Privacy Policy
Last updated · April 2026
Information We Collect
When you create an account, we collect your name, email address, and profile photo from your Google account. When you place an order, we collect your order details and payment information (processed securely through Square).
Location Data
If you enable location services, we collect your location when you use the "Come to Me" feature to request the truck. Your location is used to set a geofence so you are notified when the truck arrives near you. Location data is not stored after your request is fulfilled.
Admin users who broadcast the truck's location share their GPS coordinates with app users so customers can see where the truck is on the map. This broadcast location is visible to all users while active.
How We Use Your Information
We use your information to process and fulfill your orders, send order status notifications, improve our menu and service, and communicate with you about your orders.
Data Storage
Your data is stored securely using Google Firebase. Payment processing is handled by Square and we do not store your full payment card details.
Push Notifications
With your permission, we send push notifications about order updates and special announcements. You can disable these at any time in your profile settings or device settings.
Crash Reporting
We use Sentry to collect anonymous crash reports so we can find and fix bugs. Crash reports include your device model, operating system version, and technical stack traces. They do not include any personally identifiable information such as your name, email, or location.
Service Providers (Sub-processors)
We share limited data with the following service providers to operate the app. Each is contractually limited to the purpose listed:
- Google (Firebase) — account auth, database, file storage, hosting, push delivery (FCM).
- Square — payment processing for online orders. Card details never touch our servers; Square's iframe tokenizes them in your browser.
- Resend — order receipt and review-request email delivery. Resend sees your email address and order summary; the message body itself is rendered by us.
- Expo Push (FCM/APNs) — order-status and event push notifications on mobile.
- Sentry — anonymous crash reporting, as described above.
- Google Analytics 4 — anonymized website analytics, as described above.
- Calendly — embedded booking calendar on /book. Calendly receives the data you submit to schedule a call (name, email, event details).
How Long We Keep Your Data
We retain your data only as long as necessary for the purpose for which it was collected:
- Account data, profile, favorites — until you delete your account.
- Order history — 7 years from purchase, for tax and accounting compliance (US IRS retention).
- Push notification tokens — until you sign out or revoke notification permission.
- Crash reports (Sentry) — 90 days, then automatically purged.
- Website analytics (GA4) — 14 months, the maximum we configure.
- Truck location history — 30 days, then aggregated.
If you delete your account, we remove the personal-identity data immediately. Order records are retained as anonymized history for tax purposes — your name and email are removed but the order line items and total remain on file as a financial record only.
Do Not Sell or Share My Personal Information
We do not sell your personal information. We do not use targeted advertising or remarketing pixels. The website analytics described above use anonymized identifiers and do not transfer personal information to advertisers.
If you are a California resident or a resident of another jurisdiction with a similar right, you may opt out of any data sharing that could be considered "sharing" under the CCPA/CPRA by emailing cjscooltreats@gmail.com with the subject "Do Not Sell or Share Request." We will confirm receipt within 10 business days and complete the opt-out within 15 business days.
Website Analytics
We use Google Analytics 4 to understand which pages of our website are most useful and where visitors come from. GA4 records anonymized page views and a small number of action events (when you click "Book," "Order," call us, or email us). IP addresses are anonymized and we do not enable advertising or remarketing features — your data is not used for personalized ads.
You can opt out at any time by enabling "Do Not Track" in your browser, installing the official Google Analytics Opt-out browser add-on, or blocking analytics cookies in your browser's privacy settings.
Account Deletion
You can delete your account at any time from the Profile tab in the app. This will permanently remove your account data, order history, favorites, reviews, and push notification token from our systems.
Contact Us
If you have questions about this privacy policy, please contact us at (636) 352-7865 or email cjscooltreats@gmail.com.