Privacy Notice

Usual · Last updated 3 October 2026

This explains what Usual collects when you use a digital stamp card for the café you joined, how we collect it, why, who sees it, and what you can do about it. Usual runs the card on behalf of the café. You can contact us about privacy at any time at tapback.syd@gmail.com.

At a glance
  • We collect only what the card needs: your Google email and ID, your first name, your age and your stamps.
  • We never sell your information, use it for ads, or track you across other apps and sites.
  • You can delete your card and sign-in at any time with Delete my data.
  • Your information is stored with Google Firebase and Cloudflare, which may be outside Australia.

What we collect

From Google sign-inYour email address and your Google account ID. As part of standard Google sign-in, Google also shares your Google name and profile photo, which are stored with your sign-in record. We use the first name you give us on your card instead. We don’t get your Google password, contacts, emails, files or anything else in your Google account.
What you tell usYour first name and your age.
What the card recordsEach stamp and the date and time you got it, rewards and coupons you earn or use, and when you last opened your card.
When you tap the stampA one-time code from the NFC tag, used once to add your stamp and then thrown away.
Technical informationWhen you open your card, your IP address and browser type (user agent) are processed by Google Firebase and Cloudflare to sign you in, load the page and protect it from attacks. These are kept in their security logs for a short time (Firebase keeps sign-in IP addresses for a few weeks).
On your phoneYour browser keeps a copy of your card and a few settings (like sound on or off) so the page loads fast. You can clear this in your browser settings.

How we collect it: directly from you when you sign up, from Google when you sign in, and from the stamp tag when you tap it at the café.

We don’t collect your precise location, contacts, photos, payment details or what you buy. We don’t use advertising or tracking cookies, and we don’t use analytics or advertising tools that follow you across other apps or websites.

Why we collect it

We only use your information for these purposes. If we ever want to use it for something new, we’ll ask you first, unless the law allows or requires it. We don’t use computer programs to make decisions that significantly affect you.

Google sign-in and Firebase

We use Google sign-in only to confirm who you are and to keep your card linked to you. Your Google information is never sold, used for advertising, or shared with anyone except as described in this notice, and our use of it follows the Google API Services User Data Policy, including its Limited Use requirements.

Usual is built on Google Firebase:

Google processes this information for us under its Firebase Data Processing and Security Terms, only to provide the service, and not for its own advertising. Firebase services are independently audited against security standards including ISO 27001, ISO 27017, ISO 27018 and SOC 2. You can read more at Privacy and Security in Firebase.

Who can see it

Everyone we share your information with must protect it to the same standard as this notice. We don’t sell your information, we don’t use it for advertising, and we don’t share it with data brokers or AI services.

Where it’s stored

On Google Firebase and Cloudflare servers. Firebase sign-in is a global service that can process data in any Google data centre, and Cloudflare delivers pages from servers around the world, so your information may be stored or processed outside Australia (for example in the United States and other countries where those providers operate). Before using these providers, we check that they protect personal information to a standard that meets Australian privacy law.

How we keep it safe

No system is perfectly secure. If a data breach is likely to cause you serious harm, we’ll tell you and the Office of the Australian Information Commissioner (OAIC) as soon as we can.

How long we keep it

Your choices

Age

You need to be 16 or older to make a card. We ask your age to make sure of this and to only show 18+ offers to adults. If we learn that someone under 16 has made a card, we’ll delete it.

Questions or complaints

Email tapback.syd@gmail.com. We’ll reply within 30 days. If you’re not happy with our answer, you can contact the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.

Changes to this notice

If we change this notice, we’ll update the date at the top. If a change affects how we use your information in a significant way, we’ll show you the new notice in the app and ask you to agree again before it applies to you.