Last updated 19 September 2026
Ordering privacy
This policy covers the standalone Cafesserie pickup and delivery ordering app. It is separate from cafesserie.com.
Information we use
We use your name, phone number, optional email, order contents, branch, requested time, payment preference and any notes you provide. For delivery we also use the address, map coordinates and delivery instructions you submit. For an online payment we also retain Cafesserie and PesaPal transaction references, status, amount, currency, payment method and confirmation timestamps. We do not receive or store your full card number, card security code, mobile-money PIN or PesaPal password. Phone numbers entered at checkout are required for branch contact but are not currently verified by SMS.
Why we use it
We use this information to validate and fulfil orders, contact you about time-sensitive changes, calculate delivery eligibility, keep an order history for your account, provide private access to a guest order on the device that placed it, prevent duplicate or abusive requests and maintain operational records. After a signed-in customer successfully places an order, we keep their latest name, phone number and email as account defaults. For a delivery order, we save the submitted address as their home address only when they select that option at checkout. Pickup orders do not replace an existing saved home address, and delivery instructions stay with the order instead of the saved address.
Where it is processed
Clerk provides authentication for signed-in accounts, Convex stores and synchronizes orders and payment state, Cloudflare hosts the ordering frontend, and PesaPal processes online payments in a secure PesaPal-hosted form embedded in the app (with a full-screen fallback). Cafesserie sends PesaPal the payable amount and currency, transaction reference, name, phone, optional email and basic billing location needed to process the payment. Apple or Google receives information when you choose its sign-in option. When you check a typed address, this app sends the address text and selected country to the Nominatim search service at nominatim.openstreetmap.org; its results use OpenStreetMap data. When you choose to use your current location, your browser asks for permission and provides coordinates to this app. Those coordinates are included in the order only if you continue and place it. Guest checkout does not create a Clerk account. Each provider processes data under its own security and privacy terms.
Local device data
Guest checkout may use Cloudflare Turnstile to check for automated requests. Cloudflare processes browser and network signals for this check. Cafesserie uses keyed network identifiers and hashed guest or phone identifiers for checkout limits, without storing raw IP addresses in its checkout-protection tables. These counters are scheduled for removal after seven days without use; short-lived verification receipts are cleaned up after expiry. Security rejection logs contain categories and actions, not contact details, access tokens or card information. If verification is unavailable, you can retry or contact a branch.
This app may keep an unfinished cart, chosen order method, city or branch and requested schedule in your browser. Choosing guest checkout creates a non-identifying session marker that expires after 12 hours and is cleared after a successful order; it does not contain your phone number or address. During a PesaPal checkout, session storage also keeps the Cafesserie payment reference and, for a guest, the private access token needed to recover that payment in the same tab. No payment credentials are stored in the browser. The app keeps a private per-order access token in session storage so the live confirmation page can be reopened in the same browser session. The server stops accepting that guest token after 30 days, and closing the browser session may remove it sooner. A guest delivery address and its coordinates are stored as part of the submitted order for fulfilment, but not as a reusable saved address. The iOS app separately saves a guest customer's latest name, phone number, optional email and billing address in that iPhone's Keychain after checkout, so those editable details can be filled in next time. They are removed when the customer uses the app's clear-local-data control.
Access and retention
Only authorized staff assigned to the relevant Cafesserie branch can access full order details. Branch managers and master administrators can also review payment exceptions using the transaction reference, amount, currency and provider result; that review queue does not expose duplicated customer or cart details. The payment audit record keeps those financial facts, but duplicated checkout contact, address and cart details are automatically redacted from unsuccessful payment attempts after 30 days, completed attempts after 90 days, and reversed or unresolved-review attempts after 180 days. Order records are retained separately only as long as reasonably needed for fulfilment, customer support, fraud prevention and applicable business or legal requirements.
Your choices
You can review your orders from your account or open a guest order while its private browser-session access remains available. Signed-in account defaults are not shared with cafesserie.com. Guest defaults in the iOS app remain only on that iPhone. You can replace contact and billing details at checkout or remove guest defaults with the app's clear-local-data control. You can replace a signed-in home address by saving another delivery address or remove it during delivery checkout. Contact the branch shown on an order to ask about correction or deletion. Some records may need to be retained where required for legitimate business or legal purposes.
Contact
For an order-specific privacy request, contact the Cafesserie branch shown in your order confirmation and quote the order number.
