Privacy

Privacy Policy

Last updated: May 26, 2026 · Version 2026-05-26

Information We Collect

We collect account information such as your name, nickname, email address, phone number, avatar, and profile details when you create or update an account.

We collect order information such as cart items, selected customization options, order type, payment method selection, table, dining session, order status, and order history.

If you contact support, we save your message and contact details so the coffee shop can respond. If email delivery fails, the support ticket can still remain stored for follow-up.

Authentication And Account Security

Vaelith uses cookie-based authentication. Access and refresh tokens are stored in secure HTTP-only cookies and are not intentionally exposed to JavaScript.

We use email verification codes, password reset links, waiter setup links, Google sign-in, CSRF protection, account status checks, and session revocation to protect accounts.

Administrators may suspend, deactivate, reactivate, or revoke sessions for accounts according to the role and account lifecycle rules supported by the backend.

Cookies

Necessary cookies keep login, CSRF protection, cart, checkout, and account sessions working. These cookies are required for the application to function.

You can choose whether to allow analytics and marketing cookies. Your guest choice is stored locally and can be synced to your account after login.

If the cookie policy version changes, the application may ask you to review your cookie choice again.

Orders, Tables, And Notifications

For dine-in orders, we process dining session and table information so customers, waiters, and admins can manage reservations, occupied tables, dirty tables, and completed visits.

We use real-time WebSocket events and an in-app notification center to show updates about orders, tables, dining sessions, and account activity. We do not currently provide mobile push notifications or email order-status digests.

Order history, table history, and audit-related information may be retained so the coffee shop can operate, troubleshoot, and preserve business records.

How We Use Information

We use information to create and manage accounts, process orders, handle carts and favorites, support dine-in sessions, provide waiter and admin workspaces, send account emails, and respond to support requests.

We may use operational logs, audit logs, and request identifiers to secure the service, investigate errors, and understand important administrative actions.

Sharing And Storage

Information is used by the coffee shop and its application services. Email providers may process account, setup, reset, verification, or support emails when those messages are sent.

Uploaded media such as product images, category images, and avatars may be stored locally or in object storage depending on the deployment configuration.

Your Choices

You can update profile details, avatar, password, Google connection, email address, and cookie preferences from account settings when the backend allows the action for your role.

Customers can self-deactivate and restore their account by email code. Some admin-managed account states require administrator action or support contact.

Contact

For privacy questions or account help, use the Support page. Support messages are saved first and then delivered to the configured coffee shop support email.