Croma MNL
Home Menu Events Visit Get the app
Legal

Privacy Policy

How we handle your personal data, and what you can ask us to do about it.

Last updated: 28 July 2026

⚠️ DRAFT — not yet reviewed by counsel. The facts below are accurate to how our systems actually work, but the highlighted items still need filling in and the whole document should be checked by a lawyer before it is relied on. Items to complete: registered business name, Data Protection Officer name and contact, contact phone/email, and retention periods.

1. Who we are

Croma MNL ("we", "us") operates a café at Lot 4993-A, M.L. Quezon St., Bambang, Taguig City, Metro Manila, Philippines, together with this website (cromamnl.com) and the Croma MNL community app.

We are the Personal Information Controller for the data described here, under the Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations.

To complete: registered business name and, if applicable, DTI/SEC registration number.

2. What we collect

If you visit this website

We collect nothing about you ourselves. Our hosting provider (Railway) records standard server logs, which may include your IP address, for security and reliability.

The Menu, Events, Visit and home pages carry advertising from Travelpayouts, a third-party affiliate network. Their code runs in your browser on those four pages and may set cookies and collect technical information — your IP address, device and browser, and which pages you viewed — to choose and measure the adverts you see. That processing is theirs, not ours: we never receive it, and we cannot link it to your Croma MNL account. See the Travelpayouts privacy policy. Blocking third-party cookies or using an ad blocker stops it, and nothing on this site stops working if you do.

There is no advertising anywhere you sign in — not in the community app, not on the till, not in the admin or accountant screens. That is enforced by the server, which serves those pages a security policy that will not load an advert at all.

If you send us a message using the form on the Visit page, we receive your name, your email address or mobile number, and your message.

If you create a community app account

WhatWhy we have it
Name, email address, mobile numberTo identify your account and contact you about your orders and enquiries
Password (stored only as a cryptographic hash, never the password itself)To sign you in securely
Google account identifier, if you sign in with GoogleTo sign you in without a separate password
Profile photo, short bio, city, interests, statusShown on your profile to other members you can see
Birth date, if you provide itTo give you a birthday reward
Purchase history, points, tier and visit countTo run the loyalty programme and show you your own history
Store credit balance and its transaction historyTo hold prepaid credit you have paid us, and let you spend it
Advance orders, event RSVPs, table reservations, club membershipsTo fulfil what you asked for
Posts, comments, likes, connections and direct messagesTo operate the community features you choose to use
Device push notification tokenTo send you notifications, only if you turn them on

Some of this is visible to other members by design: your name, photo, city, interests, bio and badges appear on your profile. Members who have not yet visited the café cannot see the member directory, send connection requests, or message you.

If you buy something in the café

If you show your member QR code, we link that purchase to your account so points are credited. If you do not, the sale is recorded without identifying you, other than a name you give us for the order.

If you work for us

For staff we additionally process: role and employment details, PIN and password hashes, hourly rate and payroll records, time-in and time-out records, shift and attendance history, leave records, and sign-in audit logs that include the device used, date and time.

3. Why we process your data, and on what basis

  • To provide what you asked for — your account, orders, reservations, event places and store credit. Basis: performance of our contract with you.
  • To run the loyalty programme — points, tiers, rewards and badges. Basis: your consent when you join, and our contract with you.
  • To operate the community features — profiles, connections, messages and posts. Basis: your consent, given by choosing to use them.
  • To contact you about an order, reservation, enquiry or a notification you enabled. Basis: our contract with you, or your consent for notifications.
  • To run the business — sales records, inventory, staff payroll and attendance, and required tax and accounting records. Basis: legal obligation and our legitimate interests as an employer.
  • To keep accounts and payments secure — sign-in audit logs, and verifying a payment reference before we credit it. Basis: our legitimate interest in preventing fraud.

We do not sell your personal data, and we do not use it for advertising profiling.

4. Who else handles your data

We use a small number of service providers, who process data on our behalf:

ProviderWhat they handle
Google (Sheets, Drive, Apps Script)Our records are stored in Google Sheets and uploaded images in Google Drive. Our systems run on Google Apps Script.
Google Sign-InIf you choose it, to verify your identity when signing in.
Firebase (Google)Push notifications, and a fast read-only copy of information such as the menu and events.
RailwayHosts this website, the community app and the server they talk to. Moved here from GitHub Pages in August 2026.
TravelpayoutsServes the adverts on the Menu, Events, Visit and home pages. May set cookies. Not present on any page you sign in to.

Some of these providers store data on servers outside the Philippines. We rely on their contractual and security commitments to protect it.

We may also disclose data where we are legally required to, for example to a government authority acting within its powers.

To add when live: our payment provider, once online payment for advance orders is enabled.

5. Cookies and similar technology

Croma MNL sets no cookies of its own and runs no analytics. The four public pages listed in section 2 carry advertising from Travelpayouts, and their code may set cookies in your browser. Pages you sign in to carry no advertising and no third-party code.

The community app stores a small amount of information on your own device (browser local storage) so you stay signed in and the app loads quickly — your session token, cached screens, and which clubs you have joined. This stays on your device and is cleared when you sign out.

6. How long we keep it

We keep your account data for as long as your account is open. Sales, payroll and accounting records are kept for the period required by Philippine tax and labour law. Store credit records are kept while a balance exists and afterwards as part of our financial records.

To complete: specific retention periods, and what happens to community content (posts, messages) after account deletion. Confirm the statutory minimums for BIR and DOLE records with your accountant.

7. How we protect it

  • Passwords and staff PINs are never stored in a readable form.
  • Sign-in sessions are time-limited.
  • Access to records is restricted by role, and staff access is limited to authorised devices.
  • Staff access is logged.
  • Traffic to this website and the app is encrypted with HTTPS.

No system is completely secure. If a breach occurs that puts you at real risk of serious harm, we will notify you and the National Privacy Commission as the law requires.

8. Your rights

Under the Data Privacy Act you have the right to:

  • Be informed — know that we hold your data and how we use it.
  • Access — get a copy of the personal data we hold about you.
  • Object — refuse processing, including withdrawing consent for marketing or the community features.
  • Rectify — have inaccurate or incomplete data corrected.
  • Erasure or blocking — ask us to remove or suspend data where the law allows, for example if it is outdated or was collected unlawfully.
  • Data portability — receive your data in a usable electronic format.
  • Damages — be compensated for harm caused by misuse of your data.
  • Complain — lodge a complaint with the National Privacy Commission (privacy.gov.ph).

You can edit most of your own information directly in the app under Profile. For anything else, contact us using the details below and we will respond as soon as we reasonably can.

9. Children

The community app is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will remove it.

10. Changes to this policy

If we change how we handle your data, we will update this page and change the date at the top. For significant changes we will notify you in the app.

11. Contact us and our Data Protection Officer

To complete: DPO name, email address and contact number, plus a general contact email. The Data Privacy Act requires a Personal Information Controller to designate a Data Protection Officer and make their contact details available.

Croma MNL
Lot 4993-A, M.L. Quezon St., Bambang, Taguig City, Metro Manila, Philippines
Data Protection Officer: [name to be added]
Email: [email to be added]

You may also send us a message through the form on our Visit & contact page.

Croma MNL

Specialty coffee in Manila. WiFi with any ₱100 order, power at every table, and a community worth joining.

Visit

Lot 4993-A, M.L. Quezon St.
Bambang, Taguig City
Sun–Thu 9am – 10pm
Fri–Sat 9am – 12am
Directions →

Explore

Menu
Events
Visit & contact
Privacy Policy
Delete your account
Community app

© 2026 Croma MNL. All rights reserved. Made in Manila ☕