Legal
Privacy Policy
Effective October 11, 2026
CACFP FoodFlow ("FoodFlow", "we", "us") is a web application operated by AXORA TECH LLC at cacfpfoodflow.com. Sponsoring organizations in the USDA Child and Adult Care Food Program (CACFP) use it to keep meal counts, enrollment and eligibility records, menus and monthly claims for the child care centers and family day care homes they oversee. This policy explains what information the service handles, why, who else processes it, and the choices you have.
Who controls the data
Each sponsoring organization (a "sponsor") owns the records it and its sites enter into FoodFlow. For information about children and their households, the sponsor decides what is collected and why, as CACFP requires. We process that information only on the sponsor's behalf and on its instructions, to provide the service. If you are a parent or guardian with a question about a child's records, please contact the child care provider or its sponsor; we will help them answer you.
Information we handle
- Account information: your name and email address, the sponsor and sites you belong to, and your role (sponsor admin, monitor, site director or classroom staff). Sign-in is provided by Netlify Identity. Your password is handled by Netlify Identity, and we never see or store it.
- Sponsor and site information: organization and site names, state, addresses, license numbers, licensed capacity, approved meal types and serving times.
- Participant records entered by sponsors and sites: children's names, dates of birth, classrooms, enrollment and withdrawal dates, and eligibility information. Eligibility information includes the eligibility basis and category, household size, household income, assistance case numbers, and, where collected, ethnicity and race for civil rights reporting.
- Program records: daily attendance, meal counts by meal type with the time each meal service was recorded, closures, menus, monitor reviews, and monthly claims with their edit-check results and review notes.
- Activity (audit) log: for each change, we record who made it (user ID and email), when, which record and which fields changed, and the IP address it came from. The log stores field names only, never the values entered.
- Billing information: the sponsor's Stripe customer and subscription identifiers, subscription status and number of billed sites. Card and bank details are entered on Stripe's pages and are held by Stripe, not by us.
- Messages you send us, for example to support@cacfpfoodflow.com.
We do not use advertising or third-party analytics trackers, and we do not sell or rent personal information.
How we use it
- To run the service: record and sync meal counts, keep enrollment and eligibility records, and roll up, check and export monthly claims.
- To keep each sponsor's data separate and to enforce role-based access. Every request is checked on our servers against your sponsor, site and role.
- To send invitation emails when someone is added to a sponsor.
- To bill sponsors.
- To keep an audit trail.
- To provide support, keep the service secure and meet legal obligations.
How we protect it
- All traffic to cacfpfoodflow.com is encrypted in transit (HTTPS).
- Household income and assistance case numbers are additionally encrypted at rest with AES-256-GCM. The encryption key is kept separately from the database.
- Every record belongs to one sponsor, and site records belong to one site. Our servers filter every query by them, so one sponsor cannot see another's data.
- Access is limited by role. Classroom staff see attendance and meal counts only, and never household income, case numbers, ethnicity or race. Monitors see only the sites assigned to them.
- Recorded meal services are locked and time-stamped. Unlocking one requires a reason, which is recorded in the activity log.
No system is perfectly secure. If we learn of a security incident affecting your data, we will notify the affected sponsors without undue delay.
Information stored on your device
So that the meal-service screen keeps working without a connection, the app stores some information in your browser:
- A sign-in session cookie from Netlify Identity.
- Your selected sponsor and site, and a short summary of your account (the names of your sponsors and sites).
- An offline roster cache for each site you open on the meal-service screen. It holds each child's record key, first name, last initial and classroom. It contains no income, eligibility or birth dates.
- Meal counts recorded while offline and waiting to sync. These are record keys, meal types and times.
- A copy of the app's pages and images, so the app opens offline. Responses from our API are never cached by the service worker.
When you sign out, the app deletes the offline roster cache, the offline queue and your sponsor and site selection from that device. Counts recorded offline are sent before then if the device is online. Counts still waiting when you sign out are lost, so connect before you sign out.
Service providers
We use these providers to run FoodFlow. Each receives only what it needs for its part of the service:
| Provider | What it does | Data involved |
|---|---|---|
| Netlify, Inc. | Website hosting, server functions, database, file storage for the encryption key, and sign-in (Netlify Identity) | All service data, account and sign-in information |
| Brevo (Sendinblue SAS) | Sending invitation emails | Invitee's email and name, the inviter's name and email, and the sponsor or site name |
| Stripe, Inc. | Subscription billing, checkout and the billing portal | Sponsor name, billing contact email, payment details entered on Stripe, number of billed sites |
| Google Fonts | Web fonts used by our pages | Your browser's IP address and request details when fonts load |
We may also disclose information when the law requires it. Under CACFP rules, a sponsor's records may be reviewed by its state agency or USDA. A sponsor can export its records for such reviews.
Retention, export and deletion
- We keep a sponsor's data for as long as its account is active.
- A sponsor can export its claims from the app at any time. Other records (rosters, meal counts, audit log) can be exported on request.
- A sponsor admin can ask us to delete the sponsor's data, or a specific site's data, by emailing support@cacfpfoodflow.com. We will confirm the request and delete the data from the live service within 30 days. Copies in our providers' backups expire on their normal schedule.
- CACFP requires sponsors to keep program records for at least three years after the end of the fiscal year they relate to (7 CFR 226.10(d)). Please export what you need before asking us to delete it.
- If you are a user rather than a sponsor admin, ask your sponsor admin or contact us. We can remove your account access and tell you what information about you is held.
Children
FoodFlow is used by adults who work for sponsors and child care providers. It is not directed to children, and children do not use it. Information about children is entered by those adults, on behalf of the sponsor, for CACFP purposes only.
Your choices and rights
Depending on where you live, you may have rights to access, correct or delete personal information about you. For records a sponsor controls, we will pass your request to the sponsor and help it respond. For your own account, contact us directly.
Changes to this policy
If we change this policy, we will post the new version here with a new effective date. If a change is material, we will also notify sponsor admins by email before it takes effect.
Contact
AXORA TECH LLC, operator of CACFP FoodFlow
Email: support@cacfpfoodflow.com
Sign in