This policy explains how UD MEM handles information when you browse, use account screens, customize a meal, or contact us. For privacy questions or requests, email mem@varughese.org.
1. Information and purposes
Accounts and sign-in. We store your verified email, account ID, notification preferences and seller setup details in our hosted database. Email sign-in uses a short-lived, single-use code. We store a protected representation of that code and limit verification attempts. A secure, HTTP-only cookie keeps you signed in. We’ll never ask for your university password or Grubhub login.
Orders and sales. We store meal selections, order and sale history, status changes, matching deadlines, seller assignments, pickup details, and payment references to operate the marketplace. Buyers see pickup details for their own orders. Sellers see the exact meal and options for eligible requests and their accepted sales. Authorized administrators can review records, manage orders, and suspend accounts with documented reasons. Administrative actions are recorded for accountability.
Payments. Stripe processes card details and billing addresses through its secure payment interfaces. UD MEM stores payment references and, when you choose to save a card, its brand, last four digits, and Stripe payment-method reference. We do not store full card numbers or security codes. Stripe Connect handles seller onboarding and payout details. Read Stripe’s Privacy Policy.
Confirmation screenshots. Seller-uploaded screenshots are kept in private hosted storage and linked to the seller’s sale. Access is checked on the server. OpenAI reads the screenshot to suggest the restaurant order number, pickup time, and status. Sellers review and confirm these details before buyers receive them. Crop out student IDs, balances, and unrelated information before uploading.
Email. Bird sends sign-in codes and order and sales updates, including pickup reminders and review notices. You can turn optional status emails on or off in Notifications. Requested sign-in codes and essential account messages are still sent. Phone-number entry and SMS alerts are not currently offered.
Support. If you email or call us, we receive your contact details and any message or attachments you share. Report a problem links prepare an email with your UD MEM order number, restaurant, and meal; you choose whether to send it. We use support records to respond and resolve issues. Contact mem@varughese.org or (917) 734-0159.
Technical information. Hosting and security providers may process IP addresses, browser information, request times, and diagnostic logs to deliver and protect the service. We use request limits to reduce abuse. Google Fonts receives browser requests to display our fonts. The hosting platform may require its own sign-in.
2. Analytics and email tracking
Google Analytics
When enabled, UD MEM uses Google Analytics to understand how visitors use the site and improve its content and performance. Google Analytics may use cookies or similar identifiers to measure pages visited, time spent on pages, clicks and other interactions, browser and device characteristics, referral sources, and approximate location. Google Analytics 4 processes IP addresses during collection but does not log or store individual IP addresses.
Google processes this information to provide usage reports. Where required by law, optional analytics will run only after you consent, and you will be able to withdraw that consent. We will disclose material changes to our analytics practices. We will not send entered email addresses, verification codes, payment information, or allergy or health details to Google Analytics. We do not currently use advertising pixels or analytics advertising features.
Learn about how Google uses information from sites that use its services, read Google’s Privacy Policy, or see the Google Analytics opt-out browser add-on.
Bird email tracking
We use Bird (bird.com) to measure delivery and engagement for emails sent through that service. Bird may process your email address, message content and identifiers, delivery or bounce events, and, where enabled, email opens and link clicks. Open tracking uses small images embedded in emails. Click tracking routes links through a tracking service before taking you to their destination. Tracking events may include timestamps, IP addresses, and browser or email-client information.
We use these records to troubleshoot delivery, understand engagement, and improve our emails. An open or click does not necessarily mean you personally read a message; email privacy tools and automated scanners can affect these measurements.
If you receive promotional emails, use their unsubscribe link or contact mem@varughese.org to stop them. Blocking remote images in your email app can limit open tracking, but it does not prevent tracking when you click a tracked link. Contact us with email-tracking questions or privacy requests. For more information about Bird’s handling of information, read Bird’s Privacy Statement.
Screenshot reading. We send seller confirmation screenshots to OpenAI to extract the restaurant order number, pickup time, and status. Sellers review the extracted details before sharing them with buyers. Remove unrelated personal information before uploading. Screenshots are also stored privately for order support. We request that OpenAI not store the API response; provider security and abuse-monitoring retention may still apply.
3. Browser storage and choices
Essential cookies keep your account signed in. Browser session storage keeps unfinished meal selections and checkout request identifiers. Clearing browser storage does not delete account, payment, order, or screenshot records held on the server. Sign out to end the current account session.
Website analytics is not currently activated. Email open and click tracking is disabled for sign-in codes and status updates sent by this site. Bird tracking may apply to separate email campaigns as described above. Accepting the Terms or acknowledging this policy is not consent to optional analytics. We do not sell personal information or use it for targeted advertising. Where required, applicable privacy choices and opt-out signals will be honored.
4. Disclosure of information
We do not sell or rent your personal information. Information may be processed by providers that deliver the site, fonts, hosting security, or support email, as needed for those purposes. We also use Bird to process email communications and related delivery and engagement information on our behalf, as described in Section 2. We may disclose information where reasonably necessary to comply with law or a valid legal request, investigate fraud or security incidents, or protect rights and safety. If ownership of the service changes, relevant records may transfer subject to applicable law and appropriate notice. Meal selections and necessary order details are shared with the assigned seller. Sellers place orders separately in Grubhub. We do not share your sign-in codes or payment credentials with sellers or restaurants.
5. Retention and security
Sign-in codes expire after 10 minutes and account sessions expire after 30 days or sign-out. Automated cleanup removes expired codes, sessions, and rate-limit records after a further 24 hours. Sent email queue records are removed after 30 days. Failed and unsent messages remain available for troubleshooting.
Confirmation screenshots become eligible for deletion 90 days after the related order closes, once its refund or seller bank payout is resolved and no pickup review remains open. Order, sale, payment-reference, and audit records remain available for accounting, fraud prevention, support, and disputes. We review broader deletion requests individually and retain records required for unresolved transactions or legal obligations.
We create encrypted daily database backups in private storage and keep them for 30 days. Backup copies can temporarily contain previously deleted account information until they expire. Restoring a backup requires checking later deletion requests before returning the restored system to service. Backups do not include active sign-in codes, sessions, or service secrets. Payment and communication providers apply their own retention practices.
We use server-side access checks, protected session cookies, private screenshot storage, restricted database access, and server-held service credentials. No storage or transmission method is completely secure. Clearing browser storage does not delete records held by UD MEM, Bird, or Stripe.
Deleting your account
Sign in and use Delete account on the Support page. After confirmation, we remove the account’s sign-in email, phone number, preferences, seller profile, and saved payment-method links from our account database and revoke all sessions. We retain a non-login reference to preserve historical records. Active orders and sales, pending checkouts, refunds, and seller bank payouts must be resolved first; contact support if you need help.
Account deletion does not delete every record associated with past transactions. Authorized administrators may retain orders, sales, transaction contact details, payment references, screenshots, support correspondence, and audit logs where needed for accounting, fraud prevention, disputes, or legal obligations. These records do not provide account access. We retain them only as long as necessary for those purposes and applicable requirements, then delete or de-identify them. Payment, email, and other providers may retain their records under their own policies. Contact us for a broader deletion request or details about retained information.
6. Your privacy requests
Contact mem@varughese.org to request access, correction, deletion, or a copy of information we hold about you. Depending on applicable law, you may have additional rights to restrict processing, withdraw consent, or appeal a denied request. We may need reasonable information to verify your request and will respond within the time required by law. We do not discriminate for exercising applicable privacy rights.
We cannot retrieve unfinished selections stored only in your browser; clear site data to delete those drafts. If we deny a request, you may reply to the same email address asking for an appeal. Where applicable, you may also complain to your state attorney general or other relevant privacy regulator.
7. Children and location
UD MEM is intended for adult students and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided information to us, contact us so we can address it. The service is intended for use in the United States. Providers may process information in the United States or other countries under their own privacy practices.
8. Updates and contact
We will update the date on this page when this policy changes and provide additional notice for material changes when required. New uses of information will be handled in accordance with applicable law. Questions and requests: mem@varughese.org.