PantryOS

PantryOS — Privacy Policy

Effective date: August 7, 2026 Who we are: Nexus Connect ("Nexus Connect," "we," "us"), operator of PantryOS. Contact: support@thepantryos.com


1. Scope and our role

This Privacy Policy explains how we collect, use, and share personal information through the PantryOS service and websites (the "Service").

PantryOS is used by food pantries and nonprofits ("Customers"). Two relationships:

  • For account/administrative data about Customers and their staff/volunteers,

we are the controller.

  • For beneficiary data (information about the families a pantry serves) that a

Customer enters into or collects through the Service, the Customer is the controller and we act as a processor on the Customer's behalf and under the Customer's instructions and privacy notices.

If you are a family served by a pantry and have questions about your information, please contact that pantry directly; this policy describes our practices as the Service provider.

2. Information we collect

  • Account & profile data: name, email, phone, password (hashed), organization

name, role.

  • Beneficiary data (on behalf of Customers): family/individual names, phone,

email, address, household size, dietary/allergy or similar flags, visit and order history, and SMS opt-in status.

  • Payment data: processed by Stripe; we receive limited billing metadata

(e.g., plan, status, last-4) but do not store full card numbers.

  • Usage & device data: log data, IP address, browser type, and actions taken in

the Service, used for security and to operate the product.

  • Communications: emails and support messages you send us.

3. How we use information

We use information to: provide, secure, and support the Service; authenticate users; process subscriptions and payments; send transactional messages (e.g., password resets, receipts, and, where opted in, pantry SMS notices); prevent fraud and abuse; comply with law; and improve the Service. We do not sell personal information.

4. SMS / text messaging

4.1 The Service can send transactional text messages on behalf of a Customer to recipients who have opted in — for example, notice that the pantry is open, that a place in line or an order is ready, or similar service messages.

4.2 Consent is collected by the Customer (for example, via a checkbox on the pantry's public sign-in page) at the time contact information is provided. Consent is specific to that Customer and is not shared or transferred to any other sender.

4.3 Message frequency varies. Message and data rates may apply.

4.4 Opt-out / help: recipients can reply STOP to unsubscribe at any time and reply HELP for help. After STOP, we stop sending messages from that Customer's program (except a confirmation of the opt-out).

4.5 We do not sell or share mobile phone numbers, SMS opt-in information, or SMS consent with third parties or affiliates for their marketing or promotional purposes. Mobile information is used only to deliver the messaging the recipient opted into and to operate the Service (including our messaging provider, Twilio, acting as our processor to transmit messages).

4.6 Carriers are not liable for delayed or undelivered messages.

5. How we share information

We share personal information only as needed to run the Service:

  • Sub-processors / service providers, under contract, including: Stripe

(payments), Twilio (SMS delivery), Microsoft (Outlook) (transactional email), and our hosting/infrastructure provider Heroku (Salesforce). (Maintain a current sub-processor list.)

  • Between Customer and its Authorized Users as part of normal operation.
  • Legal / safety: when required by law or to protect rights, safety, or the

integrity of the Service.

  • Business transfers: in a merger, acquisition, or asset sale, subject to this

policy. We do not sell personal information, and (see §4.5) we do not share mobile/SMS opt-in data with third parties for marketing.

6. Cookies and tracking

We use a strictly-necessary session cookie to keep you signed in. We do not currently use advertising cookies.

7. Data retention

We retain account data for as long as the account is active and as needed to provide the Service, then delete or de-identify it in the ordinary course, subject to legal requirements. Beneficiary data is retained per the Customer's instructions and is available for export/deletion as described in the Terms; upon account termination, Customer Data may be deleted after the export window.

8. Security

We use technical and organizational measures to protect information, including encryption in transit, database row-level isolation between Customers, hashed credentials, optional two-factor authentication, and access controls. No system is perfectly secure; we cannot guarantee absolute security.

9. Your choices and rights

Depending on your location, you may have rights to access, correct, delete, or port your personal information, or to object to certain processing. Account users may exercise these by contacting support@thepantryos.com. Beneficiaries should contact the pantry that serves them (the controller of that data); we will assist that Customer in responding.

10. Children's privacy

The Service is intended for use by pantry staff/volunteers and is not directed to children. We do not knowingly collect personal information directly from children. Beneficiary household information is entered by Customers in their role as service providers; Customers are responsible for any consents required for such data.

11. International users

The Service is operated in the United States and intended for US-based organizations. If you access it from outside the US, you consent to processing in the US.

12. Changes to this policy

We may update this policy; material changes will be notified (e.g., by email or in-app) and the effective date updated.

13. Contact

Questions or requests: support@thepantryos.com.


Terms of Service · Privacy Policy · Home