Privacy for families
Parent Privacy Notice
A stand-alone explanation of student-data practices, parent choices, and request procedures.
- Effective:
- July 25, 2026
- Last updated:
- July 25, 2026
- Version:
- 2026-07-25
Plain-language summary
The school generally controls school records; Cashless Cafeteria processes them for the authorized cafeteria service. Notice acknowledgment and parental consent are separate records. The complete document below controls.
1. Who operates Cashless Cafeteria
CATHOLICORE LLC operates Cashless Cafeteria. This notice explains how student information is handled and how a parent or guardian can ask questions or exercise available rights.
2. The school and Cashless Cafeteria
The school generally creates or provides the student roster and decides how the cafeteria service is used. For those school-controlled records, Cashless Cafeteria acts under the school’s documented instructions and Data Processing Agreement. CATHOLICORE LLC separately controls limited account administration, security, fraud-prevention, legal-compliance, subscription, and support records.
4. When parental consent may be required
Separate verifiable parental consent may be required because of the student’s age, school type, jurisdiction, feature, data use, or a material change. When required, consent is requested through an authenticated guardian workflow that displays the applicable notice and records the decision, scope, method, version, and any withdrawal. Reading or acknowledging this notice—and a student’s acknowledgment—does not grant parental consent.
5. Information collected
Required school roster fields: school and internal student identifiers, first and last name, grade, enrollment and active status, and household link.
Optional or school-configured profile and lifecycle fields: email address, date of birth, gender, profile photo, account link, withdrawal date, reason and responsible staff identifier, school-created notes, and created/updated timestamps and responsible staff identifiers.
Cafeteria and account records: lunch-card and barcode identifiers; meal selections; items, quantities, prices, timestamps, serving line, purchases and order history; household wallet balance, holds, allocations, top-ups, adjustments, refunds, disputes, and safe payment references.
Access and communications: invitations, guardian and household relationships, roles and permissions, notice acknowledgments, authorization or consent status, notification preferences and delivery status, privacy requests, and support communications.
Technical and security information collected automatically: IP address or minimized/hashed IP-derived identifiers, approximate location derived from IP, device type, browser, operating system, authenticated session and login records, timestamps, sanitized page paths and referrers, persistent session or security identifiers, rate-limit records, audit logs, and error or performance information.
6. Information from the school and the child
Schools and authorized staff generally provide the required roster, enrollment, household, authorization, cafeteria setup, and school-created note fields. Parents and guardians may provide contact, household, payment, notification, and request information. An authorized student may provide sign-in credentials, profile changes the school permits, meal selections, and requests for help. Technical and security information is collected automatically during sign-in and use.
7. Cafeteria purchases and payments
The service records the student or other buyer, selected items, quantities, prices, time, serving line, purchase status, and resulting household-wallet activity. Stripe collects card or bank credentials through its hosted components. Cashless Cafeteria keeps provider references, amount, fees, status, safe instrument details such as brand or last four digits, and reconciliation records; it does not intentionally receive or store full card numbers, security codes, routing numbers, or bank-account numbers.
8. Who can see student information
Authorized school staff may see information permitted by their role. Linked guardians, students, and other household members may see the household and student information allowed by their verified relationship. CATHOLICORE LLC personnel and service providers receive only the access needed for their assigned operational function. Access ends or is restricted when the school, a valid consent withdrawal, account status, or law requires it.
9. Service providers receiving information
Stripe: Family payments, saved payment methods, refunds and disputes, school subscriptions, payout-account verification, and payment reconciliation. Student information involved: Payment amount, status, household or customer reference, safe instrument details, and transaction context. Card and bank credentials are collected by Stripe.
Supabase: Database, authentication, sessions, row-level access controls, private file storage, and server-side data operations. Student information involved: The student, household, cafeteria, authorization, account, audit, request, and operational records needed for the service.
Vercel: Application hosting, server execution, deployment infrastructure, operational logs, aggregated Web Analytics, and Speed Insights. Student information involved: HTTP and device metadata and minimized operational measurements. Student pages and student audiences are excluded from product analytics.
Resend: Transactional delivery of invitations, account, security, balance, purchase, payment-result, privacy, and support messages. Student information involved: Recipient email, safe display name, school and necessary message content, action link, and delivery metadata.
Upstash: Server-side rate limiting, idempotency, and bounded operational caching. Student information involved: Minimized tenant-scoped identifiers and operational values with short expiration periods; sensitive key values are hashed.
Sentry: Sampled error reporting, release diagnosis, and performance monitoring. Student information involved: Minimized technical context. Default PII transmission is disabled, and student records, request bodies, credentials, and free-text notes are prohibited.
10. Prohibited uses
Identifiable student information is not used for: targeted or behavioral advertising or marketing directly to children; cross-service tracking, provider-owned profiling, or commercial profiles unrelated to the school contract; sale, rental, licensing, data brokerage, or eligibility and decision-making unrelated to cafeteria service; general-purpose or unrelated artificial-intelligence model training, or prompting a third-party AI service without approval for a defined contracted function; developing products unrelated to the contracted cafeteria service; combining identifiable student information with external or other-customer datasets for unrelated purposes.
Necessary operations remain permitted only with minimization, access controls, retention limits, and re-identification restrictions: provide, secure, maintain, troubleshoot, and support the contracted cafeteria service; detect fraud, misuse, and account-security threats using minimized information; produce school-authorized reports and meet legal obligations; debug and improve service reliability and accessibility for the contracted service; measure reliability, capacity, accessibility, and feature use with aggregate or appropriately de-identified information subject to re-identification prohibitions.
11. Retention and deletion
Student identity, enrollment, household, guardian, profile, lunch card, and authorized account access: While the documented school-authorized purpose remains active; after verified termination or deletion instruction, review begins within 30 days and approved deletion or anonymization completes within 90 days unless a contract, legal hold, or nonwaivable duty requires otherwise.
Cafeteria, wallet, payment, refund, dispute, and reconciliation records: While operationally needed; qualifying financial, accounting, legal, and reconciliation evidence may be retained for up to seven years, with child-identifying fields removed sooner where feasible.
Invitations and terminated authentication sessions: Approximately 30 days after expiration or termination.
Family access requests and unanswered guardian consent requests: Family access requests: approximately 90 days. Unanswered consent requests expire after seven days and are deleted 90 days after expiry when no evidence or legal hold applies.
Privacy exports, archived notifications, and sanitized payment-webhook summaries: Privacy exports: seven days; archived notifications: approximately 180 days; sanitized payment webhook summaries: approximately 400 days.
Authorization, consent, notice, security-audit, and legal evidence: Up to seven years under manual legal review, subject to a shorter school agreement, approved deletion decision, or longer legal hold.
12. Parent and guardian rights
Depending on the record and applicable law, a verified parent or guardian may request access or review, correction, a portable export, deletion or anonymization, closure of portal access, withdrawal of consent, or a stop to further collection or use. A request to close a portal does not automatically erase financial, security, authorization, or school records that must remain for a valid purpose.
Contact the school or CATHOLICORE LLC at info@catholicore.com and identify the school and requested action without sending passwords, payment credentials, or unnecessary student records.
The request is logged and assigned a tracking record.
Identity, authority, and the relationship to the student are verified. Cashless Cafeteria may coordinate with the school before disclosing or changing school-controlled records.
The school determines applicable instructions for school-controlled records, and Cashless Cafeteria performs the applicable platform access, correction, export, deletion, anonymization, collection-stop, or access-closure action.
The verified requester receives a completion report describing actions taken, deletion or anonymization, retained exceptions and reasons, affected providers, and the expected backup-expiry cycle.
13. How identity and authority are verified
Cashless Cafeteria uses an authenticated account when available and may confirm the requester’s email, school, student, guardian record, household relationship, and authority with the school. The service asks only for the information reasonably needed to prevent disclosure or changes to the wrong person. Staff will never ask for a password, full payment credential, or unnecessary copy of a student record.
14. Withdrawing consent or closing portal access
An authenticated guardian may use the consent workflow or contact the school or info@catholicore.com to withdraw current consent. Withdrawal is recorded separately from notice acknowledgment, disables access that depended on that consent, and stops further collection for that consent scope except as legally permitted. Ask the school or privacy team to close portal access that rests on school authorization. Existing purchase, accounting, security, and authorization evidence follows the retention schedule rather than being automatically erased.
15. Contact information
CATHOLICORE LLC, 51 Orange St, Stamford, Connecticut, USA. Privacy email: info@catholicore.com. Telephone: +1 475-300-6334. Availability: Monday-Friday, 8:00 AM-5:00 PM Eastern Time, excluding company holidays; Within one business day. Security incidents: info@catholicore.com. Do not send passwords, payment credentials, or unnecessary student records.
Cashless Cafeteria
Questions? Use the Contact section on our home page.
