Privacy Policy
We collect as little about you as we can get away with, and we tell you plainly what we do with it. This page describes exactly what our website stores and why.
Last updated 18 August 2026
We hold your name, email, phone, chosen plan and delivery area so we can cook for you and get the kit to your door. We keep a record of your payments, but we never see or store your card number — that stays with WiPay. We do not sell your information to anybody, and we do not use advertising trackers.
1. Who is responsible for your information
Misora is the data controller for the information described here. You can reach us at misorainc@gmail.com, or by post at [registered business address — to be added].
We handle personal information in line with the Data Protection Act, Chap. 22:04 of Trinidad & Tobago, and with the general privacy principles it sets out — including the parts of that Act not yet brought into force. We would rather hold ourselves to the higher standard now than change our habits later.
2. What we collect
When you create an account
- Your name — so we know who we are cooking for and can address your delivery.
- Your email address — this is how you sign in, and how we send order confirmations and menu notices.
- Your password — stored only as a bcrypt hash. We cannot read it, and nobody at Misora can tell you what your password is.
- Your phone number — optional, used to reach you on delivery day.
- Your household size and nearest delivery area — to plan portions and delivery routes.
When you order and pay
- Which plan you chose, how many meals a week, and the price.
- A record of each payment: our own order reference, the amount, the date, whether it succeeded, and the reference WiPay gives back to us.
Card numbers, expiry dates and security codes never reach our servers. When you pay, you are on WiPay's own secure page, not ours. Our website has no card form and could not store a card number even if we wanted it to. This is why a data breach at Misora could not expose your card.
Technical information
Our hosting provider keeps standard server logs — IP address, browser type, pages requested, timestamps — for security and troubleshooting. We use a single sign-in cookie to keep you logged in. We do not use advertising or cross-site tracking cookies, and we do not run third-party analytics.
3. Why we hold it, and on what basis
- To perform our contract with you — taking orders, preparing kits, delivering, taking payment, and dealing with problems.
- To meet legal obligations — keeping accounting and tax records, and being able to trace an order if a food safety issue arises.
- For our legitimate business interests — keeping the site secure, preventing fraud, and understanding demand so we do not over- or under-buy.
- With your consent — for marketing emails, which you can stop at any time. Order and food safety messages are not marketing and will continue while you have a subscription.
4. Who we share it with
We share the minimum necessary with a small number of providers:
- WiPay — your name, email, phone and the amount, so they can take payment. They handle your card details under their own privacy policy.
- Our hosting and database providers — they store the site and its data on our behalf under contract.
- Delivery riders or pickup partners — your name, address and phone, only for the delivery in question.
We do not sell your personal information, and we do not share it for anyone else's marketing. We would only disclose it otherwise if the law required it, or to protect someone's safety — for example, a public health investigation into a food safety incident.
Some providers store data outside Trinidad & Tobago. Where that happens we choose providers with recognised security practices and contractual protections.
5. How long we keep it
- Account details — while your account is open, and up to 12 months after you close it, in case you come back.
- Order and payment records — at least 7 years, because tax and accounting rules require it. These stay even after you close your account.
- Allergy and dietary notes you give us — while your account is open, then deleted with it.
- Server logs — a short rolling window, typically under 90 days.
6. Keeping it safe
Passwords are hashed with bcrypt and never stored as readable text. The site is served over an encrypted connection. Access to the customer database is limited to the people who need it to run Misora.
No system is perfectly secure, and we will not pretend otherwise. If a breach affects your information, we will tell you what happened, what it means for you, and what we are doing about it.
7. Your choices
- See and correct your information — most of it is editable directly on your profile. Email us for anything else.
- Get a copy — ask and we will send you what we hold.
- Delete your account — email us and we will close it and remove your personal details, except the order and payment records we are legally required to keep.
- Stop marketing emails — use the unsubscribe link, or just tell us.
We will respond within 30 days. There is no charge unless a request is repetitive or excessive.
8. Children
Misora is for adults. We do not knowingly create accounts for under-18s. If you believe a child has given us their information, tell us and we will remove it.
9. Changes
If we change how we use your information in a way that matters, we will tell you by email or on the site before it takes effect. The date at the top of this page shows the current version.
10. Questions or complaints
Email misorainc@gmail.com and we will answer properly. If you are not satisfied, you may raise the matter with the Office of the Information Commissioner of Trinidad & Tobago.