No internet connection — some features may be unavailable

Privacy Policy

Your data,
plainly.

What we collect, why we collect it, how long we keep it, and how to get it back or get it deleted. No defined terms, no cross-references — if something here is unclear, that is a fault in this page and we want to hear about it.

Last updated 5 September 2026

01Who is responsible for your data

Bloom Coffee OS is software sold to coffee shops. That means there are two different relationships on this page, and which one applies to you decides who you should ask about your data.

If you are a café
You are the data controller for your staff and your customers. We are your processor: we hold and process that data on your instruction, and we do not use it for our own purposes.
If you are staff
Your employer decides what goes into the system. Ask them first — they can change or delete your record directly. We will help if they cannot.
If you are a customer
The café you ordered from is responsible for your data. We only store it on their behalf.
For our own accounts
When a shop owner signs up with us, we are the controller for that account (name, email, phone, billing contact).

02What we actually collect

This is the complete list. It is taken from the database schema, not written from memory.

Staff accounts
Name, email address, phone number, a bcrypt hash of the password (never the password itself), role, and the shop the account belongs to.
Two-factor secrets
If a staff member switches on two-factor authentication, the shared secret is stored encrypted.
Face recognition
Optional, and off unless a shop turns it on. See section 3 — it is the most sensitive thing here and it gets its own section.
Customers
Phone number, and optionally a name, email address and birthday if given. Order history is linked to that record.
Orders and stock
Items, quantities, prices, timestamps, the table, and which staff member handled it.
Technical logs
IP address, browser type and request paths, kept for troubleshooting and abuse detection.

What we do not collect

No card numbers.Payment happens in person — cash, or the waiter's own terminal. Card details never reach Bloom, so there is nothing here for us to lose.

No location tracking, no advertising identifiers, no marketing pixels, and no profiling that produces a decision about you automatically. We do not sell data to anyone, in any form, for any price. The public site uses one cookie-free analytics tool — see section 5 — which cannot identify you.

03Face recognition, specifically

Some shops use face recognition for staff clock-in. Biometric data is a special category under both European and Tunisian law, so it is treated separately:

  • It is off by default. A shop has to deliberately enable it.
  • It requires the explicit, informed consent of each staff member. Consent can be withdrawn at any time, and withdrawing it is not a disciplinary matter.
  • No photograph is stored. What is kept is a mathematical encoding from which the original face cannot be reconstructed.
  • That encoding is encrypted with AES-256-GCM before it is written to disk.
  • It is used for one thing — confirming identity at clock-in. It is never used for surveillance, for monitoring how long someone is at their station, or for anything performance-related.
  • Deleting a staff member deletes the encoding with them.

If a shop asks you to enrol and you would rather not, PIN clock-in works exactly the same way and is always available.

04Why we hold it

To run the service
Taking orders, routing them to the kitchen, tracking stock, paying staff. This is the contract between a café and us, and between a café and its customer.
To keep it secure
Logs, rate limiting and audit trails exist so that a break-in can be detected and reconstructed. This is our legitimate interest and yours.
On consent
Face recognition, and marketing messages, where a shop sends them. Consent is asked for separately and can be withdrawn.
Because the law says so
Sales and tax records have to be retained for a period set by Tunisian accounting law, regardless of any deletion request.

05Where it lives, and who else can see it

Your data is stored on a dedicated server in Lauterbourg, France, rented from Contabo GmbH. It is in the European Union and stays there. Nothing is stored in the United States.

These are every outside company involved, and what each one gets:

Contabo GmbH
Hosting, in France. They hold the disks; they have no reason to read them and no access to our encryption key.
Cloudflare
Carries traffic between your browser and our server, and provides the TLS certificate. Sees connection metadata, not database contents.
Groq
Only for AI features. Receives the specific question being asked — for example a list of item names and sale counts for a forecast. Staff records, customer records, phone numbers and face encodings are never sent.
Telegram
Only if a shop connects it. Receives operational alerts, such as a low-stock warning or a shift reminder.
Meta (WhatsApp)
Only if a shop connects it. Receives the recipient's phone number and the message text, in order to deliver it.
Email provider
Delivers transactional email — password resets and receipts. Receives the address and the message.
Plausible Analytics
Counts visits to the public site — page, referrer, device type, country from IP (the IP itself is never stored). It sets no cookies and cannot identify you across sites or visits. Only bloomcoffeeos.com is measured; the admin, owner, staff and vendor tools are not.

That is the entire list. If we ever add to it, this page changes before the service does.

06How long we keep it

While you are a customer
Account and operational data is kept for as long as the shop uses Bloom.
After you leave
You can export everything. 30 days after that, we delete it.
Backups
The database is backed up nightly. Backups are kept for 30 days and then destroyed, so deleted data can persist in a backup for up to 30 days after you delete it — this is normal, and it is why we tell you.
Financial records
Retained for the period Tunisian tax law requires, even after an account closes.
Technical logs
Rotated out within 90 days.

07What you can ask us to do

You have the right to:

  • See a copy of everything we hold about you.
  • Correct anything wrong.
  • Have it deleted, subject to the tax-record exception above.
  • Get it in a portable file you can take to another system.
  • Object to a particular use, or withdraw consent you gave earlier.
  • Complain to a regulator if we handle your request badly.

Ask on WhatsApp at +216 20 114 798. We reply within 30 days, and there is no charge. If you are a café's customer or staff member, we will pass your request to that café, because they are the ones who decide — and we will tell you that we did.

In Tunisia, the regulator is the Instance Nationale de Protection des Données Personnelles (INPDP). In the EU, it is the data protection authority of the country you live in.

08Cookies

Bloom sets two cookies, both strictly necessary: one keeps you signed in, one carries the CSRF token that stops a third-party site submitting forms as you. There are no advertising cookies and no tracking cookies. The public site also runs Plausible Analytics (section 5), which is built not to use cookies at all — it counts visits without storing anything in your browser or building a profile of you. That is why you still have not been shown a cookie banner: there is nothing to consent to.

09Children

Bloom is a tool for running a business and is not directed at children. We do not knowingly collect data from anyone under 16. If a customer record was created for a child, ask us and we will remove it.

10If something goes wrong

If personal data is exposed in a way that is likely to put someone at risk, we will tell the affected shops without undue delay and within 72 hours of becoming aware of it, with what happened, what data was involved, and what we are doing about it. We would rather tell you early and be wrong about the scope than tell you late and be precise.

11Changes to this page

If we change anything that affects what we collect or who receives it, we update the date at the top and tell account holders directly. We do not make a material change quietly and rely on you re-reading the page.

Related: how we protect it, what we are and are not certified for, and the terms of service.