Instagram 同傳媒報導;離開 foodfoot.app 之後,資料處理由該網站負責。
External links: cards and area pages link to restaurants’ official Instagram accounts and to press coverage. Once you leave foodfoot.app, that site’s own privacy policy applies.
5.Cookie 同瀏覽器儲存
Cookies and browser storage
- ff-player-<枱號>
- localStorage。你喺該枱嘅玩家代碼,留喺你部機直至你清除瀏覽器資料。Your player code for that table.
- ff-dex
- localStorage。你解鎖過嘅動物圖鑑。Your unlocked animal collection.
- ff-mgm
- sessionStorage。營運者「睇數」頁嘅密碼,閂 tab 即清;一般用戶唔會有。Operator dashboard password, cleared when the tab closes; ordinary users never have it.
- ff_threads_state
- httpOnly cookie。撳「用 Threads 登入」時設定嘅一次性登入狀態碼,10 分鐘到期,授權完即清。One-time OAuth state, expires in 10 minutes.
- ff_threads_token
- httpOnly cookie。你嘅 Threads access token,約 60 日到期,登出即清。見第 8 節。Your Threads access token, about 60 days; cleared on logout. See section 8.
- ff_threads_user
- cookie(非 httpOnly)。你嘅 Threads 用戶名(冇用戶名就存用戶 ID),俾頁面顯示已登入邊個;同 token 一齊到期。Your Threads username (or user ID if none), shown on the page; expires with the token.
我哋冇用廣告 cookie,亦冇第三方追蹤 cookie。
We use no advertising cookies and no third-party tracking cookies.
6.保留幾耐
Retention
- 枱、SWIPE、使用事件、店主登記、意見:目前冇自動刪除機制,會一直保留,直至你要求刪除(見第 7 節)。
- 瀏覽器儲存:留喺你部機直至你清除瀏覽器資料(Safari 可能喺 7 日冇訪問後自動清走)。
- Threads cookie:約 60 日到期,或者你喺 /threads 頁登出即清。見第 8 節。
Tables, swipes, events, owner registrations and feedback: there is currently no automatic deletion; data is kept until you ask us to delete it (section 7). Browser storage stays on your device until you clear site data (Safari may clear it after 7 days without a visit). Threads cookies expire after about 60 days or when you log out on /threads; see section 8.
7.你嘅權利
Your rights
根據香港《個人資料(私隱)條例》,你有權查閱、更正同要求刪除你嘅個人資料。Email aidonkey.work@gmail.com,我哋會喺 40 日內回覆。
- 店主:請講明餐廳名同登記時用嘅 WhatsApp 號碼。
- 玩家:我哋唔知邊個玩家代碼係你,請提供枱號(LINK 最尾嗰 5 位代碼)。
- 意見:請提供大約交表時間同內容。
- 取消推廣資訊:email 我哋,或者我哋 WhatsApp 你嗰陣直接講。
刪除步驟詳見 資料刪除。
Under the Hong Kong Personal Data (Privacy) Ordinance you may access, correct and request deletion of your personal data. Email aidonkey.work@gmail.com and we will reply within 40 days. Owners: state the restaurant name and the WhatsApp number used to register. Players: we cannot tell which player code is yours, so include the table code (the 5 characters at the end of the LINK). Feedback: give the approximate time and content. To withdraw marketing consent, email us or tell us when we WhatsApp you. See Data deletion for steps.
8.Threads 資料
Threads data
飯腳 FoodFoot 用 Meta 嘅 Threads API 搜尋公開 Threads 帖文,作為餐廳熱度嘅內部參考訊號。呢個功能係營運者嘅內部工具(/threads 頁),唔係玩家或者店主功能——玩飯腳、登記餐廳都唔需要連接 Threads。如果你用「用 Threads 登入」授權咗(例如營運者本人、Meta 審核人員),以下適用:
- 我哋攞到咩:你嘅 Threads access token(threads_basic、threads_keyword_search 權限)、你嘅 Threads 用戶 ID 同用戶名,以及你搜索時 Threads 回傳嘅公開帖文(帖文 ID、文字、時間、用戶名、連結、媒體類型、係咪回覆)。
- 點存:access token 只存喺你自己瀏覽器嘅 httpOnly cookie(約 60 日到期),伺服器唔會儲存、唔會寫入日誌、唔會回傳俾瀏覽器 script。用戶名存喺另一個 cookie,俾頁面顯示「已登入 @邊個」。搜索結果只喺當次請求同你嘅瀏覽器記憶體入面用,唔會存入資料庫。將來如果推出熱榜功能,只會儲存每間餐廳嘅提及次數聚合(餐廳、次數、統計期、取數時間),唔會儲存任何個別 Threads 用戶或者帖文嘅資料。
- 撤銷授權:Threads app → Settings → Account → Website permissions → 移除「飯腳 FoodFoot」。撤銷後 token 失效,Meta 會自動通知我哋。你亦可以喺 /threads 頁撳登出,即時清走呢啲 cookie。
- 撤銷/刪除通知:Meta 通知我哋你撤銷授權或者要求刪除資料時,會附上你嘅 Threads 用戶 ID;我哋只會將佢(連同刪除確認碼)記錄喺伺服器日誌作核對用,冇其他資料需要刪除。
- 刪除要求:資料刪除 一頁有詳細步驟同狀態查詢。
FoodFoot uses Meta’s Threads API to search public Threads posts as an internal signal of restaurant buzz. This is an operator tool (the /threads page), not a player or owner feature — using FoodFoot or listing a restaurant never involves Threads. If you have authorised us via “Log in with Threads” (for example the operator or a Meta reviewer), the following applies. What we receive: your Threads access token (threads_basic, threads_keyword_search), your Threads user ID and username, and the public posts returned when you search (post ID, text, timestamp, username, permalink, media type, whether it is a reply). Storage: the access token lives only in an httpOnly cookie in your own browser (about 60 days); our server does not store it, log it or return it to browser scripts. Your username is kept in a second cookie so the page can show who is logged in. Search results are used within the request and your browser’s memory only and are never written to our database. If a buzz ranking is launched later, we will store only aggregate mention counts per restaurant (restaurant, count, window, fetched time), never data about individual Threads users or posts. Revoke: Threads app → Settings → Account → Website permissions → remove FoodFoot; the token becomes invalid and Meta notifies us. You can also press log out on /threads to clear these cookies immediately. Deauthorise / deletion notifications: Meta sends us your Threads user ID when you revoke access or request deletion; we record only that ID (with the deletion confirmation code) in our server logs for reconciliation, and there is nothing else to delete. Deletion requests: see the Data deletion page for steps and status lookup.
9.政策更新
Changes
有改動會直接更新呢一頁同頂部嘅日期。
Changes are published on this page and reflected in the date at the top.