Information collected
Membership applications can include contact details, restaurant information, role, supporting documentation, and review notes. Private member accounts store membership status, browser sessions, preferences, contribution points, moderation history, and a recoverable mapping to one public pseudonym. Contact forms collect a name, email address, and message. Optional service-request forms collect the business information shown on the form and a record of any permission to share it. Newsletter and worksheet forms collect an email address and the information needed to complete the request.
Service providers may process limited technical request information needed to operate and protect the site. OrderBridge does not use that information to create advertising profiles and does not store IP addresses in application records.
Verification identity and posting identity are separate
Verification information establishes that an applicant operates an independent restaurant. Posting identities consist of a pseudonym and verification badge. A private D1 mapping connects the member account to current and historical pseudonyms so sign-in, recovery, moderation, and deletion requests can work. That mapping is restricted to trusted account and audited safety workflows.
Member discussions and profiles are visible only to signed-in eligible members. They do not include an application email, legal name, private profile, exact points, or restaurant-to-person association. Member APIs, analytics, RSS, and sitemaps never expose the private mapping. Editorial review starts from the pseudonymous contribution.
How information is used
- To evaluate and administer membership applications.
- To authenticate returning members, maintain essential browser sessions, and prevent account abuse.
- To provide requested communications, files, introductions, and support.
- To share submitted business information only when the submitter has explicitly authorized that specific request.
- To protect forms and screen submissions for spam, abuse, and relevance before human review.
- To publish consented contributions under a member-selected pseudonym.
- To award private contribution points and display a contribution level.
- To understand aggregate, non-identifying use of community utilities.
Essential session cookies
OrderBridge does not use advertising or analytics cookies. Signed-in member and administrator areas use essential security cookies for the private session and cross-site request protection. The session cookie is HttpOnly, Secure, and unavailable to client scripts; it expires or is revoked according to the account security controls.
Service providers and sharing
OrderBridge uses service providers for hosting, storage, email delivery, form security, restaurant lookup, requested file delivery, and site measurement. They process information only as needed to perform those functions and under their own applicable terms.
OrderBridge does not sell or rent personal information, build advertising profiles, or use third-party advertising pixels. Information is disclosed outside OrderBridge only to provide a requested service, when the submitter has explicitly authorized it, to protect the service or another person, or when required by law.
Retention
Pending applications are retained only while verification is active and are periodically removed after expiration. Approved verification records and private member accounts remain while membership is active, unless deletion is requested. Expired login links and sessions are routinely removed; revoked-session records are retained briefly for security. Point events and moderation audit events are append-only while the account remains active. Contact messages and optional service-request records, including consent evidence, are retained for up to 12 months. Temporary file-delivery records are removed after their delivery window expires. Active newsletter records remain until unsubscribe; unsubscribed records may be retained in suppression form to honor that choice.
Operational security logs follow the configured retention periods of the services that produce them. Aggregate utility records contain grouped values rather than exact restaurant figures or a durable user identifier.
Access, correction, and deletion
A person may request access to, correction of, or deletion of submitted information from the private account or by emailing editor@orderbridge.app from the address associated with the record. Identity may be confirmed before completing a request. Verified deletion requests are completed within 48 hours. Account access and the private identity mapping are deactivated, while approved discussions and replies are reduced to anonymous tombstones so the surrounding thread remains coherent without retaining the former member identity or content.
Privacy questions can be sent to the same address. Commercial and editorial boundaries are explained in the disclosure; verification controls are explained at how verification works.