Privacy Notice
This explains what Usual collects when you use a digital stamp card for the café you joined, how we collect it, why, who sees it, and what you can do about it. Usual runs the card on behalf of the café. You can contact us about privacy at any time at tapback.syd@gmail.com.
- We collect only what the card needs: your Google email and ID, your first name, your age and your stamps.
- We never sell your information, use it for ads, or track you across other apps and sites.
- You can delete your card and sign-in at any time with Delete my data.
- Your information is stored with Google Firebase and Cloudflare, which may be outside Australia.
What we collect
| From Google sign-in | Your email address and your Google account ID. As part of standard Google sign-in, Google also shares your Google name and profile photo, which are stored with your sign-in record. We use the first name you give us on your card instead. We don’t get your Google password, contacts, emails, files or anything else in your Google account. |
|---|---|
| What you tell us | Your first name and your age. |
| What the card records | Each stamp and the date and time you got it, rewards and coupons you earn or use, and when you last opened your card. |
| When you tap the stamp | A one-time code from the NFC tag, used once to add your stamp and then thrown away. |
| Technical information | When you open your card, your IP address and browser type (user agent) are processed by Google Firebase and Cloudflare to sign you in, load the page and protect it from attacks. These are kept in their security logs for a short time (Firebase keeps sign-in IP addresses for a few weeks). |
| On your phone | Your browser keeps a copy of your card and a few settings (like sound on or off) so the page loads fast. You can clear this in your browser settings. |
How we collect it: directly from you when you sign up, from Google when you sign in, and from the stamp tag when you tap it at the café.
We don’t collect your precise location, contacts, photos, payment details or what you buy. We don’t use advertising or tracking cookies, and we don’t use analytics or advertising tools that follow you across other apps or websites.
Why we collect it
- To sign you in, keep your stamp card and rewards, and show them on any phone you sign in on.
- To stop the same tap being counted twice and to prevent misuse of the stamps.
- To show the café’s offers and treats, including ones that are only for people 18 and over.
- So the café can greet you by name and see how its loyalty program is going.
- To answer you if you contact us, and to meet our legal obligations.
We only use your information for these purposes. If we ever want to use it for something new, we’ll ask you first, unless the law allows or requires it. We don’t use computer programs to make decisions that significantly affect you.
Google sign-in and Firebase
We use Google sign-in only to confirm who you are and to keep your card linked to you. Your Google information is never sold, used for advertising, or shared with anyone except as described in this notice, and our use of it follows the Google API Services User Data Policy, including its Limited Use requirements.
Usual is built on Google Firebase:
- Firebase Authentication handles Google sign-in. It stores your email, Google account ID, Google name and profile photo, when your account was made and when you last signed in, and it processes your IP address and browser type to keep sign-in secure.
- Cloud Firestore (Firebase’s database) stores your card: your first name, age, stamps, rewards, coupons and when you last opened your card.
Google processes this information for us under its Firebase Data Processing and Security Terms, only to provide the service, and not for its own advertising. Firebase services are independently audited against security standards including ISO 27001, ISO 27017, ISO 27018 and SOC 2. You can read more at Privacy and Security in Firebase.
Who can see it
- The café you joined and its staff, to run its loyalty program. Other cafés that use Usual can’t see your card.
- Our service providers, only to run the service: Google Firebase (sign-in and database, see above) and Cloudflare (hosting the page, the tag links and protection from attacks). They can only use your information to provide their service to us.
- Anyone the law requires us to give it to.
Everyone we share your information with must protect it to the same standard as this notice. We don’t sell your information, we don’t use it for advertising, and we don’t share it with data brokers or AI services.
Where it’s stored
On Google Firebase and Cloudflare servers. Firebase sign-in is a global service that can process data in any Google data centre, and Cloudflare delivers pages from servers around the world, so your information may be stored or processed outside Australia (for example in the United States and other countries where those providers operate). Before using these providers, we check that they protect personal information to a standard that meets Australian privacy law.
How we keep it safe
- Your information is sent over an encrypted (HTTPS) connection and stored encrypted by Google Firebase.
- Only you, the café you joined and the people who run Usual can access your card, and access is protected by sign-in.
- Each stamp code works only once, so a copied link can’t be reused.
No system is perfectly secure. If a data breach is likely to cause you serious harm, we’ll tell you and the Office of the Australian Information Commissioner (OAIC) as soon as we can.
How long we keep it
- We keep your card while you use it.
- If you don’t open your card for 2 years, we delete it.
- If the café closes its Usual account, we delete its customers’ cards within 30 days.
- When you use Delete my data, your card and sign-in are removed from our live systems straight away. Google then removes any copies from its backup systems within 180 days.
- Security logs kept by Firebase and Cloudflare (like IP addresses) are deleted automatically after a short time.
Your choices
- Delete: use Delete my data (at the bottom of your card) to remove your card and sign-in from Usual straight away (backup copies are cleared within 180 days). This also withdraws your agreement to this notice.
- Disconnect Google: you can also remove Usual’s access in your Google account at myaccount.google.com/connections.
- See or fix: email tapback.syd@gmail.com to ask for a copy of what we hold about you or to correct it. It’s free. We may need to check it’s you first, and we’ll reply within 30 days.
- Use a nickname: you don’t have to give your real first name. A nickname works fine.
- No marketing emails: we don’t use your email to send you marketing. If that ever changes, we’ll ask first and every message will have an unsubscribe link.
- Don’t want to join? You don’t have to. Without a card we can’t keep your stamps or rewards, but you can still buy from the café as normal.
Age
You need to be 16 or older to make a card. We ask your age to make sure of this and to only show 18+ offers to adults. If we learn that someone under 16 has made a card, we’ll delete it.
Questions or complaints
Email tapback.syd@gmail.com. We’ll reply within 30 days. If you’re not happy with our answer, you can contact the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
Changes to this notice
If we change this notice, we’ll update the date at the top. If a change affects how we use your information in a significant way, we’ll show you the new notice in the app and ask you to agree again before it applies to you.