Your customers' details, handled properly.

Before you hand us your regulars, you should know what we hold, where it sits, and who can see it. Here is all of it in plain English, including the parts we have not built yet.

Last reviewed 29 July 2026

We never see a card number.

Every payment runs through Stripe, on Stripe's own hosted payment page. Card details are typed into Stripe, not into us. They never reach our server and they are not in our database. All we keep is Stripe's reference to the customer, which is no use to anybody else.

Your money stays yours, too. Subscriptions pay out to your own Stripe account, and our fee comes out of the member's price rather than being billed to you.

No card numbers. No expiry dates. No CVV.

Because a certified provider handles the card end to end, we sit in the lightest payment-security category there is (PCI SAQ-A). There is simply no card data here to lose.

What we actually hold.

We hold

  • Member name, email and mobile
  • What they order, and when
  • Membership status and payment dates, from Stripe
  • A notification token, if they turned the ready buzz on

We do not hold

  • Card numbers, expiry dates or CVV
  • Bank account details
  • Home addresses
  • Dates of birth or any identity documents

Where it lives.

On our own server in Sydney. Not shared hosting, and not offshore. Traffic reaches it through Cloudflare over HTTPS, and the server refuses connections that have not come through Cloudflare, so it cannot be reached directly at its address.

Who can see it.

You see your cafe. Only your cafe. Every request is scoped to a single cafe, so one cafe on the platform cannot read another's members or orders. Your baristas see a first name and a coffee on the counter board, which is all they need to make it.

On our side, a small number of named people can reach the system to run and support it. There is no general staff login. We do not sell member details, and we do not share them with anyone for their own marketing. Our only suppliers are Stripe for payment and Postmark for email, and that is the whole list.

How members sign in.

There are no passwords, so there are no passwords to leak. A member signs in with a six-digit code sent to their email. That code:

Sign-in requests are rate limited, so nobody can sit there feeding guesses at it. The session itself is held in a cookie that page scripts cannot read and that only travels over HTTPS.

This area was reviewed and hardened on 29 July 2026.

Backups, and what happens if we disappear.

The live database is copied off the server every ten minutes, and an encrypted copy goes off-site to cloud storage every day at 4:30am. Backups are taken with the database's own backup command rather than a plain file copy, so every one of them is a consistent snapshot that will actually restore.

Your member list is yours. If you ever leave, ask and we will export it for you. We do not hold it hostage, and we do not treat your regulars as ours.

If something goes wrong.

Email [email protected] and it reaches a person, not a ticket queue. If member data were ever exposed, we would tell you and the affected members promptly, with what happened and what to do about it. We would rather have an awkward conversation early than a quiet one later.

What we do not have.

We would rather say this ourselves than have you find it out.

None of it changes the thing that matters most: what we hold is a name, an email, a mobile and a coffee order. The valuable stuff sits with Stripe, where it belongs.

Got a question we have not answered?

Ask it. We will give you a straight answer, including when the answer is no.

Email [email protected]