1. Who we are
Stock the Block (“Stock the Block,” “we,” “us” or “our”) is a student-run food recovery program in New York City. We move sealed, surplus cafeteria food from schools to nearby food banks and community fridges. This policy covers this website, including the public pages, the public delivery log and the member portal (together, the “Site”).
We are a volunteer student project, not a business. We do not sell anything through the Site and we do not make money from your information.
2. Summary
- You can read the public pages without giving us any information. We run no analytics, no advertising and no tracking cookies.
- If you send the contact form, we store what you type so we can reply.
- If you are a member and sign in with Google, we store your name, email address and the deliveries you log.
- The public delivery log shows only a delivery's date, weight, number of food types and review status. It never shows names, schools, locations, notes or photos.
- Some parts of the Site load content from outside services (GitHub, which hosts the Site, and Google). The map's street background comes from OpenStreetMap, but only after you tap the map. These services receive basic technical information, such as your IP address, when your browser contacts them.
- We never sell or rent personal information.
3. Information we collect
3.1 When you visit the Site
We do not collect information about visitors to the public pages. However, like any website, your browser must contact certain servers to load the pages, and those services may record technical information about the request:
- Website hosting (GitHub Pages). The Site is hosted by GitHub. When you load a page, GitHub receives your IP address and standard request details (such as browser type and the page requested), and may log visitor IP addresses for security purposes. We do not have access to these logs.
- Fonts (Google Fonts). Our pages load typefaces from Google Fonts, so your browser sends your IP address and browser details to Google.
- Map (OpenStreetMap). The map on the home page shows districts, school locations and community fridge locations from files stored on the Site. The street background (“tiles”) comes from the OpenStreetMap Foundation’s tile servers and loads only after you tap, click or select the map. From then on, your browser sends your IP address and the map area being viewed to the OpenStreetMap Foundation.
- Database (Google Firebase). The home page (for the live impact counter and the contact form), the delivery log and the member portal load code from Google's servers and connect to our Google Firebase database. Google receives your IP address and browser details when this happens.
3.2 When you contact us
If you send the “Work with us” form on the home page, we collect:
- your name and email address (required);
- the role you choose (for example, school administrator, student or partner organization);
- your school or organization, if you enter one;
- your message, if you write one; and
- the date and time you sent it.
If you email us instead, we receive your email address and whatever you include in the email.
3.3 When a member uses the member portal
The member portal is only for approved Stock the Block volunteers. It is not needed to use any other part of the Site.
- Sign-in. Members sign in with their Google account through Google Firebase Authentication. We receive the account's name, email address, a Google account identifier and, if the account has one, a link to its profile photo. We never see or store your Google password. Google's handling of your account is covered by Google's Privacy Policy.
- Member role. An administrator records whether an account is a member or an administrator.
- Delivery records. For each delivery a member logs, we store: the delivery date, a box ID that the portal assigns automatically, the school the food came from, where it was delivered, its total weight, a list of foods and amounts, optional notes, the member's account identifier and email address, the time it was logged, and its review status, including any reviewer note and the email address of the administrator who reviewed it.
- Photos. A member may attach a photo of the food. Before uploading, the photo is resized and re-saved in the browser, which removes embedded information such as the photo's GPS location and camera details. Photos should show food only, never people.
- Temperature readings. When our box sensors are in use, a delivery may include temperature readings from the box. These are about the food, not about any person.
4. How we use information
We use the information described above only to:
- reply to messages and follow up with schools, partners and students who contact us;
- let members sign in and control who can log and review deliveries;
- record, review and correct deliveries, and keep food-safety records for the food we move;
- publish the public delivery log and overall totals (see section 5);
- keep the Site secure and prevent spam and misuse; and
- meet legal obligations, if any apply.
5. What is made public
The delivery log is public and can be viewed by anyone. For each delivery it shows only:
- the delivery date;
- the total weight;
- the number of kinds of food in the box; and
- whether it is awaiting review or has been verified.
It does not show who made the delivery, the school, the delivery location, the box ID, notes, reviewer notes or photos. Deliveries that an administrator rejects are removed from the public log. Contact form messages and member account details are never made public.
6. Service providers
We use the following outside services to run the Site. They handle information on our behalf or, as described in section 3.1, receive technical information directly from your browser. Each is governed by its own privacy policy.
| Service | What it does | Information involved |
|---|---|---|
| GitHub Pages (privacy) | Hosts the Site | IP address and request details |
| Google Firebase (privacy) | Database and member sign-in | Contact form messages, member accounts, delivery records and photos, public log; IP address and browser details |
| Google Fonts (privacy) | Provides the Site's typefaces | IP address and browser details |
| OpenStreetMap Foundation (privacy) | Provides the map's street background, after you tap the map | IP address and the map area viewed |
Our information is stored on these providers' servers, which may be located in the United States or other countries. Apart from these providers, we share personal information only: with other Stock the Block team members who need it for the program; with a school or partner organization when you ask us to connect you; if required by law, such as a valid subpoena or court order; or to protect the safety of any person.
7. What we don't do
- We do not sell, rent or trade personal information.
- We do not show advertising or share information with advertisers.
- We do not use analytics, tracking pixels, fingerprinting or tracking cookies.
- We do not collect your precise location. The map shows schools and neighborhoods, not you.
- We do not use personal information for automated decision-making or profiling.
8. Storage on your device
The Site does not set cookies. It stores a few small items in your browser's local storage. These stay on your device and are never sent to us:
| Item | Purpose |
|---|---|
stb-theme | Remembers the color theme you pick (light, dark or stock). |
stb-member | Set only after a member signs in, so the “Sign in” button reads “My portal.” It is removed when the member signs out. |
| Offline copy of the Site | Where your browser supports it, a copy of the Site's pages and files is saved so the Site loads faster and works offline. |
| Firebase sign-in state | Member portal only. Keeps a member signed in until they sign out. During Google sign-in, Google may set its own cookies on its own website under Google's policies. |
You can delete all of these at any time by clearing this site's data in your browser settings.
9. How long we keep information
We keep personal information only for as long as we need it for the purposes described in this policy. Delivery records may be kept for as long as the program runs, as a record of the food we have moved. When information is no longer needed, we delete it or remove the details that identify you. We may keep information longer where the law requires it.
10. Security
We take reasonable steps to protect the information we hold. Database access is controlled by security rules that let a member see only their own deliveries and let only approved administrators see contact messages and all delivery records. Sign-in is handled by Google, so we never hold passwords. All connections to the Site and our database are encrypted (HTTPS). No system is perfectly secure, however, and we cannot guarantee the security of information sent over the internet. If we learn of a security breach that affects your personal information, we will notify you as required by law.
11. Children and students
The Site is meant for school staff, partner organizations and high school students. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you are under 13, please do not send us your information; ask a parent, guardian or teacher to contact us for you. If we learn that we have collected personal information from a child under 13, we will delete it promptly. If you believe this has happened, please contact us.
Member accounts are only for people who are at least 13 years old.
We do not receive student records from schools. The only student information we hold is what a student member or other person gives us directly through the Site or by email.
12. Your choices and rights
You can contact us at any time to:
- ask what personal information we hold about you;
- correct information that is wrong;
- ask us to delete your information; or
- withdraw from the member program.
We will respond as soon as we reasonably can. We may need to confirm your identity before acting on a request, for example by replying to the email address we have on file. A parent or guardian may make these requests on behalf of their child. We may keep some information where we need it for a legitimate reason, such as a record of a delivery, or where the law requires it.
You can also choose not to use the contact form or the member portal. All public pages work without them.
13. Links to other websites
The Site links to other websites, such as the sources we cite and our service providers' policies. We are not responsible for the content or privacy practices of those websites. Their own privacy policies apply when you visit them.
14. Changes to this policy
We may update this policy from time to time. When we do, we will post the new version on this page and change the “Last updated” date at the top. Changes take effect when they are posted. By continuing to use the Site after a change, you accept the updated policy.
15. Contact us
For questions about this policy or to make a request about your information, email us at stockingtheblock@gmail.com.