cuppPrivacy & terms

Privacy policy

Last updated October 1, 2026

How cupp uses information and the choices you have.

On this page

  1. Who we are and what this covers
  2. Information we collect
  3. Where information comes from
  4. How we use information
  5. When we share information
  6. Mobile numbers and text-message consent
  7. Cookies, device storage, and external services
  8. Retention and security
  9. Your choices and privacy requests
  10. Guest Wi-Fi at our shops
  11. Shop security cameras
  12. Children’s privacy
  13. Updates and contact

Who we are and what this covers

Cupp Coffee, LLC (doing business as cupp, “we,” “us,” or “our”) provides this policy for our customer website, mobile app, ordering kiosks, counter ordering, rewards, Coffee Pass, gift cards, and related customer support. It describes information handled through these services. Separate notices may apply to employment, suppliers, or other activities.

Some services may not yet be available at your shop. This policy describes information used when you choose an available service; it does not announce the launch of every feature.

Our launch scope is Utah shops and U.S. customers. We are not offering international delivery or directing marketing outside the United States at launch.

Information we collect

Account and profile information: your name, email, phone number, authentication identifiers, optional birthday, home shop, preferences, and messages you send us. If you sign in through Apple or Google, we receive the account information that provider shares for sign-in.

Orders and membership information: items and modifiers, pickup shop and time, order status and history, receipts, refunds, rewards and points activity, reusable-cup selections, referrals, Coffee Pass status, and billing events. Guest orders also use an order-specific identifier to let you access that order.

Payments and gifts: payment-provider identifiers, payment status, card brand and last digits, gift-card purchases, balances, redemptions, recipient contact details, sender name, and gift messages. Stripe processes card and wallet details; cupp does not store full card numbers or card security codes in its application database.

Technical information: IP address, browser and device information, request timestamps, and security or error logs generated when you access our services. Cookies and device storage remember sessions, your bag, selected shop, and pending transactions. We do not require access to your address book, microphone, or precise GPS location for the current customer ordering flow.

Optional location: when you tap the location arrow or Use my location and grant permission, shop selection uses your device's location to find nearby shops and calculate approximate straight-line distances. The ordering location arrow selects the closest shop. The coordinates used by our nearby-shop calculation remain in memory while shop selection is open; we do not send those coordinates to cupp servers or save them to your account. Map services have the separate practices described below. You can search for and choose a shop without allowing location access.

Where information comes from

We receive information from you, from your device as it communicates with our services, from payment and sign-in providers, and from people who send you gifts or referrals. Staff may enter order and support information when helping you in a shop. Only share another person’s details when you have permission to use them for that purpose.

How we use information

We use information to authenticate accounts; prepare, charge for, and track orders; issue receipts and refunds; deliver and redeem gifts; administer rewards and subscriptions; provide support; maintain service reliability; prevent fraud; and meet accounting and legal obligations.

We use your contact choices to manage optional promotions and preferences. Sign-in codes, receipts, gift delivery, security notices, and other service messages are separate from promotional messages. Rewards use purchase and participation history to calculate benefits and display relevant offers.

When we share information

Staff who need order information to prepare and hand off your purchase can see the relevant ticket. Your pickup name or order number may be called out or displayed in the shop. A gift recipient can see the sender name and message you choose to include.

We use service providers for hosting, account and database services, payment processing, and transactional messaging. These include Vercel, Supabase, Stripe, and our email delivery provider. They receive the information needed for their work. A bank, wallet, or sign-in provider may also process information under its own privacy notice.

We may disclose information to comply with law or valid legal process, investigate fraud or security incidents, protect people and legal rights, or complete a business transfer subject to appropriate protections. We may share information with your direction or permission.

We do not sell personal information or share it for cross-context behavioral advertising. The current customer experience does not use third-party advertising pixels. If these practices change, we will update this notice and provide any choices or consent required by law.

Mobile numbers and text-message consent

We do not sell, rent, or share mobile phone numbers or SMS enrollment and consent records with other companies or affiliates for their own marketing or promotional purposes. We disclose these records to providers only as needed to operate, deliver, secure, and support cupp messages, or as required by law. Promotional SMS enrollment is optional and separate from account agreement and order updates.

Cookies, device storage, and external services

Our website uses cookies and local or session storage for sign-in, guest-order access, the shopping bag, shop selection, and transaction recovery. The mobile app stores session and order information on your device. Clearing or blocking this storage can sign you out, empty your bag, or remove access to a guest order.

Payment and sign-in providers may use their own security and fraud-prevention technologies. The website loads fonts from Google Fonts, which receives technical request information such as your IP address when your browser requests a font. Maps use Mapbox, which receives technical information when your device requests maps, including IP address and map requests. Its mobile SDK includes location and usage telemetry. We initialize optional Mapbox telemetry off in the mobile app; the map’s information control provides Mapbox’s telemetry choice. Device location permission and map telemetry are separate choices. External sites you choose to visit have their own practices. Browser Do Not Track settings do not change the essential storage described here; legally applicable privacy preference signals will be respected.

Retention and security

We keep information for the purposes described here, taking account of your account activity, the transaction or gift-card lifecycle, legal retention duties, fraud prevention, and dispute resolution. Different records may need different retention periods. Financial transaction and consent records may remain linked by internal customer and payment identifiers after account deletion; necessary text-consent evidence may include the phone number and notice that enrollment covered; removing a profile does not mean every retained transaction is anonymous.

You can request account deletion in Account → Delete account. Deletion clears ordinary profile fields and removes account access and access to personal account features; transaction records may be retained for accounting, fraud prevention, and legal obligations, with identifying information removed where appropriate. Payment and other providers may retain records under their own legal duties. Backups and logs can persist for a limited operational retention period.

We use technical and organizational safeguards designed to protect personal information, but no service can guarantee absolute security. Protect your sign-in codes, passwords, gift-card codes, and order links. Services and providers may process information in the United States and other countries with different privacy laws.

Your choices and privacy requests

You can edit available profile fields in Account, change contact choices in Preferences, and request deletion using Delete account or the public Account deletion help page. Promotional emails, when sent, include an unsubscribe option. Promotional text enrollment is a separate optional choice in Preferences for a verified mobile number; promotional sending has not launched. You can withdraw enrollment in Preferences. If promotional texts launch, they will identify cupp and include opt-out instructions; carrier message and data rates may apply. Agreement to our terms, sign-in texts, and order-update choices do not enroll you in promotional texts. Device notification settings can control notifications where supported. You can allow or deny optional location access in your browser or device settings. Essential service messages may continue while you use the service.

Depending on the law that applies to you, you may have rights to access, obtain a copy of, correct, or delete personal information, and to opt out of certain uses or disclosures. Email the contact below to exercise a right, ask about a privacy signal, or request review of a decision. You do not need an active account to submit a request.

We may ask for enough information to verify your identity or an authorized agent’s authority, and will respond within applicable legal time limits. Some requests have legal exceptions; we will explain a refusal where required and any available appeal process. We will not unlawfully discriminate against you for exercising a privacy right. Rewards depend on maintaining the account and information needed to administer them; deleting an account ends those account benefits.

Guest Wi-Fi at our shops

We plan password-protected guest Wi-Fi through Ubiquiti UniFi, on a separate guest network. You will not need a cupp account, email, phone number, or captive-portal registration to connect. Connecting does not enroll you in marketing.

The network handles technical connection information such as device/network identifiers, assigned IP addresses, connection times, and traffic statistics. Depending on the configured network settings, device or traffic categories may also be visible. We use these records for operating the network, security, and troubleshooting, not to build marketing profiles or link browsing to your cupp account. Network settings and retention will be verified before the shop offers guest Wi-Fi. You can choose not to connect.

Shop security cameras

We plan Ubiquiti UniFi video security cameras at our shops for safety, security, and incident investigation, with signs at monitored entrances and areas. The approved plan is video only: no audio recording, facial recognition, or license-plate recognition. Cameras will not monitor restrooms or other private areas.

The plan stores recordings on an on-site UniFi recorder, with access limited to the owner and authorized managers. Routine recordings will be deleted after 30 days; footage relevant to an incident, insurance claim, dispute, or legal obligation may be preserved longer for that purpose. Recordings may be shared with authorized service providers, insurers, advisers, or authorities when needed for an incident or legal obligation. Hardware, access, recording settings, and the retention limit will be verified before activation. Contact us with the shop and approximate date/time for a recording-related privacy request; rights and legal preservation requirements may affect what we can provide or delete.

Children’s privacy

Our digital services are not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has provided information, contact us so we can investigate and take appropriate action. Customers under 18 should use the services with a parent or guardian’s permission and supervision.

Updates and contact

We will update the date on this policy when we revise it and provide additional notice or obtain consent for material changes when required. A privacy notice explains our practices; it does not replace any separate consent required for marketing or other processing.

For privacy requests or questions about these policies, email chandler@cupp-coffee.com or write to Cupp Coffee, LLC, 1010 W Cyan Valley Way, Bluffdale, Utah 84065. Please do not send passwords, full payment-card numbers, or sensitive identity documents by email.

Contact cupp

Cookie settings

Cookie settings

Analytics and marketing preferences start on. Switch either off and select Update preferences to opt out. Your choices do not affect account access.

We currently use no optional analytics or advertising cookies or pixels. We will update the cookie policy before adding providers.

These preferences apply to this browser. Browser settings can also block or clear necessary storage, which may sign you out or remove your bag and pending checkout details.

Loading cookie preferences…

Read the cookie policy
Privacy policyAccessibilityAccount deletionTerms of useGift-card termsOpen source
Cupp Coffee, LLC
1010 W Cyan Valley Way, Bluffdale, Utah 84065
chandler@cupp-coffee.com