Privacy Policy

Effective date: April 28, 2026 · Version 2026.04.28
Plain English first. We collect what we need to run the marketplace — your account info, the orders you place or fulfill, and the messages you exchange — and we share what we have to with the partners that make payments and email work (Stripe, Supabase, Resend). We don't sell your personal information. The full policy below explains the details.

Contents

  1. About this policy
  2. Information we collect
  3. How we use information
  4. Who we share information with
  5. Cookies and browser storage
  6. How long we keep information
  7. Security
  8. Your privacy rights
  9. For California residents (CCPA / CPRA)
  10. Children
  11. International users
  12. Changes to this policy
  13. Contact us

1. About this policy

Porch Pantry (the "Service") is a marketplace for home-cooked specialty batch foods, operated by Spiral Physical Therapy Inc. ("Porch Pantry," "we," "us"). This Privacy Policy describes how we collect, use, share, and protect personal information when you use our website at porchpantry.app, our web app, or any related services.

This policy applies to two kinds of users: eaters (people who order food) and cooks (people who prepare and sell food from a permitted home kitchen). Some sections apply to both; some are role-specific.

By using Porch Pantry, you agree to this Privacy Policy and to our Terms of Service.

2. Information we collect

2.1 Information you give us

When you create an account or use Porch Pantry, you give us:

WhatFrom whomWhy we ask
Name, email, passwordEaters & cooksTo create your account, sign you in, and contact you about orders
Profile photo (optional)Eaters & cooksSo the other side of the order knows who they're transacting with
ZIP code, neighborhoodEatersTo show you cooks and batches near you
Delivery addressEaters who choose deliverySo the cook can deliver your order. Stored on the order record
Kitchen address, kitchen photo, bio, taglineCooksSo eaters can find your kitchen and learn who you are
Permit attestation (and, if requested by us, a permit document)CooksTo verify you have a valid MEHKO or equivalent home-kitchen permit, which is required to sell on Porch Pantry
Batch details — dish name, photos, ingredients, price, capacity, pickup windows, delivery radius/feeCooksSo eaters can browse and order what you're cooking
Order details — items, quantities, fulfillment type, pickup window or delivery addressEatersTo process and fulfill your order
Reviews and ratingsEatersTo help other eaters choose cooks and to give cooks feedback
Messages between eaters and cooksEaters & cooksSo you can coordinate around a specific order. Messages are visible to both parties to that order

2.2 Payment and identity information (handled by Stripe)

Porch Pantry uses Stripe to process all payments. We never see, store, or transmit your full card number. When you place an order as an eater, your card information is collected directly by Stripe through Stripe Checkout. When you onboard as a cook, Stripe Connect collects the business and identity information it needs to verify you and pay you out, including your name, address, date of birth, last four digits of your SSN (or full SSN, depending on Stripe's verification requirements), and bank account details. That information goes from you to Stripe directly — Porch Pantry receives only Stripe's verification status (whether you can accept charges and receive payouts) and a Stripe-assigned account ID. See Stripe's privacy policy for how Stripe handles your data.

2.3 Information we collect automatically

When you use Porch Pantry, we automatically collect:

2.4 Address geocoding

To show eaters cooks nearby, and to verify a delivery address is within a cook's delivery radius, we convert addresses into latitude/longitude coordinates. We do this using the public Nominatim service operated by the OpenStreetMap Foundation. When you enter a kitchen address or delivery address, that address is sent to Nominatim. We store the resulting lat/lng on your kitchen record (cooks) or order record (eater deliveries) so we don't have to re-geocode it.

3. How we use information

We use the information described above to:

We do not sell your personal information. We do not share it with third parties for their independent advertising or marketing.

4. Who we share information with

Running a marketplace requires a small number of service providers. We share what's necessary, and those providers are bound by their own contracts and privacy policies. Here's the full list of who sees what:

ProviderWhat they handleTheir privacy policy
StripePayments, payouts to cooks, identity verification of cooks, fraud screeningstripe.com/privacy
SupabaseAuthentication, database storage of profiles, kitchens, batches, orders, reviews, messages, photos. Hosted in the United States.supabase.com/privacy
ResendTransactional email delivery (order confirmations, pickup reminders, etc.)resend.com/legal/privacy-policy
VercelWeb hosting, deployment, edge networking, server-side function executionvercel.com/legal/privacy-policy
OpenStreetMap / NominatimGeocoding street addresses to lat/lng coordinatesOSM Foundation Privacy Policy

We share information with these providers only to the extent they need it to perform their service. We share between Porch Pantry users (eaters and cooks) only as necessary to facilitate an order — eaters see a cook's name, kitchen photo, address area, and reviews; cooks see an eater's name and, for delivery orders, the eater's delivery address.

We may also share information when required by law (subpoena, court order, or other legal process), to protect the safety of our users or the public, or in connection with a merger, acquisition, or sale of all or substantially all of our assets — in which case we'll notify you before your information becomes subject to a different privacy policy.

5. Cookies and browser storage

We use a small number of cookies and browser-storage entries — only what's needed to keep you signed in and to remember basic preferences. Specifically:

We do not use third-party advertising cookies, retargeting pixels, or analytics SDKs that share data with advertising networks. You can clear cookies and browser storage in your browser settings; doing so will sign you out and clear your in-progress cart.

6. How long we keep information

We keep account and order information for as long as your account is active and for a reasonable period afterward to satisfy legal, tax, and audit obligations — typically up to seven (7) years for transaction records. You can ask us to delete your account at any time (see Your privacy rights); we'll delete what we can while preserving the minimum we're required to keep by law (for example, certain Stripe payment records and tax-relevant order data).

7. Security

We use commercially reasonable safeguards to protect your information — encrypted connections (HTTPS/TLS) for everything between your browser and our servers, encrypted storage at rest in Supabase, and access controls that limit who at Porch Pantry can see what. Stripe holds itself to PCI DSS Level 1 standards for payment data. No system is perfectly secure, though, and we can't guarantee absolute security. If we ever discover a breach that affects your information, we'll notify you and the appropriate authorities as required by law.

8. Your privacy rights

You can:

To exercise any of these rights, email privacy@porchpantry.app from the email address associated with your account. We'll verify your identity and respond within 30 days.

9. For California residents (CCPA / CPRA)

If you're a California resident, the California Consumer Privacy Act (as amended by the California Privacy Rights Act) gives you specific rights about your personal information. Those rights overlap substantially with the rights described in Section 8, plus:

To exercise these rights, email privacy@porchpantry.app. You can use an authorized agent to make a request on your behalf, in which case we may ask the agent to provide proof you authorized them and may verify your identity directly.

10. Children

Porch Pantry is not directed to children under 18. You must be at least 18 years old to create an account and to enter into the agreements that governing the Service. We don't knowingly collect personal information from children under 13. If you believe we've collected information from a child under 13, contact us at privacy@porchpantry.app and we'll delete it.

11. International users

Porch Pantry currently operates in California and serves users located in California. Our service providers (Stripe, Supabase, Resend, Vercel) are based in the United States and process data in the United States. If you're outside the United States and use the Service, your information will be transferred to and processed in the United States, which may have different data-protection laws than your country of residence.

12. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we'll post the updated policy here, update the "Effective date" at the top, and (for significant changes that affect your rights) email active users. Continued use of the Service after the new effective date means you accept the updated policy. If you don't agree, stop using the Service and ask us to delete your account.

13. Contact us

Questions, requests, or complaints about this policy or about how we handle your information:

This policy is provided in plain English to help you understand it. Where it conflicts with applicable law, the applicable law controls.