Last updated: May 27, 2026
Beans on Me ("we", "us", "the app") helps people share unclaimed coffee shop misorders with people nearby. This Privacy Policy explains what information we collect, how we use it, and the choices you have.
1. Information we collect
Account information
- Name and email from your Google or Apple account when you sign in (Apple may provide a private relay address)
- A unique user ID generated by our authentication provider
Content you submit
- The address, coffee shop name, item description, and optional note you enter when posting a misorder
- An optional photo (receipt or order screen) you choose to attach
- Which misorders you have claimed
Location
- Your approximate location, used only to (a) sort the feed by what's nearest, (b) auto-fill an address if you tap "Use My Location" when posting
- Your device location is read when the feed loads, to sort misorders by how close they are. It is used on your device and is not sent to our servers. Separately, when you POST a misorder, the coordinates of the coffee shop address you chose are saved with that post so others can see how far away it is — if you typed or picked the address, those are the shop's coordinates; if you tapped “Use My Location”, they are your device's GPS reading at that moment. Either way they are attached to that post, visible to signed-in users, and deleted when the post is deleted. We never record your location in the background or build a history of where you go.
Automatically collected
- Standard mobile device information (operating system version, app version) used for crash reporting and compatibility
- We do not use third-party advertising trackers, analytics SDKs, or behavioral profiling
- Sponsored slots are sold and served by us directly. We count how often a sponsor's card is shown or tapped, in aggregate, on our own servers — this is not linked to your identity and is never shared with the sponsor or anyone else
- Photos are checked automatically for inappropriate content before a misorder is published. A rejected photo is deleted and never stored
2. How we use your information
- To let you sign in and identify your posts and claims
- To display your first name on misorders you post (so claimers know who to look for)
- To deliver the nearby-feed and map features
- To enforce our Terms of Service and prevent abuse
3. Who we share it with
We use the following third-party services to run the app. Each receives only the data needed to do its job:
- Supabase, OpenAI (content moderation), Groq (admin analytics), Vercel (hosting) — stores your account, posts, and claims. Hosted on AWS infrastructure (US-East). Supabase privacy policy
- Google and Apple — provide account sign-in. We receive the name and email information you authorize; neither provider receives your activity inside the app.
- OpenStreetMap Nominatim — receives the address text you type in the Post form (no name or location attached) to provide autocomplete suggestions. OSM usage policy
- Apple / Google Maps — when you tap "Directions," your device opens its system maps app with the destination address. We don't share anything beyond what the OS sends.
We do not sell or rent your personal information to anyone.
4. Data retention
- Misorders stay in our database after they're claimed, so both people keep an accurate record of the exchange. A poster can remove their own misorder within 5 minutes of posting
- Deleting your account permanently erases every misorder you posted or claimed, along with any photos you uploaded
- Account data (name, email, ID) is retained as long as your account exists
- Photos attached to misorders are deleted along with the misorder
- When you delete your account, all of the above is permanently erased within 30 days
5. Your rights
You can at any time:
- Access your profile data on the Profile screen
- Correct your displayed name through your connected sign-in provider
- Delete your account and all related data from the Profile screen → "Delete Account"
- Email us at privacy@beansonme.com with any request
If you are in the EU/UK, you have additional rights under GDPR including data portability and the right to lodge a complaint with your local supervisory authority. If you are in California, you have rights under the CCPA including the right to know and the right to delete.
6. Security
- All communication between the app and our servers uses HTTPS/TLS
- Your password is never stored — authentication is delegated to Google or Apple
- Database access is restricted via row-level security policies — a signed-in user can read misorders in the feed, but can only edit or delete their own posts, and can only claim a misorder nobody has taken. If you block someone, neither of you can see the other's posts
- No financial or payment information is collected
7. Children's privacy
Beans on Me is not directed at children under 13 and we do not knowingly collect data from anyone under 13. If you believe we have, contact us and we will delete it promptly.
8. Changes to this policy
If we make material changes, we will update the "Last updated" date and, for significant changes, notify active users via an in-app message before the change takes effect.
9. Contact
Questions? Email privacy@beansonme.com.