Privacy Policy
This draft describes how RecipeYield (placeholder legal entity pending formation) (“RecipeYield,” “we”) handles information when you visit recipeyield.io, when a publisher installs our WordPress plugin, and when a reader sponsors a recipe. Counsel has not reviewed it.
Who we are
Controller (placeholder): RecipeYield (placeholder legal entity pending formation), United States. Contact: hello@recipeyield.io.
Information we collect
- Publishers. Site URL, contact name, email, phone, Stripe Connect account identifiers, license keys, ad-network credentials we store encrypted at rest, and the contents of weekly report emails.
- Readers. Email address (for a one-time passcode and receipts), optional public first name for the sponsor listing, the recipe URL purchased, duration, payment identifiers from Stripe, and a reader identifier derived from email.
- Usage. API logs (IP, user agent, route, status) with OTP codes, JWTs, and card data redacted. We do not log the one-time email code in plaintext.
- Ad metrics. Page-level RPM and impression data ingested from Raptive, Mediavine, AdSense, or a CSV the publisher sends, used only to price offers.
- Marketing site. Standard HTTPS request logs via Amazon CloudFront / S3. We do not set a first-party analytics cookie on recipeyield.io in this draft.
Email and Amazon SES
One-time passcodes and receipts are sent from no-reply-otp@recipeyield.io through Amazon SES (SMTP). Publisher onboarding and weekly reports use the same SES domain. Amazon processes the message to deliver it. We do not sell email lists.
Cookies
On the publisher’s domain, a successful sponsorship sets a first-party cookie named sponsor_ent (and sponsor_ent_1… if the token is large). It holds an ES256 JWT signed by our API. The plugin verifies it locally and does not call us on every pageview. The cookie’s lifetime matches the sponsorship (day, month, or year). See the Cookie Policy.
Payments
Card charges are processed by Stripe as Stripe Connect direct charges to the publisher. We receive payment intent identifiers, amounts, and status — not full card numbers. A later Zooot ledger, if enabled, stores wallet and transfer records on our MongoDB host.
Public sponsor names
If a reader supplies a display name, we may show up to three names on that recipe (“Sponsored by …”) and a “See all…” list. Do not submit someone else’s name. You may ask us to remove a listing by emailing from the same address used at checkout.
Retention
- OTP challenges: minutes, with a TTL, then deleted.
- Entitlements and payment grants: for the life of the sponsorship plus a limited accounting period (we expect on the order of years, not weeks).
- Ad metrics and offers: rolling operational window; older aggregates may be kept for publisher reports.
- Logs: typically 30–90 days unless needed for security or a dispute.
Subprocessors (illustrative)
- Amazon Web Services (EC2 API host, SES email, S3/CloudFront for this site, optional encrypted Mongo dumps).
- Stripe (payments).
- MongoDB running on our API host (not Atlas in the current deployment).
Rights (GDPR / CCPA-style)
If you are in a jurisdiction that grants access, correction, deletion, portability, or opt-out of sale/share, email us. We do not sell personal information. We may need to verify the request (for a reader, usually via the same email used at checkout). Publishers should route reader requests they receive to us when they concern our processing.
Security
TLS on the API and this site. JWT private keys stay on the API host. Ad-network credentials are encrypted at rest. This is not a guarantee against breach; report suspected issues to the contact above.
Children
The product is not directed at children. We do not knowingly collect information from anyone under 16.
Changes
We will update the date at the top of this page (8 September 2026 in this draft). Material changes to reader processing will be described here before they apply where the law requires.