1. Introduction
CafeRadar™ (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and website (collectively, the “Service”).
2. Information We Collect
2.1 Information You Provide
- Account Information: When you create an account, we collect your name, email address, and profile photo (via Google or Apple Sign-In).
- User Content: Reviews, check-ins, journal entries, photos, and other content you create within the app.
- Preferences: Coffee preferences, favorite drinks, roast preferences, and interests you set during onboarding.
- Communications: Messages you send to us for support or feedback.
- Direct Messages: If you and another user follow each other, the content of the one to one messages you send through Coffee Connections, which we store to deliver and display the conversation.
- Drink and Food Log: When you scan or log a drink or a meal, we store that entry and the per day nutrition estimates we derive from it, such as estimated calories, caffeine, sugar, protein, carbohydrates and fat, together with the date you logged it. We store these so the app can show you your log, your daily totals and your weekly view. These figures are estimates produced for your own reference, they are not medical, dietary or clinical advice, and they are not shared with cafés or with other users. They are visible only to you, and they are removed when you delete your account.
2.2 Information Collected Automatically
- Location Data: With your permission, we collect your precise location to show nearby cafés, enable check-ins, and send proximity alerts. The proximity alert feature requests background location access (“Always Allow” on iOS,
ACCESS_BACKGROUND_LOCATIONon Android) so the app can notify you when you walk near a high-rated specialty café even when CafeRadar is closed or not in use. Your location is used on your device to trigger geofence alerts; location samples produced by background geofencing are not sent to or stored on CafeRadar servers. Up to 20 nearby cafés are monitored at a time, refreshed when you next open the app, and the monitoring stops when you disable proximity alerts. You can disable location access at any time in your device settings. If you decline location access, the app may estimate your approximate city from your IP address (via the GeoJS service) so it can still show relevant cafés; this estimate is city-level, not precise. - Device Information: Device type, operating system, unique device identifiers, and app version.
- Usage Data: How you interact with the app, including pages visited, features used, and time spent.
- Analytics Data: We use PostHog for first-party analytics and Sentry for error tracking. No cross-app tracking identifiers are collected.
- Push Notification Tokens: With your permission, OneSignal generates a push notification token tied to Apple Push Notification service on iOS or Firebase Cloud Messaging (FCM, a Google service) on Android. This token lets us deliver notifications to your device.
- Google Play Services (Android only): On Android devices, Google Play Services supports our integration of Google Maps and Firebase Cloud Messaging. Google may collect technical information through these services governed by Google's privacy policy.
- Advertising Identifiers: We do NOT collect or use Apple's IDFA on iOS, Google's Advertising ID on Android, or any cross-app advertising identifier. We do not display advertising in the app and do not share data with advertising networks.
2.3 Merchant Information
If you submit a business inquiry to upgrade to our Enterprise plan or to add additional cafe locations, we collect: the contact email and phone number you provide, your account details (current plan, listing count, requested locations), and the free-text business context you submit. We use this information solely to evaluate, contact you about, and provision your enterprise contract (lawful basis: pre-contract performance under GDPR Art. 6(1)(b) and our legitimate interest in business-customer follow-up under Art. 6(1)(f)). Please do not include payment card data, government identifiers, health information, or other special-category data in your message. Enterprise inquiry records are retained for up to 6 years from contract end for accounting, audit, and dispute resolution; declined or withdrawn inquiries are pseudonymised after 24 months.
3. How We Use Your Information
- Provide and maintain the Service, including finding nearby cafés and personalizing recommendations.
- Process check-ins, reviews, and other user-generated content.
- Send you notifications about nearby cafés, and deliver offers from cafés you follow, save, check in at, or review to your in-app inbox. You control these in your notification settings.
- Notify you when another CafeRadar user takes an action that involves you. For example, a person you both follow can tag you as having been at a café with them or invite you to a feature of the app they use themselves, and when someone joins a shared list you are in, or adds a café to it, we let the other members know. We deliver these to your in-app inbox so that you can see who they came from and decide what to do. The lawful basis is our legitimate interest in operating features between people who have chosen to follow each other, or who have chosen to take part in something together such as a shared list (GDPR Art. 6(1)(f)). You control these in your notification settings, and you can block any user.
- Calculate achievements, badges, leaderboard rankings, and other gamification features.
- Improve the Service through analytics and error monitoring.
- Communicate with you about updates, support, and promotional offers.
- Detect and prevent fraud, abuse, or security issues.
4. AI Features
CafeRadar includes AI-powered features that process your data using third-party AI services. We currently use Google Gemini and Anthropic Claude as AI subprocessors. The legal basis for this processing is the performance of our contract with you, meaning it is needed to provide the app features you are using (GDPR Art. 6(1)(b)):
- Barista AI Chat: Your messages, coffee preferences, and check-in history are sent to our AI provider to generate personalized responses. You must provide consent before your first interaction.
- Photo, Drink, and Menu Analysis: When you scan a drink barcode or coffee bag, upload a photo, or scan a menu, the image and any related text are sent to a third-party AI vision provider to read the image and return information such as an estimated description, tasting notes, or menu items. These are AI estimates and can be inaccurate.
- Recommendations: Your preferences and activity are used to generate café and drink recommendations and the short explanations shown alongside them.
- Photo Moderation: User-uploaded café photos are analyzed by AI to detect inappropriate content before publishing.
- Notifications and Content: Your preferences may be used to personalize some notification content, and some content such as blog articles is generated or assisted by AI.
- Personalized Reminders and Café Offers: We analyze your own activity to send you personalized reminders, and to deliver offers from cafés you have a relationship with, meaning cafés you follow, have saved, have checked in at, or have reviewed. This includes win-back offers a café funds, for example when you have not visited a favorite café in a while. These offers are delivered to your in-app inbox only. We do not send them to your lock screen. You only receive a café's offers while you are in that café's city, so they stay relevant to where you are. Cafés never learn your identity from this: they only ever see anonymous counts. You can mute an individual café, or turn all café reminders and offers off, at any time in your notification settings.
To the extent our agreements with these providers allow, your data is not used to train their foundation AI models, and it is processed only to provide these features to you. You can stop using AI features at any time. Deleting your account removes all AI-related data. Our AI transparency practices are described in full in our AI Transparency Policy.
5. Information Sharing
We do not sell your personal information. We may share information with:
- Other Users: Your public profile, check-ins, reviews, and achievements are visible to other CafeRadar users. Your activity feed is only visible to users who follow you.
- Shared Lists: You can create a list of cafés and invite other people to it. When you join a shared list, the cafés on that list that you check into are shown to the other members as visited, next to your name. Members do not see when you visited or how many times, and nothing about cafés that are not on the list is shared. Cafés count from the time they were added to the list. You can choose to join a list without your name shown. If you turn on “Private visits” in your settings, your name stops being shown in every list you are in, while your visits still count toward each list's progress. You can leave a list at any time, which stops your visits from being shown or counted there. We rely on our legitimate interest in providing a shared progress feature to the people who have joined a list together, and you can object at any time using the controls described here.
- Direct Messages: The users you exchange Coffee Connections messages with can see the messages you send them. Private messages are not shown to any other user, and are shared with staff only where a message is reported to us for review.
- Peer Notifications: Some features let one user send you a notification, and the same features let you send one. When you tag a person in a check-in, or invite a person to a feature of the app you use yourself, we tell that person the request came from you and we show them your display name. Nothing else about you is included: no numbers, no history, and nothing about how you use the feature. In the other direction, we tell the sender nothing at all about you. A sender is never told whether their notification reached you, whether you already use the feature, whether you accepted or ignored it, or whether you have turned that kind of notification off. Most of these features are limited to people you and the sender both follow. Shared list invitations can also reach you through a link that a member sends you directly. Blocking a user stops these in both directions.
- Merchant Partners (analytics): Aggregated, anonymized analytics about foot traffic, engagement, and loyalty for their listings. This includes count-only signals, such as how many of their regular customers have not visited recently. These analytics never include your name or individual visit history, and merchants agree in our Terms not to attempt to identify anyone behind an aggregate number.
- Merchant Partners (your direct interactions): Separately, when you interact with a cafe directly, that cafe can see the interaction and who made it. For example, a cafe can see your booking when you reserve a table, your membership when you join their punch card, your redemption when you use an offer, reward, or win-back code, and your status as a cafe's Regular (its most frequent visitor, shown with a crown) when your public check-ins earn it. These disclosures happen because you used the feature, and check-ins are public activity as described above.
- Service Providers: Third-party services that help us operate the app, including Clerk (authentication), Supabase (database), Sentry (error tracking), PostHog (analytics), OneSignal (notifications), RevenueCat (subscriptions on iOS), Google (Maps SDK and Firebase Cloud Messaging on Android, and Gemini for AI features as described in section 4), Anthropic (Claude for AI features as described in section 4), Mapbox (café discovery), and GeoJS (approximate city from IP address, only when precise location is unavailable).
- Legal Requirements: When required by law, court order, or to protect the rights, safety, or property of CafeRadar, our users, or the public.
5.1 Meetups (Coffee Get-Togethers)
Coffee Get-Togethers (“Meetups”) are in-person gatherings at cafés that you can host or join. This section explains the information involved when you take part. Meetups are an adults-only feature: people under 18 are excluded, and to support that we ask for your date of birth before you enter these features (see below).
- What other people see: when you join a Meetup, the other attendees and the host can see your display name and profile photo, and that you are attending. The host receives a notification when you join and can see the list of attendees. On the map, a Meetup shows the host's photo on its pin. After a Meetup ends, members can see the other members who attended and can choose to follow each other. Other users are never shown your precise location, your date of birth, your email, or your other account details.
- Meetup connections: when you attend a Meetup, we associate you with the other members who attended the same Meetup so we can show you the people you met and let you follow each other. This is based on your participation in the Meetup, and you can block any member to remove yourself from their list. We may send you a notification when a Meetup you joined ends. You can turn Meetup notifications off in your settings.
- Location, used only to gate joining: to join a live Meetup you need to be near the café, so we check your device location at the moment you join to confirm you are close enough. If you RSVP before a Meetup starts, no location is required to RSVP. We also use a coarse, approximate location on your profile (updated only when you open the app's home screen) to show you things nearby. We do not share your live location or your distance with other users, and Meetups do not use background location or track your movements.
- Retention and leaving: we keep your Meetup participation while your account is active and while it is useful to run the feature and to look into any safety report. You can leave a Meetup at any time, which removes you from the attendee list, and you can block any user. When you delete your account, your Meetup participation is removed as part of that deletion (see Section 6).
- Date of birth (sensitive): we ask for your date of birth to confirm you are 18 or older before you take part in Meetups. We treat your date of birth as sensitive information. It is used only for the age check, it is visible only to you and to the systems that run that check, and it is never shown to other users or included in your public profile. If you do not provide it, you cannot use Meetups, but the rest of the Service is unaffected. The lawful basis for this age check is our legal obligation and our legitimate interest in operating an adults-only in-person feature safely (GDPR Art. 6(1)(c) and Art. 6(1)(f)).
5.2 Referrals, Invitations and Campaigns
When you sign up through an invite link or code, we record that your account came from that link or code. Some of our links and QR codes are printed on a physical surface, such as a card at a café counter, the QR on a café loyalty card in your phone's wallet, or a code handed out at a community event. When you create an account after following one of these, we record which surface it was, once, so we can see which of them bring people to CafeRadar. We record the surface, not you: we store the café or event the code belongs to, never that you visited it, when, or how often, and we never share it with the café. The lawful basis is our legitimate interest in understanding how our service is found (Article 6(1)(f) GDPR). It is stored once when you join, it is never updated, and it is deleted with the rest of your data when you delete your account. We connect a referred member to the person who referred them so we can grant referral rewards and prevent abuse. This processing is based on our legitimate interest in running and protecting the referral program (Article 6(1)(f) GDPR) and, where rewards are involved, on performing our agreement with you (Article 6(1)(b) GDPR). If you take part in an event community campaign, we process your participation in that community and, when you redeem a free coffee, the participating café learns that a valid code was redeemed.
6. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. You can delete your account at any time from the app's Settings, which permanently removes your personal data, check-ins, reviews, and associated content. Direct message content is retained while your account is active and is permanently deleted when you delete your account, which removes your conversations and the messages within them.
6.1 Moderation and Safety Data
To keep the community safe and to enforce our Terms and Community Guidelines, we store records related to safety and moderation. These include reports you or other users submit (such as the reason and any details), the moderation actions we take (such as content removal, warnings, suspensions, and bans), and any appeal you submit and its outcome. We use this information to review reports, decide and apply the right action, prevent repeat abuse, and keep a record of our decisions. The lawful basis is our legitimate interest in maintaining a safe service and protecting our users (GDPR Art. 6(1)(f)), and, where applicable, compliance with a legal obligation (Art. 6(1)(c)), including our obligations as a hosting service to act on reported content. We keep these records for as long as needed to investigate, to enforce our Terms, and to defend or resolve any dispute, which may be longer than we keep your other data, and we may retain them after your account is deleted where we have a lawful reason to do so.
7. Your Rights
You have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correct: Update or correct inaccurate personal data.
- Delete: Delete your account and all associated data from within the app.
- Export: Request a full copy of your personal data at any time, free of charge, by contacting us or using the in-app data request. Premium additionally offers a convenient in-app export of your check-in history, but your right to a copy of your data never requires a subscription.
- Opt Out: Disable location tracking, push notifications, and analytics tracking at any time.
8. Data Security
We implement industry-standard security measures to protect your data, including encrypted data transmission (TLS/SSL), secure authentication via Clerk, Row Level Security (RLS) on our database, and secure storage for sensitive tokens. However, no method of electronic transmission or storage is 100% secure.
9. Children's Privacy
CafeRadar is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected data from a child under 13, please contact us immediately.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy in the app or via push notification. Your continued use of the Service after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us at:
© 2026 CafeRadar™. All rights reserved.