Privacy Policy — MyLonchera
MyLonchera is a mobile application owned and operated by Solaurum Technologies LLC ("we", "our", "the Company"), a limited liability company formed in the Commonwealth of Kentucky, United States of America. This Policy explains what data we collect, why, who we share it with, how long we keep it and how you can control it.
This Policy is an integral part of our Terms and Conditions of Use. By using the Platform you accept the practices described here. If you disagree, please do not use the Platform.
Data controller: Solaurum Technologies LLC
Address: 102 West 13th Avenue, Bowling Green, Kentucky 42101, United States
Single contact for privacy and support: support@solaurumtech.com
1. Single-account model
The Platform operates a single-account-per-person model. If you registered as a Customer and later become a Vendor, your SAME account is upgraded with the Vendor role; no second account is created. Your internal identifier, email, order history, favourites and preferences are preserved through the conversion, and all your information remains subject to the same retention and erasure rules described below.
Each device registers a single push notification token, bound to the most recently signed-in profile. Sharing one device across different people is not a supported scenario from a notification-privacy standpoint: sign out completely before another person signs in.
2. What we collect, why, and who receives it
| Data category | Concrete examples | What we use it for | Shared? | Required? |
|---|---|---|---|---|
| Identity and account | Name, email, password (bcrypt hash), preferred language, role | Create and authenticate your account, support | Not shared | Required |
| Phone | Contact number | Order coordination, vendor verification | With the Vendor of your order | Optional (Customer) |
| Approximate and precise location | Device GPS coordinates | Show nearby food trucks, compute distances | Not shared; used in memory, we do not store a movement history | Optional (the app works without it) |
| Background location | Coordinates while the app is closed | Solely for proximity alerts of trucks you follow | Not shared | Optional, off by default |
| Orders and transactions | Items, amounts, tips, taxes, status, order notes | Process and fulfil your order, Vendor accounting, support | With the relevant Vendor and with Stripe | Required to order |
| Payment data | Card last 4 digits, brand, transaction identifier | Charges, refunds, fraud prevention | Processed by Stripe. We never receive or store your full card number or CVV | Required to pay |
| Vendor business data | Business name, truck address/location, menu, photos, hours, tax rates | Publish your profile, process sales and payouts | Profile and menu are public inside the app | Required to sell |
| Vendor tax identification | EIN or SSN, legal business name, tax email | Issue Form 1099-NEC where the law requires it | With the tax authority where applicable | Only required above USD 600 in annual payouts |
| Push notification token | Device identifier assigned by the OS | Deliver order alerts and proximity alerts | With Firebase Cloud Messaging (Google) | Optional |
| Diagnostics and crashes | Crash logs, device model, OS and app version | Detect and fix bugs, stability | With Sentry | Required (technical) |
| Usage data | Screens visited, favourites, ad interactions | Improve the app, measure ad performance | Aggregate metrics with the Advertiser (never individual data) | Required (technical) |
| Images | Profile, truck and menu photos you upload | Display your business in the app | Managed object storage; publicly visible in the app | Optional |
| Support communications | Tickets, emails, attachments you send | Handle your claim | Not shared | Optional |
We do not collect: biometric data, your phone contacts, web browsing history outside the app, health data, or information about your beliefs, sexual orientation, ethnic origin or political affiliation.
3. Prominent disclosure about background location
MyLonchera requests access to your location even when the app is closed or not in use, for one single purpose: to alert you when a food truck you follow is near you.
- This feature is called Proximity alerts and is off by default.
- It only activates if you switch it on in the app and grant the "Allow all the time" permission in the operating-system dialog.
- We do not track or store your movement history. Comparing your position against truck positions happens to generate the alert; no record of your movements is retained.
- We do not sell, rent or share your location data with advertisers, data brokers or any third party.
- You can revoke the permission at any time in the app or device settings. Doing so stops the alerts, but the rest of the app keeps working.
- To protect your battery and privacy the feature is rate-limited: max. 2 alerts per truck per encounter, 5 minutes between consecutive alerts and a 9-minute cool-down after leaving the radius. You can also configure quiet hours.
4. Legal bases for processing (GDPR / EEA and UK users)
| Purpose | Legal basis |
|---|---|
| Creating your account and processing orders | Performance of a contract (Art. 6(1)(b)) |
| Charges, refunds and invoicing | Performance of a contract and legal obligation (Art. 6(1)(b) and 6(1)(c)) |
| Location and proximity alerts | Consent (Art. 6(1)(a)), withdrawable at any time |
| Promotional push notifications | Consent (Art. 6(1)(a)) |
| Fraud prevention and security | Legitimate interest (Art. 6(1)(f)) |
| Tax and accounting retention | Legal obligation (Art. 6(1)(c)) |
5. Who we share data with (processors and sub-processors)
We share data only with the providers necessary to operate the service. All act under contract and may only use the data to provide the service to us.
| Provider | What it receives | Purpose | Policy |
|---|---|---|---|
| Stripe, Inc. (USA) | Payment data, amount, email | Process payments, payouts and refunds | stripe.com/privacy |
| Google LLC — Firebase Cloud Messaging | Device notification token | Deliver push notifications | firebase.google.com/support/privacy |
| Google LLC — Google Maps Platform | Coordinates to render the map | Display the map, compute routes/distances | policies.google.com/privacy |
| Functional Software, Inc. (Sentry) | Error logs, device model, version | Crash diagnostics and stability | sentry.io/privacy |
| MongoDB, Inc. (Atlas) | Application database, encrypted at rest | Storage | mongodb.com/legal/privacy-policy |
| Expo / Amazon Web Services | App distribution and hosting infrastructure | App delivery and servers | expo.dev/privacy · aws.amazon.com/privacy |
| Vendors | Your name (or alternate name), items, note and phone if provided | Prepare and hand over your order | Independent controller; contractually bound to use it only for your order |
| Authorities | Only what is strictly required | Comply with valid legal requests | — |
We never sell your personal data, never disclose it to data brokers, and never use it for cross-app or cross-site behavioural advertising.
6. Data retention
| Data type | Retention period |
|---|---|
| Active account | For as long as your account stays open |
| Inactive accounts | Anonymised after a prolonged period of inactivity |
| Orders, POS sales and tax records | 7 years (U.S. tax and audit obligation) |
| Error logs (Sentry) | Up to 90 days |
| Notification tokens | Until you uninstall the app or sign out |
| Data after you delete your account | Erased or anonymised immediately, except the tax records in row 3 of this table, which are retained dissociated from your identity where possible |
7. Security
- Encrypted transport via TLS/HTTPS on all communications.
- Passwords stored as bcrypt hashes; never in plain text and never recoverable.
- Database encrypted at rest (MongoDB Atlas).
- Vendor tax identification encrypted and displayed only as the last 4 digits.
- Signed session tokens (JWT) with expiry.
- Internal access on a least-privilege basis, with an audit log of administrative actions.
- We do not store full card numbers: that responsibility sits with Stripe, a PCI-DSS Level 1 certified processor.
No system is infallible. If we detect a security breach affecting your personal data we will notify you and, where applicable, notify the competent authorities within statutory deadlines (72 hours under GDPR).
8. Your rights and how to exercise them
You have the right to access, rectify, erase, port and object to the processing of your data, and to withdraw your consent at any time.
8.1. Directly in the app (no waiting):
- Export your data: Profile → Privacy → Download my data. You receive a file with your account, orders and preferences.
- Delete your account: Profile → Privacy → Delete account. Deletion is immediate and irreversible.
- Location and notifications: you can revoke any permission from the app or operating-system settings.
8.2. Deletion without access to the app. If you already uninstalled the application or cannot sign in, you can request deletion of your account and data at https://mylonchera.com/account-deletion.html or by writing to support@solaurumtech.com from the email associated with your account. We handle the request within a maximum of 30 days and confirm in writing.
8.3. We do not apply automated decision-making with significant legal effects on you. The cancellation reputation record may limit the cancellation-request feature, but any account restriction is reviewed by a human and you may appeal by writing to support@solaurumtech.com.
9. California residents' rights (CCPA/CPRA)
If you reside in California you additionally have the right to: (i) know the categories of personal information collected and the purposes; (ii) request its deletion; (iii) request its correction; (iv) opt out of the "sale" or "sharing" of personal information; and (v) not be discriminated against for exercising these rights.
Solaurum Technologies LLC does not sell or share personal information within the meaning of the CCPA/CPRA, and does not use it for cross-context behavioural advertising. We therefore do not offer a "Do Not Sell or Share My Personal Information" link, because no such activity exists. Nor do we collect or use sensitive personal information categories beyond what is strictly necessary to provide the service (Vendor tax identification and precise location with your consent).
To exercise any of these rights write to support@solaurumtech.com. You may designate an authorised agent; we will verify their authority.
10. Children's privacy
The Platform is not directed to children under 13 and we do not knowingly collect their personal data. Users aged 13 to 17 may use the Platform only with the consent and supervision of a parent or legal guardian, and may not make payments, subscribe as a Vendor or purchase advertising. If we identify an account belonging to a child under 13 we will delete it immediately. If you are a parent or guardian and believe your child provided us data, write to support@solaurumtech.com and we will act without delay.
11. International transfers
Our servers and providers are located primarily in the United States. If you use the Platform from the EEA, the UK, Mexico or another jurisdiction, your data will be transferred to the U.S. These transfers rely on the European Commission's Standard Contractual Clauses (SCCs) or equivalent recognised mechanisms, together with supplementary technical measures such as encryption in transit and at rest.
12. Cookies and tracking technologies
The mobile application does not use advertising cookies or advertising identifiers (IDFA / AAID) and performs no cross-app tracking, which is why we do not present Apple's App Tracking Transparency prompt. We use only local device storage (SecureStore / AsyncStorage) to maintain your session and preferences. Our website may use technical and aggregate-measurement cookies.
13. Push notifications
We send two classes of notifications:
- Transactional: order status changes, cancellation requests, commission invoices. These are necessary for the service to work correctly.
- Proximity and promotional alerts: entirely optional, subject to your consent, rate-limited and with configurable quiet hours.
You can disable all notifications from your device settings at any time.
14. Changes to this Policy
We may update this Policy. Material changes will be notified by email or in the app at least 30 days before they take effect, stating the new version and its date. The version history is available in the Platform.
15. Contact
Solaurum Technologies LLC
- Registered address: 102 West 13th Avenue, Bowling Green, Kentucky 42101, United States
- Privacy, rights requests, support and claims: support@solaurumtech.com
- Website: https://mylonchera.com
- Account deletion without the app: https://mylonchera.com/account-deletion.html
- Response time: 48 business hours (maximum 30 days for formal rights requests)
This Policy has been drafted to comply with the requirements of the Apple App Store (App Privacy), Google Play (Data safety and Location Permissions policy), the GDPR (EU), the UK GDPR, the CCPA/CPRA (California), COPPA (USA) and the LFPDPPP (Mexico).
Privacy Policy version 2.1.1, effective September 2026.