Privacy Policy for CoffeeGrab Limited
Effective date: 24 September 2026
CoffeeGrab Limited explains in this policy how we collect, use, disclose, protect and retain personal information under the New Zealand Privacy Act 2020. It covers our customer app, the café portal, the Terminal app and other Partner apps, our website, campaign and referral links, and support.
1. Who we are and who to contact
CoffeeGrab Limited, company number 8866914, NZBN 9429051554989, New Zealand.
Our privacy officer handles privacy enquiries, access and correction requests, and complaints at privacy@coffeegrab.co.nz. For other help contact support@coffeegrab.co.nz; cafés can contact partners@coffeegrab.co.nz; website enquiries go to hello@coffeegrab.co.nz and job applications to careers@coffeegrab.co.nz. Our registered office is listed on the New Zealand Companies Register.
2. Information we collect
Account and profile. Your name, email address and phone number where you provide them, your sign-in method (passkey, Apple ID, or a verified phone or email) and an optional profile photo. We do not store passwords. Optionally, your date of birth, for birthday offers. You choose what to give us, but we need a sign-in method to create an account and a payment method to take an order; leaving out optional details such as a photo, date of birth or location access only affects the features that use them.
Orders, payments and balances. What you order, from which café and when, payment method, transaction references, receipts, and CoffeePoints and Prepaid Balance movements. Our payment providers handle card entry; we never receive or store full card numbers. Order notes are shown to café staff. Avoid including unnecessary personal information in notes; allergy notes can contain health information.
Referrals. Your referral code and link are shared from your own device through its share sheet; we do not collect the contact details of the people you share them with. When someone applies your code, we link their account to yours. Each of you then sees the other's first name and profile photo or initial, and you see how many qualifying orders they have placed and the points each of you earned.
Reviews and feedback. Café reviews are public: other customers see your review, name and profile photo or initials; the café sees your first name, rating and comment. Feedback on an individual order is seen only by CoffeeGrab and you.
Communications and account protection. Notification settings and delivery tokens, support correspondence, and the records needed to verify and recover accounts, including verification codes, attempts and temporary locks.
App diagnostics and location. The apps record how they are used and how they perform: screens viewed, session and installation identifiers, device and operating-system details, device state, errors and logs. These records are linked to your account. Where you allow location access, the customer app records your location, including precise coordinates while the app is open, to show nearby cafés and to diagnose the service; your approximate location is also derived from your IP address. Where location-based order notifications are available and a café staff member turns them on and grants permission, the Partner apps record that device's location, including in the background, to tell whether the device is at the café. Only our systems use it, to route notifications; the café does not see it, the staff member can turn it off in the app at any time, and we do not use it to evaluate staff.
Café relationships. Operator and authorised-person details, entity, NZBN and GST details, café memberships, Platform Fee rate, bank nomination, payout records, equipment records and agreement-acceptance records. Menu scanning sends the photo and any text you provide to our AI provider (section 6); we do not keep the photo, and the extracted result is kept for 30 minutes until you accept or discard it.
Information we get from others. A café owner gives us the names and sign-in details of staff they add to the café; Stripe gives us payment results and fraud signals; Google Play gives us the install referrer on Android; our network provider gives us an approximate location from your IP address; Apple gives us your name and an email or relay address when you use Sign in with Apple; Apple and Google give us device integrity results; and when someone uses your referral code or link, we link their account to yours. Each is used for the purpose described in the section it relates to.
Server logs. Our servers keep operational and security logs, which can include information that identifies you.
3. Campaign and referral measurement
When you tap one of our campaign or referral links (coffeegrab.com and coffeegrab.co.nz are both our domains), we record the tap, the campaign it belongs to, your IP address and basic device details. We use this to measure which links lead to new customers and to verify referrals. We do not send your orders or activity to advertising platforms.
4. How we use information
We use information to create and secure accounts; provide ordering, payment, pickup and support; maintain balances and transaction history; run the loyalty programme and show you offers and rewards based on your order history; measure which campaigns and referrals bring new customers (section 3); administer café relationships, statements and payouts; maintain menus; investigate fraud and abuse; diagnose faults; and improve the service.
We send order updates, receipts, support replies and the notices required by the applicable terms, including CoffeePoints expiry reminders and notice of changed terms.
We use aggregated information that no longer identifies anyone for service analysis.
5. Marketing messages
We send marketing messages only with the consent the Unsolicited Electronic Messages Act 2007 requires. Every marketing message identifies us and has a working unsubscribe; requests take effect within five working days. Promotional push notifications have their own setting. Receipts, order updates, contractual notices and expiry reminders are service messages and are not affected by a marketing opt-out.
6. Who receives information
We never sell personal information or provide it to data brokers. We share information with:
- Cafés: your first name, profile photo if you have one, order contents, notes, pickup time and payment method for the order you place with them. Cafés may use it only to fulfil the order, deal with your requests about it and meet their legal obligations, and must not use it for marketing.
- Other customers: public café reviews with your name and profile image or initials, and, for a referral, the details described in section 2.
- Stripe, Apple Pay and Google Pay: what is needed to process payments, refunds and fraud checks.
- Google: push notifications, crash reports, maps, Play Store services and device integrity checks on Android, and website analytics (section 11).
- Apple: push notifications, maps, Sign in with Apple where you use it, and device integrity checks on iPhone.
- Microsoft: website session analytics through Clarity, which Microsoft also uses under its own privacy statement (section 11).
- Anthropic: menu images and text you submit for menu analysis.
- Infrastructure and communications providers: hosting, network, email, SMS and website providers acting on our behalf.
- Professional advisers and a business successor: where reasonably required, under confidentiality, and only if a successor assumes equivalent privacy protections.
- Authorities: where disclosure is required or permitted by law.
Providers acting on our behalf may use information only for the contracted purpose.
7. Information processed overseas
Our application servers and databases are hosted in Sydney, Australia. Our analytics and log store is hosted overseas by our infrastructure provider, and our other providers process information in the United States and other countries where they operate. We remain responsible for information our providers handle for us. Some recipients, including Stripe, Google, Apple and Microsoft, also use information for their own purposes under their own privacy terms.
8. Retention
We keep personal information for as long as it is needed for the purposes above and for the periods the law requires.
Account, profile, reviews and feedback
For the life of your account. When you close it we remove your sign-in, delete your profile photo, clear your profile details and unpublish your reviews. Earlier versions of your profile remain in our transaction records for as long as those records are kept.
Orders, payments, payouts, CoffeePoints and Prepaid Balance records
At least seven years after the end of the tax year of the transaction, as tax record-keeping law requires.
Terms and agreement acceptance records
For the life of the account or café relationship and seven years after.
App diagnostics, customer location records, campaign taps and server logs
Seven years from collection. We use campaign taps to measure our marketing and verify referrals, and all of these records to investigate fraud, deal with legal claims and keep the service secure.
Partner-app device location
Seven years from collection, for security and legal requirements only.
Verification codes and temporary locks
Minutes to a day.
Menu images sent for scanning
The image is not kept; the extracted result is kept for 30 minutes.
Support correspondence, website enquiries and job applications
As long as needed to deal with the matter.
9. Your rights
You may ask for access to your personal information and ask us to correct it. Access requests are free. Send them to privacy@coffeegrab.co.nz; we may ask you to verify your identity. We respond as soon as practicable and within 20 working days, or explain any permitted extension. If we decline a correction, you may ask us to attach a statement of the correction sought.
You may ask support to remove a café review, and you may delete your account in the app or through support. Deleting your account removes your sign-in, clears your profile details, removes your saved cards and ends your ability to use the service; any CoffeePoints and Prepaid Balance left when you confirm lapse, as the Customer Terms explain. It does not delete the financial and legal records listed in section 8, and diagnostics, location records and server logs are kept for the periods in section 8 after your account is closed. Support can supply your order and wallet history on request, before or after you close your account. Deleting the app alone does not delete your account.
Café owners: deleting your own account closes the café portal access tied to that sign-in. Contact us first to transfer ownership or to close the café and settle the final account.
You may opt out of marketing under section 5. If you are not satisfied with our response, you can complain to the Office of the Privacy Commissioner at privacy.org.nz.
10. Security
Information is encrypted in transit. We limit staff access to what their work requires and require appropriate protections from providers acting for us. If a privacy breach has caused, or is likely to cause, serious harm, we notify the Privacy Commissioner and affected people as the Act requires.
11. Website
Our website at coffeegrab.co.nz uses Google Analytics and Microsoft Clarity to understand how it is used: page views and interactions, approximate location, browser and device details, cookies that distinguish visits, and session recordings in which form inputs are masked. Data is kept for the retention periods set in those services. We are not running personalised advertising; if we begin, we will update this policy first.
Information you submit through a website form is used for the purpose stated with the form and is emailed to us at hello@coffeegrab.co.nz; job applications go to careers@coffeegrab.co.nz.
12. Children
Customer accounts are for people aged 13 or over, and a parent or guardian agrees to the Customer Terms for anyone under 18. If we discover an account belongs to someone under 13 we may close it under the Customer Terms, clear the profile as section 8 describes and keep only the records section 8 says we retain.
13. Changes to this policy
We give notice in the app before material changes take effect. The current policy and effective date are available in the app and on our website, and we keep dated previous versions.