The short version: assistance requests are private and stay private, sponsors and the public only ever see aggregates, we never touch your card number, we do not sell data or run targeted advertising, and you can access, correct, delete, port, opt out or appeal from the Privacy Center.
01 Scope
This policy covers personal data ProvisionLoop processes through the ProvisionLoop web application and its backend during the Texas pilot. It is written to meet the notice requirements of the Texas Data Privacy and Security Act (Texas Business & Commerce Code Chapter 541).
02 Data categories we actually process
These are the categories the application actually uses today — no placeholders.
- Account and contact data. Email address, password credential held by our authentication provider (never in plain text and never visible to us), display name, and the role or roles you chose.
- Household assistance data. First name, optional email and phone, service area, household size, need type, urgency and free-text notes. Free-text notes can contain sensitive details — health, disability, immigration, family or religious information — because people describe their situation in their own words.
- Kitchen and business data. Business name, kind, address, service area, website, program summary, posted capacity, posted cost per meal, menu templates, claim status and payout onboarding status.
- Partner and referral data. Organization name, kind, website, service areas, approval status, and the referrals routed to that organization with their status, scheduling and outcome.
- Volunteer and dispatch data. Volunteer name, contact, skills, availability, shift signups, delivery runs claimed, run status and hours logged.
- Transaction identifiers. Payment session and customer identifiers, subscription identifiers, amounts in cents, meal counts, neighborhood, payment environment and payout/transfer identifiers. We never receive or store your card number, CVC or bank account number — those go directly to Stripe.
- Device and security logs. Standard server and authentication logs generated by our hosting and authentication providers for security, abuse prevention and debugging.
- Household planning data (MealForge). Household size, budget, preferences, pantry contents, saved recipes and meal plans, stored locally in your browser and synced to your account when you are signed in.
- Public aggregate ledger. Meal counts, neighborhood, kitchen name and timestamps for completed orders. Recipient identity is never part of it.
03 Why we process each category
- Account data — to authenticate you, apply your role permissions and secure the account.
- Assistance data — solely to route a request to an approved partner organization and to let that organization record an outcome.
- Kitchen data — to display accurate capacity and cost, to accept and track orders, and to send payouts to the operator.
- Partner data — to review applications, gate access to identifiable request data, and record fulfillment.
- Volunteer data — to staff shifts and dispatch delivery runs, and to log hours.
- Transaction identifiers — to create checkouts, confirm payment through a signed webhook, credit the ledger only for paid meals, pay kitchens, and handle refunds and disputes.
- Security logs — to detect abuse, debug failures and meet legal obligations.
- Aggregate ledger — to publish honest, non-identifying impact figures.
04 Data minimization and sensitive data
We ask for the least we need to route help. Assistance requests do not require a full legal name, a home address, an income figure, an identity document or a benefits number, and you should not include one.
Because free-text notes can contain sensitive details, they are treated as sensitive: restricted to the approved partner handling the request and to our own administrators for support, never shown to sponsors, never shown to volunteers, never used to train models, and never published in aggregate views.
Volunteers see drop points and run instructions, not household addresses or recipient identity.
05 Who receives data
We do not sell personal data and we share it only in these ways.
- Stripe — payment processing, checkout, subscriptions, connected payout accounts.
- Supabase — database hosting, authentication and storage of application data.
- Lovable — hosting and build infrastructure for the application itself.
- Verified partner organizations — only the specific request routed to them, and only while they are approved and active.
- Kitchens — order quantity, timing and their own volunteer roster. Not recipient identity.
- Legally required disclosures — where we must respond to valid legal process, protect against fraud, or prevent imminent harm.
Sponsors, cities and the public receive aggregate figures only. There is no advertising network, analytics broker or data broker in this list.
06 Public fields versus private fields
Public: kitchen name, kind, city, neighborhood, address, website, program summary, posted capacity, posted cost per meal, verification state, and aggregate ledger totals by neighborhood and time.
Private, never public: every assistance request and its notes, referral records and outcomes, volunteer identity and rosters, household planning data, transaction identifiers, payout details, privacy and refund requests, and legal acceptance records. These are protected by row-level security so an account can read only its own rows or rows its approved role grants.
07 Retention
Our retention principle is: keep it while it is doing the job, then remove it.
- Account data — while the account exists, then deleted on request subject to the exceptions below.
- Assistance requests and referrals — while open, plus a limited period afterwards so a partner can verify what happened and correct errors. Target: 24 months, then deletion or de-identification.
- Volunteer records — while the profile is active, plus a limited period for hours verification. Target: 24 months.
- Transaction identifiers and payout records — retained as financial records for as long as tax, accounting and dispute-resolution obligations require.
- Legal acceptance records — retained for the life of the account and afterwards as evidence that a version was accepted.
- Security logs — short-lived, retained by our providers under their standard log retention.
- Aggregate ledger entries — retained indefinitely; they contain no personal identifier.
Backups expire on their own schedule; deleted records disappear from backups when those backups roll off.
08 Security
Data is encrypted in transit. Access is controlled per row by database row-level security policies tied to your account and role, privileged operations run only on the server, secrets are never shipped to the browser, and payment credentials never touch our systems. No system is perfectly secure; we will notify affected people without undue delay if a breach affecting their personal data occurs.
09 No sale, no targeted advertising, no profiling
ProvisionLoop does not sell personal data, does not process personal data for targeted advertising, and does not carry out profiling that produces legal or similarly significant effects about you. There is nothing here you need to opt out of for those purposes — but the opt-out right below is available anyway.
10 Your Texas privacy rights
As a Texas resident you can ask us to:
- Confirm and access the personal data we process about you.
- Correct inaccuracies.
- Delete personal data we hold about you.
- Port a copy in a portable, readily usable format where processing is automated.
- Opt out of sale, targeted advertising or significant profiling (we do none of these).
Submit any of these through the Privacy Center while signed in. We aim to respond within 45 days and may extend once by a further 45 days where reasonably necessary, telling you why.
Appeal. If we refuse a request, you may appeal it in the Privacy Center by choosing “Appeal”. We will respond in writing within 60 days with our decision and reasons. If the appeal is denied you may complain to the Texas Attorney General.
Pilot limitation: privacy requests are queued for review by a person. There is no automated fulfillment pipeline and no admin request queue yet — building one is a launch blocker, and we will not pretend a request completed itself.
11 Deletion exceptions
We may keep specific records after a deletion request where the law allows or requires it: financial and payout records needed for tax, accounting or dispute resolution; legal acceptance records that evidence a version you accepted; records needed to investigate fraud or protect someone's safety; and aggregate or de-identified figures that cannot be linked back to you. We will tell you which exception applies.
12 Children
ProvisionLoop accounts are for adults 18 and over. We do not knowingly collect personal data from children. If we learn a child created an account, we will delete it. A household adult may describe household size, but should not include a child's identifying details in a request.
13 Where processing happens
The pilot is operated for Texas. Our hosting, database, authentication and payment providers operate global infrastructure, so data may be processed or backed up outside Texas and potentially outside the United States, under those providers' contractual and technical safeguards.
14 Changes to this policy
Material changes get a new version number and a new effective date in the Legal Center. Where a change materially affects your rights we will ask you to acknowledge the new version before you continue with the affected action.
15 Contacting us
Signed-in users should use the Privacy Center; it is the only channel we currently monitor. A named operating legal entity and a monitored legal contact channel will be published here before the public pilot opens and before any live-money launch. We will not publish an invented address or email address in the meantime.
These are platform terms for the ProvisionLoop pilot. They are not legal, financial or tax advice to you. The operating legal entity and a monitored legal contact channel must be published here before any live-money launch; until then live payments are disabled and all checkout runs in the payment processor's test environment.