Privacy Policy
Last updated: 24 July 2026
This Privacy Policy explains what personal data QuickBrew collects when you join the loyalty program, sign up for the member app, or use a QuickBrew kiosk, why we collect it, and the rights you have over it. It's written to meet the standard set by the EU General Data Protection Regulation (GDPR), which we apply as our baseline regardless of where you're located.
1. Who this applies to
QuickBrew operates coffee kiosks and a companion member app from Kigali, Rwanda. This policy covers anyone who joins the loyalty program at a kiosk, signs up for the member app, or has an admin create a wallet account on their behalf.
2. What we collect
- Phone number — your account identifier, used to log in and to send order/wallet notifications.
- Wallet PIN — stored only as a salted cryptographic hash; we never store or can retrieve your actual PIN.
- Display name — optional, shown on receipts and in the app.
- Wallet & loyalty data — balance, top-up and spend history, lifetime spend, membership tier.
- Order history — mix recipes, kiosk used, timestamps, amounts paid.
- Receipt delivery details — email address or WhatsApp number, only if you choose to receive a digital receipt.
- Consent record — the date and version of these Terms/Privacy Policy you accepted.
- Technical data — IP address and basic request metadata, kept briefly for fraud prevention and rate-limiting (e.g. against sign-up abuse).
We do not collect full payment-card numbers — card and mobile-money top-ups are handled directly by our payment processors, who pass us only a success/failure result and a reference ID.
3. Why we collect it, and our legal basis
- Providing the Service (contract) — operating your wallet, processing orders, applying loyalty discounts.
- Your consent — sending digital receipts by email/WhatsApp, and processing your signup itself.
- Legitimate interest — fraud prevention, rate-limiting, and keeping kiosks secure and working correctly.
- Legal obligation — retaining transaction records where required for tax/accounting purposes.
4. Who we share it with
We share the minimum data necessary with the following categories of processors, each acting under contract on our behalf:
- Payment processors (card and mobile-money gateways) — to authorize and settle wallet top-ups.
- WhatsApp Business API gateway — only if you opt in to receive receipts over WhatsApp.
- Email delivery provider — only if you opt in to receive receipts by email.
- Cloud hosting/infrastructure providers — to run our servers and database securely.
We do not sell your personal data, and we do not share it with third parties for their own marketing purposes.
5. How long we keep it
We keep account and transaction data for as long as your account is active, and for a limited period afterwards to satisfy accounting/tax obligations and resolve disputes. If you request deletion (see below), we anonymize or erase data that we're not legally required to retain.
6. Security
PINs are stored as salted hashes, never in plain text. Traffic to our apps and kiosks is encrypted in transit (HTTPS/TLS). Access to production data is restricted to the systems and personnel that need it to operate the Service.
7. Cookies & local storage
The member app stores your session token in your browser's local storage so you stay signed in between visits. We don't use third-party advertising or tracking cookies on the member app or this marketing site.
8. Your rights
Under GDPR-standard protections, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate data (e.g. your display name).
- Erasure — ask us to delete your account and associated personal data, subject to legal retention requirements.
- Restriction — ask us to limit how we use your data while a request is resolved.
- Portability — request your data in a portable, machine-readable format.
- Objection — object to processing based on legitimate interest.
- Withdraw consent — opt out of digital receipts, or withdraw consent at signup by closing your account, at any time.
To exercise any of these rights, email [email protected]. We'll respond within 30 days. If you're unsatisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.
9. Children's privacy
The Service is not directed at children under 16. We don't knowingly collect personal data from children under 16 without appropriate consent.
10. Changes to this policy
We'll update the "Last updated" date above whenever this policy changes, and where a change is material, we'll ask existing self-service members to re-confirm their consent the next time they sign in.
11. Contact
For any privacy question or request, email [email protected].