Privacy
Privacy.
Daily Roast is a public coffee discovery directory. This page explains what personal data may be processed when you browse the site, create an account, save coffees, sign up for email updates, click an outbound roaster link, or appear in the directory as a public roaster contact.
This draft is prepared for founder and legal review. Fields marked for review must be completed before this page is treated as final legal copy.
Who is responsible
Daily Roast is operated by [FOUNDER/LEGAL: legal operator name].
- Controller
- [FOUNDER/LEGAL: controller/operator name]
- Legal form
- [FOUNDER/LEGAL: legal form, if applicable]
- Address
- [FOUNDER/LEGAL: registered or business address]
- Email for privacy requests
- [FOUNDER/LEGAL: privacy contact email]
- Country of establishment
- [FOUNDER/LEGAL: country]
What this policy covers
This policy covers personal data processed through the Daily Roast public website and related server endpoints.
Daily Roast does not sell coffee, process payments, provide checkout, or collect public reviews at launch. You may create an optional account to sign in, save coffees, set taste preferences, and receive recommendations. When you choose to buy coffee, you leave Daily Roast and visit the roaster’s own website.
Data we process from website visitors
When you browse Daily Roast, our hosting and security systems may process technical request data such as IP address, user-agent, request URL, referrer, timestamp, and basic error or security logs.
Purpose: operate the website, protect the service, debug errors, prevent abuse, and keep the public directory available.
Likely legal basis: legitimate interests in operating and securing the website, unless a specific processing activity requires consent or another legal basis.
[FOUNDER/LEGAL: confirm hosting provider, server-log retention period, and whether raw IP addresses are retained by any provider.]
Accounts, preferences, and recommendations
If you create an optional Daily Roast account, we process account data needed to let you sign in, keep your saved coffees, store taste preferences, and maintain your account controls.
Data may include: email address, account identifier, authentication session data, saved coffee identifiers, taste preference choices, hidden coffee identifiers, recommendation feedback, recommendation event records, event source labels, recommendation reason codes, recommendation rank or score context, account export timestamps, deletion-request status, and basic security or abuse-prevention records.
Purpose: provide account access, store your saved coffees, improve signed-in recommendations from your saved coffees, preferences, feedback, and recommendation interactions, protect the account system, prevent abuse, and respond to account or privacy requests.
Recommendation events are first-party account events such as clicks, saves, “not for me” feedback, preference updates, or recommendation-sourced shop clicks. Daily Roast does not use these account events for third-party advertising, session replay, or paid ranking.
Likely legal basis: performance of the account service you request and legitimate interests in operating and securing the service, subject to founder/legal review.
You can sign out at any time. From account settings, signed-in users can export account data as JSON and submit a deletion request for founder/manual processing. You can also request access, correction, or deletion by contacting [FOUNDER/LEGAL: privacy contact email].
Planned retention: account, saved-coffee, preference, recommendation-feedback, recommendation-event, and deletion-request records are kept while the account remains active unless you request deletion earlier, subject to any legal recordkeeping need. [FOUNDER/LEGAL: confirm account deletion workflow and retention.]
Outbound roaster links
When you click a Visit shop or similar outbound link, Daily Roast checks the destination server-side before sending you to the roaster’s website.
Data may include: product or roaster target, destination URL, event source, consent context, hashed IP address, hashed user-agent, referring hostname, timestamp, and retention metadata.
Purpose: validate that the destination is a safe public roaster URL, prevent abuse, understand whether outbound links are working, and avoid sending users to broken or unsafe destinations.
Likely legal basis: legitimate interests in operating a safe public directory and protecting users from broken or unsafe redirects.
Planned retention: outbound-click event records are currently designed to expire after approximately 180 days. [FOUNDER/LEGAL: confirm final retention.]
Daily Roast does not run affiliate links at launch. If affiliate links are added later, this policy and the visible outbound-link disclosures must be updated before they go live.
Public roaster directory data
Daily Roast indexes public business information about coffee roasters and public catalog information that roasters make available online.
Directory data may include: roaster name, website, public shop URL, public location information, public product and catalog data, public source URLs, last-observed timestamps, and other public business facts used for discovery.
Some roasters are companies. Some may be sole traders or small businesses where business information can identify a natural person. Where directory data is personal data, Daily Roast processes it only for the public directory purposes described here.
Purpose: operate an independent public directory of European specialty coffee roasters and coffee catalogs.
Likely legal basis: legitimate interests in creating and maintaining a public directory based on public business information, balanced against the rights and interests of affected people.
Sources: public roaster websites, public shop pages, public profile pages, public business pages, and reviewed public export data from Daily Roast’s internal review workflow.
Daily Roast does not publish internal scraper logs, raw payloads, prompts, quality-control logs, private evidence tables, or review queues.
Corrections, removal, and profile issues
If you operate a roaster profile listed on Daily Roast and want to correct, update, or remove information, contact [FOUNDER/LEGAL: profile/privacy contact email].
Please include enough information for us to identify the profile and verify that you are connected to the roaster. We may ask for additional information when needed to prevent unauthorized changes.
[FOUNDER/LEGAL: confirm whether there will be a dedicated correction/removal form before launch.]
Processors and service providers
Daily Roast uses service providers to host and operate the website.
Current technical providers include Vercel for hosting, Web Analytics, and Speed Insights, and Sentry for privacy-restricted error monitoring. Other processors and providers: [FOUNDER/LEGAL: confirm database, authentication/email, and any additional security or logging providers].
Transactional account emails such as confirmation or password-reset messages are sent through the configured authentication/email provider. If custom SMTP or another transactional email provider is enabled, the provider list above must identify it before launch.
These providers may process data only to provide services to Daily Roast and under the relevant contracts or terms.
[FOUNDER/LEGAL: confirm whether any providers process data outside the EU/EEA and what transfer mechanism applies.]
Your rights
Depending on your location and the type of data involved, you may have the right to request access, correction, deletion, restriction, objection, portability, and withdrawal of consent.
You can contact [FOUNDER/LEGAL: privacy contact email] to make a request.
If you believe your data protection rights have not been respected, you may also contact your local data protection authority. If Daily Roast is established in [FOUNDER/LEGAL: country], the relevant supervisory authority is [FOUNDER/LEGAL: authority name and link].
Automated decisions
Daily Roast does not use visitor personal data or signed-in recommendation preferences for automated decisions that produce legal or similarly significant effects.
Changes
We may update this policy when the site, data processing, providers, or legal requirements change. The review date below shows when this page was last reviewed.
Last reviewed
Last reviewed: [FOUNDER/LEGAL: date]