Information We Collect
Personal Information
When you create an account, place an order, or contact us, we collect information such as your full name, email address, phone number, shipping and billing address, and payment details (processed securely via Razorpay — we do not store card numbers).
Usage Data
We automatically collect information about how you interact with our website, including pages visited, time spent, browser type, device information, IP address, and referring URLs. This helps us improve your experience.
Brew Bucks Activity
We track your loyalty points balance, earning events (purchases, sign-up bonuses), and redemption history to maintain your Brew Bucks wallet accurately.
How We Use Your Information
Order Fulfillment
We use your contact and address information to process orders, arrange shipments, send tracking updates, and generate GST-compliant invoices delivered to your email.
Communication
We send transactional emails (order confirmations, shipping updates, password resets), and where you have opted in, promotional communications about new products, offers, and Brew Bucks events.
Service Improvement
Usage data helps us understand what content resonates, optimise the shopping experience, fix bugs, and develop new features that make Coffee Totaler calmer to use.
Legal Compliance
We retain certain records as required by Indian law, including the IT Act 2000, Consumer Protection Act 2019, FSSAI regulations, and GST law.
Information Sharing
We Do Not Sell Your Data
Coffee Totaler does not sell, rent, or trade your personal information to third parties for their own marketing purposes — ever.
Service Providers
We share data with trusted partners who help us operate: Razorpay (payments), shipping couriers, Cloudinary (media storage), and transactional email providers. Each is bound by data processing agreements.
Legal Requirements
We may disclose information when required by law, court order, or government request, or to protect the rights, safety, and property of Coffee Totaler, our users, or the public.
Data Security
Technical Safeguards
All data is transmitted over HTTPS with TLS encryption. Passwords are hashed using bcrypt with salt rounds. Authentication tokens are HTTP-only, secure cookies with strict SameSite policy.
Payment Security
Card details are processed directly by Razorpay (PCI-DSS Level 1 compliant). We never see or store your full card number — only a masked reference.
Incident Response
In the unlikely event of a data breach affecting your personal information, we will notify you within 72 hours of discovery, in accordance with applicable law.
Your Rights
Access & Portability
You may request a copy of the personal data we hold about you. We will provide this in a commonly used, machine-readable format within 30 days.
Correction
If any information we hold about you is inaccurate or incomplete, you can update most details directly in your account settings, or contact us to correct them.
Deletion
You may request deletion of your account and personal data at any time via your account settings. We will remove your data within 30 days, subject to legal retention obligations (e.g., GST records).
Opt-Out of Marketing
You can unsubscribe from marketing emails at any time by clicking 'Unsubscribe' in any email, or by managing notification preferences in your account.
Data Retention
Account Data
We retain your account information for as long as your account is active. After account deletion, personal profile data is removed within 30 days.
Order Records
Transaction and invoice records are retained for 7 years as required by the Indian GST Act and accounting regulations.
Communication Logs
Customer support communications are retained for 2 years to help resolve recurring issues and improve our service quality.
Third-Party Links
External Sites
Our website may contain links to third-party websites (social media, payment gateways, delivery partners). Once you leave our site, this Privacy Policy no longer applies. We encourage you to review the privacy policies of those sites.
Children's Privacy
Age Restriction
Coffee Totaler is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such data, please contact us immediately and we will delete it.
Policy Updates
How We Notify You
We may update this Privacy Policy periodically. When we make material changes, we will notify you by email (for account holders) or by displaying a prominent notice on our website. Your continued use of Coffee Totaler after changes take effect constitutes acceptance of the updated policy.
Contact Us
Privacy Inquiries
For any questions, concerns, or requests regarding your personal data or this Privacy Policy, please reach out to our team. We are committed to responding within 5 business days.
Get in touch
Thank you for trusting Coffee Totaler with your data. We take that trust seriously — and we always will.
