Vetted is a curated guide to specialty coffee, and — at cafés that offer it — a way to order ahead, timed to your arrival. This policy explains what we collect and why. We do not sell your data and we do not show ads. We load no cross-site trackers on the public website. Detailed usage analytics in the app are first-party, on by default, and can be turned off from Profile → Privacy & data. Public-website analytics are first-party, on by default, and can be turned off from this page or the website privacy choices control.
Website analytics choices
Website analytics are on for this browser.
What we collect
Account identity. If you sign in with Apple, we store the anonymous Apple user identifier and, if you share it, your email address (which may be an Apple private-relay address). If you sign in with Google, we store the Google account identifier and verified email address from the Google identity token. If you sign up with email and password instead, we store your email address, a salted hash of your password (never the password itself), and short-lived verification codes while you confirm your address or reset your password. You may also set an optional display name on your account. This is used only to keep you signed in, show your account identity, and sync your account across devices.
Saved cafés. The cafés you bookmark, linked to your account so they appear on your devices.
Café notes. Notes you write on a café are stored on our servers so they sync across your devices. Notes are private by default. If you choose to share a note with followers, it can be read only by signed-in users whose follow request you have accepted, only while you still have that café saved, and not by anyone either of you has blocked. You can make a shared note private again or delete it at any time. Notes are deleted with your account.
Following and private notes. If you use Vetted's following features, we store your handle if you set one, opaque follow-link token, follow requests, accepted follow relationships, and blocks so the app can show trusted notes and enforce your choices. Exact handles and share links are private request mechanisms, not public profile pages or suggested follows. Vetted does not upload your phone contacts or address book, and we do not use phone numbers to help people find, follow, or identify each other.
Café suggestions. If you suggest a café, we store the name, address, optional website, and your account id so Vetted can review the suggestion, avoid duplicate submissions, and notify you if it becomes a published café page.
Café issue reports. If you report a problem with a café listing, we store the issue category, your description, and your account id so Vetted can review and resolve it.
Studio contributor applications. If you apply to author café data in Studio, we store your name, email, coffee background, optional city/region, optional website or social links, and the information you provide so Vetted can review the application. Applying does not guarantee access or a response.
Orders & payments. When you order ahead, payment is processed by Square, the café's payment processor, through that café's own Square account — the café is the seller. Your card details go directly to Square and never touch Vetted's servers. For card checkout, Vetted may supply your account email address to Square as billing contact information so Square can run payment authentication and fraud-prevention checks. For each order Vetted stores what you'd expect on a receipt: the items, totals, timestamps, order status, your optional pickup note, and Square's order/payment identifiers. If you choose Track in Apple Wallet, Vetted sends that order's café, items, total, status, timestamps, and order identifier to Apple Wallet so Wallet can show and update the pickup card; we do not include your pickup note, name, email, card details, or address in the Wallet order. Order records are kept as financial records — they survive account deletion, but are no longer linked to a usable identity once your account data is erased. (How charging works is covered in the Purchase Terms.)
Arrival check-in (geofenced ordering). Arrival-timed orders work by your phone monitoring the café's location region on-device, using Apple's geofencing — your movements are processed by iOS on your phone, not streamed to us. When you arrive (or tap “I'm here”), the app tells our server to start the order, and we store an order-level arrival record: a timestamp and which café. We never receive or store your coordinates, route, or movement history.
Notification tokens. If you allow order-status notifications, we store the Apple push token for your device; it is deleted when you sign out and, in any case, when you delete your account. For the Lock Screen / Dynamic Island order tracker we also store a short-lived, per-order Live Activity token, which is removed when that order finishes or is cancelled — and always deleted with your account. If you choose Track in Apple Wallet, Apple Wallet registers a per-order Wallet device identifier and Wallet push token with Vetted so Wallet can request order updates; those registrations are removed when Wallet unregisters, when a stale token is pruned, or when you delete your account.
Order issue reports. If you report a problem with an order, your messages in that thread are shared with the café you ordered from (and visible to the Vetted team as a backstop) so it can be resolved.
Approximate area. If you grant location permission or choose an area manually, we use that area to show relevant cafés and sort them by distance. Device location stays in the app; only a reduced-precision area is sent with discovery requests, and we do not store any location history for discovery on our servers. The only location-related fact we ever store is the order-level arrival record described above — a timestamp and a café, not coordinates.
Usage analytics — on by default in the app, first-party, switchable off. The app records which screens and features you use — for example opening a café, tapping “Take me there”, saving a café, or viewing a menu — so we can understand what’s useful and improve Vetted. You can turn this off any time in Profile → Privacy & data. This is first-party product analytics, processed on our behalf by Mixpanel through its standard ingestion endpoint. In the app it is linked to your account after sign-in. Mixpanel may use your network IP address to estimate city, region, and country for analytics; Mixpanel discards the IP address after deriving that approximate location. Our first-party analytics in Mixpanel are never used for advertising, never combined with data from other apps or websites, and never shared for anyone else’s use. We send only structural facts (which action, counts, and internal café or relationship identifiers) — never your search text, notes, handles, share-link tokens, phone contacts, credentials, or precise GPS location.
Public-website analytics — on by default, first-party, switchable off. So we can understand public-website journeys, conversion, and funnels, the website creates a random web visitor id in this browser and a per-tab web session id. We use those to record public page views, link/CTA clicks, which page sections you scroll to, roughly how far down a page you scroll (in coarse buckets), and time on page, including the page type, route bucket, clean public page path (for example a role page or café slug), café slug/id, link category, destination type/host, sanitized UTM fields, referring domain, first-touch attribution, whether a paid-ad click id was present and what type it was, approximate city/region/country/timezone from Cloudflare request metadata, Cloudflare edge colo/continent, and coarse device/browser/operating-system family and major-version buckets parsed from the request. These events are sent to our own server first, sanitized, and then processed in Mixpanel through its standard ingestion endpoint. We do not load the Mixpanel browser SDK. We do not send Mixpanel the raw ad-click id, raw referrer URL, raw search term, page query string, private or unknown raw paths, raw IP address, raw user-agent, or any name, email, account, notes, credentials, or precise GPS location. Mixpanel IP geolocation is disabled for these website events.
Anonymous public-website counts — always on. In addition to the per-browser website journey above, we also keep anonymous aggregate website counts for page requests, browser page views, and link/CTA clicks. These aggregate count rows have no account id, no device id, no session id, no browser analytics id, no raw IP address, no raw user-agent property, and no Mixpanel IP geolocation. They are used for traffic totals and bot/human splits.
Ad-campaign measurement — website only. If you reached the site from one of our ads and tap “Get Vetted” / an App Store or TestFlight link, our own server may confirm that click to the configured ad platform that referred you (currently Reddit or Meta) so we can measure whether the campaign worked. This is server-to-server by Vetted; no third-party ad script runs in your browser. We send the ad-click identifier that platform itself gave you, sanitized campaign (UTM) fields, and the clean public page path. We do not send your IP address, raw user-agent, page query string, name, email, account id, notes, credentials, or location to the ad platform. Turning website analytics off clears the stored website visitor id, session attribution, and ad-click id state and stops this measurement for that browser.
Anonymous app usage counts — always on. In the app, we also keep a daily tally of active devices: it derives a coarse, daily-changing fingerprint that cannot be traced back to you and cannot be linked from one day to the next, is never tied to your account, stays on our own servers, and is never used for advertising or profiling.
Anonymous crash reports. If the app crashes or freezes, Apple's on-device diagnostics (MetricKit) give us a technical report — the app build number, the failure signal, and a technical stack trace. It is sent to our own servers with no account identifier attached, contains no location and nothing you typed, and is deleted after 90 days.
What we don't do
No advertising inside the app, no advertising SDKs or trackers loaded in your browser, and no “Allow Tracking” (ATT) prompt. Anonymous aggregate count rows never include an ad-click identifier’s value.
No selling of personal data, and no sharing with third parties for their own independent use. The third parties that touch your data are processors working for us or for the café: Square (payments), Apple (sign-in, push notifications, and Wallet order tracking if you choose it), Google (sign-in if you choose it), Mixpanel (app analytics, first-party website journey analytics, and anonymous aggregate website counts), Cloudflare (hosting), and — only for the website ad-campaign measurement described above — the ad platform that referred the visit.
No storing of card numbers — payment details are handled entirely by Square.
No tracking of your location in the background beyond the on-device arrival check described above, and no location history on our servers.
No third-party advertising or behavioural-profiling SDKs in your browser. Website analytics are first-party and can be switched off at any time. Any ad-campaign measurement happens server-to-server, never through a tracker loaded in your browser.
How it's stored
Data is stored on Cloudflare infrastructure. Authentication uses short-lived tokens; passwords are stored only as salted hashes. Vetted does not store phone numbers or uploaded address-book contacts for social matching, and it does not expose public profile pages or suggested follows. Café photography uploaded by café owners and Studio contributors is stored first-party on Vetted's own Cloudflare storage and served from our domain. If you choose Apple Wallet order tracking, Wallet update registrations are stored with the order so Vetted can notify Wallet when the order status changes. App usage analytics, while enabled, are processed and stored by Mixpanel as our processor through its standard ingestion endpoint. Public-website journey analytics and anonymous aggregate website counts are also processed in Mixpanel without raw IP, raw user-agent, or Mixpanel IP geolocation identifiers. No third-party ad code runs in your browser.
Your rights
Access & deletion, in-app. You can see your saved cafés, notes, and orders in the app, and delete your account at any time from Profile → Delete account — no email required.
Export & anything else, by email. Want a copy of your data, or have a request this policy doesn't cover? Email us (below). Honestly: export isn't a self-serve button yet — we prepare it by hand — but we will do it.
Deleting your account
You can delete your account at any time from Profile → Delete account in the app. This permanently removes your account record, saved cafés, notes, following data (handles, follow links, follows, and blocks), account-linked Studio contributor applications, sign-in, notification tokens (push and Live Activity), and Apple Wallet order registrations, revokes the associated Sign in with Apple token, disconnects Google sign-in when present, and deletes your analytics profile. Order records are kept as financial records, as described above. If you sent a Studio contributor application while signed out, email us to request deletion or export because that application is not linked to an account id. You can also stop analytics without deleting your account from Profile → Privacy & data.
Who is responsible & contact
Vetted operates this app and website and is the controller for the data described here (except your payment, which the café and Square process as described above). A formal legal entity designation for Vetted is pending and this policy will be updated when it is in place.