Privacy Policy
This Privacy Policy explains how Coff LLC ("Coff", "we", "us", or "our") collects, uses, discloses, and protects information when you visit coff.app, sign in at dashboard.coff.app, or otherwise use the Coff platform and related services (together, the "Services").
Coff provides software that local and small businesses use to run their operations — managing leads and customers, quotes and invoices, scheduling, inventory, messaging, and an AI assistant. In most cases the businesses that use Coff (our "Customers") decide what information about their own clients they put into Coff; for that information the Customer is the controller and Coff acts as a processor on the Customer’s behalf, as described in Section 9.
1. Who this policy applies to
This policy applies to three groups of people whose information we may handle:
- Visitors
- People who browse our public marketing site at coff.app without signing in.
- Account users
- People who create or use a Coff account to operate a business workspace — owners, employees, and invited teammates.
- Customer contacts
- People whose details a Customer stores in Coff (for example, a business’s own leads, clients, or patients). We process this information on the Customer’s instructions; the Customer’s own privacy notice, not this one, primarily governs it.
2. Information we collect
Information you provide
- Account and profile details — name, email address, phone number, business name, role, and password credentials (stored only as a salted hash, never in plaintext).
- Content you enter into the Services — customer and lead records, quotes, invoices, notes, calendar events, inventory items, files you upload, and messages you send through Coff.
- Billing details — your plan and, for paid subscriptions, information needed to process payment (see Section 5). Full card numbers are handled by our payment processor and are never stored on Coff’s servers.
- Communications — messages you send to support at team@coff.app or by phone, and your responses to surveys or prompts.
Information collected automatically
- Device and log data — IP address, browser type, operating system, referring pages, and timestamps, recorded in server logs for security and reliability.
- Usage data — features used and general activity within the Services, used to keep the product working and to improve it.
- Cookies and similar technologies — a small number of strictly necessary cookies keep you signed in and secure. We do not use third-party advertising or cross-site tracking cookies. See our Cookie Policy for the full list.
Information from third parties
If you sign in with Google, we receive basic profile information (such as your name and email address) from Google to create or match your account. If you connect an optional integration, we receive data from that service only as needed to provide the feature you enabled.
3. How we use information
We use the information above to:
- Provide, maintain, and secure the Services and your account.
- Authenticate you, prevent fraud and abuse, and enforce our terms.
- Process payments and manage subscriptions.
- Respond to your requests and provide customer support.
- Send service and transactional messages (for example, security alerts, receipts, and important changes to the Services).
- Understand how the Services are used so we can fix problems and improve them.
- Comply with law and enforce our agreements.
We do not sell your personal information, and we do not use the content you or your Customers store in Coff to train generative-AI models. AI features process your content only to produce the output you request, in the moment you request it.
4. Legal bases for processing
Where the EU or UK GDPR applies, we rely on the following legal bases:
- Contract
- To provide the Services you or your organization signed up for.
- Legitimate interests
- To secure, maintain, and improve the Services, and to prevent abuse — balanced against your rights.
- Consent
- Where we ask for it, such as certain optional communications; you may withdraw consent at any time.
- Legal obligation
- To meet our obligations under applicable law, including tax and accounting rules.
Where Coff processes personal information on a Customer’s behalf, the Customer is responsible for having a valid legal basis for that processing.
5. Payments
Paid subscriptions are processed by Whop, Inc. When you pay, your card details are collected and processed directly by Whop under Whop’s own privacy policy and security standards. Coff receives only limited billing metadata — such as the membership and plan identifiers, the status of a charge, and the billing period — which we use to manage your subscription and produce receipts. Coff does not receive or store payment-card numbers.
6. How we share information
We share information only as described here, and never sell it:
- Within your workspace
- Content in a business workspace is visible to the account users that workspace’s administrators authorize.
- Service providers (sub-processors)
- Vendors that help us run the Services under contract, listed in Section 8, including our hosting and payment providers.
- Legal and safety
- When required by law, to respond to lawful requests, or to protect the rights, property, and safety of Coff, our users, or the public.
- Business transfers
- In connection with a merger, acquisition, or sale of assets, subject to this policy and with notice where required.
- With your direction
- To third-party services you connect, or otherwise at your instruction.
7. How we protect information
Coff is built to meet the requirements of HIPAA, SOC 2, and GDPR. We do not claim to hold any third-party certification or attestation, and none is asserted here. The safeguards we currently maintain include:
- Encryption of data in transit (TLS) and at rest.
- Role-based, tenant-scoped access controls that separate each business’s data (logical multi-tenant isolation).
- Mandatory two-factor authentication (TOTP) available on accounts, and required where a workspace enables it.
- Audit logging of access to sensitive records, with least-privilege access for our own staff.
- Least-necessary retention and per-request AI processing that does not train models on your content.
No method of transmission or storage is perfectly secure, but we work to protect your information using measures appropriate to its sensitivity.
8. Where information is processed
Coff hosts and operates the Services on Amazon Web Services (AWS) in the us-east-1 region in the United States. Our current sub-processors are:
- Amazon Web Services (AWS)
- Cloud hosting, storage, database, and email delivery — United States (us-east-1).
- Whop, Inc.
- Payment processing for paid subscriptions — United States.
If you access Coff from outside the United States, your information will be transferred to and processed in the United States. Where required, we rely on appropriate transfer mechanisms such as the EU Standard Contractual Clauses. We will update this list and provide a way to be notified of material sub-processor changes as our vendors evolve.
9. Coff as a processor
When a Customer stores information about its own clients in Coff, the Customer decides what to collect and why, and Coff processes that information only on the Customer’s documented instructions and to provide the Services. For that information:
- The Customer is responsible for its own privacy notices, consents, and legal bases.
- Requests from a Customer’s clients to access, correct, or delete their information should be directed to that Customer; we will assist the Customer in responding.
- Where a Customer operates in a health-care context, Coff will enter into a Business Associate Agreement and act as a HIPAA Business Associate for that Customer’s Protected Health Information.
10. Data retention
We keep personal information for as long as your account is active and as needed to provide the Services, then for a limited period afterward to meet legal, tax, security, and dispute-resolution needs, after which it is deleted or de-identified. When an account is closed, we delete or return workspace content in line with our agreement with the Customer and applicable law. Backups are cycled out on a rolling schedule.
11. Your rights and choices
Depending on where you live, you may have some or all of the following rights over your personal information: to access it, to correct it, to delete it, to port it, to object to or restrict certain processing, and to withdraw consent. Under U.S. state privacy laws such as the California Consumer Privacy Act (CCPA/CPRA), you also have the right not to be discriminated against for exercising these rights; because Coff does not sell or "share" personal information for cross-context behavioral advertising, there is no such activity to opt out of.
To exercise a right, email team@coff.app. We will verify your request and respond within the time required by applicable law (generally within 30–45 days, extendable where permitted). If you are a Customer’s client and your request concerns information a business stored in Coff, we will refer you to that business, which controls the information.
If you are in the EEA or UK, you also have the right to lodge a complaint with your local data protection authority.
12. Children’s privacy
The Services are intended for businesses and are not directed to children under 16. We do not knowingly collect personal information directly from children. If you believe a child has provided us information directly, contact us and we will delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes, provide a more prominent notice (such as an email or an in-product message). Your continued use of the Services after an update takes effect means you accept the revised policy.
14. How to contact us
Coff LLC is the entity responsible for the information described in this policy. You can reach us at team@coff.app or +1 (425) 465-1290, or by mail addressed to Coff LLC, Seattle, Washington, United States. For privacy-specific requests, please put "Privacy" in your subject line so we can route it quickly.
Questions about this policy?
Coff LLC stands behind these terms. If anything here is unclear, or you want to exercise a right described above, reach our team and we'll help.
