UniDash

Privacy Policy

Last updated: 18 September 2026

UniDash ("the App", "we", "us") is a university cafeteria pre-order service consisting of a student app and a staff/admin app. This policy explains what personal data we collect, why, how it is protected, and the rights you have under the Jordanian Personal Data Protection Law No. 24 of 2023 (PDPL).

Data controller: Al Hujra Information Technology LLC, Amman, Jordan (Companies Control Department registration no. 83622)
Contact for privacy requests: [email protected]

1. Data we collect

Account data

DataWhy we collect it
Full nameIdentifying your order at pickup
Email address (a university email for student accounts)Account login, verification and password-reset codes, order/wallet notifications
Student/matriculation number (student accounts only)Verifying university affiliation, preventing duplicate accounts
Account role (student/staff/admin)Access control

Order data

DataWhy we collect it
Items ordered, quantities, pricesFulfilling your order
Pickup time slotScheduling preparation
Special instructions you typePreparing your order correctly (do not enter sensitive information here)
Payment method (card or wallet balance)Settling the order
Order status history and timestampsOrder tracking, dispute resolution

Wallet data

DataWhy we collect it
Wallet balancePrepaid payment feature
Transaction history (credits, debits, refunds)Your ledger, refund processing, fraud prevention

Card payments (including Apple Pay and Google Pay) are processed by Mastercard Payment Gateway Services (MPGS) through secure card fields provided by the gateway. Your card number goes directly to the gateway, so it is never seen or stored by UniDash; if you choose to save a card for reuse, we retain only a non-sensitive gateway token and the card's brand, expiry, and last four digits to display it.

Technical data

DataWhy we collect it
Push notification token (Firebase Cloud Messaging)Sending order-status and wallet notifications to your device
Crash and diagnostic data (Firebase Crashlytics)Fixing bugs and keeping the App stable
App usage: which screens are opened, session starts, and whether a sign-in or signup completed (Firebase Analytics, student app only)Understanding which parts of the App are used so we can improve them. This is tied to a random app-install identifier, never to your account, and it is switched off entirely in the staff app
A bot-protection check when you sign in, sign up or reset your password: IP address and browser/device signalsProtecting accounts from automated sign-in and signup abuse

We do not collect your device's location, contacts, photos, or advertising identifiers, and we do not use your data for advertising, nor sell it, nor build a profile of you as an individual. The usage measurement above is aggregate and is not linked to your account.

2. Legal basis for processing

Under the PDPL we process your data:

3. Who can see your data

4. Processors (third parties)

Each receives only the data required for its function and may not use it for its own purposes:

ProcessorFunctionData involved
Supabase (supabase.com)Database, authentication, backend hostingAll account, order, and wallet data
Mastercard Payment Gateway Services (MPGS)Processing card payments (including Apple Pay and Google Pay)Card details entered in the gateway's card fields; payment amount and result; saved-card token and last four digits
Google Firebase: Cloud MessagingDelivering push notificationsPush token, notification content
Google Firebase: CrashlyticsCrash reportingDevice model, OS version, crash stack traces
Google Firebase: AnalyticsAggregate usage measurement (student app only)Screen names, session and sign-in events, app-install identifier, device model, OS version, country
Brevo (brevo.com)Sending account emails (verification and password-reset codes)Email address, email content, delivery status
Cloudflare (cloudflare.com)Bot protection on sign-in, signup and password resetIP address and browser/device signals during the check
Google Fonts (fonts.gstatic.com)Delivering the App's typeface the first time it is shown, then kept on your deviceIP address and device/browser signals of the download request; no account data

Data hosted with these processors may be stored outside Jordan. We rely on the processors' contractual data-protection commitments and industry-standard safeguards for any such transfer, as contemplated by the PDPL's cross-border transfer provisions.

We do not sell your data or share it with anyone else, except where a competent Jordanian authority requires disclosure by law.

5. How we protect your data

Your data is encrypted in transit, and access is enforced on our servers so that each account can reach only the data its role allows.

6. Retention

7. Your rights under the PDPL

To exercise any of these rights, contact us at [email protected]. We will respond within the timeframes required by the PDPL and will verify your identity before acting on a request.

8. Account deletion

You can delete your account and personal data at any time: in the app via Profile → Delete account, or by request (see the account deletion page). Deletion is irreversible; any remaining wallet balance is forfeited. Order and transaction records we must keep for accounting are retained in anonymised form.

9. Children

The App is intended for university students and staff. It is not directed at children under 16, and we do not knowingly collect data from them.

10. Changes to this policy

We will post any changes here and update the "Last updated" date. For material changes we will notify you in the App before they take effect.