Campus Connect Privacy Notice

Version: 2026-10-05.2
Controller: Connect Technologies LLC, doing business as Campus Connect
Privacy contact: info@campusdelivery.app | 418 Broadway, Ste R, Albany, NY 12207

1. Who we are and what this Notice covers

Connect Technologies LLC, doing business as Campus Connect, runs the Service. This Notice explains what personal information we collect, why, who receives it, how long we keep it, and what you can do about it.

It covers everyone whose information the Service handles: Students, Couriers, people applying to be Couriers, and anyone who writes to us. "You" means you, whichever of those you are; where a part applies only to Students or only to Couriers, it says so.

Campus Connect is a pickup-and-delivery service for an Order you have already bought and paid for at the Venue. We do not sell food, show menus or food prices, or take payment for food, so we never receive your payment for the food itself.

2. Definitions

3. What we collect

3.1 From Students

3.2 From Couriers and people applying to be Couriers

3.3 From everyone

3.4 Location

3.5 Sensitive information

We do not ask for health information. But a chat message, a note for your Courier or a help question can mention an allergy, a disability or another health matter, and item names read from a screenshot can suggest one. We treat such text as sensitive: it is shown only to the people who need it for that Delivery or that help question, and a leak of it is handled under our security incident plan like any other personal information. Please share only what your Courier or Admin needs.

A Courier's answer about an F-1 or J-1 student visa is also sensitive. We ask it only because those visas generally do not allow this kind of paid work, we use it only to decide whether you can deliver. It is kept with your signed Courier Agreement (section 6).

4. How we use it

We use personal information to:

Automated processing. Three things are done by software rather than a person:

We do not sell personal information, and we do not use it for advertising. The app does not read your device's advertising identifier, contains no advertising software, and does not track you across other companies' apps or websites. Usage measurement is limited to the feature-use records in section 3.3; Mapbox's map software reports separately, as section 5.2 describes. The Delivery Fee depends only on your school, your Handoff Spot and any promotion we offer, never on anything else about you.

5. Who we share it with

5.1 Other people using the Service

5.2 Service providers

Each receives only what it needs to provide its service to us, and may use it only for that:

5.3 Other disclosures

We may disclose personal information to professional advisers and insurers when reasonably necessary to protect someone's safety, prevent fraud or resolve a claim.

Requests from the police or the government. We give personal information to law enforcement, campus safety or a government body only when the law compels us, such as by a warrant, subpoena or court order, or when it is reasonably necessary to protect someone's safety, such as reporting a threat or an assault during a Delivery. We give only what is needed. When the law compels us, we tell the person whose information it is before we hand it over, unless the law forbids it or it is an emergency.

If Campus Connect is sold. We may transfer personal information to a buyer or successor in a merger, financing or sale, which must protect it as this Notice does. We will tell you before your information is transferred or becomes subject to a different privacy notice.

Parts of this section are adapted from the 37signals privacy policy, used under the Creative Commons Attribution 4.0 license. We changed them to fit Campus Connect.

6. How long we keep it

These periods are enforced automatically. A period measured in days is checked once a day, so it can run up to a day longer than stated. While we investigate a security incident, we may pause this automatic deletion until the investigation ends, so that records showing what happened are not destroyed; a period below then runs late by as long as the pause lasted. A pause never delays deleting your Account when you ask (section 7).

InformationWhen it is deleted
Screenshot image24 hours after you upload it. What was read from it stays with the Delivery record
A photo a Courier takes when leaving an Order at a Handoff Spot or at a Student's room door, which can show where it was left, including a door and its room number30 days after the Delivery. The Delivery record still says the Order was left with a photo
An applicant's photo30 days after the application is declined, or 30 days after an unsubmitted application was last changed. An approved applicant's photo becomes their Courier photo
A Courier's photoWhen the Courier replaces it, and when the Account is deleted
A Courier's live locationWithin a minute of the Route ending, or of it stopping without ending
One-time sign-in codes1 day after they expire. They expire 10 minutes after they are sent
Sign-in sessions30 days after they expire or you sign out. A session lasts up to 30 days
Sign-in attempt counters1 day after they start
Feature-use records90 days after they are made. The counters that limit how often they are sent: 1 day after they start
The record that a phone or browser has signed in to your Account180 days after that device last signed in to it. Straight away for every other device when you change your password or sign out your other devices, and when your Account is deleted
A photo sent in a Delivery's chat, by the Student or the Courier30 days after it is sent. The chat still says a photo was sent
Chat access tickets1 day after they expire. They expire after 1 minute
The stored answer to a repeated "create my Delivery" tap (the Delivery's identifier, status and pickup details, never its access token or Handoff Code)1 day after it is created
A phone's push token for one DeliveryWithin two days after the Delivery is handed over or cancelled, and when the Account is deleted
A phone's push token for a Student's AccountWhen you sign out on that phone or delete your Account, and within a day of your sign-in on that phone ending
A phone's push token for a CourierWhen you sign out on that phone, sign out your other devices, or delete your Account, and when Admin pauses your courier access. It is not deleted just because your sign-in on that phone ends
The name, phone number, email address, quad, hall, room, typed Handoff Spot detail, note for the Courier and Delivery Pin on a Delivery placed without an Account90 days after the Delivery. The rest of the Delivery record stays
The same details on a Delivery placed with an AccountWhen you delete your Account. Until then they stay on each past Delivery, and your latest Delivery's Handoff Spot, detail and Delivery Pin are offered back to you at your next checkout
Cloudflare's record of each request to the Service (its time, address, and the app's log lines for it)Within 7 days, by Cloudflare
A Courier's record of going online and offline400 days
Which friends were told about a Delivery, and which days a group was reminded30 days
A reminder you asked for on a night we were full or before we opened: your Account, your school, and when to send it30 days after it is sent, and when you delete your Account
An unanswered invitation to a group7 days
Your friends and group seatsWhen you leave the group, and when you delete your Account. A friend you removed or said no to is kept only as a note not to suggest you to each other again, until you delete your Account. A group you started stays for the others in it, without you
A tracking link you sharedIt stops working when you stop sharing, or an hour after the Delivery is handed over or cancelled. Its record is deleted a day after the Delivery closes

Records kept without a fixed period. We keep the following for payment, tax, refund, chargeback, safety, contract and legal purposes, for as long as those purposes require:

Deleting your Account removes the parts section 7 lists, straight away, even from the records above.

7. Your choices and rights

8. Security

We protect information with role-limited access; hashed sign-in codes, sessions, delivery access tokens, Handoff Codes and passwords; encrypted connections; and short retention for screenshots, applicant photos and location. No system is perfectly secure.

If personal information is exposed in a security incident, we will notify the people affected as New York law requires, and no later than 30 days after we discover it unless law enforcement asks us to wait. Where the law requires, we also notify the New York Attorney General, the Department of State and the Division of State Police.

9. Children and people under 18

You must be 18 or older to use the Service. Every checkout, and every Courier application and agreement, asks you to confirm it. The Service is not directed to children. If we learn that someone under 18 has used it, we will close their access and delete their information except what we must keep for payment and legal records, and we will not use it for anything else. A parent or guardian can contact info@campusdelivery.app.

10. Changes to this Notice

When we change this Notice we publish the new version with a new date at app.campusdelivery.app/legal/privacy. If a change affects what you agreed to at checkout or as a Courier, the app asks you to agree again before your next checkout or Route.

11. Contact

Questions and requests: info@campusdelivery.app, (518) 888-7462, or Connect Technologies LLC, 418 Broadway, Ste R, Albany, NY 12207. We respond in writing.