UniDash ("the App", "we", "us") is a university cafeteria pre-order service consisting of a student app and a staff/admin app. This policy explains what personal data we collect, why, how it is protected, and the rights you have under the Jordanian Personal Data Protection Law No. 24 of 2023 (PDPL).
| Data | Why we collect it |
|---|---|
| Full name | Identifying your order at pickup |
| Email address (a university email for student accounts) | Account login, verification and password-reset codes, order/wallet notifications |
| Student/matriculation number (student accounts only) | Verifying university affiliation, preventing duplicate accounts |
| Account role (student/staff/admin) | Access control |
| Data | Why we collect it |
|---|---|
| Items ordered, quantities, prices | Fulfilling your order |
| Pickup time slot | Scheduling preparation |
| Special instructions you type | Preparing your order correctly (do not enter sensitive information here) |
| Payment method (card or wallet balance) | Settling the order |
| Order status history and timestamps | Order tracking, dispute resolution |
| Data | Why we collect it |
|---|---|
| Wallet balance | Prepaid payment feature |
| Transaction history (credits, debits, refunds) | Your ledger, refund processing, fraud prevention |
Card payments (including Apple Pay and Google Pay) are processed by Mastercard Payment Gateway Services (MPGS) through secure card fields provided by the gateway. Your card number goes directly to the gateway, so it is never seen or stored by UniDash; if you choose to save a card for reuse, we retain only a non-sensitive gateway token and the card's brand, expiry, and last four digits to display it.
| Data | Why we collect it |
|---|---|
| Push notification token (Firebase Cloud Messaging) | Sending order-status and wallet notifications to your device |
| Crash and diagnostic data (Firebase Crashlytics) | Fixing bugs and keeping the App stable |
| A bot-protection check when you sign in, sign up or reset your password: IP address and browser/device signals | Protecting accounts from automated sign-in and signup abuse |
We do not collect your device's location, contacts, photos, or advertising identifiers, and we do not use your data for advertising or profiling of any kind.
Under the PDPL we process your data:
Each receives only the data required for its function and may not use it for its own purposes:
| Processor | Function | Data involved |
|---|---|---|
| Supabase (supabase.com) | Database, authentication, backend hosting | All account, order, and wallet data |
| Mastercard Payment Gateway Services (MPGS) | Processing card payments (including Apple Pay and Google Pay) | Card details entered in the gateway's card fields; payment amount and result; saved-card token and last four digits |
| Google Firebase: Cloud Messaging | Delivering push notifications | Push token, notification content |
| Google Firebase: Crashlytics | Crash reporting | Device model, OS version, crash stack traces |
| Brevo (brevo.com) | Sending account emails (verification and password-reset codes) | Email address, email content, delivery status |
| Cloudflare (cloudflare.com) | Bot protection on sign-in, signup and password reset | IP address and browser/device signals during the check |
Data hosted with these processors may be stored outside Jordan. We rely on the processors' contractual data-protection commitments and industry-standard safeguards for any such transfer, as contemplated by the PDPL's cross-border transfer provisions.
We do not sell your data or share it with anyone else, except where a competent Jordanian authority requires disclosure by law.
Your data is encrypted in transit, and access is enforced on our servers so that each account can reach only the data its role allows.
To exercise any of these rights, contact us at support@unidash.food. We will respond within the timeframes required by the PDPL and will verify your identity before acting on a request.
You can delete your account and personal data at any time: in the app via Profile → Delete account, or by request (see the account deletion page). Deletion is irreversible; any remaining wallet balance is forfeited. Order and transaction records we must keep for accounting are retained in anonymised form.
The App is intended for university students and staff. It is not directed at children under 16, and we do not knowingly collect data from them.
We will post any changes here and update the "Last updated" date. For material changes we will notify you in the App before they take effect.