Version 2026-07-25 · Effective 2026-07-25

Language: English

COPPA Direct Notice to Schools

Operator and contact

CATHOLICORE LLC operates Cashless Cafeteria. 51 Orange St, Stamford, Connecticut, USA. Privacy email: info@catholicore.com. Telephone: +1 475-300-6334.

What the School is authorizing

The School may authorize CATHOLICORE LLC to process student information only where legally permitted and only for the contracted cafeteria service. The School must identify the legal basis, authorized student population, signer authority, service scope, notice delivery, effective DPA, and whether separate parental consent is required. Acknowledging this notice alone is not qualified authorization.

Student information

Required school roster fields: school and internal student identifiers, first and last name, grade, enrollment and active status, and household link. Optional or school-configured profile and lifecycle fields: email address, date of birth, gender, profile photo, account link, withdrawal date, reason and responsible staff identifier, school-created notes, and created/updated timestamps and responsible staff identifiers. Cafeteria and account records: lunch-card and barcode identifiers; meal selections; items, quantities, prices, timestamps, serving line, purchases and order history; household wallet balance, holds, allocations, top-ups, adjustments, refunds, disputes, and safe payment references. Access and communications: invitations, guardian and household relationships, roles and permissions, notice acknowledgments, authorization or consent status, notification preferences and delivery status, privacy requests, and support communications. Technical and security information collected automatically: IP address or minimized/hashed IP-derived identifiers, approximate location derived from IP, device type, browser, operating system, authenticated session and login records, timestamps, sanitized page paths and referrers, persistent session or security identifiers, rate-limit records, audit logs, and error or performance information.

Purposes and providers

Stripe: Family payments, saved payment methods, refunds and disputes, school subscriptions, payout-account verification, and payment reconciliation. Payment amount, status, household or customer reference, safe instrument details, and transaction context. Card and bank credentials are collected by Stripe. Supabase: Database, authentication, sessions, row-level access controls, private file storage, and server-side data operations. The student, household, cafeteria, authorization, account, audit, request, and operational records needed for the service. Vercel: Application hosting, server execution, deployment infrastructure, operational logs, aggregated Web Analytics, and Speed Insights. HTTP and device metadata and minimized operational measurements. Student pages and student audiences are excluded from product analytics. Resend: Transactional delivery of invitations, account, security, balance, purchase, payment-result, privacy, and support messages. Recipient email, safe display name, school and necessary message content, action link, and delivery metadata. Upstash: Server-side rate limiting, idempotency, and bounded operational caching. Minimized tenant-scoped identifiers and operational values with short expiration periods; sensitive key values are hashed. Sentry: Sampled error reporting, release diagnosis, and performance monitoring. Minimized technical context. Default PII transmission is disabled, and student records, request bodies, credentials, and free-text notes are prohibited.

Prohibited uses

Identifiable student information is not used for targeted or behavioral advertising or marketing directly to children; cross-service tracking, provider-owned profiling, or commercial profiles unrelated to the school contract; sale, rental, licensing, data brokerage, or eligibility and decision-making unrelated to cafeteria service; general-purpose or unrelated artificial-intelligence model training, or prompting a third-party AI service without approval for a defined contracted function; developing products unrelated to the contracted cafeteria service; combining identifiable student information with external or other-customer datasets for unrelated purposes.

Retention, rights, and stopping collection

Student identity, enrollment, household, guardian, profile, lunch card, and authorized account access: While the documented school-authorized purpose remains active; after verified termination or deletion instruction, review begins within 30 days and approved deletion or anonymization completes within 90 days unless a contract, legal hold, or nonwaivable duty requires otherwise. Cafeteria, wallet, payment, refund, dispute, and reconciliation records: While operationally needed; qualifying financial, accounting, legal, and reconciliation evidence may be retained for up to seven years, with child-identifying fields removed sooner where feasible. Invitations and terminated authentication sessions: Approximately 30 days after expiration or termination. Family access requests and unanswered guardian consent requests: Family access requests: approximately 90 days. Unanswered consent requests expire after seven days and are deleted 90 days after expiry when no evidence or legal hold applies. Privacy exports, archived notifications, and sanitized payment-webhook summaries: Privacy exports: seven days; archived notifications: approximately 180 days; sanitized payment webhook summaries: approximately 400 days. Authorization, consent, notice, security-audit, and legal evidence: Up to seven years under manual legal review, subject to a shorter school agreement, approved deletion decision, or longer legal hold. Rights: Verified schools, parents, guardians, and eligible students may request review/access, correction, export, deletion or anonymization, access closure, consent withdrawal, and a stop to further collection where applicable. How to stop further collection: Contact the school or CATHOLICORE LLC at info@catholicore.com and identify the school and requested action without sending passwords, payment credentials, or unnecessary student records. The request is logged and assigned a tracking record. Identity, authority, and the relationship to the student are verified. Cashless Cafeteria may coordinate with the school before disclosing or changing school-controlled records. The school determines applicable instructions for school-controlled records, and Cashless Cafeteria performs the applicable platform access, correction, export, deletion, anonymization, collection-stop, or access-closure action. The verified requester receives a completion report describing actions taken, deletion or anonymization, retained exceptions and reasons, affected providers, and the expected backup-expiry cycle.

Material changes

CATHOLICORE LLC will not materially expand collection, use, disclosure, AI processing, or retention without updated review, contract authority, notice, and consent where required.

Required School action

Before relying on school authorization, an authorized signer must review the current English and Spanish notices, complete the Data Processing Agreement, document the permitted legal basis and scope, deliver required family notices, identify students needing parental consent, and preserve the resulting evidence. Student acknowledgment never supplies parental consent.