Legal

Privacy policy

Last updated: April 11, 2026

Pulled Coffee (“Pulled,” “we,” “us”) operates the Pulled mobile application and the pulled.coffee website. This policy explains what data we collect, how we use it, and your rights.

Data we collect

Account information. Email address, username, display name, profile photo (optional), and city. If you sign in with Apple or Google, we receive the name and email associated with that account.

Check-in data. When you check in at a shop, we collect: two photographs (captured in-app only), GPS coordinates, GPS accuracy, timestamp, device identifier, IP address, accelerometer data, and an optional rating and note. Photos are stored in Supabase cloud storage. Photos may be reviewed by automated AI systems and human reviewers for fraud prevention and challenge verification. We do not sell photographs to third parties.

Payment data. Subscriptions are processed by Apple (StoreKit) or Google (Play Billing). We receive a transaction identifier and subscription status but never see your full payment card details. Your PayPal email is collected solely for processing challenge reward payouts and is not shared with third parties beyond PayPal.

Device and usage data. Device type, operating system, app version, session duration, screens viewed, and crash reports. Device information is used for app operation and fraud prevention only.

Precise location data. We collect your precise GPS coordinates during each check-in to verify your proximity to the claimed shop (within approximately 100 meters). Location data is stored with your check-in record and is used for verification, fraud prevention, leaderboard ranking, and your Pull Map. We do not track your location in the background. We do not sell location data to third parties. Aggregated, anonymized location data may be used for internal analytics and product development.

Behavioral data. Streak history, challenge enrollment and progress, tier selection, badge achievements, leaderboard ranking, subscription history, and in-app activity. This data is used to operate the app, calculate leaderboard positions, verify challenge completions, and improve the product.

Quick Pulse responses. We collect optional responses to short in-app questions about your coffee habits and visit context. This data is anonymized and may be used in aggregate to improve the product. Individual responses are never shared with third parties in identifiable form.

Tax information. For users whose cumulative rewards reach $500 in a calendar year, we collect full legal name, mailing address, and a tax identification number (SSN, EIN, or local equivalent) for tax reporting compliance. This information is encrypted at rest and is used solely for compliance with applicable tax reporting obligations.

Referral data. When you use a referral code, we collect the referral relationship between accounts, the date of referral, and device identifiers to prevent fraud. Referral data is not sold or shared with third parties.

How we use your data

We use your data to operate the app, verify check-ins, process challenge rewards, maintain leaderboards, prevent fraud, send transactional emails, and improve the product. GPS and photo data are used for check-in verification and are not repurposed for advertising or profiling. We do not sell your personal data to third parties. Tax information is shared with applicable tax authorities as required by law.

Third-party services

We share data with the following services as necessary to operate Pulled:

  • Supabase: backend infrastructure, database, authentication, and photo storage
  • Google Places: shop location data and nearby shop detection
  • Mapbox: mapping and location services
  • Resend: transactional email delivery
  • PayPal: reward payouts (USD only)
  • AI photo verification services: challenge check-in and content moderation
  • OneSignal: push notifications
  • Apple and Google: subscription billing and app distribution

Each service processes data under its own privacy policy.

Data retention

Account data and check-in data, including photographs, are retained while your account is active. If you delete your account, we remove your personal data within 30 days. Anonymized, aggregated data (total check-ins per shop, city-level statistics) may be retained indefinitely.

Ratings and survey responses. Individual ratings and Quick Pulse responses are anonymized and retained permanently, even after account deletion. Your personal identity is removed from these records. Shop owners and third parties receive only aggregated data.

Tax records. Tax identification information and filing data are retained for a minimum of 7 years as required by applicable recordkeeping regulations, even after account deletion.

Winners page. If you complete a challenge and your payout is processed, your completion may be displayed on our Winners page using your first name, last initial, city, challenge type, and payout amount. You can opt out at any time in Settings.

Dormant accounts. Accounts dormant for more than 30 days after trial expiration are permanently deleted.

Data security

All data is transmitted over HTTPS. Photos and personal data are stored in Supabase with row-level security policies. Payment credentials are handled entirely by Apple, Google, and PayPal. We never store card numbers. Access to production data is restricted to authorized personnel.

Your rights

You can request a copy of your data, correct inaccurate data, or delete your account at any time by contacting hello@pulled.coffee. If you are in the EU, UK, or California, you have additional rights under GDPR, UK GDPR, or CCPA respectively, including the right to data portability and the right to opt out of data sales (we do not sell data, but you may exercise this right formally).

Account deletion

You can delete your account at any time through the app settings. Upon deletion, all personal data including your profile, check-in history, and photos is removed within 30 days. Tax records are retained for the legally required period. Subscriptions must be cancelled separately through Apple or Google to stop billing.

Age requirement

Pulled Coffee is intended for users 18 and older. We do not knowingly collect personal information from anyone under 18. The app enforces an age confirmation gate during account creation. If we learn that a user is under 18, we will delete their account and associated data.

Cookies and tracking

The pulled.coffee website uses essential cookies only. No third-party tracking cookies. The mobile app does not use cookies.

Changes to this policy

We may update this policy from time to time. Material changes will be communicated via email or in-app notification. Continued use of Pulled after changes constitutes acceptance of the updated policy.

Contact

Questions or requests: hello@pulled.coffee