Last updated: June 2026 · Effective: June 2026
Petit Lunch Inc. ("Petit Lunch", "we", "our") operates the Petit Lunch school lunch ordering platform at app.petitlunch.com. We are registered in Canada and process personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.
Questions or requests regarding this policy: contact@petitlunch.com
| Category | Examples | Purpose |
|---|---|---|
| Account information | Name, email address, password (hashed) | Account creation and authentication |
| Child profiles | Child name, grade, school, student number | Meal ordering and school roster matching |
| Health information | Food allergies, dietary restrictions | Allergen safety alerts and meal filtering |
| Order data | Meal selections, order history, delivery status | Order fulfilment and billing |
| Payment information | Billing address, last 4 digits of card (Stripe tokenized) | Payment processing — full card numbers are never stored by Petit Lunch |
| Usage data | Pages visited, device type, IP address | Platform security and performance |
We do not sell your personal information. We share information only as follows:
Schools and school boards
Your child's name, order status, and allergy profile are shared with the school for meal service and delivery verification.
Food vendors
Order contents (meal selection, child name, allergens) are shared with the vendor preparing the meal. Vendor access is limited to order-specific data.
Stripe (payment processing)
Payment card data is processed by Stripe, Inc. under their Privacy Policy. Petit Lunch does not store full card numbers.
AWS (cloud infrastructure)
All data is stored on AWS ca-central-1 servers located in Canada. AWS processes data as a sub-processor under our data processing agreement.
Firebase Cloud Messaging (Google)
If you enable order status notifications, a device identifier (push token) is shared with Google Firebase to deliver those notifications to your phone or browser. No order, payment, or child information is included in this token.
Legal requirements
We may disclose information if required by law, court order, or to protect the safety of users.
Child profiles (name, grade, allergy data) are created by parents or guardians and are used solely for meal ordering and safety purposes. We do not use children's information for advertising or share it with third parties beyond what is necessary for meal service. School access to child data is governed by a data sharing agreement with each school board.
All personal information is stored on servers located in Canada (AWS ca-central-1). We use HTTPS/TLS for all data in transit, BCrypt password hashing, and HTTP-only cookies for session tokens. Access to personal data is restricted to authorized Petit Lunch staff on a need-to-know basis. Push notification delivery (see Section 4) is the one exception — device push tokens are routed through Google's global Firebase infrastructure, not exclusively Canadian servers.
Under PIPEDA, you have the right to:
To exercise any of these rights, contact contact@petitlunch.com. We will respond within 30 days.
Account and order data is retained for 7 years to comply with CRA (Canada Revenue Agency) record-keeping requirements for GST/HST-exempt transactions. Health profiles (allergy data) are deleted within 30 days of account closure unless retention is required by a school board agreement.
We use essential cookies only: a session cookie for authentication (HttpOnly, Secure) and a language preference cookie. We do not use advertising or third-party tracking cookies.
We will notify registered users by email at least 14 days before any material change to this policy. Continued use of the platform after that date constitutes acceptance of the revised policy.
Contact our Privacy Officer
Petit Lunch Inc. · contact@petitlunch.com