Vetted is a curated guide to specialty coffee, and — at cafés that offer it — a way to order ahead, timed to your arrival. This policy explains what we collect and why. We do not sell your data and we do not show ads. We load no cross-site trackers on the public website. Detailed usage analytics in the app are first-party, on by default, and can be turned off from Profile → Privacy & data. Public-website analytics are first-party, on by default, and can be turned off from this page or the website privacy choices control.
Website analytics choices
Website analytics are on for this browser.
What we collect
Account identity. If you sign in with Apple, we store the anonymous Apple user identifier and, if you share it, your email address (which may be an Apple private-relay address). If you sign in with Google, we store the Google account identifier and verified email address from the Google identity token. If you sign up with email and password instead, we store your email address, a salted hash of your password (never the password itself), and short-lived verification codes while you confirm your address or reset your password. You may also set an optional display name on your account. This is used only to keep you signed in, show your account identity, and sync your account across devices.
Saved cafés and folders. The cafés you bookmark and any custom folder names you use to organize them, linked to your account so they appear on your devices.
Café notes. Notes you write on a café are stored on our servers so they sync across your devices. Notes are private by default. If you choose to share a note with followers, it can be read only by signed-in users whose follow request you have accepted, only while you still have that café saved, and not by anyone either of you has blocked. Before follower sharing, Vetted runs a narrow automated check for clearly objectionable text and obvious link spam; this check runs on Vetted's server and does not send your note to an outside moderation service. You can make a shared note private again or delete it at any time. Notes are deleted with your account.
Following and private notes. If you use Vetted's following features, we store your handle if you set one, opaque follow-link token, follow requests, accepted follow relationships, and blocks so the app can show trusted notes and enforce your choices. Exact handles and share links are private request mechanisms, not public profile pages or suggested follows. Vetted does not upload your phone contacts or address book, and we do not use phone numbers to help people find, follow, or identify each other.
Café suggestions. If you suggest a café, we store the name, address, optional website, and your account id so Vetted can review the suggestion, avoid duplicate submissions, and notify you if it becomes a published café page.
Café issue reports. If you report a problem with a café listing, we store the issue category, your description, and your account id so Vetted can review and resolve it.
Feedback & support emails. If you choose Send feedback in the app, Vetted opens a pre-addressed email composer. The draft includes the app version, build number, iOS version, and whether you are using the development or production app so we can troubleshoot; the email links that diagnostic context to its sender address, but it does not add your account id, device identifier, or location. Your email provider sends the message, and we receive the sender address and whatever you choose to write at the support inbox.
Follower-note reports. If you report a note shared by someone you follow, we store your account id, the note author's account id, the café, a bounded report reason, the exact reported note text and update time, and the report's moderation status. This lets an authorized Vetted administrator review what you actually saw even if the author later edits the note. A moderator can dismiss the report or return the exact reported version to private visibility; an old report cannot remove a later edit. Report records and their note snapshots are deleted if either the reporter or author deletes their account. Reporter identity and report details are not shown to the note author or other users.
Studio contributor applications. If you apply to author café data in Studio, we store your name, email, coffee background, optional city/region, optional website or social links, and the information you provide so Vetted can review the application. Applying does not guarantee access or a response.
Orders & payments. When you order ahead, payment is processed by Square, the café's payment processor, through that café's own Square account — the café is the seller. Your card details go directly to Square and never touch Vetted's servers. For card checkout, Vetted may supply your account email address to Square as billing contact information so Square can run payment authentication and fraud-prevention checks. For each order Vetted stores what you'd expect on a receipt: the items, totals, timestamps, order status, your optional pickup note, and Square's order/payment identifiers. If you choose Track in Apple Wallet, Vetted sends that order's café, items, total, status, timestamps, and order identifier to Apple Wallet so Wallet can show and update the pickup card; we do not include your pickup note, name, email, card details, or address in the Wallet order. Order records are kept as financial records — they survive account deletion, but are no longer linked to a usable identity once your account data is erased. (How charging works is covered in the Purchase Terms.)
Arrival check-in (geofenced ordering). Arrival-timed orders work by your phone monitoring the café's location region on-device, using Apple's geofencing — your movements are processed by iOS on your phone, not streamed to us. When you arrive (or tap “I'm here”), the app tells our server to start the order, and we store an order-level arrival record: a timestamp and which café. We never receive or store your coordinates, route, or movement history.
Notification tokens. If you allow notifications, we store the Apple push token for your device; it can deliver order-status updates and, while your nearby-café alert preference is on, subscribe that device to untargeted background wakes telling the app to check for newly published cafés. For active Vetted administrator accounts only, other authorized administrators can see in Studio whether the account has registered notification devices and the number registered for each APNs environment; they never see the tokens. After preview and explicit confirmation, an administrator can send those devices a clearly marked test café notification to validate delivery and tap routing. This test use does not change the account's discovery preference or expose device information to consumers or curators. Beside the token, we store the subscription flag plus operational pacing markers: the last wake-attempt time and the public café publication timestamp and identifier last claimed for that device. We use those markers only to limit wake attempts and avoid duplicates. They are not your coordinate, a local café match, or a location-targeted audience. Turning nearby-café alerts off disables those wakes without disabling order updates or the narrow administrator-account test described above. When you sign out, the app clears alert state on the phone and makes a best-effort deletion request for the server registration; if the device is offline, that request may not arrive. Deleting your account removes the registration on the server. For the Lock Screen / Dynamic Island order tracker we also store a short-lived, per-order Live Activity token, which is removed when that order finishes or is cancelled — and always deleted with your account. If you choose Track in Apple Wallet, Apple Wallet registers a per-order Wallet device identifier and Wallet push token with Vetted so Wallet can request order updates; those registrations are removed when Wallet unregisters, when a stale token is pruned, or when you delete your account.
Nearby-café alerts. Where this feature is available, its in-app preference defaults on. Delivery requires iPhone notification permission. Discovery never shows Apple's notification prompt automatically; its dedicated permission action is Allow notifications in Profile > Notifications. Order-update flows may request the same system permission separately after an order-related action. You can turn the discovery preference off at any time in Profile > Notifications. While the app is open, it may obtain and round a fresh device location. The app treats that local coordinate as eligible for alert matching for no more than 24 hours. Because iOS can suspend the app, the stored local record may remain until the app can next process or clear its state, but it is not used for alert matching after the 24-hour limit. An untargeted list of recently published cafés comes from Vetted; your phone compares that public list with the eligible local coordinate. Neither the coordinate nor the resulting match set is sent to Vetted as part of alert matching; opening a result makes the same ordinary café request as opening it elsewhere in the app. While app analytics are enabled, the only alert-specific facts sent to Mixpanel are the count/status/interaction facts described below. The app never starts Core Location from a background wake.
New-city discovery. Where this separately gated feature is available, its in-app preference defaults on and uses the same iPhone notification permission described above. New-city decisions use only fresh locations obtained while the app is open. The first valid location silently seeds local state. The app rounds each eligible coordinate to two decimal places and keeps at most eight local travel anchors with first-seen time, last-seen time, and visit count. Nearby observations merge locally and least-recently-used anchors beyond the cap are removed. An anchor not observed for 180 days stops qualifying for decisions; a separate local record containing a rounded coordinate and time stops preventing a repeat city discovery after 90 days. Because iOS can suspend the app, those expired records may remain stored until the app next processes city state, when they are removed. Your phone compares eligible local state with an untargeted public index of published Vetted cafés. Vetted does not receive the device coordinate, anchors, detection records, or resulting match set as inputs to the decision. A city card may schedule one passive local reminder; movement-based cancellation is best-effort when the app later receives a foreground fix because the feature adds no background location monitoring. Turning new-city discovery off, signing out, or deleting the account removes its anchors, detection records, and pending reminder. Re-enabling it silently seeds a new first anchor.
Order issue reports. If you report a problem with an order, your messages in that thread are shared with the café you ordered from (and visible to the Vetted team as a backstop) so it can be resolved.
Approximate area. If you grant location permission or choose an area manually, we use that area to show relevant cafés and sort them by distance. For ordinary Browse and Discover requests, only a reduced-precision area is sent, and we do not store location history for discovery on our servers. On-device discovery alerts are different: the recent-café list and city-coverage index are untargeted, while the alert coordinate, travel anchors, and city-detection records stay on your phone. The only location-related fact we ever store on Vetted's servers is the order-level arrival record described above — a timestamp and a café, not coordinates.
Usage analytics — on by default in the app, first-party, switchable off. The app records which screens and features you use — for example opening a café, tapping “Take me there”, saving a café, viewing a menu, or interacting with an on-device discovery alert — so we can understand what’s useful and improve Vetted. For nearby-café and new-city discovery, custom analytics properties contain only structural facts such as whether a detection, card, or reminder occurred; notification-permission and preference changes; candidate counts; bounded scheduling reasons; and bounded open destinations. Vetted does not add café identity, coordinates, distance, city/neighbourhood labels, cached-location age, notification payloads, travel anchors, city-detection records, or travel history to those events. Subsequent ordinary café views and saves use the same analytics already described for opening or saving a café elsewhere. You can turn analytics off any time in Profile → Privacy & data. This is first-party product analytics, processed on our behalf by Mixpanel through its standard ingestion endpoint. In the app it is linked to your account after sign-in. Mixpanel may use your network IP address to estimate city, region, and country for analytics, including for alert events; Mixpanel discards the IP address after deriving that approximate location. Our first-party analytics in Mixpanel are never used for advertising, never combined with data from other apps or websites, and never shared for anyone else’s use. Apart from the alert limits just described, we send only structural facts (which action, counts, and internal café or relationship identifiers) and the café's public business display name — never your search text, notes, handles, share-link tokens, phone contacts, credentials, or precise GPS location.
Public-website analytics — on by default, first-party, switchable off. So we can understand public-website journeys, conversion, and funnels, the website creates a random web visitor id in this browser and a per-tab web session id. We use those to record public page views, link/CTA clicks, which page sections you scroll to, roughly how far down a page you scroll (in coarse buckets), and time on page, including the page type, route bucket, clean public page path (for example a role page or café slug), café slug/id and public business display name, link category, destination type/host, sanitized UTM fields, referring domain, first-touch attribution, whether a paid-ad click id was present and what type it was, approximate city/region/country/timezone from Cloudflare request metadata, Cloudflare edge colo/continent, and coarse device/browser/operating-system family and major-version buckets parsed from the request. These events are sent to our own server first, sanitized, and then processed in Mixpanel through its standard ingestion endpoint. We do not load the Mixpanel browser SDK. We do not send Mixpanel the raw ad-click id, raw referrer URL, raw search term, page query string, private or unknown raw paths, raw IP address, raw user-agent, or any person or account name, email, account, notes, credentials, or precise GPS location. Mixpanel IP geolocation is disabled for these website events.
Anonymous public-website counts — always on. In addition to the per-browser website journey above, we also keep anonymous aggregate website counts for page requests, browser page views, and link/CTA clicks. These aggregate count rows have no account id, no device id, no session id, no browser analytics id, no raw IP address, no raw user-agent property, and no Mixpanel IP geolocation. They are used for traffic totals and bot/human splits.
Ad-campaign measurement — website only. If you reached the site from one of our ads and tap “Get Vetted” / an App Store or TestFlight link, our own server may confirm that click to the configured ad platform that referred you (currently Reddit or Meta) so we can measure whether the campaign worked. This is server-to-server by Vetted; no third-party ad script runs in your browser. We send the ad-click identifier that platform itself gave you, sanitized campaign (UTM) fields, and the clean public page path. We do not send your IP address, raw user-agent, page query string, name, email, account id, notes, credentials, or location to the ad platform. Turning website analytics off clears the stored website visitor id, session attribution, and ad-click id state and stops this measurement for that browser.
Anonymous app usage counts — always on. In the app, we also keep a daily tally of active devices: it derives a coarse, daily-changing fingerprint that cannot be traced back to you and cannot be linked from one day to the next, is never tied to your account, stays on our own servers, and is never used for advertising or profiling.
Anonymous crash and performance diagnostics. If the app crashes or freezes, Apple's on-device diagnostics (MetricKit) give us a technical report — the app build number, crash signal or hang duration, and a technical stack trace. Crash reports are classified as Crash Data and freeze/hang reports as Performance Data. They are sent to our own servers with no account identifier attached, contain no location and nothing you typed, and are deleted after 90 days.
What we don't do
No advertising inside the app, no advertising SDKs or trackers loaded in your browser, and no “Allow Tracking” (ATT) prompt. Anonymous aggregate count rows never include an ad-click identifier’s value.
No selling of personal data, and no sharing with third parties for their own independent use. The third parties that touch your data are processors working for us or for the café: Square (payments), Apple (sign-in, push notifications, and Wallet order tracking if you choose it), Google (sign-in if you choose it, and Gmail for feedback and support email), Mixpanel (app analytics, first-party website journey analytics, and anonymous aggregate website counts), Cloudflare (hosting), and — only for the website ad-campaign measurement described above — the ad platform that referred the visit.
No storing of card numbers — payment details are handled entirely by Square.
No tracking of your location in the background beyond the on-device arrival check described above, and no location history on our servers. Nearby-café alerts never start location services in the background; a background wake can use only a recent coordinate already cached on your phone. New-city discovery uses foreground fixes only and adds no background location monitoring.
No third-party advertising or behavioural-profiling SDKs in your browser. Website analytics are first-party and can be switched off at any time. Any ad-campaign measurement happens server-to-server, never through a tracker loaded in your browser.
How it's stored
App and account data is stored on Cloudflare infrastructure. Feedback and support emails are received and stored in Google Gmail; we keep them while reasonably needed to respond, investigate the issue, and maintain a support record, and you can ask us to delete one. Authentication uses short-lived tokens; passwords are stored only as salted hashes. Vetted does not store phone numbers or uploaded address-book contacts for social matching, and it does not expose public profile pages or suggested follows. Follower-note reports and their snapshots are visible only to authorized administrators through the role-gated moderation queue. Café photography uploaded by café owners and Studio contributors is stored first-party on Vetted's own Cloudflare storage and served from our domain. If you choose Apple Wallet order tracking, Wallet update registrations are stored with the order so Vetted can notify Wallet when the order status changes. App usage analytics, while enabled, are processed and stored by Mixpanel as our processor through its standard ingestion endpoint. Public-website journey analytics and anonymous aggregate website counts are also processed in Mixpanel without raw IP, raw user-agent, or Mixpanel IP geolocation identifiers. No third-party ad code runs in your browser.
Your rights
Access & deletion, in-app. You can see your saved cafés, custom folders, notes, and orders in the app, and delete your account at any time from Profile → Delete account — no email required.
Export & anything else, by email. Want a copy of your data, or have a request this policy doesn't cover? Email us (below). Honestly: export isn't a self-serve button yet — we prepare it by hand — but we will do it.
Deleting your account
You can delete your account at any time from Profile → Delete account in the app. This permanently removes your account record, saved cafés and custom folders, notes, follower-note reports involving you and their snapshots, following data (handles, follow links, follows, and blocks), account-linked Studio contributor applications, sign-in, notification tokens and their discovery-wake subscription/pacing markers, Live Activity tokens, and Apple Wallet order registrations, revokes the associated Sign in with Apple token, disconnects Google sign-in when present, and deletes your analytics profile. The app also clears its cached alert coordinate, pending café digest, local travel anchors, city-detection records, and pending or delivered discovery notifications when you sign out or delete the account. Turning new-city discovery off performs the same city-state cleanup without deleting the account. Sign-out deletion of the server push registration is best-effort as described above; account deletion removes it server-side. Order records are kept as financial records, as described above. Feedback and support emails are not removed automatically because the composer does not add your account id; ask us by email if you want one deleted. If you sent a Studio contributor application while signed out, email us to request deletion or export because that application is not linked to an account id. You can also stop analytics without deleting your account from Profile → Privacy & data.
Who is responsible & contact
Vetted operates this app and website and is the controller for the data described here (except your payment, which the café and Square process as described above). A formal legal entity designation for Vetted is pending and this policy will be updated when it is in place.