Part A — For BrewPass Members
1. Personal Information We Collect
We may collect the following personal information:
Account and Identity Information
- name
- email address
- password (stored securely)
Subscription and Payment Information
- subscription status
- billing status
- transaction history
Payments are processed through third-party payment providers. BrewPass does not store full payment card details.
Location Information
We may collect:
- GPS location data (if enabled on your device), and
- café visit location data through QR check-ins.
Usage Information
- redemption timestamps
- café visit counts
- app activity and interactions
Device and Security Information
We may collect device identifiers and technical data to support fraud prevention and platform security.
2. Sensitive Information
BrewPass does not collect sensitive information such as:
- health or medical data
- biometric data
- racial or ethnic origin
- religious beliefs
- political opinions
3. How We Collect Information
We collect information when you:
- register an account
- subscribe and make payments
- redeem beverages through QR check-in
- enable location services
- communicate with BrewPass support
- interact with the Service through your device
We may also collect information automatically through app and platform logs.
4. How We Use Personal Information
- operate and administer subscriptions
- provide beverage redemptions through participating cafés
- enforce redemption rules and prevent misuse
- process payments and billing
- provide customer support
- send communications and service notices
- improve platform performance and user experience
- comply with legal and regulatory obligations
5. Communications and Marketing
BrewPass may send you:
Transactional communications
Receipts, activation notices, redemption confirmations, service notices, and other communications necessary to operate and administer your account and subscription. These are sent regardless of your marketing preference.
Promotional communications
Offers, new cafés, product features, and other marketing content, sent only if you have opted in.
When you create a BrewPass account, you can choose whether to receive promotional communications by ticking an opt-in checkbox at sign-up. You may change this preference at any time via the unsubscribe link in any promotional email, your in-app notification settings, or your account preferences where available.
Promotional communications may be sent by email or push notification, using third-party email service providers, push notification providers, or digital advertising platforms, which may store or process data overseas (see Part C, section 2 – Overseas Disclosure).
6. Disclosure to Participating Cafés
Participating cafés can see, via their partner dashboard, your first name and the time you check in, so staff can verify your redemption in person. Cafés also receive aggregated information such as visit counts, redemption volume, and payout calculations and history.
Cafés do not receive your surname, email address, payment details, or any other personal information, and are contractually required to use your first name and check-in time only to verify your redemption — not for marketing, profiling, or any other purpose.
Café partners’ obligations regarding this data are set out in Part B of this Policy and in the Café Partner Agreement.
7. Cookies, Analytics & Tracking
BrewPass may use analytics and tracking tools to understand app usage, improve performance, detect fraud and abuse, and support product development. You may adjust device settings to limit tracking, though some features may not function properly.
8. Access, Correction & Deletion
You may request:
- access to personal information we hold about you
- correction of inaccurate information
- account deletion or deactivation (subject to legal retention requirements)
We may refuse requests in limited circumstances permitted by law.
Part B — For Café Partners
1. Information We Collect From Café Partners
To onboard and pay a Café, we collect:
- business name, trading name, ABN/ACN and business address;
- contact person name, email address and phone number;
- bank account details for payouts;
- GST registration status and other tax information reasonably required for compliance;
- evidence of insurance where requested (clause 2.6 of the Café Partner Agreement).
Where the Café is a sole trader or partnership, this information may constitute personal information about an individual under the Privacy Act 1988 (Cth).
2. How We Use This Information
- to onboard the Café and administer the Café Partner Agreement;
- to calculate and make payouts (see Part B of the Café Partner Agreement), and to meet tax and accounting obligations;
- to provide support and respond to queries;
- for marketing the Café’s participation, as described in Schedule 2 of the Café Partner Agreement;
- to comply with legal and regulatory obligations.
3. Data Shared With Participating Cafés
To operate the subscription and settlement model, BrewPass shares the following data with participating cafés, as further described in Schedule 1 of the Café Partner Agreement:
- each Member’s first name and live check-in time, shown via the partner dashboard so staff can verify a redemption in person;
- monthly visit counts;
- real-time visit metrics;
- redemption volume; and
- payout calculations and payout history.
This is limited personal information. Cafés do not receive a Member’s surname, email address, phone number, payment details, or any other identifying or contact information, and must only use a Member’s first name and check-in time to verify that redemption — see section 5 below.
4. Data Not Shared With Participating Cafés
BrewPass does not share the following data with Participating Cafés:
- Member surnames, email addresses, phone numbers or other contact details;
- Member payment or financial information;
- Member device information;
- Member GPS location data;
- Member account history or behavioural profiles;
- Member marketing preferences;
- Member demographic attributes;
- Member personal health or sensitive information.
5. Purpose of Data Disclosure to Cafés, and Café Obligations
Data is disclosed to cafés solely to:
- verify payout calculations;
- understand aggregated demand and subscription utilisation; and
- support operational planning (e.g., staffing, inventory).
Cafés may not use BrewPass data to:
- further identify Members beyond the first name shown at check-in;
- combine BrewPass data with external datasets to re-identify individuals;
- record, copy, export, screenshot or retain a Member’s first name or check-in time outside the BrewPass dashboard;
- contact, market to, or profile a Member using their first name or check-in data;
- sell or disclose BrewPass data to third parties; or
- use data to compete with BrewPass.
6. Access and Correction
The Café’s authorised representatives may request access to, or correction of, personal information BrewPass holds about them by contacting us using the details below. We may refuse requests in limited circumstances permitted by law.
Part C — General Provisions (Applicable to All)
1. Disclosure to Third-Party Service Providers
We may disclose personal information to trusted service providers, including:
- payment processors;
- cloud hosting and infrastructure providers;
- communications providers (email, push);
- analytics, monitoring, or fraud-prevention tools;
- customer and partner support platforms; and
- professional advisers (legal, accounting).
These providers process data only to support BrewPass operations and are not permitted to use it for their own purposes.
BrewPass does not disclose full payment card or bank account details beyond what is necessary to process transactions and payouts; these are handled by our payment providers.
2. Overseas Disclosure
Some service providers may store or process personal information (including Member and Café partner information) outside Australia — for example, where marketing is conducted using email service providers, push notification providers, or digital advertising platforms.
At this stage, BrewPass is unable to confirm that all personal information will be stored exclusively in Australia, but we take reasonable steps to ensure compliance with the Australian Privacy Principles where overseas processing occurs.
3. Security
We take reasonable technical and organisational measures to protect personal information, including secure storage and access controls. No system can guarantee absolute security.
4. Data Retention
Members:
We retain personal information for as long as your account remains active, and afterwards as required by law for financial, tax, regulatory and accounting purposes.
Certain transaction and subscription records may be retained for at least seven (7) years, consistent with Australian bookkeeping and taxation obligations.
Café partners:
We retain Café partner information for as long as the Café participates in BrewPass, and afterwards as required by law for financial, tax, regulatory and accounting purposes (generally at least seven (7) years for transaction and payout records).
When information is no longer required, we take reasonable steps to destroy or de-identify it.
5. Law Enforcement & Regulatory Disclosure
BrewPass may disclose data if required by law, court order or a regulatory authority, or to enforce the Consumer Terms of Service or the Café Partner Agreement (as applicable).
6. Complaints
If you have concerns or complaints about how we handle personal information, please contact us first using the details below. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC).
7. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email, in-app notice, or (for Café partners) the partner dashboard.
8. Contact Us
For privacy-related queries, contact:
