- Scope & Who We Are
- Information We Collect
- How We Use Information
- Sharing & Disclosure
- Legal Bases (EEA/UK/Similar)
- Data Retention
- Security
- Your Choices & Rights
- Cookies & Similar Technologies
- International Data Transfers
- Children’s Privacy
- Third‑Party Services
- Do Not Track
- Changes to This Policy
- Contact Us
1) Scope & Who We Are
This Privacy Policy applies to personal information processed by RECOLETOS CAFE through the App and related services such as ordering, loyalty, promotions, customer support, and feedback collection.
Controller/Operator: RECOLETOS CAFE (“we”, “us”, “our”)
- Legal entity name: RECOLETOS CAFE LLC (replace with your exact company name)
- Registered address: Av. Example 123, City, Country
- Contact email: privacy@recoletoscafe.com
- Data Protection Officer (if applicable): dpo@recoletoscafe.com
Note: Update the legal details above to reflect your real business information. If you are established in the EEA/UK or target users there, you may need a representative and/or DPO under applicable law.
2) Information We Collect
A. Information you provide to us
- Account & profile data: name, email, phone number, password (hashed), delivery addresses, preferences (e.g., favorite drinks, allergens).
- Orders & payments: items ordered, store/location, timestamps, subtotal/taxes/total, payment method token (processed by payment provider), loyalty points.
- Support & feedback: messages, ratings, survey responses, attachments you voluntarily provide.
B. Information collected automatically
- Device & usage: device model, OS version, app version, unique identifiers (e.g., advertising ID where permitted), IP address, language, time zone, diagnostic logs, crash data, performance metrics.
- Location: approximate location from IP or precise geolocation if you grant permission (used for store finder, delivery/collection estimates, location-based offers).
- Cookies/SDK data: identifiers and events from analytics and messaging SDKs (see Third‑Party Services).
C. Information from third parties
- Authentication providers: if you sign in with Google/Apple/Facebook, we receive basic profile info and an identifier per their terms.
- Payment processors: confirmation of payment status, masked card details, and fraud signals.
- Marketing & referrals: campaign attribution and referral info where applicable.
3) How We Use Information
- Provide, maintain, and improve the App and our services.
- Process orders, payments, refunds, and loyalty rewards.
- Personalize content, menus, and promotions; remember preferences.
- Send transactional messages (order confirmations, receipts, service notices) and—with your consent where required—marketing communications (offers, news).
- Enable features like store locator, delivery/collection estimates, and push notifications.
- Monitor performance, debug issues, detect/prevent fraud and abuse, and ensure security.
- Comply with legal obligations and enforce our terms.
5) Legal Bases (EEA/UK/Similar Jurisdictions)
Where GDPR/UK GDPR or similar laws apply, we rely on the following legal bases:
- Contract: to provide the services you request (e.g., processing your order).
- Consent: for items like marketing or precise location when required. You may withdraw consent at any time.
- Legitimate interests: to secure and improve the App, prevent fraud, and personalize experiences—balanced against your rights.
- Legal obligations: to meet accounting, tax, and regulatory requirements.
6) Data Retention
We keep personal information only as long as necessary for the purposes described above and as required by law. Typical periods include:
- Account data: retained while your account is active; deleted or anonymized within 30–90 days after deletion, unless we must keep it longer for legal reasons.
- Order & transaction records: retained for 5–10 years (subject to local tax/accounting laws).
- Analytics & logs: typically 13–36 months, then aggregated or deleted.
7) Security
We implement administrative, technical, and physical safeguards designed to protect personal information (e.g., encryption in transit, access controls, secure development practices). However, no method of transmission or storage is 100% secure.
8) Your Choices & Rights
A. App settings
- Notifications: control push notifications in your device settings.
- Location: enable/disable precise location in system settings.
- Marketing emails/SMS: use unsubscribe links or App toggles where available.
B. Privacy rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to processing, or request portability of your personal information. You may also have the right to lodge a complaint with your local data protection authority.
To exercise rights, contact us at privacy@recoletoscafe.com. We may verify your identity before responding.
C. California/US State Notices (if applicable)
For residents of California and certain US states, you may have additional rights regarding “personal information” as defined by applicable laws. We do not sell or share personal information for cross‑context behavioral advertising. We honor verifiable consumer requests as required by law.
10) International Data Transfers
If we transfer personal information across borders, we use appropriate safeguards (e.g., Standard Contractual Clauses, adequacy decisions) as required by applicable laws.
11) Children’s Privacy
The App is not directed to children under the age of 13 (or the age required by your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided personal information, please contact us to request deletion.
12) Third‑Party Services
The App may include third‑party SDKs or integrations. Examples include:
- Analytics & crash reporting (e.g., Firebase Analytics/Crashlytics or similar)
- Payments (e.g., card processors or mobile wallets)
- Messaging (e.g., push notification services, email/SMS vendors)
- Social login (e.g., Sign in with Apple/Google/Facebook)
Each provider processes data under its own terms and privacy policies. Where required, we establish appropriate data processing agreements.
13) Do Not Track
Some browsers offer a "Do Not Track" (DNT) setting. Because there is no common industry standard for DNT, we do not respond to DNT signals. We will update this policy if standards emerge.
14) Changes to This Policy
We may update this Privacy Policy from time to time. We will post the new version in the App and update the "Last updated" date at the top. For material changes, we may provide additional notice (e.g., in‑App message or email).
15) Contact Us
If you have questions or requests regarding this Privacy Policy or our practices, contact us at:
- Email: privacy@recoletoscafe.com
- Postal: RECOLETOS CAFE – Privacy, Av. Example 123, City, Country
If you are in the EEA/UK, you also have the right to lodge a complaint with your local supervisory authority. If you are in Morocco, you may contact the CNDP (Commission Nationale de Contrôle de la Protection des Données à Caractère Personnel).