who we are
The Daily Press Cafe (“we”), 22001 Michigan Ave, Suite 150, Dearborn, MI 48124. questions about this policy or your data go to support@dailypresscafe.com.
what we collect and why
we only ask for what the order or the account needs. optional fields are marked optional.
| category | what it is | why |
|---|---|---|
| account | name, email, password (stored hashed), optional phone and birthday | run your account, your press pass and rewards, the birthday treat |
| orders | items, pickup name, phone, email for the receipt, order history; for delivery also the address and drop-off notes | make and hand off the order, send the receipt and status, handle problems, keep the books |
| rewards | press points ledger, reward redemptions, promo codes you claim | count and honor your points and promos |
| devices | push notification token and platform, only if you allow notifications in the app | order status pushes; news and offers only if you turn those on |
| website | your cart, your checkout contact details and your last order link, saved in your own browser (see storage below) | keep your order between pages and visits |
we don’t use analytics scripts, advertising pixels or cross-site tracking, and we don’t make automated decisions about you.
payments
cards are processed by Clover (Fiserv). on the website and in the app the card number is typed into Clover’s secure hosted form, so it never reaches our servers and we never store it. we keep only the payment status and Clover’s payment reference with the order record.
face id and fingerprint
biometric unlock in the app happens entirely on your device through Apple or Google. we never receive or store biometric data.
who receives it
each service gets only what its job needs:
- Clover (Fiserv): card payments and refunds.
- Vercel: hosts the website and our api; Neon: hosts our database. both in the united states.
- Resend: sends order receipts and account emails.
- Expo: delivers push notifications to the app.
- our delivery partner, only when you choose delivery: your name, phone, address and drop-off notes, so the driver can find you.
- OpenStreetMap: the map on our site loads from openstreetmap.org, which receives your ip address when it loads. it sets no cookies.
we don’t sell or share personal information for advertising, so there is nothing to opt out of. if that ever changes we will add an opt-out link to the footer before it does.
cookies and storage
we set no cookies of our own. the site keeps three items in your browser’s local storage, all strictly necessary:
| name | purpose | how long |
|---|---|---|
| dp.cart.v1 | your cart, pickup or delivery choice and address | until you order or clear it |
| dp.contact.v1 | the name, phone and email you typed at checkout, so you don’t retype them | until you clear your browser data |
| dp.lastOrder.v1 | a link back to your most recent order’s tracker | until you clear your browser data |
on the checkout page Clover’s secure card form may set strictly necessary cookies for fraud prevention and to complete the payment. you can clear local storage any time in your browser settings.
news and offers
order updates are part of the service. news and offers are separate: they are off until you switch them on in the app, and you can switch them off any time in account settings. every marketing email has a one-click unsubscribe.
how long we keep it
- account details: until you delete the account.
- order and payment records: seven years, for tax and bookkeeping. after an account deletion they are kept without your name.
- guest checkout details: kept with the order record above.
- push tokens: until you sign out, uninstall the app, or 90 days without use.
- hosting request logs (including ip addresses): kept briefly by our hosting provider for security, then discarded.
your choices and requests
you can ask to see, correct, export or delete the information we hold about you, or ask us to stop using it. email support@dailypresscafe.comfrom the address on your account or order so we can confirm it’s you. guests can use the email from their receipt. we answer within 30 days.
you can also delete your account yourself in the app (account → delete account). the full steps are on delete your account.
children
accounts are for people 13 and over. we don’t knowingly collect information from children under 13; if you think we have, email us and we will delete it.
security
every page and api call runs over https, passwords are hashed, and card numbers never touch our systems. no system is perfect; if something goes wrong we will tell affected people promptly.
changes to this policy
each version is dated at the top of this page. before a material change to how we use your information takes effect we will announce it in the app’s news feed and by email to account holders.
