KantinApp is a school cafeteria service that helps students and participating schools view menus, vote on dishes, save favorites, send feedback, and manage optional notifications.
This Privacy Policy explains what information KantinApp processes, why the information is used, when it may be shared, and what choices you have. It applies to the KantinApp mobile app and the public website at kantinapp.app.
1. Information We Collect
The exact information KantinApp processes depends on how you use the service, but it can include the following categories:
- Account information such as your name, school email address, school affiliation, and user role.
- Authentication and security information such as password hashes, sign-in sessions, verification codes, and password-reset activity.
- Preference data such as hidden allergens, hidden tags, default catalog view, default sort order, gluten-free interest preference, and notification settings.
- Usage data tied to your account, including votes, favorites, and school-specific menu interactions inside the app.
- First-party mobile usage analytics such as categorical menu opens, notification opens, changes to interest or meal intent, votes, and the stage at which an unauthenticated registration flow was left.
- Sanitized JavaScript error reporting and API failure categories. Error events contain a categorical screen, status category, and opaque fingerprint, but not raw URLs, query strings, error messages, stack traces, access tokens, dish names, allergen choices, or user-entered text.
- User submissions such as tips, reports, support-style feedback, and requests to change school.
- Notification device data such as Expo push token, device key, platform, and device name when you enable push notifications.
- Microsoft sign-in identifiers such as tenant ID, object ID, and school onboarding status when Microsoft sign-in is enabled.
- Administrative submissions and support content such as tips, app issue reports, school-change requests, admin notes, and review status.
- AI image reference data when authorized administrators use OpenAI-powered dish image generation.
- Basic website analytics data on the public website, including data collected through Vercel Analytics.
2. How We Use Information
KantinApp uses personal information only as needed to operate and improve the service.
- Create and maintain user accounts.
- Authenticate users, protect accounts, and prevent misuse of the service.
- Show the correct school menu, favorites, tips, and other school-relevant content.
- Save your preferences and personalize the app experience.
- Send account verification messages and password-reset emails.
- Send push notifications that you choose to enable.
- Monitor service performance, investigate errors, and improve reliability and product quality.
- Understand aggregate app usage and improve registration, menu, notification, and feedback flows without using the event stream for advertising or individual profiling.
- Allow authorized school administrators to review school-scoped student submissions, app issue reports, tips, school-change requests, and aggregated menu engagement for their school.
4. Retention and Security
KantinApp keeps information for as long as it is reasonably needed to operate accounts, provide the service, maintain security, and meet operational or legal obligations.
- Push delivery attempt records are cleaned up after 7 days by the scheduled cleanup job.
- Raw first-party mobile usage and sanitized JavaScript error events are deleted after 90 days. Account-linked events use a pseudonymous server-generated identifier rather than storing the user ID in the event row; registration-abandonment events use a pseudonymous installation identifier.
- Email verification, password reset, and account-deletion tokens are temporary security records and are deleted after use or expiry.
- Account deletion removes the account, related user-scoped records, and account-linked raw mobile analytics events according to the app's deletion flow, while operational logs may be retained for security and abuse prevention.
- Student accounts that never become active may be warned after 60 days and deleted after 90 days of inactivity.
- Previously active student accounts may be warned after 335 days and deleted after 365 days of inactivity.
- At the end of each school year, KantinApp may store aggregated school-year summaries for participating schools. These summaries are designed for statistics and planning and do not include account emails, device tokens, raw authentication data, or raw free-text feedback bodies.
- At the start of a new school year, student school affiliation may be cleared so students confirm their current school again.
KantinApp uses reasonable technical and organizational safeguards. For example, passwords are stored as cryptographic hashes rather than plain text, and some sensitive actions are rate-limited. No method of storage or transmission is perfectly secure, so absolute security cannot be guaranteed.
5. Your Choices
- You can review and update many preferences directly inside the app.
- You can enable or disable push notifications through the app and through your device settings.
- You can request deletion of your account through the app or through the public deletion page at https://kantinapp.app/delete-account.
- You can contact KantinApp to request privacy help, correction of inaccurate data, or deletion of your account data where applicable.
- You can stop using the service at any time, but some data may remain for security, operational, or legal reasons.
6. Children's Privacy
KantinApp is intended for students and staff at participating schools. It is not designed as a children-directed service for young children.
7. Changes to This Policy
KantinApp may update this Privacy Policy from time to time. When the policy changes, the version on this page will be updated together with the last updated date.
8. Contact
If you have questions about this Privacy Policy or want to request privacy-related help, contact KantinApp at kantinapp.support@gmail.com.