Daily Roast

Privacy

Privacy.

Daily Roast is a public coffee discovery directory. This page explains what personal data may be processed when you browse the site, create an account, save coffees, sign up for email updates, click an outbound roaster link, or appear in the directory as a public roaster contact.

This draft is prepared for founder and legal review. Fields marked for review must be completed before this page is treated as final legal copy.

Who is responsible

Daily Roast is operated by [FOUNDER/LEGAL: legal operator name].

Controller
[FOUNDER/LEGAL: controller/operator name]
Legal form
[FOUNDER/LEGAL: legal form, if applicable]
Address
[FOUNDER/LEGAL: registered or business address]
Email for privacy requests
[FOUNDER/LEGAL: privacy contact email]
Country of establishment
[FOUNDER/LEGAL: country]

What this policy covers

This policy covers personal data processed through the Daily Roast public website and related server endpoints.

Daily Roast does not sell coffee, process payments, provide checkout, or collect public reviews at launch. You may create an optional account to sign in, save coffees, set taste preferences, and receive recommendations. When you choose to buy coffee, you leave Daily Roast and visit the roaster’s own website.

Data we process from website visitors

When you browse Daily Roast, our hosting and security systems may process technical request data such as IP address, user-agent, request URL, referrer, timestamp, and basic error or security logs.

Purpose: operate the website, protect the service, debug errors, prevent abuse, and keep the public directory available.

Likely legal basis: legitimate interests in operating and securing the website, unless a specific processing activity requires consent or another legal basis.

[FOUNDER/LEGAL: confirm hosting provider, server-log retention period, and whether raw IP addresses are retained by any provider.]

Newsletter signups

If you sign up for Daily Roast email updates, we process the email address you submit and the consent information needed to manage that signup.

Data may include: email address, locale, consent source, consent text version, consent timestamp, hashed IP address, hashed user-agent, and retention metadata.

Purpose: send the updates you requested, keep a record of consent, prevent abuse, and manage unsubscribe or deletion requests.

Likely legal basis: consent for email updates. Legitimate interests or legal obligation may apply to limited consent and abuse-prevention records.

You can withdraw newsletter consent at any time by using the unsubscribe link in an email or by contacting [FOUNDER/LEGAL: contact email].

Planned retention: newsletter signup records are currently designed to expire after approximately 2 years unless you unsubscribe or request deletion earlier, subject to any legal recordkeeping need. [FOUNDER/LEGAL: confirm final retention.]

Accounts, preferences, and recommendations

If you create an optional Daily Roast account, we process account data needed to let you sign in, keep your saved coffees, store taste preferences, and maintain your account controls.

Data may include: email address, account identifier, authentication session data, saved coffee identifiers, taste preference choices, hidden coffee identifiers, recommendation feedback, recommendation event records, event source labels, recommendation reason codes, recommendation rank or score context, account export timestamps, deletion-request status, and basic security or abuse-prevention records.

Purpose: provide account access, store your saved coffees, improve signed-in recommendations from your saved coffees, preferences, feedback, and recommendation interactions, protect the account system, prevent abuse, and respond to account or privacy requests.

Recommendation events are first-party account events such as clicks, saves, “not for me” feedback, preference updates, or recommendation-sourced shop clicks. Daily Roast does not use these account events for third-party advertising, session replay, or paid ranking.

Likely legal basis: performance of the account service you request and legitimate interests in operating and securing the service, subject to founder/legal review.

You can sign out at any time. From account settings, signed-in users can export account data as JSON and submit a deletion request for founder/manual processing. You can also request access, correction, or deletion by contacting [FOUNDER/LEGAL: privacy contact email].

Planned retention: account, saved-coffee, preference, recommendation-feedback, recommendation-event, and deletion-request records are kept while the account remains active unless you request deletion earlier, subject to any legal recordkeeping need. [FOUNDER/LEGAL: confirm account deletion workflow and retention.]

Public roaster directory data

Daily Roast indexes public business information about coffee roasters and public catalog information that roasters make available online.

Directory data may include: roaster name, website, public shop URL, public location information, public product and catalog data, public source URLs, last-observed timestamps, and other public business facts used for discovery.

Some roasters are companies. Some may be sole traders or small businesses where business information can identify a natural person. Where directory data is personal data, Daily Roast processes it only for the public directory purposes described here.

Purpose: operate an independent public directory of European specialty coffee roasters and coffee catalogs.

Likely legal basis: legitimate interests in creating and maintaining a public directory based on public business information, balanced against the rights and interests of affected people.

Sources: public roaster websites, public shop pages, public profile pages, public business pages, and reviewed public export data from Daily Roast’s internal review workflow.

Daily Roast does not publish internal scraper logs, raw payloads, prompts, quality-control logs, private evidence tables, or review queues.

Corrections, removal, and profile issues

If you operate a roaster profile listed on Daily Roast and want to correct, update, or remove information, contact [FOUNDER/LEGAL: profile/privacy contact email].

Please include enough information for us to identify the profile and verify that you are connected to the roaster. We may ask for additional information when needed to prevent unauthorized changes.

[FOUNDER/LEGAL: confirm whether there will be a dedicated correction/removal form before launch.]

Cookies and analytics

Daily Roast uses Vercel Web Analytics and Speed Insights by default to understand aggregate website traffic and performance, including page views, broad location, device type, browser, and referring website. These services do not use analytics cookies. Vercel Web Analytics uses a daily rotating hash that is automatically discarded after 24 hours, and both services report anonymous, aggregated measurements rather than results tied to a person or IP address.

Daily Roast removes search terms and page fragments from page addresses before analytics events are sent. We do not send custom analytics events, account identifiers, email addresses, or advertising identifiers to Vercel Web Analytics. Speed Insights reports website performance measurements rather than advertising or user profiles.

While Analytics is on, Daily Roast keeps one first-source label for the current browser session. It may contain an approved campaign label from a Daily Roast link, the referring website’s hostname, and the landing page path. We use it to understand, in aggregate, which sources lead to actions such as saving a coffee, creating an account, or visiting a roaster shop. The browser copy uses session storage and is removed when Analytics is turned off or the browser session ends. We do not store the full referring page, search terms, or a cross-site browsing history.

Source labels attached to these first-party action records are designed to expire after approximately 180 days. Traffic without a reliable source remains labelled direct or unknown rather than being guessed. Analytics starts on by default. Turning it off stops page, speed, and source measurement and removes the browser's session source. [FOUNDER/LEGAL: confirm final source-measurement lawful basis, retention, and consent wording.]

Daily Roast uses Sentry to identify and diagnose technical errors. Our Sentry configuration sends error reports without optional user details, cookies, request or response headers, request bodies, query strings, breadcrumbs, performance traces, application logs, or session recordings. Search terms and page fragments are removed from request addresses before error reports are sent. The Sentry project uses its Germany data-storage location.

Daily Roast stores the visitor's analytics choice in a first-party cookie named daily_roast_consent for up to 180 days. Analytics is on by default, and turning it off keeps browser source storage, action-level source measurement, anonymous page statistics, and speed statistics off. Visitors can change this choice at any time using Privacy choices in the footer. Authentication cookies remain necessary for signed-in account, email-confirmation, and password-reset features. Sentry is used only for privacy-restricted technical error diagnosis. [FOUNDER/LEGAL/ENGINEERING: confirm final lawful basis, consent or opt-out requirements, and provider retention periods.]

Processors and service providers

Daily Roast uses service providers to host and operate the website.

Current technical providers include Vercel for hosting, Web Analytics, and Speed Insights, and Sentry for privacy-restricted error monitoring. Other processors and providers: [FOUNDER/LEGAL: confirm database, authentication/email, and any additional security or logging providers].

Transactional account emails such as confirmation or password-reset messages are sent through the configured authentication/email provider. If custom SMTP or another transactional email provider is enabled, the provider list above must identify it before launch.

These providers may process data only to provide services to Daily Roast and under the relevant contracts or terms.

[FOUNDER/LEGAL: confirm whether any providers process data outside the EU/EEA and what transfer mechanism applies.]

Your rights

Depending on your location and the type of data involved, you may have the right to request access, correction, deletion, restriction, objection, portability, and withdrawal of consent.

You can contact [FOUNDER/LEGAL: privacy contact email] to make a request.

If you believe your data protection rights have not been respected, you may also contact your local data protection authority. If Daily Roast is established in [FOUNDER/LEGAL: country], the relevant supervisory authority is [FOUNDER/LEGAL: authority name and link].

Automated decisions

Daily Roast does not use visitor personal data or signed-in recommendation preferences for automated decisions that produce legal or similarly significant effects.

Changes

We may update this policy when the site, data processing, providers, or legal requirements change. The review date below shows when this page was last reviewed.

Last reviewed

Last reviewed: [FOUNDER/LEGAL: date]