Effective date: 5 March 2026
1. Who We Are
JoyBow Coffee & Play ("we", "us", "our") operates the JoyBow Loyalty App. We are a business registered in Cyprus. This Privacy Policy explains how we collect, use, and protect your personal data when you use our mobile application.
We are committed to protecting your privacy in accordance with the General Data Protection Regulation (GDPR) and applicable Cyprus data protection legislation.
2. Data We Collect
| Data | Source | Purpose |
|---|---|---|
| Name | Registration / Google Sign-In | Account identification & personalisation |
| Email address | Registration / Google Sign-In | Account login & communication |
| Date of birth | Provided by you (optional) | Age verification & birthday rewards |
| Mobile phone number | Provided by you (optional) | Account recovery & notifications |
| Loyalty visit history | QR code scans | Tracking reward progress |
| Authentication tokens | Firebase / Google Auth | Secure sign-in |
3. Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Consent — You provide consent when you create an account and agree to these terms.
- Contractual necessity — Processing is necessary to provide you with the loyalty programme services.
- Legitimate interests — To improve our services, prevent fraud, and ensure the security of the App.
4. How We Use Your Data
- To create and manage your loyalty account.
- To track your visits and issue rewards.
- To personalise your experience (e.g. welcome messages, birthday offers).
- To communicate important updates about the App or your account.
- To detect and prevent fraudulent or abusive behaviour.
5. Third-Party Services
We use the following third-party services to operate the App:
- Firebase (Google) — Authentication, cloud database (Firestore), and hosting. Data may be processed in the EU and/or US. Firebase Privacy & Security.
- Google Sign-In — If you choose to sign in with Google, we receive your name and email from your Google account. Google Privacy Policy.
We do not sell your personal data to any third parties.
6. Data Retention
We retain your personal data for as long as your account is active. If you request account deletion, we will delete your personal data within 30 days, except where we are required to retain it by law.
7. Data Security
We implement appropriate technical and organisational measures to protect your data, including:
- Encrypted data transmission (HTTPS/TLS).
- Firebase security rules restricting database access to authenticated users and their own data only.
- Secure authentication via Firebase Auth with persistence.
No system is 100% secure, but we take reasonable precautions to safeguard your information.
8. Your Rights (GDPR)
As a data subject under the GDPR, you have the following rights:
- Right of access — Request a copy of your personal data.
- Right to rectification — Request correction of inaccurate data.
- Right to erasure — Request deletion of your account and data.
- Right to restrict processing — Request limited use of your data.
- Right to data portability — Receive your data in a machine-readable format.
- Right to object — Object to processing based on legitimate interests.
- Right to withdraw consent — Withdraw consent at any time without affecting prior processing.
To exercise any of these rights, please contact us at thejoybow@gmail.com.
9. Cookies
The App itself does not use cookies. Our website may use essential cookies for functionality (e.g. the OAuth authentication redirect). We do not use tracking or advertising cookies.
10. Children's Privacy
The App is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
11. International Data Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States, where Firebase servers are located. Such transfers are protected by appropriate safeguards, including Google's Standard Contractual Clauses.
12. Changes to This Policy
We may update this Privacy Policy from time to time. The "Effective date" at the top will be revised accordingly. We encourage you to review this page periodically.
13. Contact Us
If you have questions or concerns about this Privacy Policy or your personal data, please contact:
JoyBow Coffee & Play
Email: thejoybow@gmail.com
Website: joybowcoffeeandplay.com
You also have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection in Cyprus if you believe your data protection rights have been violated.