This policy explains what information Feed Our Team LLC (“Feed Our Team,” “we,” “us”) collects when you use feedourteam.com, how we use it, who else sees it, and the choices you have. We wrote this in plain English because a policy you can't understand isn't protecting anyone.
Who we are
Feed Our Team LLC is a Georgia limited liability company. We run a directory that helps teams and groups find catering in the cities they travel to. Searching is free and needs no account. Restaurants pay a flat membership to be listed. You can reach us any time at [email protected].
Two very different groups use this site, so we've split the next two sections that way: coaches and teams who search, and restaurants who pay for a listing.
What we collect from teams and coaches
You do not need an account to search, filter, or open a listing.
What you type into a form
- Contact form. Your name, email address, organization, role, team size, and message.
- Coverage requests — the “tell us where to go next” panel in the search results. The town or venue you searched, your email address, and your team size if you fill it in. We also record the filters the search was using (meal type, budget band, dietary tags), because that is exactly what tells us which restaurants to go sign next.
What we record when you use the site
- Interaction events. Map pin clicks, menu views and contact clicks, with the listing involved and a timestamp. We also record the town you type into the search box and how many results it returned, which filter chips you change, the town on a coverage request, and which “get on the roster” button was clicked — plus the ?ref= tag if you arrived from one of our outreach emails. These tell us which listings are earning their spot and, more importantly right now, which towns teams are looking in so we know where to sign restaurants next. Your email address and name are never attached to these events; the server strips anything that looks like one before storing.
- A hashed IP address. We don't store your raw IP. We run it through SHA-256 with a fixed site-wide salt and keep the first 16 hex characters, so what sits in our database is a short fingerprint rather than the address itself. We use it to rate-limit abuse and to count unique interactions. Be clear-eyed about what it is not: the pool of possible IPv4 addresses is small and our salt doesn't change, so someone determined could work a fingerprint backwards. We hash it to avoid keeping your raw address on file, not as a promise of anonymity.
- Your browser's user-agent string, stored alongside events and form submissions.
What we collect from restaurant members
Restaurants pay a flat membership — $5 a month or $50 a year — to appear on the roster. Joining means giving us:
- Business and listing details. Brand, city and state, contact name, email, phone, cuisine, signature dishes, budget band, meal types, dietary tags, lead time, minimum order, delivery fee, and menu URL. Most of this is the listing itself, and is meant to be public.
- An operator account. An email address and a password, which we store only as a hash — never as plain text. Signing in creates a server-side session that lasts 30 days.
- Billing identifiers from Stripe. The customer and subscription IDs Stripe hands back, plus when we last collected and when the current period ends.
We never see or store card numbers. Checkout happens on Stripe's own hosted pages. Your card details go to Stripe; what comes back to us is a confirmation and the identifiers above. If a renewal payment fails, the listing is deactivated straight away; if the payment goes through later, it is reactivated.
How we use it
- To reply to you. Contact and coverage submissions are stored in our own database and emailed to our inbox so a real person can follow up.
- To decide where to go next. Coverage requests are the recruiting list. Your town on that list is the reason a restaurant in it gets a call.
- To run listings and memberships. Member details become the public listing; the Stripe identifiers keep the subscription and the listing in sync.
- To operate and improve the site. Interaction events show which listings and which filters are pulling weight, and which towns teams are searching.
- To report activity back to restaurant members. A member sees counts of the clicks, menu views and contact taps on their own listing over the last 30 days. They see totals only — never your name, email, IP address or which individual person did what.
- To prevent abuse. Hashed IPs and user agents let us rate-limit and block abusive patterns without keeping raw addresses.
- To comply with law. We may use or disclose information when legally required, in response to valid legal process, or to protect the rights and safety of Feed Our Team, our users, or the public.
Who else touches your data
We use a short list of outside services to run this thing. Each gets only what the job needs.
- Stripe — payment processing for restaurant memberships. Stripe collects and holds the card details and processes the charge; we receive customer and subscription identifiers and payment status. Applies to members only, never to coaches searching the site.
- Resend — delivers our email: account mail to members (welcome, password reset), our own internal notification when a lead comes in, and cold outreach to restaurants we're inviting to join. The content of a contact form or coverage request travels inside those internal notifications.
- Google Gemini — drafts suggested menu items when a member asks for it. At that point the restaurant details they gave us, and the menu PDF if they upload one, are sent to Google's Gemini API to generate the draft. Nothing about a coach or a site visitor is ever sent to Gemini, and the feature only runs on a member's request.
- OpenStreetMap / Nominatim — map tiles and geocoding. Your browser loads tiles from OpenStreetMap directly, so their servers see your IP address the way any site you visit would. When you type a town name, we pass that text to Nominatim to turn it into coordinates.
- Cloudflare — sits in front of everything as our CDN and TLS terminator, so it sees ordinary request metadata (IP address, URL, user agent) in order to deliver and protect the site. We also use Cloudflare Web Analytics for page-view counts; it is cookieless, sets no identifier on your device, and does not follow you to other websites.
That is the entire list. Everything else — every contact submission, coverage request, restaurant intake and interaction event — is stored only in our own database on our own infrastructure. No advertising network, no third-party ad or social tracking pixels, no data brokers, no cross-site profiling. We do not sell your personal information, and we don't hand it to anyone else for their own marketing.
Cookies and browser storage
You won't see a cookie banner on this site. That's not an oversight — there's nothing here to consent to.
- One cookie, and only for signed-in members. When a restaurant operator signs in we set fot_op, a session cookie that keeps them signed in for 30 days. It is strictly necessary: without it, signing in does nothing. Browsing or searching the site sets no cookie at all.
- Browser storage stays on your device. We use localStorage and sessionStorage for your own convenience — remembering a half-finished restaurant signup so you can pick it back up, and holding the ?ref= tag from an outreach email for the length of your visit. (That tag is also stored on the interaction events above, so we can tell which outreach email brought someone in.) That data lives in your browser, isn't an advertising identifier, and clearing your browser data clears it.
- Analytics without cookies. Cloudflare Web Analytics counts page views without setting a cookie and without tracking you across sites.
If we ever add something that genuinely needs consent, we'll ask for it and update this page before we turn it on.
How long we keep it
Straight answer: we have not set a fixed retention schedule yet. What happens today:
- Contact and coverage submissions stay in our database while we're working with you or still have a live reason to follow up.
- Member records stay for the life of the membership and afterward as the business record of a paid relationship. Stripe keeps its own transaction records under its own rules.
- Interaction events are kept as an ongoing history of how listings perform.
- Sessions and email links expire on their own — 30 days for a signed-in session, 15 minutes for a one-time link we email you.
Ask us to delete your data and we will, schedule or no schedule. When we do set one, this page changes with it.
Your rights and choices
Whatever privacy law applies where you live, here's what we'll do when you ask. Email [email protected] from the address you gave us and say what you want.
- Access. We'll tell you what we have on file for you.
- Correction. Wrong details get fixed. Members can also edit most listing details themselves in the dashboard.
- Deletion. We'll delete your record, minus anything we're legally required to keep, such as payment records. Deleting a member account also takes the listing down.
- Stop hearing from us. Reply to any email from us and ask to be removed. That's the whole process.
- Do Not Track and Global Privacy Control. We honour both. If your browser sends DNT or GPC, this site sends no interaction events at all — no searches, no filter usage, no button clicks. The site works exactly the same; we just stop counting. We don't track you across other websites in any case.
Cancelling a membership. There's no self-serve cancel button in the member dashboard yet. Email us from the address on your account and we'll cancel the subscription so it does not renew again. Your listing stays live through the end of the period you have already paid for, then goes inactive. Don't just let a payment fail — that deactivates the listing immediately instead of closing things out cleanly.
We describe what we actually do here rather than claiming blanket compliance with any particular regime. If you have a right under the GDPR, the CCPA, or a state privacy law that this page doesn't name, ask us and we'll deal with it.
Children
Feed Our Team is for adults organizing meals on behalf of teams and groups. It is not directed at children, and we don't knowingly collect personal information from anyone under 13. We do collect team-size numbers, and the athletes behind those numbers are often minors — but a team size is a count, not a roster. We never ask for a player's name, age, contact details, or anything else about an individual on the team. If you believe a child has sent us personal information, email us and we'll delete it.
Security
The site runs on infrastructure we control. Traffic is encrypted in transit with TLS, passwords are stored only as hashes, one-time email links are stored only as digests, member and admin areas sit behind authentication, and abusive traffic is rate-limited. No system is perfect and we're not going to pretend otherwise, but we take reasonable steps to protect what you trust us with. If you think you've found a security problem, email [email protected].
Changes to this policy
We'll update this policy as the product changes. Material changes get a new effective date at the top of this page and, where it makes sense, a note to the people affected.
Contact
Questions about this policy? Email [email protected] — a real person reads every message.