Pulling the latest…
Alongside Events is built and operated by Roman Kucheryavyy and Anna Kucheryava, doing business as Alongside Coffee, in Auburn, Washington, USA (“Alongside,” “we,” “us”), alongside our mobile coffee bar of the same name. This is a plain-language privacy policy that is still meant to be legally substantive. We don’t run ad networks, we don’t sell your data, and we collect as little as the product needs.
It covers alongsideevents.com, the operator dashboard and barista app, the iOS companion app, the guest ordering microsite (/g/…), the couple customization page (/c/…), and the recap microsite (/r/…).
Alongside serves three kinds of people, and our role differs for each — this distinction matters legally:
Operators (the coffee-cart business that pays us). For an operator’s account data, we are the controller. For the guest and event data an operator collects while running an event, the operator is the controller and we act as their service provider / processor. Practically: if you’re a guest and want your data deleted, the operator who ran your event makes that call, and we help them do it.
Couples / event hosts customize the experience through a private link; we process what they submit on the operator’s behalf. Guests scan a QR and order; we process their data on behalf of the operator running that event.
From operators: name, email, business name, slug, phone (kept private — never shown to guests or couples), city + state, website/Instagram, bio, your cart logo and photo, your event and menu settings, your client roster if you use the Studio CRM, and a Stripe customer ID. We never receive or store full card numbers (see Payments).
From couples / event hosts: only what they submit through their customization link — colors, fonts, welcome message, their story, drink-brief questionnaire answers, a display name, and any photos they upload. No account and no email are required unless they choose to share one.
From guests: first name (always) and last name (optional) at order time; order contents (drinks, modifiers, notes, optional table number); a review (rating, optional comment, optional anonymous flag) if they write one; and photos or short guest-book notes if they choose to upload them.
Guest phone — only with consent. A phone number is stored only if the guest both types one in AND ticks an unchecked-by-default consent box. Give a phone without consent, or tick consent without a phone, and we store no phone at all — you simply get the name-call experience. When stored, it’s kept two ways: the raw E.164 number (to send the text) and a salted SHA-256 hash (for repeat-guest memory and abuse review). Walk-up orders taken at the cart deliberately collect no phone number — the field is absent from every walk-up surface, so SMS only ever runs against guest-supplied, guest-consented numbers from QR ordering.
Automatically: standard server/request logs (IP address, user agent, timestamps) via our hosting provider, for security, rate-limiting, and debugging. We do not embed third-party advertising or analytics trackers and don’t track you across other sites.
Guest payment information (we don’t process guest drink payments — those are between the guest and the operator), location data beyond the venue an operator typed, browsing history from other sites, contacts, or device data beyond what’s required to run the product. We strip GPS coordinates, capture timestamps, and camera metadata (EXIF) out of every uploaded JPEG, PNG, and WEBP photo before it is stored, so a photo posted to a public recap never leaks where or when it was taken.
To deliver the service: show menus to guests, route orders to the barista queue, send the order notifications a guest consented to, render the recap keepsake, support operator accounts, and power Studio analytics and CRM. We use operator contact details for account, billing, and support communication. We do not sell personal information, and we do not use it for cross-context behavioral advertising.
If a guest opts in at order time — via an unchecked consent box; we never pre-tick it — they may receive up to two transactional texts per order: an order-received receipt and a “your order is ready” alert. The same opt-in enrolls them in the operator’s loyalty & rewards program, which may send occasional perks, offers, and giveaway-prize messages. Every message identifies the sender (the operator’s business name), includes the reason, and ends with “Reply STOP to unsubscribe, HELP for help.”
Message frequency: varies — up to 2 messages per order, plus occasional loyalty & rewards messages. Message and data rates may apply on the guest’s carrier. STOP unsubscribes immediately (honored at the carrier level and in our own operator-scoped opt-out ledger); HELP returns help info. Rewards messages come only from the operator whose bar the guest ordered from — never from other operators, and never from third parties. We text US numbers only, and run a carrier lookup before sending to avoid invalid, premium-rate, landline, or non-US numbers.
We never share, sell, rent, or license guest phone numbers to third parties or affiliates for their marketing purposes. The only processor that touches the number is Twilio, our carrier-of-record SMS provider, strictly to deliver these transactional alerts. You can see the exact consent UI a guest sees at alongsideevents.com/sms-opt-in.
Guest photo uploads go straight to a private storage bucket — nothing appears publicly until the operator approves it. Before submitting, the guest must affirm that everyone in the photo consents to being shared on the couple’s keepsake, with explicit guardian language for any minors. We strip EXIF/GPS metadata from every image on upload. Approved photos and notes are rendered on the recap microsite at an unguessable, token-gated URL; couples can download the photo pack. Couples can report a photo from the recap — reported photos are pulled from public view immediately and returned to the operator’s moderation queue. Per-event upload caps protect operators from spam (10 entries per order, 500 per event; lower on demo events).
The recap (/r/…) is the couple’s keepsake, shared at an unguessable, token-gated URL, and it includes a shareable Open-Graph preview image. By placing an order, a guest agrees that the first name they enter, and any guest-book note they choose to write, may appear on that keepsake — in celebratory elements (a wall of first names, light highlights, the guest book) alongside aggregate, non-identifying stats. We do not publish a named list tying a guest to the exact drinks they ordered; drink choices feed only aggregate counts. Reviews a guest writes may appear as anonymous (stars + comment, no name) social proof on the operator’s public cart page. A guest or couple can ask the operator to remove any name or note at any time. Note that “token-gated” means addressed by an unguessable link — anyone the couple shares that link with can view the recap.
Review tagging (free): short guest reviews are sent to Anthropic’s Claude to tag them against a fixed set of quality flags (e.g. “bitter shot,” “slow wait”) surfaced to the barista. AI signature drinks (paid): the couple’s drink-brief answers plus the cart’s menu are sent to Claude to propose drink ideas, with a content-safety post-check on the output.
AI barista (guest chat): when a guest chats with the AI barista, the messages they type, the cart’s menu, and non-identifying live context (the current wait, what’s been popular, and — if a machine is connected — whether it is warming up or pouring) are sent to Claude to suggest a drink. We do not send the guest’s phone number, last name, or photos. AI debrief email (paid, optional): after an event, the operator can receive a short summary written by Claude from that event’s own aggregate numbers only.
Anthropic processes these requests transiently to return a response and, per its commercial data terms, does not use our API traffic to train its models. No phone numbers, last names, or photos are sent to Anthropic.
If an operator connects a compatible La Marzocco Home account (an optional, opt-in Beta feature), we use their La Marzocco login once to sign in and then store only a revocable, encrypted access token — never the password. Using that token, our servers communicate with La Marzocco’s cloud (lion.lamarzocco.io) to read shot times, shot counts, and machine status for that operator’s own machine. This data is espresso-equipment telemetry, not guest personal data.
The operator can disconnect anytime, and changing the La Marzocco password immediately invalidates the stored token. This integration is not affiliated with or endorsed by La Marzocco; your use of La Marzocco’s service is governed by La Marzocco’s own privacy policy. See our Terms, Section 19, for details.
Operator subscriptions ($79/mo Studio) and per-event charges ($30) run through Stripe Checkout, Stripe’s hosted, PCI-DSS-compliant payment pages. Card numbers are entered on Stripe’s pages and never touch our servers (PCI SAQ-A posture). We receive only a Stripe customer ID and non-sensitive billing metadata via Stripe webhooks. We do not store full card numbers.
Menus show allergen tags per drink and per modifier. These tags are operator-supplied; we display but do not verify them. Guests with serious allergies should always confirm with the barista before ordering.
The menu may also show approximate calorie and macronutrient figures for a drink and its options. These are automated estimates derived from the drink’s name, description, size, and modifiers using general reference values — they are labeled “approx,” are not a verified nutrition panel, and are not medical or dietary advice. Actual values vary with recipe and preparation; guests with medical, dietary, or caffeine sensitivities should confirm with the barista. Allergen tags remain the authoritative safety information.
We keep personal data only as long as needed, and enforce this automatically with daily scheduled jobs:
Alongside Events is intended for adults and is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. The product is used at events where children may be present; photos that may include minors pass through (a) the uploader’s affirmation that any minors have guardian permission and (b) operator approval before appearing publicly. If you believe a child’s information was collected or a child’s image was posted without guardian consent, email support@alongsidecoffee.com and we will remove it promptly and route the request to the relevant operator.
Everyone: email support to access, correct, export, or delete your data; we respond within seven days and complete verified requests within applicable legal timeframes. Guests: because the operator who ran your event is the controller of your event data, we’ll route your request to that operator and assist; you can also ask the operator directly to remove your order, name, note, or photo.
California residents (CCPA/CPRA): you have the right to know, access, correct, delete, and to data portability; to opt out of “sale” or “sharing” of personal information; to limit use of sensitive personal information; and not to be discriminated against for exercising these rights. We do not sell or share personal information as those terms are defined under the CPRA, and we do not use sensitive personal information beyond providing the service. We honor opt-out preference signals (such as Global Privacy Control) where applicable.
Other US state privacy laws (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and others as they take effect) provide comparable rights — exercise them the same way. Washington “My Health My Data”: we do not collect consumer health data, and image uploads are not used to infer health status.
We share data only with the infrastructure providers required to run the service, each bound by its own data processing agreement:
| Provider | Purpose | Data it touches |
|---|---|---|
| Supabase | Database, auth, realtime, private photo storage | All operational data; private photo files |
| Vercel | App hosting + request logs | Request metadata (IP, user agent, timestamps) |
| Stripe | Subscription + per-event payments | Operator billing data; card data on Stripe’s pages |
| Twilio | Transactional SMS + carrier lookup | Recipient phone number + message body |
| Anthropic (Claude) | Review tagging; AI drink suggestions; AI barista; debrief email | Review text; drink-brief answers + menu; guest chat messages + non-identifying context |
| Resend | Transactional email | Recipient email + message content |
| Apple Push (APNs) | Operator iOS push notifications | Device token + order metadata (operator-side) |
| La Marzocco (optional, Beta) | Espresso-machine shot data for connected operators | Operator’s machine telemetry (shot times, status); no guest data |
We’ll update this list when our providers change; material changes are announced in-product.
Operator data is isolated per account via Postgres row-level security; one operator cannot read another’s events. Service-role keys and all third-party secrets are server-only and never exposed to the browser. Guest-facing pages are addressed by unguessable tokens, with rate limiting on sensitive endpoints to deter enumeration and SMS-pump abuse. No system is perfectly secure; we work to protect your data but cannot guarantee absolute security.
We operate in the United States and store data in the US. SMS is currently US-only. If you access the service from outside the US, you consent to processing in the US.
We’ll update this page when things change, and announce material changes in-product. The “updated” date at the top reflects the most recent edit.
support@alongsidecoffee.com — Alongside Coffee, Auburn, Washington, USA.
Questions? Email us at support@alongsidecoffee.com.