Legal
Privacy Policy
BrewSpace holds the least it can: enough to seat you at the café you booked, and nothing sold, traded, or handed to advertisers. This page says exactly what that means.
Last updated
1. Who is responsible for your data
Two organisations are involved in a single visit, and it matters which one answers for what.
- Tony Loutfallah, an individual trading as BrewSpace, based in Beirut, Lebanon, operates BrewSpace. We are the controller of your account: the details you gave us when you registered, how you use the platform, and the security records that keep it safe.
- The café you book with is the controller of your visit: the reservation, the check-in, what you ordered, and anything you asked staff for. For that data we act as the café’s processor, under a written data processing agreement that binds us to handle it only on their instructions.
You can raise any request with us at support@brewspace.coffee whichever role it falls under. Where a request concerns data a café controls, we pass it to that café and help them answer it.
2. What we collect
Your account
First name, last name, email address, date of birth, and — if you give one — a phone number. Your password is never stored: we keep only an argon2id hash of it, which cannot be turned back into the password you typed. We also record when you confirmed your email address.
Your date of birth is collected for one purpose: to check you are old enough to hold an account. It is never shown to a café, never used to profile you, and never shared with anyone.
Your bookings
The café and branch, the seat, the date and time, how many of you there are, any note you added, your check-in code, and how the booking ended — checked in, completed, cancelled, or not turned up to. If a booking was cancelled or reported by the café, we keep who did it and what they wrote, and you are sent the same words.
Orders and requests at the table
The items you ordered, quantities, any note to the kitchen, the totals the café calculated, and any service request you raised — a waiter, water, the menu, the bill.
Reviews
Your rating and comment, if you leave one. These are public, shown under your first name and the initial of your surname.
Security records
Enough to keep you signed in, to stop someone guessing their way into an account, and to keep a record of decisions that affect people — an account being suspended, a booking cancelled by staff, a review taken down. Those records say who did what and when.
What we don’t collect
- No analytics, advertising, or tracking of any kind. There is no Google Analytics, no advertising pixel, no third-party tracker, and no profiling of you across other websites.
- No payment details. Booking is free to you and you pay the café directly, so we never see a card number.
- No location tracking. Times are shown in the café’s local clock, not your device’s.
3. Why we use it
- To give you the service you asked for — hold a seat, confirm the booking, let staff know you have arrived, take your order. Without this data there is no booking. (Legal basis: performance of a contract with you.)
- To contact you about a booking — a confirmation, a change, a closure, a password reset. (Contract, and our legitimate interest in reaching you about a table you reserved.)
- To keep the platform secure and honest — limits against attacks, a record of decisions that affect people, and the report count that pauses booking after 3 reports for 30 days. (Our legitimate interest, and the café’s, in a booking system that isn’t abused.)
- To run the business — the commission a café owes us is calculated from confirmed reservations, which requires keeping those records. (Legitimate interest, and legal obligations around accounting.)
- To answer you when you write to support, and to handle a complaint or dispute. (Legitimate interest, and establishing or defending legal claims.)
We do not sell your data, we do not share it for anyone else’s marketing, and we do not make automated decisions about you with legal effects. The booking pause after repeated reports is applied by a rule rather than a person, so if it hits your account you can ask a human to look at it — write to support@brewspace.coffee and we can lift it.
6. How long we keep it
- Seat holds disappear five minutes after they are taken, automatically.
- Sign-in sessions expire after seven days, and immediately when you sign out or change your password.
- Your account and its bookings are kept while the account is open. Booking, order, and commission records are also the café’s business records and ours, so they are retained for as long as tax and accounting law requires them.
- Security records are kept while they remain useful for investigating abuse of the platform.
- When you delete your account, it stops working immediately and you are signed out everywhere. Every table you were still holding is let go and the café is told, so nobody is left holding one for you. Your past bookings and orders are the café’s business records as well as yours, so those are kept for as long as tax and accounting law requires — which is why deleting your account removes it from BrewSpace rather than erasing every trace of it. Ask us at support@brewspace.coffee and we will erase whatever we are not required to keep.
7. Your rights
Depending on where you live, you have some or all of the following rights over your data:
- See it — ask for a copy of what we hold about you.
- Correct it — your name and phone number are yours to edit on your account page; write to us for anything else.
- Delete it — delete your account yourself from your account page, or ask us to, subject to the records we are required to keep.
- Object or restrict — tell us to stop using your data for a particular purpose we rely on legitimate interests for.
- Take it with you — receive the data you gave us in a portable, machine-readable form.
- Complain — to us first, we hope, and to your national data protection authority if we have not put it right.
Write to support@brewspace.coffee to exercise any of these. We answer within one month, and we will not charge you or treat you differently for asking. We may need to confirm who you are before acting on a request, so that nobody else can make it for you.
8. How we protect it
- Nobody who runs BrewSpace can read your password.
- Everything you send us travels over an encrypted connection.
- Changing or resetting your password signs you out everywhere else, immediately.
- One café can never see another café’s customers. Staff and administrators only reach the branches they actually work at.
- Signing in and resetting a password are limited against guessing, and decisions that affect a person are recorded.
No system is perfectly secure. If we discover a breach affecting your data, we will notify you and the relevant authority as the law requires.
9. Where your data is stored
Your data is held in the United States, and the providers who work for us may handle it in other countries. Where they do, the transfer is covered by the standard legal safeguards for moving personal data abroad. Ask us at support@brewspace.coffee and we will tell you which apply.
10. Children
BrewSpace is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has created an account, write to support@brewspace.coffee and we will remove it.
11. Changes and contact
When this policy changes, the version here changes with it and the date at the top moves. If a change materially affects how we handle your data, we will tell you by email before it takes effect.
For anything on this page — a question, a request, or a complaint — write to support@brewspace.coffee. Our terms of service cover the rest of the relationship.