PRIVACY & DATA
Privacy Policy
Request account or Member Pass deletion
Effective and last updated September 19, 2026
This policy explains how The Roaming Bean handles information through app.theroamingbean.coffee, its installed web app, the iPhone and iPad app, the Android app, and the related notification service (together, the “App”).
Operator and contact
The Roaming Bean operates The Roaming Bean app and website. Privacy questions and requests can be sent to info@theroamingbean.coffee.
Privacy at a glance
No account is required to view the public schedule or use the App's general features. An optional, invitation-only Member Pass creates a first-party membership when activated. The App does not contain advertising or cross-app advertising trackers, and The Roaming Bean does not sell personal information or share it for targeted or cross-context behavioral advertising. The native apps do not contain a general-purpose analytics or crash-reporting SDK. The website uses Cloudflare Web Analytics for aggregate traffic and performance reporting.
Information handled by the App
Location. Location access is optional. The native apps request foreground, while-in-use location for nearby stops, distance estimates, widgets, watch companions, and map context. If you grant precise or fine location, the apps may use it for more accurate results; reduced or approximate location is also accepted. The native apps do not request continuous background location, and the public schedule remains available without location. Approximate distance estimates can be calculated on the device. Automatic web refreshes never open a browser permission prompt: the PWA requests location automatically only after permission is already granted, while a first prompt is limited to an explicit location or refresh action. The web app may keep its latest accepted fix on the device for up to 24 hours so a reload or a later visit can use it as a visibly stale fallback while a fresh fix is requested; the original timestamp is retained, and the fix is removed on permission denial, when a previously granted permission reverts to Ask, or on expiry. After location permission is granted, opening or returning to the app requests a fresh position. The optional scheduled-update switch adds location requests every five minutes while the app is open; turning it off keeps the launch and return refreshes. Watch companions follow the phone’s switch and request a fresh authorized position when opened or brought back on screen. When the web app’s Google drive-route option is enabled, only a current, non-stale coordinate is sent to the read-only routing endpoint for that calculation; only a hashed, rounded origin area is cached for up to five minutes, and raw coordinates are not stored in script properties or returned. The Roaming Bean does not maintain a location-history profile. Map, navigation, calendar, or sharing providers may receive location or route details when you use those features.
On-device information. Saved stops, menu favorites, reminders, map and appearance choices, haptic settings, the public schedule cache, and similar preferences are stored in app or browser storage. A saved stop can include its public name, schedule, address, and coordinates. This information is not an account profile.
Member Pass. If you accept an invitation and activate a Member Pass, The Roaming Bean stores the display name supplied for the membership, an internal member identifier, opaque pass credentials, activation and status details, and redemption records. A redemption record can include the date and time, trailer or service location, item, and the staff member who completed it. A member may optionally sign in with an email address that The Roaming Bean invited. That address is stored with the membership and used only to send one-time sign-in codes and to place the pass on a new device; it is visible to authorized membership administrators, is not shown to staff scanners, is not placed in the QR code, and is removed when the membership is deleted. The App does not ask a Member Pass holder for a phone number, mailing address, or payment card. A pass credential is stored on the activated device so the App can display and manage the pass.
Staff scanner. Invited staff can enrol a scanner device using a staff identity, role, invitation, PIN, and a first-party device credential. While an enrolled staff member has opened a shift, the camera may be used to read a Member Pass QR code. QR decoding occurs in the camera capture pipeline; camera images are not stored or uploaded. The QR code contains an opaque credential rather than a member's name or contact details.
Paired-watch companion sync. To provide native watch features, a phone app may send the current routable public schedule, saved-stop and reminder state, limited appearance/theme and scheduled-update preferences, and a bounded recent location fix to the same signed companion app on a paired Apple Watch or Wear OS watch through the platform’s companion-connectivity service. That information is cached locally on the paired devices, is not an account profile, and is not sent to The Roaming Bean’s backend for companion synchronization. Apple or Google may process connection and device metadata while providing their platform service under their own privacy terms.
Website requests. When the App requests the schedule or another website feature, hosting and security providers may process standard network information such as IP address, request time, path, response status, browser or app version, device type, approximate region, performance data, and security signals.
Notifications
Native-app saved-stop reminders are scheduled locally and do not currently upload Apple or Firebase push tokens to The Roaming Bean. Optional Web Push sends the notification service a browser push endpoint and encryption keys, random installation credentials, requested reminder details, and delivery or inbox state. This information is used only to authenticate the installation and provide, secure, synchronize, or remove requested web notifications.
Service providers and optional actions
Business website analytics. The business website, which can be displayed inside the App for informational pages, uses Google Analytics provided through SpotHopper to measure page views and interactions. It can process a pseudonymous browser identifier, approximate location derived from IP address, and browser/device details for analytics. Google Signals and advertising personalization are disabled. The App’s privacy page and website also use Cloudflare Web Analytics for aggregate page-view and performance measurements. See Google Analytics data collection.
Cloudflare provides hosting, content delivery, security, Member Pass and staff-scanner Worker routes, web-notification routing, and aggregate Web Analytics. Cloudflare may process the network information described above, Member Pass requests sent to those first-party routes, and limited operational and security logs. Its handling is described in the Cloudflare Privacy Policy.
Maps and directions. The website uses Google Maps or OpenStreetMap-based tiles, the Android app uses Google Maps SDK for Android, and the iPhone and iPad app uses Apple MapKit. When Google Maps is used, it may automatically process request and device metadata, IP address, Maps crash diagnostics, a Maps-specific pseudonymous identifier, map interactions, the viewed area, and location when shown on a map. Other map and navigation providers may process comparable information under their own policies. A selected navigation app may also receive the origin, destination, account, and device information. In the web app, a typed home address and the device's location fix when a place name is looked up for it are sent to Nominatim (OpenStreetMap) for geocoding and reverse geocoding under the OpenStreetMap Foundation's privacy policy. The native apps use Android's platform geocoder and Apple's geocoding service for these lookups; those providers may process the address or coordinate used for the lookup. See Google Privacy and Apple Maps Privacy.
Android QR scanning. The Android staff scanner uses Google's ML Kit barcode-scanning SDK. Camera images and decoded results are processed on the device and are not sent to Google for recognition. To maintain and improve the SDK, Google may receive device and app details, per-installation identifiers, SDK configuration, performance and usage metrics, and error information over HTTPS. These SDK diagnostics are separate from the Member Pass credential sent to The Roaming Bean when an authorized staff member looks up or redeems a pass. See ML Kit data disclosure and Google Privacy.
Android voice shortcuts and spoken responses. When you choose a voice shortcut, your assistant provider processes your command under its own privacy settings and sends the requested action, including a stop name when needed, to the App. The App does not record microphone audio. It uses authorized location on the device to rank stops; a response may include public stop details, your saved-stop choices, and derived distance estimates. Response text is passed to the text-to-speech engine selected in your device settings. That engine may process the text remotely under its provider's privacy terms. You can use the App's ordinary screens without voice shortcuts. See Google Privacy for Google-provided assistant and speech services.
Calendar, sharing, links, and email. These actions occur only when you choose them. The iPhone and iPad app requests write-only calendar access and does not read calendar history. Calendar or shared content can include a stop's public details and a directions link, which may include an origin coordinate when Google routing is selected. Linked websites, social networks, shops, booking pages, hiring pages, email providers, and selected sharing apps apply their own privacy practices.
Optional support. The Support The App screen offers sharing actions and a link to the developer's website, madebykenb.com. The App does not process payments or tips, and no payment information is collected through it.
How information is used and disclosed
Information is used to provide requested features, deliver the schedule and notifications, operate and secure Member Pass memberships and redemptions, enrol authorized staff scanners, remember preferences, answer messages, troubleshoot the service, measure aggregate website performance, keep required business and fraud-prevention records, and comply with law. It is disclosed only to the providers described above, an app or recipient you select, advisers or authorities when legally required, or as part of a legally permitted business reorganization.
Retention and Member Pass deletion
Local information remains until removed in the App, displaced by storage limits, cleared with app or browser data, or removed by uninstalling. Web Push records are retained while needed to provide the connection and for limited security, backup, or deletion-retry periods; disabling Web Push attempts to delete the server-side installation record. Staff enrolment, invitation, security, and audit records are retained only as reasonably needed to operate and protect the program. The current service does not automatically expire redemption or audit ledger records; those records remain until a documented retention decision and applicable business, fraud-prevention, tax, or legal requirements permit a sanctioned deletion. Email and other transaction records are kept only as reasonably needed for support, business, tax, fraud-prevention, or legal purposes. Service providers retain information under their own policies.
A Member Pass holder can choose Delete my membership inside the App. Deletion immediately revokes every active pass credential. If the membership has no redemption history, its member and pass records are removed. If a redemption ledger must remain as a business, fraud-prevention, or legal record, the display name and internal notes are erased, the membership is closed, and the retained ledger is linked only to a non-active, anonymized member record. Clearing app data or uninstalling by itself removes local data but does not request server-side membership deletion.
You can request deletion of your The Roaming Bean account or Member Pass without installing or signing in to the App by emailing info@theroamingbean.coffee. Identify the request as a Member Pass deletion request, but do not email a QR code, pass credential, staff PIN, or invitation code. The Roaming Bean may ask for reasonable verification before acting on a request.
You can also clear saved items, disable notifications, or clear app or browser data. Requests to access, correct, or delete information controlled by The Roaming Bean may be sent to the contact above. Provider-controlled, legally required, security, or aggregate information that cannot reasonably be identified may not be available for deletion.
Your choices and security
Location, notifications, camera, and calendar access can be denied or revoked in device or browser settings, and the public schedule remains available without them. Maps, sharing, calendar, email, social, shop, and support features are optional, and so is the Member Pass.
Network requests use HTTPS where controlled by The Roaming Bean. Administrative and staff access is restricted, and Member Pass, staff-device, and Web Push requests use opaque credentials. No internet or storage system can be guaranteed completely secure.
Children
The app is a general-audience schedule utility and is not directed to children under 13. The Roaming Bean does not knowingly seek personal information from a child under 13. A parent or guardian who believes a child has provided personal information can contact The Roaming Bean to request review and deletion.
Changes to this policy
This policy may be updated when the App, providers, or legal requirements change. The date above will be revised when an update is published. Privacy questions, rights requests, and concerns can be sent to info@theroamingbean.coffee.