Privacy policy
Last updated October 1, 2026
How cupp uses information and the choices you have.
Who we are and what this covers
Cupp Coffee, LLC (doing business as cupp, “we,” “us,” or “our”) provides this policy for our customer website, mobile app, ordering kiosks, counter ordering, rewards, Coffee Pass, gift cards, and related customer support. It describes information handled through these services. Separate notices may apply to employment, suppliers, or other activities.
Some services may not yet be available at your shop. This policy describes information used when you choose an available service; it does not announce the launch of every feature.
Our launch scope is Utah shops and U.S. customers. We are not offering international delivery or directing marketing outside the United States at launch.
Information we collect
Account and profile information: your name, email, phone number, authentication identifiers, optional birthday, home shop, preferences, and messages you send us. If you sign in through Apple or Google, we receive the account information that provider shares for sign-in.
Orders and membership information: items and modifiers, pickup shop and time, order status and history, receipts, refunds, rewards and points activity, reusable-cup selections, referrals, Coffee Pass status, and billing events. Guest orders also use an order-specific identifier to let you access that order.
Payments and gifts: payment-provider identifiers, payment status, card brand and last digits, gift-card purchases, balances, redemptions, recipient contact details, sender name, and gift messages. Stripe processes card and wallet details; cupp does not store full card numbers or card security codes in its application database.
Technical information: IP address, browser and device information, request timestamps, and security or error logs generated when you access our services. Cookies and device storage remember sessions, your bag, selected shop, and pending transactions. We do not require access to your address book, microphone, or precise GPS location for the current customer ordering flow.
Optional location: when you tap the location arrow or Use my location and grant permission, shop selection uses your device's location to find nearby shops and calculate approximate straight-line distances. The ordering location arrow selects the closest shop. The coordinates used by our nearby-shop calculation remain in memory while shop selection is open; we do not send those coordinates to cupp servers or save them to your account. Map services have the separate practices described below. You can search for and choose a shop without allowing location access.
Where information comes from
We receive information from you, from your device as it communicates with our services, from payment and sign-in providers, and from people who send you gifts or referrals. Staff may enter order and support information when helping you in a shop. Only share another person’s details when you have permission to use them for that purpose.
How we use information
We use information to authenticate accounts; prepare, charge for, and track orders; issue receipts and refunds; deliver and redeem gifts; administer rewards and subscriptions; provide support; maintain service reliability; prevent fraud; and meet accounting and legal obligations.
We use your contact choices to manage optional promotions and preferences. Sign-in codes, receipts, gift delivery, security notices, and other service messages are separate from promotional messages. Rewards use purchase and participation history to calculate benefits and display relevant offers.
Mobile numbers and text-message consent
We do not sell, rent, or share mobile phone numbers or SMS enrollment and consent records with other companies or affiliates for their own marketing or promotional purposes. We disclose these records to providers only as needed to operate, deliver, secure, and support cupp messages, or as required by law. Promotional SMS enrollment is optional and separate from account agreement and order updates.
Cookies, device storage, and external services
Our website uses cookies and local or session storage for sign-in, guest-order access, the shopping bag, shop selection, and transaction recovery. The mobile app stores session and order information on your device. Clearing or blocking this storage can sign you out, empty your bag, or remove access to a guest order.
Payment and sign-in providers may use their own security and fraud-prevention technologies. The website loads fonts from Google Fonts, which receives technical request information such as your IP address when your browser requests a font. Maps use Mapbox, which receives technical information when your device requests maps, including IP address and map requests. Its mobile SDK includes location and usage telemetry. We initialize optional Mapbox telemetry off in the mobile app; the map’s information control provides Mapbox’s telemetry choice. Device location permission and map telemetry are separate choices. External sites you choose to visit have their own practices. Browser Do Not Track settings do not change the essential storage described here; legally applicable privacy preference signals will be respected.
Retention and security
We keep information for the purposes described here, taking account of your account activity, the transaction or gift-card lifecycle, legal retention duties, fraud prevention, and dispute resolution. Different records may need different retention periods. Financial transaction and consent records may remain linked by internal customer and payment identifiers after account deletion; necessary text-consent evidence may include the phone number and notice that enrollment covered; removing a profile does not mean every retained transaction is anonymous.
You can request account deletion in Account → Delete account. Deletion clears ordinary profile fields and removes account access and access to personal account features; transaction records may be retained for accounting, fraud prevention, and legal obligations, with identifying information removed where appropriate. Payment and other providers may retain records under their own legal duties. Backups and logs can persist for a limited operational retention period.
We use technical and organizational safeguards designed to protect personal information, but no service can guarantee absolute security. Protect your sign-in codes, passwords, gift-card codes, and order links. Services and providers may process information in the United States and other countries with different privacy laws.
Your choices and privacy requests
You can edit available profile fields in Account, change contact choices in Preferences, and request deletion using Delete account or the public Account deletion help page. Promotional emails, when sent, include an unsubscribe option. Promotional text enrollment is a separate optional choice in Preferences for a verified mobile number; promotional sending has not launched. You can withdraw enrollment in Preferences. If promotional texts launch, they will identify cupp and include opt-out instructions; carrier message and data rates may apply. Agreement to our terms, sign-in texts, and order-update choices do not enroll you in promotional texts. Device notification settings can control notifications where supported. You can allow or deny optional location access in your browser or device settings. Essential service messages may continue while you use the service.
Depending on the law that applies to you, you may have rights to access, obtain a copy of, correct, or delete personal information, and to opt out of certain uses or disclosures. Email the contact below to exercise a right, ask about a privacy signal, or request review of a decision. You do not need an active account to submit a request.
We may ask for enough information to verify your identity or an authorized agent’s authority, and will respond within applicable legal time limits. Some requests have legal exceptions; we will explain a refusal where required and any available appeal process. We will not unlawfully discriminate against you for exercising a privacy right. Rewards depend on maintaining the account and information needed to administer them; deleting an account ends those account benefits.
Guest Wi-Fi at our shops
We plan password-protected guest Wi-Fi through Ubiquiti UniFi, on a separate guest network. You will not need a cupp account, email, phone number, or captive-portal registration to connect. Connecting does not enroll you in marketing.
The network handles technical connection information such as device/network identifiers, assigned IP addresses, connection times, and traffic statistics. Depending on the configured network settings, device or traffic categories may also be visible. We use these records for operating the network, security, and troubleshooting, not to build marketing profiles or link browsing to your cupp account. Network settings and retention will be verified before the shop offers guest Wi-Fi. You can choose not to connect.
Shop security cameras
We plan Ubiquiti UniFi video security cameras at our shops for safety, security, and incident investigation, with signs at monitored entrances and areas. The approved plan is video only: no audio recording, facial recognition, or license-plate recognition. Cameras will not monitor restrooms or other private areas.
The plan stores recordings on an on-site UniFi recorder, with access limited to the owner and authorized managers. Routine recordings will be deleted after 30 days; footage relevant to an incident, insurance claim, dispute, or legal obligation may be preserved longer for that purpose. Recordings may be shared with authorized service providers, insurers, advisers, or authorities when needed for an incident or legal obligation. Hardware, access, recording settings, and the retention limit will be verified before activation. Contact us with the shop and approximate date/time for a recording-related privacy request; rights and legal preservation requirements may affect what we can provide or delete.
Children’s privacy
Our digital services are not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has provided information, contact us so we can investigate and take appropriate action. Customers under 18 should use the services with a parent or guardian’s permission and supervision.
Updates and contact
We will update the date on this policy when we revise it and provide additional notice or obtain consent for material changes when required. A privacy notice explains our practices; it does not replace any separate consent required for marketing or other processing.
For privacy requests or questions about these policies, email chandler@cupp-coffee.com or write to Cupp Coffee, LLC, 1010 W Cyan Valley Way, Bluffdale, Utah 84065. Please do not send passwords, full payment-card numbers, or sensitive identity documents by email.