Campus Connect Privacy Notice
Version: 2026-10-05.2
Controller: Connect Technologies LLC, doing business as Campus Connect
Privacy contact: info@campusdelivery.app | 418 Broadway, Ste R, Albany, NY 12207
1. Who we are and what this Notice covers
Connect Technologies LLC, doing business as Campus Connect, runs the Service. This Notice explains what personal information we collect, why, who receives it, how long we keep it, and what you can do about it.
It covers everyone whose information the Service handles: Students, Couriers, people applying to be Couriers, and anyone who writes to us. "You" means you, whichever of those you are; where a part applies only to Students or only to Couriers, it says so.
Campus Connect is a pickup-and-delivery service for an Order you have already bought and paid for at the Venue. We do not sell food, show menus or food prices, or take payment for food, so we never receive your payment for the food itself.
2. Definitions
- Account: the sign-in you create with your school email address. One Account is used both to order as a Student and to carry Routes as a Courier.
- Added Tip: an amount a Student adds to the Tip after the handoff.
- Admin: Campus Connect's administrative staff.
- Campus Connect, "we", "us", "our": Connect Technologies LLC, doing business as Campus Connect.
- Courier: a person we have approved to carry Orders.
- Delivery: one request to carry one Order from its Venue to a Handoff Spot.
- Delivery Fee: what a Student pays Campus Connect for a Delivery.
- Delivery Pin: an exact point a Student may drop on the map, or place where they are standing with "Use my location", to show where they will stand at their Handoff Spot.
- Handoff Code: the 4-digit code the Student gives the Courier at handoff.
- Hashed: stored as a one-way code that cannot be turned back into the original value.
- Handoff Spot: the meeting point the Student chooses. The app calls it the "delivery spot".
- Hold: the card authorization placed at checkout for the Delivery Fee and Tip, charged at Pickup.
- Order: the food the Student bought and paid for directly from the Venue.
- Pickup: the moment the Courier confirms at the Venue that they have the Order, by checking it at the counter or marking it collected.
- Route: one Courier's walk carrying one or more Deliveries.
- Service: the Campus Connect apps, website ordering, and delivery service.
- Student: a person who uses the Service to have an Order delivered.
- Tip: an optional amount for the Courier, chosen at checkout.
- Venue: the campus restaurant or dining location where the Student bought the food.
3. What we collect
3.1 From Students
- Account details. Your school email address (an Account can only be made with an address at a school we serve, such as @albany.edu or @binghamton.edu), your preferred name, mobile number, quad and residence hall, a password if you choose to set one, and whether you turned friend notifications off. We do not ask for or keep a room number on your Account.
- If you order without an Account. The name, mobile number and email address you give at checkout, or that our payment provider collects and passes back to us. If you later sign in with the same email address, those Deliveries are added to your Account and fill in any blank Account details.
- Delivery details. The Venue, order number, your Handoff Spot or Delivery Pin, the hall, room, floor or other detail you type for that one Delivery, any note you write for your Courier, whether you asked for napkins and utensils, whether you asked for it to be left at your door, the Delivery's status and times, the Handoff Code (hashed), and the rating and comment you give. If your Courier leaves your Order with a photo, that photo too; at a room door it shows the door and its room number.
- Your order screenshot. The screenshot of your order confirmation, and what we read from it: Venue, order number, order time, ready time, preparation status, and item names and quantities. Our software is instructed not to read or keep prices, totals or payment details; a price that appears within an item's name is kept only as part of that text and is not used. The image itself is deleted as section 6 says.
- Payment records. The Delivery Fee, Tip, any Added Tip, the Hold and its status, refunds, and our payment provider's transaction identifiers. On the website's checkout page, our payment provider also asks for your billing address, and for your phone number if we do not already have it. If you pay with Apple Pay or Google Pay, the wallet shares the cardholder's name and your email with our payment provider, Apple Pay also the card's billing address and Google Pay your billing postal code, when your Delivery has no name and email of its own; we use the name and email only when your Delivery has none. We never receive your full card number, and we do not store your billing address.
- Messages. Chat with your Courier, including any photo either of you sends in it; questions you send to Help, the answers, and the help agent's own notes on how it reached each answer; and, when you report a problem with the app, the phone model and system version, or the browser description, that the app sends with it.
- Reports about a Courier. If you tell us the Courier who arrived was not the person in their photo, that report and when you made it. If you report your Courier's chat messages, that report, when you made it, and the chat it is about, including any photos your Courier sent in it. If your Courier reports your chat messages, Admin can read the chat, including any photos you sent in it.
- Push-notification tokens. A code that lets us send notifications to your phone: one for each Delivery you follow on a phone, and, while you are signed in on a phone, one for your Account, so that a Delivery you place in a browser can still notify your phone.
- Friends and invite codes. The invite code each Delivery receives and which Delivery's code yours was placed with; the students you and another Student added as friends, and who said no; groups you start or join, with their name, days, time, area of campus and members; and, if you told friends you were ordering before October 6, 2026, which Delivery and which friends.
- Tracking links. When you share tracking with a friend, a hashed copy of the link's code and which Delivery it follows.
- Promo codes. If we sent you a promo code, the email address we sent it to and which Delivery used it.
3.2 From Couriers and people applying to be Couriers
- Application. Your school email address, and whether you live on or off campus and, if on, which area you live in.
- Eligibility and agreement. Your answers that you are 18 or older and not on an F-1 or J-1 student visa, the versions of the Courier Agreement, Courier Rules and this Notice you agreed to, when, and from which platform and app version.
- Legal name and mailing address, which you give when you agree to the Courier Agreement. New York law requires a written agreement naming both parties and their mailing addresses. When you are approved, and your Account has no name yet, the first word of your legal name becomes your Account's name, the first name Students see (section 5). You can change it on the Account screen at any time. The rest of your legal name is never shown.
- Your photo. One photo of your face, taken with the camera when you apply. Section 4 explains the automated check it goes through. You can retake it at any time; you cannot go online without one. We do not ask for a photo of any ID.
- Your year, if you add it (for example "Sophomore"). It is blank unless you fill it in, and you can clear it.
- Location during a Route. See section 3.4.
- Work records. When you went online and offline and why the app took you offline, Routes offered to you and whether you accepted, declined or missed them, Orders you declined or left, each stop and when you reached it, pickup checks, "too much to carry" reports, photos you take when you leave an Order at a Handoff Spot or a Student's room door, your chat with each Student on your Route (including any photo either of you sends in it), Students' ratings and comments, reviews of your service, reports that you were not the person in your photo, and reports about your chat messages, and any you make about a Student's.
- Admin' note on your application, written when Admin decides it. You can see it in the app.
- Pauses to your courier access. Each time Admin pauses your courier access or restores it: when, which member of Admin did it, and the reason Admin wrote for pausing it.
- Pay records. Route pay, Tips, transfers, your payment provider account identifier, and what the payment provider still needs from you. Our payment provider collects your identity, bank and tax details itself; we never receive your bank account number or taxpayer identification number.
- A push-notification token for your phone, so we can send you Route offers.
3.3 From everyone
- Agreement records. Which version of our Terms, this Notice, the Refund Policy or the Courier Agreement you agreed to, when, and from which platform and app version.
- Sign-in records. One-time sign-in codes and session records, both hashed; your password, hashed; short-lived counters, hashed, that limit how often an email address or internet address can try to sign in; and, for each phone or browser that has signed in to your Account, a hashed copy of a random code we give that device (in a browser, a cookie named
cc_known_device, sent only to our sign-in and account-security addresses) and when it expires. A device you have signed in on before can still sign in with an emailed code on a day when too many wrong codes have paused signing in with your email address. - Technical records. Our hosting provider records the internet (IP) address and details of each request to our servers. The app sends error reports as section 5.2 describes.
- Feature use. Which parts of the app are used, and in which hour: for example that the app was opened, that the share button on the tracking screen was tapped, or that help was opened. Each record carries which app it came from (Student, Courier or Admin), the device's platform and app version, the school, and a hashed random code the app makes for itself on your device. It is never linked to your Account, your name, your contact details or a Delivery, and it never includes anything you type. Short-lived hashed counters limit how often one device or internet address can send these records.
- Records of our own access. When Admin exports everything we hold about a person, we record whose data, who exported it, when and why. When Admin opens a courier applicant's photo, we record whose photo, which copy of it, who opened it and when.
3.4 Location
- Students. If you allow it, your phone uses its location to suggest your school. When you tap "Use my location" on the delivery step, the app also places your Delivery Pin where your phone is, if that is inside the delivery area and precise enough, and picks the nearest Handoff Spot; you see the pin on the map and can move it. That pin is sent to us with your Delivery and shown to your Courier, like a pin you drop yourself. The app does not track your location: it reads it only when you tap, and nothing else is sent.
- Couriers. The app needs location on to go online, accept a Route and carry it. While you carry a Route, including with the app in the background, your phone sends your position to us. We store only your latest position, only while the Route is live, and only when it is on campus; we do not keep a trail of where you have been.
3.5 Sensitive information
We do not ask for health information. But a chat message, a note for your Courier or a help question can mention an allergy, a disability or another health matter, and item names read from a screenshot can suggest one. We treat such text as sensitive: it is shown only to the people who need it for that Delivery or that help question, and a leak of it is handled under our security incident plan like any other personal information. Please share only what your Courier or Admin needs.
A Courier's answer about an F-1 or J-1 student visa is also sensitive. We ask it only because those visas generally do not allow this kind of paid work, we use it only to decide whether you can deliver. It is kept with your signed Courier Agreement (section 6).
4. How we use it
We use personal information to:
- create and secure Accounts, and limit repeated sign-in attempts;
- take a Delivery request, place the Hold, charge the Delivery Fee and Tip at Pickup, and handle cancellations and refunds;
- read your order screenshot so the Courier collects the right Order;
- group Deliveries into Routes, offer Routes to Couriers, and show a Student where their Courier is;
- let the Student and Courier chat, and send notifications about a Delivery or Route;
- send the one reminder a Student asks for on a night we are full, or before we open at their school, when orders open;
- send a Student with an Account occasional promotional emails about ordering with us (section 7 says how to turn them off);
- let the Student recognize their Courier, and look into a report that the Courier was not the person in the photo;
- run friend invites and promo codes, including comparing the phone numbers and email addresses on two Deliveries so that nobody uses their own invite code;
- pay Couriers, and keep the tax and contract records the law requires;
- open a review of a Courier's service when their average rating falls below the standard in the Courier Rules;
- pause a Courier's access while Admin looks into a problem, and make sure that a Courier whose access is paused cannot come back under a new Account without a person from Admin reviewing it;
- pause a Student's ordering when they have harassed, threatened or endangered a Courier or anyone else (Terms, sections 5.6 and 12), and make sure a paused Student cannot order again from a new Account, from another Account, or as a guest with the same email inbox or phone number until a person from Admin resumes it. To do this we compare the email address and phone number on a new order with those of Accounts whose ordering is paused;
- answer help questions, and respond to requests about personal information;
- measure how the Service is doing (for example, how many Deliveries share a Route, how often Students order again, and which parts of the app are used), using counts rather than individuals; and
- prevent fraud and abuse, investigate security problems, and fix errors.
Automated processing. Three things are done by software rather than a person:
- Reading the screenshot. An AI model reads the Venue, order number, time and items. If it cannot, you can type the details in.
- Checking a Courier's photo. An AI model looks at the photo once, when you take it, and answers only whether it clearly shows one real person's face. It does not identify you, compare your face with anyone's, or keep anything about your face; we store only its verdict. If it cannot confirm the photo, you are asked to take it again. When the check passes and you submit your application, it is approved automatically, unless we declined an earlier application from you, in which case a person from Admin decides.
- The help agent. An AI model answers help questions from our published help articles and the status of your own Delivery or Route. Its answers may be wrong, and a person from Admin can take over.
We do not sell personal information, and we do not use it for advertising. The app does not read your device's advertising identifier, contains no advertising software, and does not track you across other companies' apps or websites. Usage measurement is limited to the feature-use records in section 3.3; Mapbox's map software reports separately, as section 5.2 describes. The Delivery Fee depends only on your school, your Handoff Spot and any promotion we offer, never on anything else about you.
5. Who we share it with
5.1 Other people using the Service
- Your Courier, for your Delivery and only until it is handed over or cancelled, sees: the Venue, order number and items; your screenshot; your first name and the initial of your last name, to give at the Venue's counter; your Handoff Spot or Delivery Pin; the hall, room, floor or other detail you typed; your note; whether you asked for napkins and utensils; and your chat messages, including any photo you send in the chat. Your Courier never sees your phone number, email address, or the quad and hall saved on your Account.
- The Student whose Order a Courier carries sees the Courier's first name and photo, the Courier's year if they added it, the Courier's average rating and number of completed Deliveries once they have enough to be meaningful, and the Courier's live location while the Order is on its way. If the Courier leaves the Order with a photo, that Student sees the photo on the Delivery's screen too, and sees any photo the Courier sends in the chat. The first name, photo and year stay on that Delivery's screen for up to 14 days after it is handed over, and the first name appears in the Student's order history and receipt. The Student never sees the Courier's last name, email address or phone number.
- Your friends, if you add each other, see your first name and the groups you share. Everyone in a group sees the first names of its other members. Being friends never shows them when you are ordering. They never see your Order, your Courier, your location or your other friends.
- Anyone you send a tracking link to, if you tap "Share with friends" or the share button on the tracking screen, sees your first name, which step your Delivery is at, the area of campus it is going to (never your exact Handoff Spot or Delivery Pin), when your food should be ready, and your invite code while a friend still has time to use it. They never see your Order, your Courier, your Courier's location or your Handoff Code. The link stops working when you stop sharing, or an hour after your Delivery is handed over or cancelled.
- Admin can see the information described in this Notice to run the Service, including help conversations with the name, email address and phone number of the person asking. When a Courier declines a Route that is still waiting, Admin can see who declined it.
5.2 Service providers
Each receives only what it needs to provide its service to us, and may use it only for that:
- Stripe, Inc. takes payments, places and captures Holds, makes refunds, and pays Couriers. It receives the amounts and Delivery identifiers; on the website, the email address of a signed-in Student; and whatever you enter into its payment form. For Couriers, it receives your email address when your payout account is created and collects your identity, bank and tax details itself.
- Cloudflare, Inc. hosts the Service, its database and its file storage, keeps request logs, and runs the AI models described in section 4 (Cloudflare Workers AI, on Cloudflare's own network). The screenshot, the Courier's photo and help questions are processed there. The help agent receives your question and your Delivery's status, Venue, order number, Handoff Spot, Delivery Fee and Tip, never your email address, phone number or room.
- Resend sends our emails, and so receives the recipient's address and the full email: sign-in codes, the notice that a password was set or changed, the notice (at most once a day) that too many wrong sign-in codes or passwords have paused that way of signing in with your email address, the receipt after each Delivery (which names the Courier's first name), promotional emails to a Student (section 7), and, for a Courier, a copy of the signed Courier Agreement, which includes the Courier's legal name and mailing address. Emails to Admin about a help question say that someone is waiting, not what they wrote.
- Expo (650 Industries, Inc.) delivers push notifications, through Apple or Google, and receives the push token and the notification's text. That text can include your Courier's first name, the Venue or your Handoff Spot; it never includes chat messages. The app also checks Expo's update service for new versions of the app when it opens, which receives your device's internet address and the app version.
- Mapbox, Inc. draws the campus maps. Your phone or browser calls Mapbox directly, not through our servers, so Mapbox receives information including your device's internet address, the map area shown, and, for the walking line, its two ends: the pickup point and the Student's Handoff Spot or Delivery Pin. When a Courier searches for their mailing address while agreeing to the Courier Agreement, Mapbox receives what they type. In a browser, Mapbox's map software also sends Mapbox anonymous reports about how the map is used (keeping a random code in your browser's storage), under Mapbox's privacy policy. The iPhone and Android app switches those reports off.
- Apple and Google deliver the app through the App Store and Google Play and carry our push notifications to your phone, under their own privacy terms. They tell us nothing about who installed the app. The "App Privacy" and "Data safety" panels on our store listings summarize what this Notice describes.
- Apple Maps or Google Maps. When a Courier taps "Open walking directions", their phone opens its maps app (Apple Maps on an iPhone, Google Maps elsewhere) with the destination: the pickup area, or the Student's Handoff Spot or Delivery Pin. That app's provider handles it under its own terms.
- Sentry (Functional Software, Inc.) receives error reports from the app, when error reporting is switched on. When the app hits an error and keeps running, email addresses, access tokens, names, phone numbers, message text, Handoff Codes and map coordinates are removed from the report on your device before it is sent. When the app crashes outright, the report is built and sent by the crash handling built into iOS and Android versions of the app, which does not run that removal, so it can carry your device's name and what was on screen. Sentry also sees the internet address the report comes from.
5.3 Other disclosures
We may disclose personal information to professional advisers and insurers when reasonably necessary to protect someone's safety, prevent fraud or resolve a claim.
Requests from the police or the government. We give personal information to law enforcement, campus safety or a government body only when the law compels us, such as by a warrant, subpoena or court order, or when it is reasonably necessary to protect someone's safety, such as reporting a threat or an assault during a Delivery. We give only what is needed. When the law compels us, we tell the person whose information it is before we hand it over, unless the law forbids it or it is an emergency.
If Campus Connect is sold. We may transfer personal information to a buyer or successor in a merger, financing or sale, which must protect it as this Notice does. We will tell you before your information is transferred or becomes subject to a different privacy notice.
Parts of this section are adapted from the 37signals privacy policy, used under the Creative Commons Attribution 4.0 license. We changed them to fit Campus Connect.
6. How long we keep it
These periods are enforced automatically. A period measured in days is checked once a day, so it can run up to a day longer than stated. While we investigate a security incident, we may pause this automatic deletion until the investigation ends, so that records showing what happened are not destroyed; a period below then runs late by as long as the pause lasted. A pause never delays deleting your Account when you ask (section 7).
| Information | When it is deleted |
|---|---|
| Screenshot image | 24 hours after you upload it. What was read from it stays with the Delivery record |
| A photo a Courier takes when leaving an Order at a Handoff Spot or at a Student's room door, which can show where it was left, including a door and its room number | 30 days after the Delivery. The Delivery record still says the Order was left with a photo |
| An applicant's photo | 30 days after the application is declined, or 30 days after an unsubmitted application was last changed. An approved applicant's photo becomes their Courier photo |
| A Courier's photo | When the Courier replaces it, and when the Account is deleted |
| A Courier's live location | Within a minute of the Route ending, or of it stopping without ending |
| One-time sign-in codes | 1 day after they expire. They expire 10 minutes after they are sent |
| Sign-in sessions | 30 days after they expire or you sign out. A session lasts up to 30 days |
| Sign-in attempt counters | 1 day after they start |
| Feature-use records | 90 days after they are made. The counters that limit how often they are sent: 1 day after they start |
| The record that a phone or browser has signed in to your Account | 180 days after that device last signed in to it. Straight away for every other device when you change your password or sign out your other devices, and when your Account is deleted |
| A photo sent in a Delivery's chat, by the Student or the Courier | 30 days after it is sent. The chat still says a photo was sent |
| Chat access tickets | 1 day after they expire. They expire after 1 minute |
| The stored answer to a repeated "create my Delivery" tap (the Delivery's identifier, status and pickup details, never its access token or Handoff Code) | 1 day after it is created |
| A phone's push token for one Delivery | Within two days after the Delivery is handed over or cancelled, and when the Account is deleted |
| A phone's push token for a Student's Account | When you sign out on that phone or delete your Account, and within a day of your sign-in on that phone ending |
| A phone's push token for a Courier | When you sign out on that phone, sign out your other devices, or delete your Account, and when Admin pauses your courier access. It is not deleted just because your sign-in on that phone ends |
| The name, phone number, email address, quad, hall, room, typed Handoff Spot detail, note for the Courier and Delivery Pin on a Delivery placed without an Account | 90 days after the Delivery. The rest of the Delivery record stays |
| The same details on a Delivery placed with an Account | When you delete your Account. Until then they stay on each past Delivery, and your latest Delivery's Handoff Spot, detail and Delivery Pin are offered back to you at your next checkout |
| Cloudflare's record of each request to the Service (its time, address, and the app's log lines for it) | Within 7 days, by Cloudflare |
| A Courier's record of going online and offline | 400 days |
| Which friends were told about a Delivery, and which days a group was reminded | 30 days |
| A reminder you asked for on a night we were full or before we opened: your Account, your school, and when to send it | 30 days after it is sent, and when you delete your Account |
| An unanswered invitation to a group | 7 days |
| Your friends and group seats | When you leave the group, and when you delete your Account. A friend you removed or said no to is kept only as a note not to suggest you to each other again, until you delete your Account. A group you started stays for the others in it, without you |
| A tracking link you shared | It stops working when you stop sharing, or an hour after the Delivery is handed over or cancelled. Its record is deleted a day after the Delivery closes |
Records kept without a fixed period. We keep the following for payment, tax, refund, chargeback, safety, contract and legal purposes, for as long as those purposes require:
- Delivery records, including what was read from the screenshot, the Delivery's timeline and each step of a Route;
- payment, Hold, refund, Tip and Courier pay records;
- records of which Terms and policies you agreed to. A signed Courier Agreement, with the legal name and mailing address in it, is kept for at least six years, as New York's Freelance Isn't Free Act requires, even if you delete your Account;
- chat messages (a photo in one is deleted as the table above says), help conversations (including the help agent's notes and any device description), ratings and comments, reports that a Courier was not the person in their photo, and reports about chat messages;
- Routes offered to, declined by or missed by a Courier, and their stops, pickup checks and reviews;
- Admin' note on a decided courier application;
- records of Admin pausing or restoring a Courier's access, with the reason written for pausing it, and records of Admin opening an applicant's photo;
- if your courier access was paused when you deleted your Account, the hashed form of your email address, the dates it was paused and deleted, and the reason (section 7);
- records of Admin pausing or resuming a Student's ordering, with the reason written for pausing it;
- if your ordering was paused when you deleted your Account, the hashed forms of your email address and phone number, the dates it was paused and deleted, and the reason (section 7);
- the email address a promo code was sent to;
- which promotional emails we sent to your Account and when, and when you turned them off;
- a group that has ended; and
- your Account, while it exists.
Deleting your Account removes the parts section 7 lists, straight away, even from the records above.
7. Your choices and rights
- Change your details. You can change your name, phone number, quad and hall in the app. A Courier can retake their photo and add or clear their year under Account in the courier menu.
- Notifications and location. You can turn notifications and location off in your phone's settings, all of them or one kind (on Android, "Reminders" is the one for a reminder you asked for). A Courier cannot go online or carry a Route with location off, and cannot go online without a photo.
- Friends. You can remove a friend, and leave any group you are still in, in the app. We no longer send notifications about friends or groups. Deleting your Account removes your friends and any group seats.
- Promotional emails. If you have an Account, we may send you occasional promotional emails about ordering from Campus Connect. Every one says it is promotional and has a link to turn them off, and your mail app's own unsubscribe button works too. Turning them off does not stop sign-in codes, receipts or other emails about your orders.
- Delete your Account. Open the account menu, choose Delete account, and confirm. This immediately: replaces your email address; removes your name, phone number, quad, hall and password; removes the name, phone number, email address, quad, hall, room, typed Handoff Spot detail, note and Delivery Pin from every past Delivery placed under your Account or your email address; signs you out everywhere, and forgets every phone and browser you signed in on; deletes your push tokens, friends, group seats, friend-sharing records and tracking links; and, for a Courier, takes you offline and deletes your photo, year, live location and online and offline history. The records kept under section 6 stay, no longer linked to your name or contact details, except that if Admin ever exported your data for you (section 3), the record of that export keeps the email address it was sent for. Feature-use records were never linked to your Account, so they cannot be found from it; they are deleted 90 days after they are made. Three exceptions. If you are a Courier and we still owe you money that has not reached you, we keep your email address and name with that payment only so we can pay you another way, and remove them once it is sent or confirmed paid. And if Admin had paused your courier access when you delete your Account, we keep a hashed form of your email address, the dates your access was paused and your Account deleted, and the reason, and no name. If someone later applies to be a Courier with that address, a person from Admin reviews the application instead of it being approved automatically. And if Admin had paused your ordering when you delete your Account, we keep hashed forms of your email address and phone number, the dates your ordering was paused and your Account deleted, and the reason, and no name. An order placed later with that email inbox or phone number is declined; if you think that is a mistake, email us, and a person from Admin can let you order again from an Account. The app will not delete an Account while one of its Deliveries or Routes is in progress, for a day after a checkout that could still be paid, or for the few minutes while a Courier payment is being sent. Your account with our payment provider is kept by that provider; a Courier closes it there.
- See, copy, correct or delete. Email info@campusdelivery.app from the address on your Account (or the address you used at checkout) to ask for a copy of everything we hold about you, or to correct or delete it. We will answer within 30 days. We will also tell you which of your information is held by the service providers in section 5.2 and how to ask them.
8. Security
We protect information with role-limited access; hashed sign-in codes, sessions, delivery access tokens, Handoff Codes and passwords; encrypted connections; and short retention for screenshots, applicant photos and location. No system is perfectly secure.
If personal information is exposed in a security incident, we will notify the people affected as New York law requires, and no later than 30 days after we discover it unless law enforcement asks us to wait. Where the law requires, we also notify the New York Attorney General, the Department of State and the Division of State Police.
9. Children and people under 18
You must be 18 or older to use the Service. Every checkout, and every Courier application and agreement, asks you to confirm it. The Service is not directed to children. If we learn that someone under 18 has used it, we will close their access and delete their information except what we must keep for payment and legal records, and we will not use it for anything else. A parent or guardian can contact info@campusdelivery.app.
10. Changes to this Notice
When we change this Notice we publish the new version with a new date at app.campusdelivery.app/legal/privacy. If a change affects what you agreed to at checkout or as a Courier, the app asks you to agree again before your next checkout or Route.
11. Contact
Questions and requests: info@campusdelivery.app, (518) 888-7462, or Connect Technologies LLC, 418 Broadway, Ste R, Albany, NY 12207. We respond in writing.