Privacy Policy
Last updated: October 2026
1. Information we collect
We collect different types of information depending on how you use DailyBrew:
- Account data: email address, name, and password (or OAuth provider ID for Google/Apple sign-in).
- Workspace data: restaurant name, employee records (first name, last name, phone number, date of birth, join date), shift schedules, and closure periods.
- Attendance data: check-in and check-out timestamps, IP address at the time of check-in/out, and late/early-departure flags computed from shift schedules.
- Device data: when device verification is enabled (Espresso plan), we store a browser-generated device identifier and parsed device name for each check-in and check-out to prevent fraud.
- Location data: when geofencing is enabled (Espresso plan), your device sends its coordinates at check-in time. We use this only to verify you are within the configured radius and do not store your location history.
- Card check-in and the kiosk app: a shop can issue staff a DailyBrew card and run the DailyBrew Kiosk app on an Android device at the door. A card holds a signed card number, the workspace it belongs to and its validity dates, not the holder's name. When a card is tapped on the kiosk (by NFC) or its QR code is shown to the kiosk's camera, we record the card number, the kiosk's name, the time of the tap and the kiosk's network address, and file the check-in or check-out against the employee the card was issued to. The camera is used only to read the kiosk's setup code and staff QR codes: images are processed on the device and are never stored or sent to us. The kiosk app does not use the microphone or location.
- Leave requests: dates, times (for partial-day leave), reason, and type (paid/unpaid).
- Push notification tokens: if you opt in to push notifications, we store your Expo push token and platform (iOS, Android, or web).
2. How we use your information
We use your data to:
- Provide the DailyBrew service: tracking attendance, managing shifts, processing leave requests, and enforcing workspace settings (IP restriction, device verification, geofencing).
- Send notifications about leave request updates, shift changes, closures, and daily attendance summaries (via push notifications and email, Espresso plan and above).
- Detect and prevent fraudulent check-ins through device verification and IP validation.
- Improve and maintain the service, including troubleshooting and security monitoring.
We do not sell, rent, or share your personal data with third parties for marketing purposes.
3. Subscription and payment processing
DailyBrew offers a free plan and paid subscription plans (Espresso and Double Espresso), billed monthly or annually. All payments are processed by Paddle (paddle.com), our merchant of record. We do not store credit card numbers or payment credentials. Paddle handles all payment data under their own privacy policy.
4. Authentication
We support email/password, Google OAuth, and Apple sign-in. When using OAuth providers, we receive only your email address and provider-specific identifier. We do not access your contacts, calendar, or any other data from these providers.
5. Notifications
On paid plans, DailyBrew sends push notifications via the Expo push service and emails via Mailgun. You can unregister your device token at any time to stop receiving push notifications. Email notifications are sent to the address associated with your account.
6. Data sharing
We share data only with the following service providers, solely to operate DailyBrew:
- Paddle — payment processing and subscription management.
- Expo — delivery of push notifications.
- Mailgun — delivery of transactional emails.
- Google / Apple — OAuth authentication only.
7. Data retention
Your data is retained as long as your account is active. Employee records are soft-deleted and can be restored by the workspace owner. You may request permanent deletion of your account and all associated data by contacting us. Upon deletion, all personal data, attendance records, and workspace data are permanently removed.
8. Cookies and local storage
We use JWT tokens for authentication and store workspace preferences in browser local storage for faster access. When device verification is enabled, a unique device identifier is stored in local storage. We do not use tracking cookies or third-party analytics. The kiosk app keeps its setup key in the device's secure storage and keeps taps that have not been sent yet in a local database until they reach us; it is excluded from device backups.
9. Your rights
You have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your account and data.
- Unlink your user account from any employee record at any time.
- Unregister your device from push notifications.
10. Contact
For privacy-related inquiries, email us at support@mail.dailybrew.work.