Privacy-First,
Anonymous Data Only
DinnerVeto does not require you to create an account, and we do not harvest personal identity data. We only store the minimum anonymous signals needed to keep your real-time room running.
What we store (and why)
- Temporary browser local storage — used to enforce free-round limits and remember the room you are currently in. It lives on your device and is never transmitted as an identity.
- Active game room IDs — the 4-digit room code and a per-room session identifier so the host and guest can sync votes in real time.
- Anonymous choice logs (veto_events) — which restaurant was vetoed or selected, with no link back to who you are. Strictly used to keep the multiplayer engine functional and to improve restaurant suggestions.
- Standard secure cookies during Stripe checkout — used only while you are processing payment for a premium pass.
What we never do
- No forced accounts. You can play the entire game without ever signing up.
- No personal identity data harvested — no email, name, phone, or address required.
- No persistent cross-session advertising identifier or third-party tracking pixels.
- No precise location stored after your restaurant search completes.
Payments & checkout cookies
When you purchase a premium pass, we hand the entire checkout flow off to Stripe (PCI Level 1). Standard secure cookies are used strictly to process that checkout — your card details never touch our servers, and the cookies are not used for advertising or cross-site tracking.
Optional sign-in
If you choose to sign in for extra free rounds or a premium pass, we use passwordless Google or Apple OAuth — we never see or store your password. Sign-in is always optional; the core game works fully without an account.
Questions? Email us at dinnerveto1@gmail.com.