Privacy policy

Last updated:

Enable Coffee only collects the information it needs to run the service. We don't sell your data, run ads, or track you across other apps.

Who we are

Enable Coffee ("the app", "we", "us") is operated by Ironstone Software in Australia. The operator is Brian Dance, trading as Ironstone Software.

We aim to respond to privacy enquiries within 5 business days.

What we collect

WhatWhenWhy
Email addressWhen you sign upTo create your account and contact you about your orders
Display nameWhen you sign upSo your runner or clients see who they're dealing with
Phone number (optional)If you choose to add it in SettingsHelps a runner reach you about an order
Role (runner or client)When you sign upThe app behaves differently for the two roles
Business details (runners only)When you set up your businessSo clients can identify your service when pairing
Order detailsWhen you place or accept an orderOrders are the core of the service
Receipt photos (runners only)When you complete an orderSo clients can see what was bought; underlying record for the tab
Tab + reconciliation entriesFrom your orders + recorded paymentsWe track who owes whom; we don't process the payment itself
Push notification tokenWhen you grant permissionSo we can deliver order updates to your device
Authentication metadataEvery sign-inAccount security (timestamps, IP at login, device type)

What we don't collect

How we use your information

  1. To run the app — show your orders, deliver push notifications, calculate your tab balance, surface receipts to the client whose order they relate to
  2. To support you — investigate bugs, respond to email enquiries
  3. To meet legal obligations — when we're legally required to disclose (for example, in response to a valid Australian court order)

We do not use your information for advertising, profiling, or behavioural analytics.

Who we share your information with

We use a small set of third-party services to operate the app. None of them are sold your data — they are processors acting on our instructions.

ProviderWhat they receiveWhere
Supabase (database, authentication, file storage)Everything in the table above, stored at restSydney, Australia (ap-southeast-2)
OneSignalPush token + a non-personal user ID — nothing elseUnited States
RenderTransient HTTP traffic only (no at-rest storage)Singapore
Apple Push Notification Service (APNs)Push token (iOS only)Apple infrastructure
Firebase Cloud Messaging (FCM)Push token (Android only)Google infrastructure
ResendYour email address + transactional message body (e.g. password reset)United States
CloudflareEmail metadata (envelope sender, recipient alias) when you write to usCloudflare's edge network

We do not share your information with advertisers, data brokers, or analytics platforms.

How long we keep your information

DataRetention
Account profile (email, name, phone)While your account is active. Anonymised within 30 days of account deletion.
Your ordersWhile your account is active. After deletion, anonymised but retained for the linked counterparty's records.
Tab + reconciliation entriesSame — anonymised but retained for the counterparty.
Receipt photosDeleted within 30 days of account deletion.
Push tokensRemoved within 24 hours of sign-out, uninstall, or revoking notification permission.
Authentication logs90 days, then automatically purged.

If a deletion would leave the linked counterparty with an incomplete record (e.g. half a tab), we anonymise rather than delete the order rows — the counterparty sees their record intact, but with no personal information about you.

How we keep your information secure

We are a small team and don't yet have an external security audit. If that changes, we'll update this policy.

Your rights

Whichever country you're in, you have rights over your data. We aim to honour them all without making you invoke a specific framework.

Children

Enable Coffee is not intended for users under 18. We do not knowingly collect data from children. If you believe a child has used the service and given us their information, please email [email protected] and we'll delete the account.

International transfers

Your data is stored in Australia (Supabase's Sydney region). Some processors operate from elsewhere — Render hosts our API in Singapore; OneSignal, APNs and FCM are based in the United States. Where data crosses borders, the receiving processor handles it under contractual arrangements that meet Australian Privacy Principle 8 ("cross-border disclosure of personal information").

If you're in the European Economic Area or the UK, transfers outside the EEA are made under the relevant Standard Contractual Clauses. If you're in California, see the CCPA section below.

Australian Privacy Principles

We comply with the Australian Privacy Principles under the Privacy Act 1988 (Cth). We treat the obligations seriously even though, as a small business, we may technically fall outside the Act's threshold. The contact for APP-related queries is [email protected].

GDPR / UK GDPR (if you're in the EEA or UK)

CCPA (if you're in California)

Changes to this policy

If we make material changes (for example, start using a new third-party processor, change retention periods, or expand what we collect), we'll:

  1. Update the "Last updated" date at the top of this page
  2. Show a banner in the app on next launch asking you to acknowledge the change
  3. Email you if the change is significant

Contact

What you wantWhere to reach us
Privacy questions[email protected]
General support[email protected]
Bug reports[email protected]
Postal mailIronstone Software, 24 Heron Place, Hazelbrook NSW 2779, Australia