What we collect
- Your account
- Your name and your university email address. If you sign in with Google, we receive your name and email from your university Google account — we do not use your Google profile photo. If you create an account with a password instead, we also ask for a student ID. We never check it against any roster, it cannot be changed afterwards, and nobody sees it but you — and the admin, if you apply to sell.
- Your profile, if you add it
- A phone number and the campus block where you usually are. Both are optional and you can leave them blank. Your block is shown to nobody else — not to a seller, not to another student, not to the admin.
- Your orders
- What you ordered, from which seller, the drop-off point, any note you attach, and whether the seller has marked it paid.
- Sellers you follow
- Which sellers you have followed, so you can find them again. A seller is told how many people follow them and never who; no other student sees the number or the names.
- One photograph per batch, if you sell
- A seller may attach a picture of the food to a batch they post. It is the only image this app stores, and the section below is entirely about it.
- Technical
- Cookies that keep you signed in, and error reports when something breaks. An error report records what failed and which page it happened on. It is never linked to you — there is no name, no email and no account in it.
Why we collect it
Only to run the marketplace: to create and secure your account, show you who is open right now, let you follow a seller, let you place an order and watch it come, let a seller you have ordered from reach you about that specific order, and let the admin resolve a dispute if one is raised. We do not use your data for advertising, and we do not sell it to anyone.
Who can see your information
- Sellers — only ones you have actually ordered from
- A seller can see your name, email and phone number for customers who have placed an order with them, so they can hand over the food and follow up on payment. No seller can see anyone else. The rule runs both ways and by the same test: you can see a seller’s phone number only for sellers you have ordered from. Cancelling does not undo it — the seller who has just called off your order is exactly the person who may need to ring you and say why. There is no directory and no way to search for a person.
- Other customers — a number, never a name
- Your orders are private. Other students never see your name, never see what you ordered, and can never tell which order is yours. On a seller’s open batch they see one number: how many people have ordered from it. It stays hidden until at least five people have ordered, so it can never point at one person; it never says who they are; we show it on the batch’s own page rather than on the list of who is open; and it goes when the batch closes.
- The admin
- The admin can read accounts, orders and batches — that is what keeping the platform running and settling a dispute takes. Even the admin cannot read your phone number or your usual block, and your student ID reaches them only if you apply to sell. Suspending someone, changing a role or deciding an application must state a reason, and each one writes a line to a log the app gives nobody a way to edit or erase. The admin account cannot place an order or sell anything; the database refuses both.
These limits are enforced inside the database itself, not only by what a screen chooses to show — a seller’s request for another student’s details is refused by the database, not merely hidden.
Photos on a batch
A seller can attach one photograph to a batch. It is the only picture Kedai Ku stores, and these are its rules.
- Only a seller, and only the food
- The photograph must be of the food being sold. Pictures of people, and of the inside of anyone’s room, are not allowed, and an account that posts one can be suspended. Only the seller who owns the batch can upload it — customers upload nothing, and there are no profile pictures.
- The camera’s location is removed first
- A photo taken on a phone usually carries the coordinates of where it was taken. Your browser re-encodes the picture before it is sent, which drops those coordinates along with everything else the camera wrote into the file. Where a seller cooks never leaves their phone.
- Treat it as public
- Any signed-in student sees a batch photograph the same way they see the batch. The file itself is kept under a long random name that is published nowhere, but the store it sits in is public — so anyone holding that exact link can open the picture, signed in or not. This is the honest reason the rule above is food only.
- Taking one down
- If a seller removes or replaces a batch’s photograph, the file is deleted from the store, not merely hidden — unless another batch still shows the same picture, because a batch keeps the picture it was posted with. If an account is suspended, every photograph it uploaded is deleted and cannot be brought back. What we cannot reach is a copy someone had already saved, or one still sitting in a cache elsewhere on the internet.
What we deliberately do not do
- No payments. You pay the seller directly — cash, Touch ’n Go or a bank transfer, as the two of you agree — and Kedai Ku is not a party to that. We store no payment details, no bank or e-wallet account, and no record of which method you used. A seller can mark an order paid before you collect it, because plenty of students pay in advance; that mark is the seller’s record of what the two of you settled, not a payment we saw or handled.
- No pictures of people. The only photograph this app stores is a seller’s picture of their own food, under the rules above. There are no profile pictures, customers upload nothing, and we do not use your Google profile photo.
- No public ratings. We keep no public ratings and no campus-wide reputation score; whether a customer has paid is visible only to the seller they owe, never to everyone.
- Nothing personal kept on your phone. If you install Kedai Ku to your home screen, it keeps only its own files and one “you are offline” page on the device. No page showing your orders, and no page showing anyone’s details, is ever stored there.
Services we rely on
We use Supabase (to store data, manage sign-in, and hold batch photographs), Vercel (to host the website and deliver those photographs), and Google (for Sign in with Google). These providers process data on our behalf so the app can work. When we add the ability to send emails, we will use an email provider for that and update this page.
How long we keep it
We keep your order history as the record of trades made on the platform; we do not delete it, and neither can you or the seller — an order is two students’ record, not one person’s. We keep the rest of your account data for as long as your account exists. Error reports are cleared out once they have gone thirty days without happening again, and sooner if the log fills up. There is no button anywhere that deletes an account: if you want yours closed, email us and we will suspend it, which means it can no longer order or sell. A suspended account can still sign in, and your name, email and order history stay in the record.
How we protect it
Sign-in is handled by our authentication provider; we never see or store your password in a readable form, and if you use Google we never handle a password at all. The site runs over an encrypted (HTTPS) connection, and access to data is restricted at the database level so that each person reaches only what the rules above allow.
Your rights
Under the PDPA you may ask what personal data we hold about you, ask us to correct it, and ask questions about how it is used. You can edit your name, phone and usual block yourself on your profile. Your role and whether your account is active are set by the admin, not by you. Your student ID is fixed when the account is created and cannot be changed afterwards. Your email is tied to the account you sign in with, and a new one still has to be a university address. There is no button that downloads your data: email us and we will answer.
Cookies and your device
We use one kind of cookie: the kind that keeps you signed in. We do not use advertising or tracking cookies, and there is no analytics on this site at all. Your appearance choice, whether the side menu is collapsed, and one prompt you have dismissed are remembered by your browser on your own device and are never sent to us.
Who this is for
Kedai Ku is for members of Albukhary International University who sign up with a university account.
Changes
If we change how we handle your data, we will update this page and its date. Continued use after a change means you accept the updated notice.
Contact
For any privacy question or request, email kedaiku.support@gmail.com.
See also our Terms of Use.