UniDash

Privacy Policy

Last updated: 16 September 2026

UniDash ("the App", "we", "us") is a university cafeteria pre-order service consisting of a student app and a staff/admin app. This policy explains what personal data we collect, why, how it is protected, and the rights you have under the Jordanian Personal Data Protection Law No. 24 of 2023 (PDPL).

Data controller: Al Hujra Information Technology LLC, Amman, Jordan (Companies Control Department registration no. 83622)
Contact for privacy requests: support@unidash.food

1. Data we collect

Account data

DataWhy we collect it
Full nameIdentifying your order at pickup
Email address (a university email for student accounts)Account login, verification and password-reset codes, order/wallet notifications
Student/matriculation number (student accounts only)Verifying university affiliation, preventing duplicate accounts
Account role (student/staff/admin)Access control

Order data

DataWhy we collect it
Items ordered, quantities, pricesFulfilling your order
Pickup time slotScheduling preparation
Special instructions you typePreparing your order correctly (do not enter sensitive information here)
Payment method (card or wallet balance)Settling the order
Order status history and timestampsOrder tracking, dispute resolution

Wallet data

DataWhy we collect it
Wallet balancePrepaid payment feature
Transaction history (credits, debits, refunds)Your ledger, refund processing, fraud prevention

Card payments (including Apple Pay and Google Pay) are processed by Mastercard Payment Gateway Services (MPGS) through secure card fields provided by the gateway. Your card number goes directly to the gateway, so it is never seen or stored by UniDash; if you choose to save a card for reuse, we retain only a non-sensitive gateway token and the card's brand, expiry, and last four digits to display it.

Technical data

DataWhy we collect it
Push notification token (Firebase Cloud Messaging)Sending order-status and wallet notifications to your device
Crash and diagnostic data (Firebase Crashlytics)Fixing bugs and keeping the App stable
A bot-protection check when you sign in, sign up or reset your password: IP address and browser/device signalsProtecting accounts from automated sign-in and signup abuse

We do not collect your device's location, contacts, photos, or advertising identifiers, and we do not use your data for advertising or profiling of any kind.

2. Legal basis for processing

Under the PDPL we process your data:

3. Who can see your data

4. Processors (third parties)

Each receives only the data required for its function and may not use it for its own purposes:

ProcessorFunctionData involved
Supabase (supabase.com)Database, authentication, backend hostingAll account, order, and wallet data
Mastercard Payment Gateway Services (MPGS)Processing card payments (including Apple Pay and Google Pay)Card details entered in the gateway's card fields; payment amount and result; saved-card token and last four digits
Google Firebase: Cloud MessagingDelivering push notificationsPush token, notification content
Google Firebase: CrashlyticsCrash reportingDevice model, OS version, crash stack traces
Brevo (brevo.com)Sending account emails (verification and password-reset codes)Email address, email content, delivery status
Cloudflare (cloudflare.com)Bot protection on sign-in, signup and password resetIP address and browser/device signals during the check

Data hosted with these processors may be stored outside Jordan. We rely on the processors' contractual data-protection commitments and industry-standard safeguards for any such transfer, as contemplated by the PDPL's cross-border transfer provisions.

We do not sell your data or share it with anyone else, except where a competent Jordanian authority requires disclosure by law.

5. How we protect your data

Your data is encrypted in transit, and access is enforced on our servers so that each account can reach only the data its role allows.

6. Retention

7. Your rights under the PDPL

To exercise any of these rights, contact us at support@unidash.food. We will respond within the timeframes required by the PDPL and will verify your identity before acting on a request.

8. Account deletion

You can delete your account and personal data at any time: in the app via Profile → Delete account, or by request (see the account deletion page). Deletion is irreversible; any remaining wallet balance is forfeited. Order and transaction records we must keep for accounting are retained in anonymised form.

9. Children

The App is intended for university students and staff. It is not directed at children under 16, and we do not knowingly collect data from them.

10. Changes to this policy

We will post any changes here and update the "Last updated" date. For material changes we will notify you in the App before they take effect.