DELIVERYDAMAGE.COM

Privacy Notice

The short version: your Uber Eats file never leaves your device. There is no server, database, account or advertising behind this site, and the only analytics are Cloudflare’s cookieless visit counts.

Last updated 24 September 2026

1. Who runs this

Delivery Damage is a personal portfolio project by Inderpreet Singh Vohra, an individual in Ontario, Canada. It is not a company, and it is not affiliated with, endorsed by or sponsored by Uber.

Questions about privacy: support@deliverydamage.com.

2. Your order files

When you choose a ZIP or CSV, your browser reads it and calculates your recap on your own device. Your file, your orders and your recap are never sent to me or to anyone else. The site’s security policy blocks it from making any outgoing network connections, so it technically cannot upload them.

Nothing is saved in your browser either. Reloading, closing the tab or pressing “Clear my data” discards everything. Your original file and any share card you download stay on your device until you delete them.

3. Hosting

The site is hosted on Cloudflare Pages. Like any web host, Cloudflare processes standard connection information, such as your IP address, browser type and the pages you request, to deliver the site and protect it from attacks. That data never includes your order file.

I use Cloudflare Web Analytics to understand how many people visit and where they come from. A small Cloudflare script reports the page you viewed, the site that referred you, your browser and device type, your approximate country and how quickly the page loaded. It does not use cookies or local storage, and it never receives your order file, your stats or anything you upload or choose. I only see aggregated totals. Cloudflare’s security tools may also show me details of requests they block. Cloudflare may process this information outside Canada. See Cloudflare’s Privacy Policy.

4. Cookies and tracking

This site does not set cookies or use browser storage. It loads no ads or tracking pixels. The only outside script is Cloudflare Web Analytics, described above, which is cookieless. Fonts are hosted on this site. That is why there is no cookie banner.

Cloudflare may occasionally set a strictly necessary security cookie (such as __cf_bm) if it needs to check whether a visitor is a bot.

5. Ko-fi tips

Tipping is optional and happens on Ko-fi, not on this site. Nothing from your recap is sent to Ko-fi.

If you tip, Ko-fi shares your display name, email address and any message you leave with me. The payment goes directly to my PayPal or Stripe account, and those providers may share extra details, such as your legal name. I use this only to keep a record of the tip, reply to you, and handle refunds. I will never add you to a mailing list.

Ko-fi and the payment providers handle your payment under their own policies. See Ko-fi’s Privacy Policy.

6. If you email me

I receive your email address and whatever you write, and I use it only to reply. I delete support emails once they are no longer needed. Please don’t send your Uber export, card details, passwords or anyone else’s information. Screenshots with personal details covered are fine.

7. Sharing your card

The share card shows a playful label, order counts, restaurant and late-night totals, and your date range. Spending appears only if you tick the box. Nothing is posted automatically. Once you share the card, the app or person you share it with controls that copy.

8. Your rights

You can ask me what information I hold about you, and ask me to correct or delete it. In practice, this is only tip records and emails, because I never receive order data. I can’t retrieve or delete an order file I never had. Tip records may also be kept by Ko-fi, PayPal or Stripe under their own policies.

If you’re not satisfied with my response, you can contact the Office of the Privacy Commissioner of Canada.

9. Security and reporting problems

The site has no backend to break into. It uses a strict content security policy, limits file sizes, validates ZIP files, and treats all imported text as plain text. No website is perfectly secure, though: a compromised device or a malicious browser extension can see anything you open.

Found a bug or a security issue? Email support@deliverydamage.com with the steps to reproduce it, using sample data instead of a real export. Please don’t test with other people’s data or try to disrupt the site.

10. Changes

If this notice changes, I’ll update the date at the top. If the site ever needs to handle your order data differently, I’ll say so on this page before that change happens.