Responsible handling

Data Policy

These are the practical rules CampusCravings and its authorised technology provider follow when collecting, using, sharing, storing, and deleting customer information.

Effective 23 September 2026

1. What this policy covers

This policy covers customer information handled through the CampusCravings preorder app, Paystack payment confirmation, the paid-order dashboard, exported delivery lists, customer support, and privacy requests. It applies to CampusCravings staff and anyone authorised to support the service.

2. How customer data may be used

  • Taking orders: use a customer’s name and contact details to create and identify the order.
  • Preparing food: use product quantities and notes to prepare the correct order.
  • Managing collection: use the delivery date and contact details to organise the Monday or Friday list and contact the customer when necessary.
  • Confirming payment: use Paystack’s transaction reference, amount, and status to decide whether an order is paid.
  • Providing support: use the order record and customer messages to answer questions, correct mistakes, or manage refunds.
  • Protecting the service: use limited technical and transaction records to detect errors, misuse, duplicate orders, or security incidents.
  • Meeting obligations: keep the minimum records needed for accounting, tax, legal, regulatory, or dispute-resolution purposes.

Customer information must not be used for an unrelated purpose unless the customer is clearly informed and there is an appropriate lawful reason.

3. Data-minimisation rules

  • Collect only the fields shown in the approved preorder, support, or privacy-request forms.
  • Do not ask for date of birth, home address, identity documents, financial passwords, or other information that is not needed for the order.
  • Do not put sensitive personal information in order notes.
  • Do not copy customer lists into personal notebooks, private messaging groups, or unrelated applications.
  • Remove personal information from reports when totals or anonymous sales information are sufficient.

4. Payment-data rules

Paystack handles card and payment-account details. CampusCravings may store only the transaction reference, payment status, amount, and related order information needed for confirmation and reconciliation. Staff must never request or record a customer’s card PIN, CVV, complete card number, online-banking password, or one-time password.

5. Access and confidentiality

  • The paid-order and privacy-request dashboard must remain protected by the administrative access code.
  • Access is limited to people who need the information to prepare, deliver, reconcile, secure, or support orders.
  • Staff may view only the information needed for the task they are performing.
  • Exported lists must be stored securely, shared only with authorised personnel, and deleted when the delivery or approved business need is complete.
  • Access codes must not be shared publicly and should be changed if unauthorised access is suspected.
  • Customer information must not be discussed where unauthorised people can see or hear it.

6. Accuracy and customer requests

Reasonable steps must be taken to correct inaccurate contact or order information. Privacy requests for access, correction, deletion, restriction, objection, portability, or complaint must be recorded in the dashboard, verified where necessary, and handled without unnecessary delay. A refusal or limitation must be documented with the reason.

7. Sharing and service providers

Data may be shared only with an authorised recipient that needs it for order fulfilment, payment processing, application hosting, technical support, professional advice, or a legal requirement. Before introducing a new provider, CampusCravings should check what information it receives, why it needs it, where it stores it, its security measures, and how deletion or return of the data will work.

8. Retention and disposal

  • Unpaid and abandoned orders may be deleted after seven days.
  • Paid-order identifying information should normally be anonymised after 24 months unless a documented legal, tax, accounting, fraud, or dispute reason requires longer retention.
  • The administrator should regularly use the dashboard’s retention preview and confirmed cleanup controls.
  • Printed lists must be shredded or otherwise securely destroyed. Digital exports must be permanently deleted when no longer needed.
  • When a retention exception is required, the reason and expected review date should be documented.

9. Security incidents

Suspected loss, unauthorised access, mistaken disclosure, account compromise, or misuse must be reported immediately to the person responsible for CampusCravings operations and to Ancherem Innovation Ltd for technical investigation. Relevant access should be restricted, evidence preserved, the impact assessed, and affected people or authorities notified where required.

10. Marketing and new uses

Order data must not be sold, rented, used for third-party advertising, or added to marketing lists automatically. Any optional marketing must use a clear separate choice, record the customer’s preference, provide a simple way to opt out, and stop after an opt-out request.

11. Review and accountability

This policy should be reviewed whenever the ordering process, payment provider, service providers, collected information, security controls, or applicable requirements change, and at least on the agreed review schedule. Changes should be reflected in the customer-facing Privacy Policy and staff instructions.

12. Questions and requests

Customers can submit a request through the privacy request form. Other privacy questions may be sent to info.anchereminnovationltd@gmail.com.