Teambrew Privacy Policy
Last updated: 14 September 2026
Teambrew helps hospitality businesses coordinate staff, shifts, announcements, and operational checks (food safety, cleaning, opening/closing). This page describes what Teambrew actually stores and does.
Who this covers
Teambrew is used by two kinds of people: the owner/manager who sets up a business workspace, and staff who join it with an invite code. This policy covers both.
Information we store
- Account credentials — email address and password, handled by Supabase Auth, Teambrew's database and authentication provider. Teambrew itself never sees or stores your raw password.
- Workspace details — business name, location names and addresses you enter, invite codes.
- Staff details — name, role (staff/manager), which location you belong to, and, if the owner chooses to enter one, an hourly pay rate (visible only to the owner, never to other staff).
- Shift and attendance data — shift times, clock-in/clock-out timestamps, time-off requests and their status, shift-cover requests and claims.
- Operational records — food-safety check results, cleaning-task completions, opening/closing checklist configuration, equipment settings.
- Device push token (only if you enable notifications) — a token that identifies your device to Apple/Google/Expo's push-delivery services, so Teambrew can send you a notification. This token is deleted if you turn notifications off or uninstall the app.
- Billing status — trial start date and, if you redeem a discount code, which code and when. Teambrew does not currently process payments and stores no payment card details anywhere.
We only use this information to operate, secure, and improve Teambrew — never to sell to third parties, and never for advertising.
Who else sees this data
- Supabase, the database/auth provider Teambrew is built on, processes and stores all of the above on Teambrew's behalf.
- Expo's push notification service relays a notification to your device using the device push token above, if you have notifications enabled. It does not see the content of shift data, only the notification text itself.
- Data is scoped per business: a staff member's data is only ever visible to people in the same business workspace, enforced at the database level, never to another business using Teambrew.
- No data is sold, rented, or shared with advertisers.
Your control
Workspace owners can request corrections or deletion of workspace data, and any user can request their own account be deleted, by contacting the address below. Deleting a workspace removes its staff, shift, and operational records.
Data retention
Data is kept for as long as the workspace remains active, so managers retain an accurate operational history. If a workspace owner requests deletion, associated records are removed within a reasonable time, subject to any records Teambrew is legally required to retain longer (for example, food-safety logs relevant to a health inspection).
Security
Teambrew uses authenticated access controls and row-level workspace isolation enforced by the database itself, not only the app. No service can guarantee absolute security, so keep your account credentials private and use a strong, unique password.
Children's privacy
Teambrew is a workplace tool intended for use by employees of hospitality businesses and is not directed at children.
Changes to this policy
If how Teambrew handles data changes materially, this page will be updated and the "Last updated" date above will change.
Contact
Add a real support email here before submitting to the App Store or Play Store — both require a working contact address on this page.