1. Who this policy covers
Cater Bundles is a group catering marketplace operated by Foodie Game Changer (FGC) of Fremont, California. In this policy, “Cater Bundles”, “we”, “us” and “our” mean that business. “You” means anyone who uses caterbundles.com, places an order, contacts us, or runs a restaurant account on our partner portal.
This policy applies to our website and services. It does not apply to the separate privacy practices of the restaurants, payment processors or courier services described in section 4, each of which handles the information it receives under its own policy.
2. Information we collect
Information you give us
- Account details: your email address, a password (which we store only as a salted hash, never as text we can read), and optionally your first and last name and phone number.
- Order details: the delivery address, delivery date and time, headcount, occasion, company name, drop-off instructions, whether you want contactless delivery, dietary notes, and the dishes and quantities you order.
- Contact details of the person receiving the order, if that is not you.
- Messages you send us through the contact form, including your name, email, phone number, subject and message.
- Restaurant partner details, if you apply to sell on Cater Bundles. See section 11.
Information collected automatically
- Session data needed to keep you signed in, held in a strictly necessary cookie. See section 7.
- Server logs generated when your browser or app calls us, which include the request path, timing, outcome and IP address. We use these to run, secure and debug the service.
- Your cart, which is stored in your own browser's local storage on your device. It holds dish identifiers, quantities and a headcount. It stays on your device until you check out or clear it.
We do not ask for or collect precise device location. When you type a delivery address, the partial text you type is sent to Photon, an address-autocomplete service operated by komoot, to return suggestions. We send only the address text, with no account identifier attached to it.
Information from others
Our payment processor tells us whether a charge succeeded and, if you chose to save a card, the card brand, last four digits and expiry date. Our courier partner tells us the live status of your delivery. We do not buy personal information from data brokers or advertising cooperatives.
If you sign in with Google
Signing in with Google is optional. You can always use an email address and password instead, and it is never required to place an order.
- What we receive: your email address, whether Google has verified it, and your first and last name if Google shares them. Nothing else. We ask Google only for your basic profile and email, never for your contacts, calendar, files, or any other data, and we do not request ongoing access to your Google account.
- What we do with it: we use the email address to identify your Cater Bundles account, and the name to fill in your profile. If the address matches an existing Cater Bundles account, we connect the two so you keep one account and one order history.
- What we store: Google's permanent identifier for you, the email address at the time you connected, and the fact that it was Google. We never receive or store your Google password.
- Disconnecting: you can revoke our access at any time in your Google account settings. Doing so stops the sign-in button from working; your Cater Bundles account and order history remain, and you can set a password to sign in again.
We do not use anything received from Google for advertising, and we do not sell or share it. Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
3. How we use information
- To take, price, place and deliver your order, including sending each restaurant the part of the order it is cooking and arranging a courier for each pickup.
- To charge you accurately. All money is calculated on our servers, including per-restaurant sales tax, so the total you approve is the total charged.
- To show you your order status live, and your order history if you have an account.
- To send you transactional messages: order confirmations, status updates, receipts, password reset and email verification codes, and replies to messages you send us.
- To keep the service working and safe: preventing fraud and abuse, enforcing order limits, investigating disputes and chargebacks, and diagnosing failures.
- To meet legal, tax and accounting obligations.
- To improve the catalog and the product, using order and usage patterns in aggregate.
We rely on your information to perform the contract you enter into when you place an order, to meet our legal obligations, and for our legitimate interest in operating a secure and functional service.
5. What we do not do
- We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined by California law.
- We do not run third-party advertising networks, advertising pixels or third-party analytics trackers on this site.
- We do not use your dietary notes, or anything else you tell us about your order, for advertising or profiling.
- We do not store your full card number, security code or expiry on our systems.
- We do not require an account to place an order.
Because we do not sell or share personal information, there is no “Do Not Sell or Share My Personal Information” mechanism to offer. If that ever changes, we will update this policy and provide one before the change takes effect.
6. Payment information
Card details are collected in your browser by Stripe’s own hosted card field and sent straight to Stripe. Our servers receive only a payment method reference, which is a token that identifies the card to Stripe but is useless to anyone else.
If you choose to save a card for next time, we store that reference, your Stripe customer identifier, and a display snapshot of the card brand, last four digits and expiry date. The reference and customer identifier are held server side and are never sent to your browser, so a stolen or guessed token cannot be charged against your account. You can remove a saved card from your profile.
8. How long we keep information
- Order records, including the delivery address and the items ordered, are kept for as long as needed to support the order and then to meet tax, accounting and dispute-resolution obligations.
- Account information is kept while your account is open, and removed on request as described in section 10.
- Session records expire on their own and are deleted when you sign out.
- Password reset and email verification codes are stored only as hashes and expire shortly after being issued.
- Contact form messages are kept while we handle your enquiry and for a reasonable period afterwards.
- Server logs are kept for a limited period for security and debugging.
When we no longer need information for these purposes, we delete it or de-identify it. Backups and archived copies may persist for a short time after deletion before they age out.
9. How we protect information
Traffic is encrypted in transit. Passwords are stored only as salted hashes. Session cookies are HTTP-only and scoped to the site that issued them. Card data never touches our servers. Restaurant partners are scoped by account so one restaurant cannot read another restaurant’s orders or any customer’s contact details. Administrative access is limited to staff who need it.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach affects your personal information, we will notify you and the relevant authorities as required by law.
10. Your privacy rights
Depending on where you live, including under the California Consumer Privacy Act as amended by the California Privacy Rights Act, and under comparable laws in states such as Colorado, Connecticut, Delaware, Iowa, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah and Virginia, you may have the right to:
- Know what personal information we have collected about you, where it came from, why we collected it, and who we disclosed it to.
- Get a copy of that information in a portable form.
- Correct information that is inaccurate.
- Delete information we hold about you, subject to the exceptions the law allows, such as records we must keep to complete a transaction, resolve a dispute or comply with a legal obligation.
- Limit the use of sensitive personal information. We do not use sensitive personal information for anything beyond providing the service you asked for.
- Opt out of the sale or sharing of personal information, and of profiling. As stated in section 5, we do none of these.
- Not be discriminated against for exercising any of these rights. Our prices and service do not change because you made a privacy request.
To make a request, email privacy@caterbundles.com or use our contact form. So that we do not hand your information to someone else, we will verify your identity before we act, usually by confirming control of the email address on the account and details of a recent order. An authorised agent may act for you with written permission that we can verify.
We will respond within the time the law allows, normally within 45 days, and will tell you if we need longer. If you disagree with our decision, you may appeal by replying to our response, and you may contact your state attorney general.
You can also change some things yourself: update your name, phone, address and saved card from your profile, and unsubscribe from any non-essential email using the link in it. Transactional messages about an order you placed cannot be switched off while that order is live.
11. Restaurant partner accounts
If you apply to sell catering on Cater Bundles, we collect your business email, a hashed password, a contact name and phone number, and the answers to our onboarding questionnaire: your store address, your self-declared sales tax rate, your catering hours and advance notice, your delivery arrangements, and any menu files you upload. Our staff review these answers to approve or decline the account, and an approved restaurant’s address and menu information becomes part of the public catalog.
Business contact information used to run a partner account is handled under this policy in the same way as any other personal information, and the rights in section 10 apply to it.
12. Children
Cater Bundles is intended for adults arranging catering. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, email privacy@caterbundles.com and we will delete it. We do not sell or share the personal information of anyone under 16.
13. Third-party links
Our site links to restaurants, courier tracking pages and other third-party sites. We do not control them and are not responsible for their privacy practices. Read their policies before giving them information.
14. Changes to this policy
We may update this policy as the service changes or the law does. The effective date at the top always reflects the current version. If a change materially affects how we handle your information, we will tell you before it takes effect, by email or a notice on the site.
15. How to reach us
Questions, requests or complaints about privacy go to privacy@caterbundles.com. For anything else, use the contact page.
Cater Bundles
Operated by Foodie Game Changer
Fremont, CA 94538
privacy@caterbundles.com