Privacy Policy
Last updated: 26 July 2026
This policy explains how Baffee (“we”, “us”) collects and uses personal data when you use our website, business console, and tap experiences. We are the data controller for the information described here. For the purposes of UK GDPR, our contact details are in the Contact section below.
Who we collect data about
Baffee involves two kinds of people, and we treat their data differently:
- Businesses — the owners and staff who register and run a Baffee account.
- Customers— people who tap or scan a business’s Baffee TapPoint to leave feedback, collect loyalty stamps, or claim a card.
What we collect
From businesses
- Account email address and authentication data (via our auth provider).
- Business details you enter — name, locations, Google review link, branding.
- Billing information, processed by our payment provider (we do not store card numbers).
From customers
- An anonymous device identifier stored in your browser, used to keep your loyalty card and feedback session working. This is not linked to your identity unless you choose to claim your card.
- Feedback you submit (a rating, and any comment or contact detail you optionally provide).
- If you claim a card: your email address, used to verify you and to let your cards follow you across devices and businesses.
- Tap events (which TapPoint, and when) used for the business’s analytics.
Why we use it, and our legal basis
- To provide the service (create accounts, record feedback and stamps, show analytics) — performance of a contract, or our legitimate interest in operating the platform.
- To take payment for business subscriptions — performance of a contract.
- To verify a claimed customer card — your consent, and our legitimate interest in preventing fraud.
- To keep the service secure and improve it — our legitimate interests.
Who we share it with
We use trusted processors to run Baffee. They only process data on our instructions:
- Supabase — database, authentication, and storage.
- Vercel — application hosting.
- Stripe — business subscription payments.
- Resend — sending transactional emails.
When a customer chooses to leave a public review, they are taken to a third-party site (such as Google) governed by that site’s own privacy policy. We never sell your personal data.
International transfers
Some of our processors may store or process data outside the UK. Where that happens, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or equivalent adequacy decisions.
How long we keep it
We keep business account data for as long as the account is active, and for a reasonable period afterwards to meet legal and accounting obligations. Customer feedback and loyalty data are retained for as long as the relevant business account exists, unless you ask us to delete it sooner.
Your rights
Under UK GDPR you have the right to:
- access the personal data we hold about you;
- ask us to correct or delete it;
- object to or restrict certain processing;
- withdraw consent where we rely on it;
- data portability; and
- complain to the Information Commissioner’s Office (ico.org.uk).
To exercise any of these, contact us using the details on our Contact page.
Cookies and local storage
We use essential cookies and browser local storage to keep you signed in and to remember your loyalty card on a device. We do not use advertising cookies.
Changes
We may update this policy from time to time. Material changes will be reflected in the “last updated” date above.