Legal

Privacy Policy

Updated: August 2026

This policy explains what information HuddleEats collects when you use our platform, why we collect it, who we share it with and by what method, how long we keep it, and how we protect it. We have tried to write it in plain language rather than boilerplate.

1. Who this policy covers

HuddleEats is a software platform that helps athletic programs schedule and order team meals from independent food vendors. This policy applies to everyone who uses the platform: parents and guardians, coaches and school staff, and vendor operators.

It also covers the athlete records that adults create in the platform. Athletes themselves do not have accounts and do not use the platform — see section 9.

2. Information we collect

We collect the minimum needed to run team meal ordering. Specifically:

Account information
Email address
Identifies your account, used to sign in and to send order notifications.
Phone number (optional)
Only if you provide it, for order-related contact.
Role and program membership
Determines what you can see — parent, coach, school admin, or vendor.
Sign-in and security settings
Whether multi-factor authentication is enabled on your account.
Payment information
Payment processor customer reference
An identifier issued by Stripe so your saved payment method can be charged for meals you authorize.
Order and charge history
What was ordered, for which game, the amount, and its status — for receipts, refunds, and program reporting.

Card numbers are entered directly into Stripe and are never sent to, seen by, or stored on HuddleEatssystems.

Athlete records
First name and last initial
Enough for a coach to run a roster and for meals to reach the right athlete. We do not collect an athlete's full last name.
Jersey number (optional)
Coach-entered, to identify athletes on a roster.
Dietary flags (optional)
So a vendor can accommodate a dietary need. Can only be set by the athlete's own parent or guardian.

We do not collect athlete dates of birth, home addresses, photographs, grades, or medical records.

Program and vendor information
Organization and team details
Program name, location, teams, seasons, and game schedule.
Vendor business details
Business name, address, contact and manager email, menus, and pricing — business contact information, not personal consumer data.
Technical information
Security and audit logs
Records of significant actions, kept to investigate errors, abuse, and unauthorized access.

We use first-party cookies and browser storage strictly to keep you signed in. We do not use advertising cookies or third-party tracking pixels.

3. How we use it

We use the information above to:

  • Create and secure your account, and sign you in.
  • Show the meal events, menus, and rosters relevant to your program and role.
  • Take your meal selection, consolidate it into a single vendor order, and send that order to the vendor.
  • Charge your authorized payment method for meals you select, and process refunds.
  • Send order-related notifications — cutoff reminders, confirmations, and receipts.
  • Give coaches and program administrators the headcount and reconciliation reporting they need.
  • Detect and investigate fraud, abuse, and security incidents, and meet legal and tax obligations.

We do not use your information to build advertising profiles, and we do not make automated decisions that produce legal or similarly significant effects about you.

4. Who we disclose it to, and how

We disclose information only to the parties below, only for the purpose listed, and only the fields needed for that purpose. The method of each disclosure is stated so it is clear how the information travels.

The vendor fulfilling your order
Method: the consolidated order is transmitted to the vendor through the platform's vendor portal, or by email to the vendor's designated address. Content: meal quantities, athlete first name and last initial, dietary flags, and the pickup or drop-off details for that event. Vendors do not receive your payment details.
Coaches and program administrators
Method: displayed inside the platform to authenticated users whose role grants access to that program. Content: rosters, headcounts, and order status for their own program only.
Stripe (payment processing)
Method: card details are collected by Stripe directly in your browser and transmitted to Stripe, not to us; we exchange order amounts and customer references with Stripe over an encrypted API connection. Stripe acts as the payment processor and money transmitter and handles your information under its own privacy policy.
Amazon Web Services (infrastructure)
Method: the platform runs on AWS in the United States. Application data is stored in an encrypted AWS database, sign-in is handled by AWS Cognito, and order notification emails are sent through AWS SES. AWS processes this data on our instructions as our infrastructure provider.
Legal and safety disclosures
Method: written response to a valid legal request. We may disclose information where required by law, or where necessary to investigate fraud or protect someone's safety.
A successor in a business transfer
Method: transferred as part of the assets in a merger, acquisition, or sale. Any successor remains bound by this policy or gives you notice before changing it.

5. What we never do

  • We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
  • We do not give athletes accounts and never contact an athlete.
  • We do not store card numbers.
  • We do not let one program see another program’s rosters, orders, or families.
  • We do not run third-party advertising or analytics trackers on this site.

6. How we protect it

The safeguards in place today:

  • Encryption. All traffic to the platform is encrypted in transit with HTTPS. Data at rest in our database and storage is encrypted.
  • Authenticated, role-scoped access. Sign-in is handled by AWS Cognito. Multi-factor authentication is available, and required for administrative roles.
  • Database-level isolation between programs.Access rules are enforced in the database itself, not only in application code, so a query cannot return another program’s records even if application logic is wrong.
  • Restricted write access to sensitive fields.Dietary flags on an athlete can be written only by that athlete’s own parent or guardian; this is enforced by the database, and every change records who made it.
  • Audit logging. Significant actions are recorded so access can be reviewed and incidents investigated.
  • Least privilege. Staff access to production data is limited to what a role requires.
  • Payment isolation. Card data never touches our systems, which removes an entire category of risk.

No system is perfectly secure. If we become aware of a breach affecting your information, we will notify affected users and the appropriate authorities as required by law.

7. How long we keep it

Athlete records are retained for a limited window tied to the program’s season and then anonymized — by default 180 days, and never less than 150. Anonymization clears identifying fields, including dietary flags, and is not reversible.

Order, charge, and tax records are kept for as long as financial and tax law requires, since we are obligated to be able to produce them. Account records are kept while your account is active.

8. Your choices and rights

You can ask us to:

  • Tell you what information we hold about you.
  • Correct information that is wrong.
  • Delete your account and associated records, subject to records we must keep by law.
  • Provide a copy of your information in a portable format.

Email support@huddleeats.com from the address on your account and we will verify and action the request. We do not charge for this and we will not treat you differently for asking.

Order notification emails are part of the service rather than marketing, so they are not something you can unsubscribe from while keeping an active order — but we do not send marketing email to parents.

9. Children and athlete records

HuddleEats is used by adults on behalf of athletes. Athletes do not have accounts, do not sign in, and are never contacted through the platform. This is deliberate: it keeps children out of scope for online account data collection entirely.

Athlete records are created and managed only by an adult — a parent, guardian, or coach — and are minimized by design to a first name, a last initial, an optional jersey number, and optional dietary flags. Only that athlete’s own parent or guardian can set dietary information.

A parent or guardian can review, correct, or request deletion of their athlete’s record at any time using the contact address in section 10.

10. Changes and contact

If we change this policy we will update the version and effective date above. For a change that materially affects how we handle your information, we will give notice in the app before it takes effect.

Questions, requests, or privacy concerns: support@huddleeats.com. See also our Terms of Service and Support pages.

HuddleEats is a technology platform that facilitates marketplace orders. The vendor is the seller of all food.