1. About this policy
My Cuppa Coffee Pty Ltd (“MCC”, “we”, “us”), based in Brisbane, Australia, operates the My Cuppa Coffee platform, including our website, mobile apps, and related services.
This policy explains what personal information we collect, how we use it, who we share it with, and the rights you have under Australian privacy law. It applies to both consumers and café owners using the platform.
2. Information we collect
- Account information (name, email address, a secure hash of your password)
- Coffee personality quiz responses and the profile they generate
- Location data: the suburb and city you select, and precise GPS location if you grant browser permission
- Café visit patterns captured via loyalty stamp scans
- Payment information, processed by Stripe. We do not store full card numbers on our systems
- Review content, ratings, and photos you choose to upload
- Device and browser information (user agent, screen size, operating system)
- Cookies and similar technologies (see the Cookie Policy at /cookies)
3. Personality data
Your quiz responses are used to generate a coffee personality profile. Depending on how you interpret your answers, this profile may constitute sensitive information under the Privacy Act 1988 (Cth).
We collect this information with your explicit consent when you complete the quiz. You can retake the quiz, review your profile, or delete your personality data at any time from your account settings.
4. How we use your information
- To provide personality-matched café recommendations
- To operate the universal loyalty card system across participating cafés
- To calculate and display match scores between you and a given café
- To send transactional emails relating to your account, stamps, and rewards
- To send marketing emails, only when you have opted in
- To generate aggregated analytics for café owners (never individual user data)
- To improve the matching experience over time
5. What café owners can see
Café owners see aggregated information only: the distribution of personality types among their visitors, visit-frequency trends, and loyalty programme statistics.
Café owners never see individual user profiles, quiz answers, personal contact details, or the visit history of any specific consumer.
6. Data sharing
We do not sell personal data. The following third parties process data on our behalf under their own privacy policies:
- Supabase: database hosting (Australia region)
- Vercel: application hosting
- Stripe: payment processing
- Resend: email delivery
- Google Maps: location and mapping services
7. Cookies and tracking
We use essential cookies to keep you logged in, functional cookies to remember preferences such as dark mode, and analytics cookies only with your consent. See the full Cookie Policy for details.
8. Your rights under Australian law
You can:
- Access the personal information we hold about you
- Ask us to correct information that is inaccurate
- Request deletion of your account and associated data
- Opt out of marketing communications at any time
- Lodge a complaint with the Office of the Australian Information Commissioner (OAIC)
To exercise these rights, email support@mycuppacoffee.com.au or use the relevant controls in your account settings.
9. Data retention
Account data is retained while your account is active and deleted within 30 days of an account-deletion request. Anonymised data may be retained for analytics. Loyalty stamp records are retained for two years after your last activity to support reward claims.
10. Data security
We use TLS encryption in transit, encryption at rest through Supabase, strict role-based access controls, and regular security reviews. No system is 100% secure, but we take reasonable steps to protect your information.
11. Changes to this policy
We may update this policy as the platform evolves. Significant changes will be notified by email. Your continued use of the platform after a notified change constitutes acceptance of the updated policy.