SensoCup CVA — Privacy Policy
Privacy Policy — SensoCup CVA
1. About us
SensoCup CVA is a professional tool for coffee sensory evaluation developed by Garage Coffee Bros. S.r.l. The application implements the CVA (Coffee Value Assessment) protocol of the Specialty Coffee Association (SCA) and allows professionals and enthusiasts to record, analyze, and share coffee sensory evaluations.
2. Data we collect
2.1 Account data
- First and last name
- Email address
- Password (stored encrypted via Supabase Auth)
2.2 Professional profile data
- Professional category (e.g., roastery, importer, producer)
- Age range
- Country of origin and country of operation
- Gender (optional)
- SCA Qualifications (Q Grader Evolved, Q Instructor) — optional
2.3 Sensory evaluation data
- Descriptive Sheet: aromatic intensities, CATA descriptors, sensory notes
- Affective Sheet: CVA scores for fragrance, aroma, flavor, aftertaste, acidity, sweetness, mouthfeel, overall; calculated CVA Score
- Extrinsic Sheet: origin data (country, region, farm, producer, variety, process, certifications, FOB/farm gate prices)
- Physical Sheet: color, moisture, defects (cat. 1 and 2), granulometric distribution
2.4 Technical data
- IP address (recorded by Vercel/Supabase for security)
- Date and time of evaluations
- Device type and browser
3. Purposes and legal bases of processing
| Purpose | Legal basis |
|---|---|
| Service delivery (account, saving evaluations, sessions) | Contract performance (Art. 6(1)(b) GDPR) |
| Authentication and security | Legitimate interest (Art. 6(1)(f) GDPR) |
| Research and service improvement through anonymous aggregated data | Consent (Art. 6(1)(a) GDPR) — given at registration |
| Tax and accounting compliance (subscriptions) | Legal obligation (Art. 6(1)(c) GDPR) |
| Service communications (updates, technical issues) | Legitimate interest (Art. 6(1)(f) GDPR) |
4. Data sharing
4.1 Individual data
Individual user data (evaluations, profile) is not sold, transferred, or shared with third parties for commercial or marketing purposes.
4.2 Aggregated and anonymous data
Except for users with a Business plan (who explicitly opt for full privacy), evaluation data may be included in aggregated and anonymized datasets used for:
- Research on coffee quality in collaboration with industry bodies (e.g., SCA)
- Improvement of evaluation algorithms
- Publication of aggregated statistics without user identification
Aggregated data does not contain identifying information (name, email, sensitive extrinsic data such as prices).
4.3 Sub-processors
| Provider | Service | Headquarters |
|---|---|---|
| Supabase Inc. | Database, authentication, storage | USA (applicable SCCs) |
| Vercel Inc. | Application hosting | USA (applicable SCCs) |
| Lemon Squeezy LLC | Payments and subscriptions | USA (applicable SCCs) |
Transfers to the USA are based on the Standard Contractual Clauses (SCCs) approved by the European Commission.
5. Data retention
- Account and profile data: kept for the duration of the contractual relationship + 10 years for tax obligations
- Evaluation data: kept for the duration of the account; deleted within 30 days after cancellation
- Payment data: managed by Lemon Squeezy; stored according to their policies
- Technical logs: kept for 90 days
6. Security
Data is protected by:
- TLS encryption in transit
- Encryption at rest (Supabase)
- Row Level Security (RLS) on all data: each user accesses only their own data
- Secure authentication via Supabase Auth (passwords never in clear text)
- Limited and logged administrative access
7. Rights of data subjects
As a data subject, you have the right to:
- Access to your personal data (Art. 15 GDPR)
- Correction of inaccurate data (Art. 16 GDPR)
- Deletion ("right to be forgotten") (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability in a structured format (Art. 20 GDPR)
- Objection to processing for legitimate interest (Art. 21 GDPR)
- Withdrawal of consent at any time for processing based on consent
To exercise these rights, write to: info@garagecoffeebros.com
You also have the right to file a complaint with the Data Protection Authority (www.garanteprivacy.it).
8. Cookies and tracking
SensoCup CVA uses only technical cookies necessary for the service to function (authentication session). It does not use profiling, advertising tracking, or third-party analytics cookies.
9. Minors
The service is not intended for persons under 16 years of age. We do not knowingly collect data from minors. If you believe a minor has created an account, contact us at info@garagecoffeebros.com.
10. Changes to this privacy policy
Any substantial changes will be communicated via email to registered users with at least 30 days' notice. Continued use of the service after this period constitutes acceptance of the changes.
11. Contacts
Garage Coffee Bros. S.r.l.
Via Basso Acquar 30/C — 37135 Verona (VR)
Email: info@garagecoffeebros.com
Tel: +39 347 221 3724
SensoCup CVA — by Garage Coffee Bros. S.r.l. — Version 1.0 — June 2026