Entity: Little Way Studios Pty Ltd as trustee for Little Way Holdings Trust (ABN 83 213 012 011), trading as 'BeanRun'
Contact: Adrian Barr, support@beanrun.au, +61 475 740 086
Personal Information Collected
- Name, mailing/street address, email, phone
- Social media information (including auth tokens if social sign-up is used)
- Credit card/payment information (via Stripe Connect — not stored directly by BeanRun)
- Bank account details for cafes (via Stripe Connect)
- Business information for cafes: ABN/ACN, location, trading names, opening hours, key contact
- Location services data (only if activated by user — defaults to identifying nearby cafes)
- Device identity/type, IP address, geo-location, page view statistics, advertising data, web log information
- Survey/questionnaire/promotion responses
- Suggestions and feedback you send us through the app or the cafe dashboard (we keep these for up to 24 months, then delete them)
- Third-party information
How We Collect
- Directly from users (website, app, forms, email, phone, SMS, social media)
- Automatically via cookies and web analytics (PostHog)
- Sign in with Apple: if you sign up using your Apple ID, Apple shares your name and email address with us. You may choose to hide your real email — Apple then provides a private relay address that forwards emails to your real inbox. We never see your Apple ID password.
- Sign in with Google: if you sign up using your Google account, Google shares your name, email address, and profile photo URL with us. We never see your Google password.
Use of Personal Information
- Provide goods, services, or information you have requested
- Record keeping and administration
- Share with cafes: strictly limited to your first name, first names of group members in an order, and group name
- De-identified reports: compile and share de-identified analytics with participating and prospective cafes
- Provide information to our contractors, employees, and agents for service delivery
- Improve and optimise our service offering
- Comply with legal obligations
- Send administrative messages, reminders, notices, updates, and security alerts
- Consider employment applications
Disclosure
- We may disclose your personal information to cloud providers, contractors, and third parties inside or outside Australia.
- We take reasonable steps to ensure overseas recipients have similar privacy safeguards in place.
Overseas disclosure
- We use the following sub-processors who may process personal information:
- PostHog Inc. — product analytics and website analytics; data is stored in the European Union (AWS Frankfurt, Germany).
- Sentry (Functional Software, Inc.) — error monitoring; United States.
- Supabase Inc. — database, authentication, and serverless functions hosting.
- Stripe Inc. — payments and cafe operator onboarding (Stripe Connect).
- Amazon Web Services (AWS) — website hosting.
- Resend (Resend.com, Inc.) — transactional email delivery.
- Apple Inc. — Sign in with Apple identity verification, push notification delivery on iOS and to the installed cafe dashboard on Safari.
- Google LLC — Sign in with Google identity verification, push notification delivery on Android and to the installed cafe dashboard on Chrome (Firebase Cloud Messaging).
- Mozilla Corporation — web push notification delivery to the installed cafe dashboard on Firefox.
- In accordance with Australian Privacy Principle 8, we disclose that the above sub-processors are located outside Australia (primarily in the European Union and the United States).
- We take reasonable steps to ensure overseas recipients handle personal information consistently with the Australian Privacy Act 1988 (Cth).
Marketing
- We comply with the Spam Act 2003 (Cth).
- We will only send you marketing communications if you have opted in or were given the opportunity to opt out at signup and did not do so.
- You can opt out at any time via the unsubscribe link in any marketing email, or by contacting us.
Security
- We take reasonable steps to protect your personal information from misuse and unauthorised access.
- Our IT systems are password protected with administrative and technical security measures.
- We cannot guarantee the security of information transmitted over the internet.
Access and Correction
- You may request access to your personal information at any time.
- We may require identity verification before providing access.
- You may request correction of any inaccurate information we hold about you.
Deleting Your Account
- You can delete your BeanRun account from inside the mobile app at Profile → Account → Delete my account.
- Deleting your account starts a 7-day grace period. If you sign in again within those 7 days, your account is restored — except for any saved payment methods, which are removed immediately (see below). After 7 days, deletion is permanent and cannot be reversed.
- After the 7-day period ends, we permanently remove the personal information we hold about you — including your full name, email address, mobile number, residential or delivery address, drink preferences and saved usual orders, group memberships, push notification tokens, and any remaining payment-method references.
- Your saved payment methods are removed immediately at the start of the 7-day period, not at the end. If you restore your account, you will need to add a card again before your next order.
- If you cannot use the in-app flow, you can email support@beanrun.au. We will start the same 7-day grace period from when we action your request, so you can still restore by signing in within that window.
- Suggestions and feedback: if you sent us a suggestion through the app or the cafe dashboard, we keep what you wrote but detach it from your account, so it can no longer be linked back to you. We do this because a suggestion tells us what to build, and that remains true after someone leaves. It is deleted 24 months after you sent it.
- Records we keep for tax and regulatory purposes: we retain records of past payments, refunds, and runs (for example, transaction amounts, dates, and the cafes involved) so we can meet our Australian tax record-keeping obligations. These records are stripped of personal identifiers and your row is replaced with a "deleted user" placeholder, so the records can no longer be linked back to you.
- This approach aligns with Australian Privacy Principle 11 (destruction or de-identification of personal information no longer needed) under the Privacy Act 1988 (Cth): personal information is destroyed where we no longer need it, and de-identified where retention is required by law.
Complaints
- If you have a complaint about how we handle your personal information, please contact us at support@beanrun.au or +61 475 740 086.
- Complaints are investigated promptly and responded to within a reasonable timeframe.