Pantry Route — Privacy Policy
Effective September 30, 2026
Pantry Route is a delivery-operations app used by a food pantry in the Bridgeview, Illinois area. It is used by pantry coordinators and volunteer delivery drivers — not by the people receiving food. This policy explains what information the app handles and how it is protected.
What we collect, and why
- Volunteer accounts (coordinators and drivers): name, email address, phone number, an optional device token so anyone assigned a run can receive "you've been assigned a run" notifications, and the version of the app they last signed in with (so coordinators can see who still needs to update). Collected so the pantry can organize deliveries.
- Household delivery information, entered by pantry staff on behalf of the families served: a contact name, phone number, street address and map location, delivery notes (e.g., "use the side door"), preferred text-message language, and a record of deliveries made. Collected solely to deliver food and honor the pantry's monthly delivery limits.
Who processes this information
- Supabase hosts the database (United States), with row-level security restricting every user to the minimum they need — drivers can only see households on their own active delivery run.
- Twilio sends the delivery text messages (phone number and message content only).
- Mapbox renders maps; map-tile requests are made by the app, and route-drawing and route-ordering requests containing only the stop coordinates for a delivery run (no names, addresses, or household details). If a driver chooses a custom place for their route to end (for example, their home), the app sends that address to Mapbox to look it up, and its coordinates for route ordering; it is stored only on the driver's phone, is never sent to the pantry's servers, and is erased when they sign out. Mapbox telemetry is disabled.
- Apple / Google / Expo deliver driver push notifications (a device token and the notification text only).
Each processor receives only what its job requires. None of them may use this information for their own purposes.
SMS Consent
Delivery text notifications are operated by PorSignal LLC on behalf of the food pantry program. Recipients opt in verbally during in-person registration at the pantry. Staff use this exact consent script:
Only households that say yes receive texts. Message frequency depends on your deliveries (typically 1–2 messages per delivery day); message and data rates may apply.
- STOP: reply STOP to any delivery text to opt out immediately — you'll receive no further texts. You can also tell your pantry coordinator at any time.
- HELP: reply HELP to any delivery text for assistance information, or contact your pantry coordinator.
Retention & deletion
Delivery records are kept for the pantry's operational and grant reporting needs. A household may ask the pantry at any time to correct its information or remove it entirely; a volunteer's account is deactivated (and may be deleted on request) when they stop volunteering.
Your choices
If your family receives deliveries and you want your details corrected or removed, or you no longer wish to receive delivery text messages, tell your pantry coordinator — or reply STOP to any delivery text.
Contact
Questions about this policy: contact the pantry coordinator, or email endiaye677@gmail.com.