Privacy Policy

Last updated: February 12, 2026

Overview

This Privacy Policy explains how bag.coffee collects, uses, and shares information when you use our website and related services (the “Service”).

Information we collect

We collect the following categories of information:

  • Account information: If you sign in using Google, we receive information such as your name, email address, profile picture, and provider identifiers needed to authenticate you and keep you signed in.
  • Usage and device information: Like most websites, we and our infrastructure providers may log information such as IP address, user agent, approximate location derived from IP, pages requested, timestamps, and analytics identifiers for security, reliability, abuse prevention, and service improvement.
  • Service data: We may record limited event data (for example, referral/click information used to measure how the Service is used).

How we use information

We use information to:

  • Provide, operate, and maintain the Service (including authentication and session management).
  • Monitor, prevent, and investigate fraud, abuse, and security incidents.
  • Improve the Service, including performance and product experience.
  • Communicate with you about the Service (for example, responding to support requests).

How we share information

We share information with service providers and partners who help us operate the Service. Depending on how you use the Service, this may include:

  • Google (for authentication, if you choose to sign in with Google).
  • Cloudflare (for hosting, content delivery, and network security).
  • Database and storage providers (to store account and Service data).
  • Analytics providers: PostHog (for product analytics and error monitoring) and Umami (for privacy-focused, cookieless web traffic analytics).
  • AI service providers (to extract and normalize coffee listing information from roaster-provided product pages; this is intended to process product content, not your personal information).

We do not sell your personal information.

Cookies and similar technologies

We use essential cookies and similar technologies to keep you signed in and to help protect the Service (for example, security and CSRF protections). Our infrastructure providers may also set cookies or use similar technologies for security and performance.

PostHog may set cookies for session tracking and user identification when you are signed in. Umami is cookieless and does not set any cookies or store personal data in your browser.

Data retention

We retain personal information for as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. For example, we retain account information while your account is active and may retain certain records for a period of time after deletion for security, fraud prevention, backups, and compliance.

Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, or restrict the processing of your personal information. You may also have the right to object to certain processing.

To make a request, contact us using the email below. We may need to verify your identity before responding.

International transfers

Our service providers may process and store information in countries other than your own. When information is transferred internationally, we take steps designed to ensure an appropriate level of protection consistent with applicable law.

Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version on this page and update the “Last updated” date.

Contact

If you have questions about this privacy policy, please reach out to hello@bag.coffee.