Last updated: 9 September 2026
COUNTLOYAL is a registered business name of the Trustee for the Reeve Family Trust, ABN 56 462 924 953. We are referred to as "we", "us" and "our" in this policy. We operate the countloyal.com website and digital loyalty platform, and our postal address is PO Box 23036, Docklands VIC 8012, Australia. We are committed to protecting the privacy of our users, including both business operators and their customers.
We collect the following types of information:
Business operators: email address, business name, and programme configuration when you create an account. Payment information is processed securely by Stripe and is not stored on our servers.
Public business contacts for a one-off introduction: where a café visibly publishes a generic business inbox on its own website, we may record the business name, that exact address, the page URL and the capture time. We do not use personal webmail addresses, named contacts, guessed addresses, purchased lists or enrichment data for this purpose.
Customers of businesses: name and mobile phone number when you join a loyalty programme, plus stamp and reward activity. If you explicitly link Square on your CountLoyal card, we also record the linked purchase's item names, quantities, time and total, including non-qualifying items. We do not store your card number or payment credentials.
People who use the free café audit: the café name you type, and any website or profile links you choose to add. If you ask us to email you a copy of the result, we also collect your first name and email address. See section 4.
Website visitors: usage analytics via Cloudflare Web Analytics, Vercel Analytics and PostHog. These tell us which pages are used and where people get stuck. We do not use them to build advertising profiles, and we do not sell what they collect.
We use information to operate the loyalty platform, produce the café audit you request, send transactional SMS and email messages (such as card links, reward notifications and your audit report), process payments, improve our service, and, where you have explicitly linked Square, understand purchase patterns for your loyalty experience. We do not sell personal information to third parties.
We send marketing email — the six-week café marketing course and the Weekly Café Growth Note — only to people who have explicitly asked for it. Every one of those emails carries an unsubscribe link, and unsubscribing from one does not change any other preference you have set.
Separately, and only where permitted by applicable law, we may send a single relevant business-to-business introduction to a generic café inbox that the café has publicly listed on its own website. It is not a subscription: we do not send a follow-up unless the recipient engages. The message identifies us, includes a free unsubscribe link and is suppressed immediately if the recipient opts out, complains or bounces.
The audit reads public information only. It never logs in to any account, never publishes anything, and never contacts anyone on your behalf.
To find your café, we send the name you typed to the Google Places API and read the public listing it returns. We then fetch the public pages of the website that listing points to, or the website link you supplied. If you give us a Facebook or Instagram link we check that it is a validly formed address for that platform; we do not fetch those pages.
Information Google returns about a business is shown to you live and is not stored by us, beyond the place identifier and coordinates that Google's terms permit. If you do not ask us to email you a report, the audit stores nothing about the café you checked.
Application data is stored in Supabase, hosted on Amazon Web Services in the Tokyo region (ap-northeast-1). We use row-level security policies so that business data is only accessible to the account owner, and all connections use TLS encryption.
This means personal information is stored outside Australia. Several of the providers listed below also operate outside Australia, so your information — and, where you are a business operator, your customers' information — may be stored or processed overseas, including in Japan, the United States and the European Union. We take reasonable steps to ensure our providers handle it appropriately, but overseas recipients are not always subject to Australian privacy law. We intend to move application data to an Australian region; this section will be updated when that happens, and not before.
We use the following providers. Each has its own privacy policy.
We keep account, programme, member and transaction records while an account is active and for only as long afterwards as they are needed to provide the service or meet legal, accounting, dispute, fraud-prevention and security obligations. A cancellation stops future paid service but does not itself delete records.
After a verified closure or deletion request, we delete or de-identify personal information that is no longer required. Limited records may remain where we must keep them for one of the obligations above. Suppression records are retained so that an unsubscribe, complaint or hard bounce stays honoured. Copies in provider backups expire through the provider's backup cycle rather than being removed from an individual backup immediately.
You may request access to, correction of, export of, or deletion of your personal information at any time by contacting us at hello@countloyal.com. Business operators and customers can request account or personal-information deletion by emailing us directly; customers may also contact the business whose programme they joined. We verify the requester's identity and authority before disclosing or deleting information. There is currently no self-service business-account deletion control in the dashboard.
We may update this policy from time to time. We will notify registered users of material changes via email.
You do not need an account to contact us about privacy. Email hello@countloyal.com, or write to us at PO Box 23036, Docklands VIC 8012, Australia.