LEFTOVER LOVE, INC. — PRIVACY POLICY

Leftover Love, Inc. — 501(c)(3) Nonprofit Organization

Effective Date: February 12, 2026 | Last Reviewed: March 4, 2026

Version 1.0.0

Leftover Love, Inc. ("Leftover Love," "we," "our," or "us") operates a volunteer-and-admin portal to coordinate food rescue and delivery operations. This Privacy Policy explains what personal data we collect, why we collect it, with whom we share it, and the rights you have over your information. By creating an account or using our portals, you agree to the practices described in this policy. If you do not agree, please do not use the service.

1. Who We Are

Leftover Love, Inc. is a 501(c)(3) nonprofit organization based in Baltimore, Maryland, dedicated to reducing food waste and addressing food insecurity in the community through coordinated food rescue and delivery operations. We are the data controller for personal information processed through our volunteer and admin portals.

Contact: info@leftoverloveinc.org | PO Box 12189, Baltimore, MD 21281

2. Information We Collect

2.1 Account & Identity Information

When you create a volunteer or administrator account, we collect:

  • Full name (first and last)
  • Email address — used for authentication and communications
  • Phone number — used for operational contact and scheduling
  • Password (for email/password sign-up only) — stored as a cryptographic hash by Firebase; we never see your plaintext password
  • Google account information (if you use Google Sign-In) — limited to your email address and display name as provided by Google

2.2 Volunteer Profile & Logistics Information

During volunteer onboarding and profile setup, we collect:

  • Home address, geographic coordinates (latitude/longitude), and Google Place ID — used to calculate proximity to donors and recipients and to assign you to nearby food rescue trips
  • Preferred volunteering times and pickup days
  • Whether you hold a valid driver's license and have access to a vehicle
  • Preferred contact method (email, phone, or both)
  • How you heard about Leftover Love
  • Profile "landmark" — an optional nearby point of interest you select to describe your general area

2.3 Delivery & Operational Data

In connection with food rescue trips and scheduling, we record:

  • Trip assignments: donor, recipient, and volunteer identifiers; scheduled pickup time; food type and notes
  • Delivery status and outcome
  • Recurring schedule details (frequency, day, time)
  • Delivery photos and videos uploaded by volunteers

2.4 Reimbursement Data

Volunteers who request mileage or expense reimbursements must submit:

  • Receipt images (uploaded as image files and stored in Firebase Storage)
  • Requested amount and the associated delivery
  • Dates of request, admin review, approval/rejection, and payment

Reimbursement records are retained for a minimum of seven (7) years to comply with IRS requirements applicable to 501(c)(3) organizations.

2.5 Automatically Collected Technical Data

When you use our portals, we automatically collect:

  • Authentication session cookies and tokens
  • IP addresses — used for rate-limiting certain API endpoints (via Upstash Redis); not stored as part of your profile
  • Error and performance data (via Sentry), including user identifiers when you are logged in and technical audit logs of significant actions; no full payment data, passwords, or cookie payloads are transmitted to Sentry
  • Device and browser type as collected by our hosting provider

2.6 Organization Data

For donor and recipient organizations, we store: organization name, contact person name, phone number, address, coordinates, and operational notes. This information is entered by administrators and is not collected directly from the organizations via this portal.

3. How We Use Your Information

We use personal information for purposes including:

  • Account creation and authentication
  • Volunteer onboarding and approval
  • Trip assignment, routing, and distance calculations
  • Reimbursement processing and record-keeping
  • Email notifications and operational communications
  • Error monitoring, security, rate limiting, and abuse prevention
  • Impact reporting and communications using delivery media you upload

We do not use your personal information for automated decision-making or profiling that produces legal or similarly significant effects.

4. Third-Party Service Providers (Sub-Processors)

We share personal data only with service providers that are contractually bound to protect it. These include:

  • Firebase (Google LLC) — authentication, database, and file storage
  • Google Maps Platform — address autocomplete, routing, distance calculation
  • Resend — transactional email delivery
  • Sentry — error monitoring, performance tracing, audit logging
  • Upstash (Redis) — API rate limiting
  • Netlify — web hosting and edge delivery
  • Givebutter — donation processing

We do not sell, rent, or otherwise monetize your personal information, and we do not share personal data with third parties for their own marketing purposes.

5. Google Maps Platform and Location Data

Our portals use the Google Maps Platform, including the Places API, Distance Matrix API, and Directions API, to enable address autocomplete and to calculate efficient food rescue routes. Your address queries, coordinates, and Place IDs may be sent to Google to provide these services. Google's processing of this data is governed by the Google Maps Platform Terms of Service and Google's Privacy Policy.

6. Cookies and Browser Storage

We use essential cookies and browser storage (including session cookies for authentication, preference cookies, and local storage for theme settings). Authentication cookies are HttpOnly, Secure, and have short expirations. We do not use advertising or tracking cookies.

7. Data Retention

We retain personal data only for as long as necessary for the purposes described in this policy and to meet legal obligations. For example:

  • Active accounts are retained while your relationship is active.
  • Volunteer profiles are retained for 3 years following deactivation.
  • Delivery and trip records, and reimbursement records/receipts, are generally retained for at least 7 years.
  • Error and audit logs, and rate-limit data, are retained for shorter operational windows.

8. Security Measures

We implement industry-standard technical and organizational measures to protect your personal data, including HTTPS encryption, secure cookies, Firebase Security Rules, short-lived authentication tokens, API rate limiting, and restricted access to administrative features. While we take reasonable steps to safeguard your data, no system can be guaranteed 100% secure.

9. Your Privacy Rights

Depending on your location, you may have rights to access, correct, delete, or restrict processing of your personal data, as well as rights to data portability, to object to certain processing, and to withdraw consent where processing is based on consent.

To exercise these rights, please email info@leftoverloveinc.org. We may need to verify your identity before fulfilling your request.

10. Children's Privacy

Our portals are not directed to individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us and we will take steps to delete it.

11. International Data Transfers

Our third-party service providers may process data in data centers located in the United States or other countries. By using our portals, you acknowledge that your data may be transferred to and processed in locations that may have different data protection standards than your home country. Where required, we rely on appropriate safeguards such as standard contractual clauses.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify registered users of material changes by email and/or by posting a notice in the portal. The updated policy will be effective as of the date noted at the top of this page. Your continued use of the portal after the effective date constitutes acceptance of the revised policy.

13. Contact Us

If you have questions, concerns, or requests related to this Privacy Policy, please contact:

Leftover Love, Inc.
Attn: Executive Director — Omar Tarabishi
PO Box 12189, Baltimore, MD 21281
Email: info@leftoverloveinc.org
Website: leftoverloveinc.org