Privacy Policy
Last updated 13 August 2026
This document is still being finalised and has not been reviewed by a lawyer. It does not yet apply to anyone. Please don’t rely on it — if you need to know where you stand right now, email hello@lunchtrolley.com and we’ll tell you plainly.
2 items are still being finalised.
LunchTrolley is operated by Parker Howard, sole trader, ABN 88 206 778 370, trading as LunchTrolley.
This policy explains what personal information we collect, why, who we share it with, and what you can do about it.
A note on scope. As a small business we may fall within the small business exemption in the Privacy Act 1988 (Cth). We have chosen to comply with the Australian Privacy Principles anyway, and you should hold us to this policy as though the Act applied to us in full.
1. The short version
- We collect the least we can get away with: enough to know whose lunch is whose, to work out what each person owes, and to reach you about your order.
- Nobody ordering lunch needs an account. First name, last name, email, and that's it.
- Your browser can remember your name and email so you don't retype it every round. That stays on your device, we never receive it, and nothing is ever filled in for you until you tap to say so — the page offers, it doesn't assume. Section 5 explains it.
- We never handle money. There are no card numbers here, because there are no card payments.
- We do store a coordinator's bank details if they choose to offer bank transfer, because showing them to colleagues is how people get paid back. They are encrypted, and section 4 explains exactly what happens to them.
- We don't use analytics, advertising trackers or third-party cookies. No Google Analytics, no advertising pixels, nothing following you around.
- We don't sell your information. To anyone. Ever.
2. What we collect
If you order lunch
| What | Why |
|---|---|
| Your first and last name | So the coordinator knows whose meal is whose, and so they can match your payment to your order on their bank statement |
| Your email address | To send you your order and how to pay it, and to tell you if something changes |
| What you ordered, including notes and dietary requests | To pass to the vendor, and to work out what you owe |
| Whether you say you've paid, when, and by which method | So your coordinator knows to look for it, and knows where |
You do not create an account and you do not set a password.
We ask for a last name as well as a first name for one specific reason: your coordinator is matching your payment against a line on a bank statement, and "Dave" does not reconcile.
Please note: your name and what you ordered are visible to the coordinator running that round. That is the point of the product, but it is worth being explicit about. Anything you type into the notes field goes to your coordinator and to the vendor.
Others in the same round see a little, too. So everyone can see the order coming together, a round shows a live activity feed to the people in it — but only your first name and last initial (e.g. "Dave S."), and only that you placed, changed, cancelled or said you'd paid for an order. Your full name, your email, what you actually ordered, and whether the coordinator has confirmed your payment are never shown to other colleagues — those stay between you and the coordinator.
If you run a round (a coordinator)
| What | Why |
|---|---|
| Your email address | To sign you in, by emailed link — we don't use passwords |
| Your first and last name | So colleagues know who they are paying |
| Rounds, vendors and menus you create | To run the service |
| A contact number on a round, if you add one — optional | So that round's vendor can ring you about the order. It is printed on the order sheet they receive |
| Your payment details — see section 4 | So colleagues know where to send the money |
Technical information
Our hosting provider processes standard server logs — IP address, browser type, pages requested — to serve the site and to protect it from abuse.
3. What we don't collect
- Card numbers, CVCs or expiry dates. LunchTrolley does not take card payments at all.
- Identity documents. We don't verify anyone's identity.
- Phone numbers, to contact you with. We have no way to send you an SMS and no phone line, so we never ask for a number in order to reach you. Two numbers can end up in our database anyway, and neither is us collecting a way to contact you: a mobile given as a PayID is a payment detail, covered in section 4, and is only ever shown to people who have ordered in that coordinator's round; and a coordinator may add a contact number to a single round, which is printed on the order sheet that round's vendor receives so the vendor can ring about the food. That one is optional, blank unless it is typed, never filled in from anything else we hold, and deleted with the rest of that round's details — see section 8.
- Location data.
- Advertising or cross-site tracking data. We don't run any.
4. Coordinator payment details
This is the most sensitive information we hold, so it gets its own section.
What we store. Whichever of these a coordinator chooses to offer: a PayID (a mobile number or an email address), bank account details (account name, BSB and account number), and cash. Plus an optional note like "put your name in the reference".
Who sees it. Only people who have placed an order in that coordinator's round, and only through a signed link to their own order. It is deliberately not shown to anyone who merely has the round's share link — a link gets forwarded and screenshotted, and a bank account on the end of one would follow it.
How it's protected. The account number is encrypted at rest and is decrypted in exactly one place: the page where somebody who has ordered is about to pay. Once saved, it is never shown back to the coordinator in full — they see the last three digits, enough to tell two accounts apart.
How long we keep it. The copy attached to a round is deleted 30 days after that round's deadline, by a job that runs every day. What remains on the round is a masked description — "Bank transfer · BSB 083-••• · acct •••678" — so the record of which account a round told people to pay survives, without the account itself doing so. The reusable copy on a coordinator's profile stays until they change or delete it, and there is a "delete my payment details" button that removes all of it at once.
What we don't do. We do not verify that an account exists, that it belongs to the coordinator, or that it is correct. We do not use these details for anything except displaying them to the people who ordered.
5. Cookies, and what your browser keeps
We use cookies only where they are necessary for the site to work:
- Coordinator sign-in. A session cookie keeps you signed in after you click your magic link.
- Security. Cookies used to protect against cross-site request forgery.
People ordering lunch are not given a sign-in cookie, because there is no account to sign in to.
We do not use advertising, analytics or cross-site tracking cookies.
Things kept in your browser, not on our servers
Two parts of the site ask your browser to hold onto something for you. Neither is a cookie, and neither is sent to us — a cookie travels with every request, and these do not travel at all.
| What | Where | How long |
|---|---|---|
| Your first name, last name and email, if you've ordered lunch from that device | Local storage, on your device | 60 days from your last order, then it's discarded |
| A menu a coordinator is part-way through building, so leaving the page and coming back doesn't lose it | Session storage, on your device | Until you close the tab |
The first one is there so you don't type the same three fields every week. It is worth being precise about what it is not: we do not look you up. There is no "who ordered last time" lookup on our side, and there could not be one — a share link gets forwarded and screenshotted, so anything that answered questions about an email address would answer them for whoever held the link, about colleagues whose addresses are easy to guess. It is your own browser holding your own details, and nothing about it reaches us until you place an order, which is the same moment those details were going to reach us anyway.
Nothing is filled in without you asking for it. The ordering page does not put saved details into the form by itself. It shows a short offer beside the name fields — "this device remembers Robin S. · ro•••@example.com" — and only fills anything in when you tap the button. The name is shortened and the address is partly hidden on purpose, because a shared or hot-desk machine may be read by somebody other than the person whose details are saved: enough to recognise yourself, not enough for anyone else to copy down. A form that filled itself in would put one person's lunch, confirmation and payment under another person's name before either of them noticed.
To clear it: the same offer carries a "Not you? Forget them" button, which removes the saved copy from your browser as well as dismissing the offer. If you have already used it, the note under the fields offers the same thing. Clearing your browser's site data does it too, and it expires on its own after 60 days.
6. Who we share it with
We share personal information only with the providers needed to run the service:
| Provider | What they handle | Where |
|---|---|---|
| Supabase | Database and authentication | Sydney, Australia (ap-southeast-2) |
| Vercel | Website hosting | Sydney, Australia (syd1) for application code |
| ZeptoMail (Zoho) | Sending the emails described in section 7 | Australia |
Our database, our application and our email sending all run in Australia. There is no routine cross-border disclosure of your personal information.
Stripe is no longer a processor of your information. It was, when LunchTrolley took card payments; it does not receive anything now.
We may also disclose information where the law requires it, or where it is reasonably necessary to investigate suspected fraud — including providing the record of a round to people who lost money in it, or to police.
We do not sell personal information, and we do not disclose it for marketing.
7. Email we send you
We send two kinds of email.
Messages about your own order, which you get because you placed one: your order and how to pay it, a note when your coordinator confirms your payment, a note if they change your order, when ordering closes, when the food arrives and where to collect it, and if the round is cancelled. These have no unsubscribe link, because switching them off would mean you could lose money without being told.
Updates from your coordinator about that round — running late, the shop is out of laksa. These are limited to the round you ordered in, they carry an unsubscribe link, and we honour it immediately and permanently for that address.
We do not send marketing email, and a coordinator cannot use LunchTrolley to build a mailing list. The addresses in one round are not available to any other round.
8. How long we keep it
| Data | Retention |
|---|---|
| Order records | 7 years, to meet tax and financial record-keeping obligations |
| Coordinator payment details attached to a round | Deleted 30 days after that round's deadline; a masked description remains |
| A contact number added to a round | Deleted 30 days after that round's deadline, with the payment details |
| Coordinator payment details on a profile | Until changed or deleted by the coordinator |
| Coordinator account details | While the account is open, then 7 years for records relating to a round |
| Record of emails we sent | 7 years, as part of the record of a round |
| Server logs | Kept by our hosting provider on their standard schedule, then deleted. We don't keep a separate copy. |
Financial records have to be kept whether or not you ask us to delete them; that is the law, not a preference of ours. Note that these are records of what was ordered and owed — we hold no record of an actual payment, because we never see one.
9. Security
- All traffic is encrypted in transit (HTTPS).
- Access to order data is restricted at the database level, not just in application code.
- Coordinator account numbers are encrypted at rest and are decrypted only to be shown to someone who has ordered in that round.
- Your access to your own order is authorised by a signed, single-order token rather than by a guessable identifier.
- Payment details are frozen while a round is open, and a coordinator is emailed whenever their payment details change — so a change nobody made is visible immediately.
No system is perfectly secure. If a data breach occurs that is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner, as required by the Notifiable Data Breaches scheme.
10. Your rights
You can ask us to:
- Tell you what we hold about you;
- Correct it if it's wrong;
- Delete it, subject to the retention obligations in section 8.
Email hello@lunchtrolley.com. We'll respond within 30 days. We may need to verify your identity first — usually by confirming you control the email address on the order. If you ordered lunch and have no account, that email address is how we find you, so please write from it.
11. Complaints
If you think we've mishandled your personal information, email hello@lunchtrolley.com with the details and we will investigate and respond within 30 days.
If you're not satisfied with our response, you can complain to the Office of the Australian Information Commissioner:
- oaic.gov.au
- 1300 363 992
- GPO Box 5288, Sydney NSW 2001
12. Changes
If we change this policy in a way that materially affects you, we'll tell you by email or in the app before it takes effect.
13. Contact
LunchTrolley — Parker Howard, sole trader ABN 88 206 778 370 PO Box 27, Mascot NSW 1460, Australia hello@lunchtrolley.com