rebrew.coffee

Privacy policy

Last updated: 15 August 2026

Who is responsible

rebrew.coffee is operated by Issy Long as an individual, who is the data controller for the personal data described below. Contact: me@issylong.com.

What data is collected

  • Mobile telephone number. Stored in international format. Used to send the service’s text messages and to identify you when you reply.
  • Collection arrangements. Whether pods are collected at the kerbside, collected by prior booking, or taken to a drop-off point, and the relevant day of the week.
  • Usage records. The dates on which each bag was started, filled and handed over, the number of bags remaining, and a rolling estimate of how quickly you fill one.
  • Authentication data. A six-digit verification code, the number of failed attempts to enter it, and a secret token used by the optional NFC tag feature.

No name, email address, postcode, street address or payment details are collected. The service performs no analytics, advertising or tracking of any kind, and sets no cookies other than the two described under “Cookies” below.

Lawful basis

The lawful basis for processing is Article 6(1)(b) of the UK GDPR: processing necessary for the performance of a service you have requested. Each item listed above is required for the service to function; none of it is optional or used for any other purpose.

Cookies

Two strictly necessary cookies are used. The first maintains your signed-in session on the account page and expires after 30 days. The second holds your telephone number between signing up and entering your verification code, and expires after 15 minutes. Both are HTTP-only and cryptographically signed. No consent banner is presented because no non-essential cookies are set.

Processors and recipients

The following third parties process personal data on behalf of the service:

  • Twilio — delivery of text messages, through its Ireland region. Twilio, and the mobile network carrying the message, necessarily process your telephone number and the contents of messages sent and received.
  • Neon — database hosting, in its London region.
  • Bitfolk Ltd — the virtual server on which the service runs.
  • Better Stack — server log storage, used to diagnose faults. Logs record events such as a code being sent or a reply being received, together with the final four digits of the telephone number concerned. Complete telephone numbers and the contents of messages are not written to these logs.

Personal data is not sold, and is not shared with Podback, which has no involvement in this service.

The server and the database are in the United Kingdom, and messages are processed in Ireland. Some of these providers are companies established outside the United Kingdom, and may process data elsewhere in the course of running their services.

Retention

Account data and usage records are retained until you delete them. Deletion is immediate and permanent: the account and all associated bag records are removed together, and no copy or archive is kept.

Verification codes expire ten minutes after they are issued. Server logs are retained for a short period, typically a few days, and are then deleted automatically. Because logs contain no complete telephone number, they cannot be searched by individual and are unaffected by a deletion request.

Your rights

Under the UK GDPR you have the right of access to your personal data, and the rights to rectification, erasure, restriction of processing, data portability, and to object to processing.

Access and erasure can be exercised directly and without making a request. Visit your account, confirm your telephone number with a code, and the page will display every item of data held about you, with the option to delete all of it. Replying STOP to a text message stops further messages but does not delete your data.

To exercise any other right, contact me@issylong.com. A response will be provided within one month, as required by the UK GDPR.

Complaints

If you consider that your personal data has been handled improperly, you may lodge a complaint with the Information Commissioner’s Office, the UK supervisory authority, at ico.org.uk/make-a-complaint.

Changes to this policy

This policy is updated whenever the data held by the service changes. The date of the most recent revision is shown at the top of this page.