1. Who we are
This Privacy Policy describes how CafeSuite (“we”, “us”) processes personal data in connection with the CafeSuite web application and related sites.
Contact for privacy requests: privacy@cafesuite.net.
2. What this policy covers
It covers (a) personal data of staff who create or use CafeSuite accounts, and (b) personal data about venue customers and operations that organizations store in CafeSuite.
For venue-customer data, the organization (the venue) is typically the data controller. CafeSuite acts as a processor on the organization’s instructions. For staff SaaS accounts and our own website/admin operations, CafeSuite is the controller.
3. Data we process as controller
When you sign up or are invited as staff we process: name, email address, password (stored as a hash by our auth provider), role and permissions, locale and theme preferences, login times, and audit logs of actions you take in the product.
We use this data to create and secure your account, provide the Service, communicate about the account, and maintain security and logs.
4. Data we process as processor
Organizations may store Venue Data such as customer names, logins, contact details, photos, balances, session history, reservations, shop sales, and operator notes. We process this data only to provide the Service to that organization, in accordance with these Terms and the organization’s instructions.
If you are a venue customer (end guest) and have questions about your data, contact the venue that served you. We will assist that organization where required.
5. Legal bases (GDPR)
Where we are controller, we rely on: performance of a contract (providing the account and Service); legitimate interests (security, product improvement, preventing abuse); and legal obligation where applicable. Where required, we ask for consent (for example certain cookies or marketing, if we introduce them).
Organizations using CafeSuite must have their own lawful basis for the Venue Data they enter (for example contract with their guests or legitimate interests in running the venue).
6. Subprocessors
We use service providers to host and operate CafeSuite, including database, authentication, and file storage (currently Supabase) and application hosting. They process data on our instructions and must implement appropriate security.
If we add material subprocessors, we will update this policy.
7. Cookies and similar technologies
We use essential cookies and similar storage to keep you signed in, remember language and appearance, and operate till/shift features. These are required for the Service to work.
We do not currently use advertising cookies. If we add analytics cookies, we will update this policy and, where required, request consent.
8. Retention
Staff account data is kept while the account or organization is active and for a limited period afterwards (for backups, dispute handling, and legal requirements).
Venue Data is retained until the organization deletes it or the workspace is closed, then for a short backup window, unless a longer period is required by law.
9. Sharing
We do not sell personal data. We share data with subprocessors as described above, with staff inside your organization according to roles you configure, and if you enable outbound webhooks or API access — with the endpoints and integrations you choose.
We may disclose data if required by law or to protect the Service, our users, or others from harm.
10. International transfers
Your data may be processed in the European Economic Area or in other countries where our subprocessors operate. Where data leaves the EEA, we use appropriate safeguards such as Standard Contractual Clauses where required.
11. Your rights
If we are the controller of your data, you may request access, rectification, erasure, restriction, portability, and objection to processing, and you may withdraw consent where processing is based on consent. You may also lodge a complaint with a supervisory authority (in Poland: the President of the Personal Data Protection Office — UODO).
Use Settings → Profile to update your staff details, or email privacy@cafesuite.net. For Venue Data, contact the venue organization first.
12. Security
We use industry-standard measures including encrypted transport, access control, and hashed passwords. No method of transmission or storage is completely secure. You must use strong passwords and limit staff access appropriately.
13. Children
The Service is intended for venue operators and their adult staff, not for children. We do not knowingly create staff accounts for anyone under 16. Organizations are responsible for how they handle data about minors who visit their venues.
14. Changes
We may update this Privacy Policy. The effective date at the top will change. Material changes will be indicated in the product or by email where practicable.
15. Contact
Privacy requests: privacy@cafesuite.net. Legal notices: legal@cafesuite.net. Website: https://www.cafesuite.net.