Privacy & Data Protection
Privacy Policy
A complete, readable account of what happens to information when you use The 7 Brews Menu, including the parts most sites leave vague, like exactly which cookies run and what stays on your own device.
- Last updated
- Effective
- Length
- 14 min read
- Review cycle
- Every 6 months
At a glance
A plain-English summary. It is a convenience only. The full text below is what governs.
- No accounts, no sign-ups, no profiles. You can read every guide, run every calculator and browse every location page without telling us who you are.
- Our tools run in your browser. Calorie logs, customiser builds and dietary filters are saved in your own browser storage, not on our servers.
- We do not sell personal information for money, and we do not run cross-context behavioural advertising of our own.
- Ads and analytics are third-party. Google AdSense and our analytics provider set their own cookies; we link to their controls and honour Global Privacy Control.
- You can ask us anything about your data at the7brewsmenu@gmail.com, a person replies within 2 business days.
Who we are and what this policy covers #
The 7 Brews Menu (https://the7brewsmenu.com) is an independent consumer publication: a menu reference, nutrition database and set of free ordering tools for people who drink at 7 Brew drive-thru stands. Throughout this policy, "we", "us" and "our" mean the editorial team that operates this website, and "you" means anyone who visits it.
This Privacy Policy explains what information we and our service providers collect when you use the site, why we collect it, who it is shared with, how long it is kept, and the rights you can exercise over it. It applies to every page on our domain, including the menu guides, the nutrition database, the calorie calculator, the drink customiser, the allergen matrix, the secret menu database and the store locator.
It does not apply to 7 Brew Coffee, its franchisees, its app, or its corporate website. We are not affiliated with that company in any way; see our disclaimer for the full trademark and non-affiliation notice. If you order through 7 Brew's own app or hand your details to a stand, that company's privacy practices apply, not ours.
The four principles we hold ourselves to #
We would rather commit to a short list we actually follow than publish a long one we don't.
1. Anonymous by default
There is no login, no newsletter wall and no gate in front of any tool. If you never email us, we never learn your name.
2. Local before remote
Anything personal enough to feel like a diary, such as your drink log, your saved builds and your allergen filters, is stored in your browser instead of our database.
3. No data sales
We do not sell, rent or trade personal information, and we do not build or licence audience segments about our readers.
4. Say what we actually run
We name our advertising and analytics providers, list the cookie categories in use, and keep the cookie policy current when that changes.
Information we collect #
Three categories, in order of how much they can identify you.
A. Information you choose to give us
This only exists if you contact us. When you email the7brewsmenu@gmail.com or use the contact form, we receive whatever you put in the message: typically your name or handle, your email address, the subject you selected and the body of your enquiry. If you send us a correction, we may also receive the photo or receipt you attach.
We use that information to answer you, to verify and apply corrections, and to keep a record of legal notices such as DMCA complaints. We do not add correspondents to any marketing list, there is no marketing list.
B. Information collected automatically
Like every website on the public internet, our hosting infrastructure and content-delivery network write standard request logs. These may include:
- IP address (truncated or replaced with a coarse region wherever the tooling allows)
- Date and time of the request, and the URL requested
- Browser type and version, rendering engine and operating system
- Referring URL, so we can tell whether you arrived from search, social or a direct link
- Response status codes, transfer sizes and page timing metrics
- Approximate location at city or region level, inferred from the IP address
We read these logs in aggregate to find broken pages, size our servers, catch scraping and abuse, and understand which guides people actually need. We do not attempt to identify individual readers from log data, and we do not combine logs with contact emails to build profiles.
C. Information collected by third parties on our pages
Our advertising and analytics partners collect their own data directly from your browser when their scripts load. That may include cookie identifiers, device and browser characteristics, pages viewed, and interactions with ad units. We do not receive that data in a person-level form; we see only aggregated reports. Sections 8 and 9 set out who these partners are and how to control them.
| Category | Examples | Source | Identifies you? |
|---|---|---|---|
| Contact data | Name, email address, message body, attachments | You, when you write to us | Yes. Directly |
| Technical log data | IP address, user agent, timestamps, referrer | Automatic, server-side | Only indirectly |
| Usage & measurement | Pages viewed, time on page, scroll depth, tool interactions | Analytics provider | Pseudonymous |
| Advertising data | Ad cookie IDs, impressions, clicks, frequency capping | Google AdSense & partners | Pseudonymous |
| Tool preferences | Saved drinks, calorie log, dietary filters, unit choice | Your browser storage | No. Stays local |
Never collected: payment-card details, government identifiers, precise GPS location, contacts, biometrics, health records, or any special-category data under GDPR Article 9. We have no mechanism to receive them.
Data that never leaves your device #
This is the part we are proudest of, and the part most often misunderstood.
Our interactive tools are built to run entirely in your browser. When you log a drink in the
calorie calculator, assemble a build in the
drink customiser, or set dietary filters on the
allergen guide and the result is written to localStorage,
a storage area that belongs to your browser profile on your device.
That has three practical consequences:
- We cannot see it. The data is not transmitted to our servers, so we could not produce your drink history even if someone asked us to.
- You control it completely. Clearing site data in your browser settings erases it permanently and immediately.
- It does not follow you. Because it is tied to one browser profile on one device, your log will not appear on your phone if you built it on a laptop.
Two features do send a request onward, and we want to be exact about them. The weather-based drink suggestion sends the coordinates or city name you provide to OpenWeatherMap so a local forecast can be retrieved. If you use the browser location prompt, your device supplies that position and you can decline it and type a city instead. Our AI-assisted suggestion feature sends the preferences you type, plus that forecast context, to OpenAI so the wording of a recommendation can be generated. In both cases the request exists only to complete the action you asked for: no contact details are attached, nothing is stored against your identity, and no profile is built from it.
The cookie policy lists the individual storage keys these tools write, what each one holds, and how long it survives.
How and why we use information #
- To deliver the site
- Serving pages, images and scripts; routing requests through our CDN; keeping load times and Core Web Vitals within acceptable ranges.
- To run the tools you asked for
- Calculating calories and macros, modelling customisation deltas, filtering allergens, producing order scripts, retrieving a forecast for a weather-based suggestion.
- To answer you
- Replying to enquiries, verifying and applying data corrections, and handling legal notices such as DMCA takedowns or rights requests.
- To improve editorial coverage
- Reading aggregate usage to decide which drinks, categories, cities and comparisons deserve deeper guides, and which existing pages are underperforming or confusing.
- To keep the site secure and available
- Detecting scraping, credential-stuffing attempts against our infrastructure, denial-of-service traffic, spam submissions and other abuse; investigating incidents.
- To fund free access
- Serving and measuring advertising so that every calculator, table and PDF can stay free with no paywall or subscription. See section 8.
- To meet legal obligations
- Retaining records where the law requires it, responding to valid legal process, and enforcing our Terms of Service.
We do not use your information to make automated decisions that have a legal or similarly significant effect on you, and we do not carry out profiling of that kind.
Legal bases for processing (UK & EEA) #
If you are in the United Kingdom or the European Economic Area, we must identify a lawful basis for each processing purpose. Here they are.
| Processing activity | Lawful basis | Why it applies |
|---|---|---|
| Serving pages and essential site operation | Legitimate interests, Art. 6(1)(f) | You requested the page; delivering it reliably and securely is a minimal, expected use of technical data. |
| Answering your email or form enquiry | Legitimate interests, or contract where relevant, Art. 6(1)(f) / (b) | You initiated the correspondence and expect a reply. |
| Security, anti-abuse and fraud prevention | Legitimate interests, Art. 6(1)(f) | Protecting the site and its readers from scraping, spam and attacks. |
| Analytics and audience measurement | Consent, Art. 6(1)(a) | Non-essential cookies and measurement run only where consent is given or permitted by local law. |
| Personalised advertising | Consent, Art. 6(1)(a) | Collected through the IAB Transparency & Consent Framework prompt shown by our ad partner in applicable regions. |
| Keeping records of legal notices | Legal obligation / legitimate interests, Art. 6(1)(c) / (f) | Copyright and rights-request records must be retained to show we handled them properly. |
Where we rely on consent, you may withdraw it at any time and processing stops going forward. Where we rely on legitimate interests, you may object. see section 14.
Advertising and Google AdSense #
This site is free because it carries advertising. We use Google AdSense, and Google may work with additional certified advertising partners and exchanges to fill inventory. Those partners receive information directly from your browser when an ad loads.
What that involves
- Cookies and identifiers. Google and its partners use cookies and similar identifiers to select ads, cap how often you see the same creative, and measure clicks and conversions.
- Personalised advertising. Where permitted and consented to, ads may be selected based on your prior visits to this and other sites. Where consent is refused or unavailable, Google serves non-personalised or limited ads, which use contextual signals and coarse location instead of a behavioural profile.
- Consent management. In the UK, EEA and Switzerland, a consent prompt built on the IAB Europe Transparency & Consent Framework is presented before non-essential advertising cookies are set, and your choice is stored so you are not asked repeatedly.
- What we do not do. We do not upload email lists for ad targeting, do not receive person-level ad data, and do not allow advertisers to place their own tracking on our pages outside the standard AdSense pipeline.
Your advertising controls
- Turn off ad personalisation in your Google account at My Ad Center.
- Opt out of participating vendors at optout.aboutads.info (DAA) or optout.networkadvertising.org (NAI).
- In Europe, use youronlinechoices.eu.
- Read how Google uses information from sites that use its services .
We have no access to, and no control over, cookies set by third-party advertisers, and we cannot delete them on your behalf. Their own privacy policies govern that data. Our full FTC advertising disclosure, including the firewall between advertising and editorial judgement, is in the disclaimer.
Analytics and measurement #
We use a web analytics service to understand aggregate behaviour: which pages are read, how long people stay, where they arrive from, which tools get used, and where readers give up. This tells us that, for example, a category page needs a clearer comparison table, or that a city page is missing the store people were looking for.
Analytics reporting is configured to be as coarse as remains useful. We view reports at the page and segment level, not the individual level. We do not enable advertising features that would join analytics identifiers to ad profiles beyond what is described in section 8, and we do not send personal identifiers such as email addresses into analytics.
If you use Google Analytics-based measurement and want to opt out across every site you visit, install the Google Analytics Opt-out Browser Add-on . You can also block analytics cookies for our domain specifically using the instructions in the cookie policy.
Service providers and who else sees data #
We keep the vendor list deliberately short. These are the categories of recipient, and we do not add others quietly.
| Recipient category | Function | Data involved |
|---|---|---|
| Hosting & CDN provider | Serving pages and static assets, caching, DDoS protection | Request logs, IP address, user agent |
| Google AdSense & certified ad partners | Selecting, delivering and measuring advertising | Ad cookie identifiers, page context, device signals |
| Web analytics provider | Aggregate audience measurement | Pseudonymous usage events, coarse location |
| Email provider | Receiving and replying to your correspondence | Your message and email address |
| OpenWeatherMap | Returning the local forecast behind a weather-based drink suggestion | The coordinates or city name you supplied |
| OpenAI | Generating the wording of an AI-assisted drink suggestion | The preferences you typed and the forecast context |
| Professional & legal advisers | Advice on notices, disputes or compliance, when needed | Only what is strictly relevant |
We disclose information outside these categories only where we must: to comply with valid legal process, to protect the rights, safety or property of readers or the public, or in connection with a merger or transfer of the site. In which case we would update this policy and note the change on this page.
We do not sell personal information for monetary consideration, and we do not share it for cross-context behavioural advertising other than through the standard AdSense pipeline described above, which you can opt out of at any time.
International data transfers #
We operate from, and our infrastructure is primarily located in, the United States. Our service providers may also process data in other countries. If you access the site from the UK, the EEA, or anywhere with data-export rules, your information may be transferred to a country whose data-protection laws differ from your own.
Where such a transfer takes place, we rely on the safeguards our providers have in place, typically the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, adequacy decisions, or certification under the EU–US and UK–US Data Privacy Framework where the provider participates. Google's transfer safeguards are documented in its own privacy resources, which we link to in section 8. You may ask us for more detail about the mechanism relevant to a specific provider.
How long we keep information #
| Data | Retention period | Then what |
|---|---|---|
| Email correspondence | Up to 24 months after the matter closes | Deleted from the mailbox and trash |
| Records of legal notices (e.g. DMCA) | Up to 3 years | Retained to evidence proper handling, then deleted |
| Server & CDN request logs | Typically 30–90 days, per provider defaults | Rotated and overwritten automatically |
| Aggregate analytics reports | Up to 26 months at event level | Retained only as non-identifying aggregates |
| Advertising cookies | Set by Google, generally up to 24 months | Expire, or clear immediately when you delete cookies |
| Tool data in your browser | Until you clear it | Under your control, not ours |
Where a retention period is set by a provider rather than by us, we apply the shortest option the service makes available.
How we protect information #
We apply security measures proportionate to the very limited personal data we hold:
- The entire site is served over HTTPS with modern TLS; HTTP requests are redirected.
- Our architecture is deliberately minimal. There is no user database, no stored passwords and no payment processing, which removes the most attractive targets entirely.
- Administrative access is limited to the editorial team and protected by multi-factor authentication.
- Dependencies are kept patched, and third-party scripts are limited to the vendors named above.
- Contact submissions are rate-limited and filtered to reduce spam and abuse.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach affecting personal data occurs, we will investigate promptly, notify the relevant supervisory authority where required. Within 72 hours where GDPR applies and inform affected individuals where the law requires it or where there is a real risk to them.
Your privacy rights #
Which rights apply depends on where you live, but we handle every request we receive to the same standard.
- Right to know and access
- Ask what personal information we hold about you, where it came from, why we have it and who we shared it with, and receive a copy.
- Right to correction
- Have inaccurate or incomplete personal information about you corrected.
- Right to deletion or erasure
- Ask us to delete personal information we hold about you, subject to narrow legal exceptions such as records of legal notices.
- Right to opt out of sale or sharing
- We do not sell personal information for money. To opt out of sharing for cross-context behavioural advertising, use GPC or the advertising controls in section 8.
- Right to limit use of sensitive information
- We do not collect sensitive personal information, so there is nothing to limit but we will confirm that in writing on request.
- Right to data portability
- Receive the information you gave us in a structured, commonly used, machine-readable format.
- Right to object and to restrict processing
- Object to processing based on legitimate interests, or ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
- Right to withdraw consent
- Where processing relies on consent. Analytics and personalised advertising, withdraw it at any time without affecting anything done beforehand.
- Right to non-discrimination
- Exercising any of these rights will never degrade your access to this site. Every page and tool stays fully available.
- Right to appeal
- If we decline a request, you may ask us to reconsider. We will review the decision and respond in writing, as required by several US state laws.
How to make a privacy request #
- Email us at the7brewsmenu@gmail.com with a clear subject line such as "Privacy Request", "CCPA Request" or "GDPR Request".
- Tell us what you want. Access, correction, deletion, portability, objection, opt-out or appeal and any detail that helps us locate the data, such as the email address you used to contact us.
- Verification. Because we hold no accounts, we usually verify by corresponding with the same email address in our records. We ask for the minimum needed and never request identity documents. An authorised agent must include written proof of authority.
- Our response. We acknowledge within 2 business days and substantively respond within 30 days (or one month under GDPR), extendable once where a request is genuinely complex. We will tell you if that happens and why.
- No charge. Requests are free. We only charge or refuse where a request is manifestly unfounded, excessive or repetitive, and we explain the reasoning if so.
Notices for US state privacy laws #
Additional disclosures for residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and other states with comprehensive privacy laws.
California (CCPA as amended by CPRA)
In the 12 months before the date of this policy we collected the categories described in section 3: identifiers (including IP address and, if you write to us, name and email), internet or network activity information, and coarse geolocation inferred from IP address. Sources, purposes and recipients are set out in sections 3, 5 and 10.
- We have not sold personal information for monetary consideration, and we have not knowingly sold or shared the personal information of consumers under 16.
- Sharing for cross-context behavioural advertising may occur through third-party advertising cookies. You may opt out using GPC or the controls in section 8.
- Sensitive personal information is not collected, and therefore is not used or disclosed for purposes requiring a limitation right.
- Authorised agents may submit requests on your behalf with written proof of authorisation.
Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and similar states
You have rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale and profiling with legally significant effects. We do not conduct such profiling. Where your state provides an appeal process, we honour it. see section 14. We recognise universal opt-out mechanisms including GPC.
Because we conduct no processing that presents a heightened risk of harm, we do not carry out data-protection assessments of the kind those statutes require for such processing.
Nevada
Nevada residents may submit a verified request not to have covered information sold. We do not sell covered information, but you may still submit a request to the address in section 21.
Notice for the UK and EEA (UK GDPR & EU GDPR) #
If you are in the United Kingdom or the European Economic Area, the lawful bases in section 6 apply, along with the rights in section 14. A few additional points:
- Providing data is not mandatory. You are never required to give us personal data. If you choose not to contact us, the only consequence is that we cannot reply.
- Consent is genuinely optional. Refusing analytics and advertising cookies does not restrict access to any content or tool on this site.
- Right to complain. You may lodge a complaint with your national supervisory authority. In the UK that is the Information Commissioner's Office; in the EEA, your local Data Protection Authority. We would appreciate the chance to resolve the matter first, but you are not obliged to come to us before going to a regulator.
- No EU representative. As a small publisher whose processing of EEA data is occasional, limited and low-risk, we have not appointed an Article 27 representative. You can reach us directly at any time.
Children's privacy #
This site is written for a general adult audience. People planning a coffee order, tracking calories or checking allergens. It is not directed to children, and we do not knowingly collect personal information from anyone under 13 (or under 16 in jurisdictions that set that threshold).
We have no accounts, no profiles and no social features, so there is no route for a child to publish or share personal information through our pages. Consistent with our AdSense obligations, we do not label this site as child-directed content or request personalised ads for users identified as children.
Links to other websites #
Our guides link out to mapping services for directions, to official brand and nutrition sources, to research and regulatory references such as FDA caffeine guidance, and occasionally to social platforms. Following any of those links takes you to a site we do not operate.
We are not responsible for the content, security or privacy practices of external sites, and this policy stops at our domain boundary. We choose outbound links on editorial merit and review them during content audits, but we cannot monitor them continuously. Read the privacy policy of any site that asks you for information.
Changes to this policy #
We review this policy at least every six months and whenever we change a vendor, add a feature that touches data, or the law shifts. When we make a change, we update the "Last updated" date in the header of this page.
For material changes, a new category of data, a new purpose, or a new recipient. We will make the change prominent on the site for a reasonable period, and where consent is legally required we will ask for it again rather than assume it. Continuing to use the site after a non-material update means the revised policy applies to you.
Contact our privacy team #
Privacy questions, rights requests, appeals and complaints all go to the editorial team, and a person. Not an autoresponder, reads them.
- the7brewsmenu@gmail.com
- Contact form
- https://the7brewsmenu.com/contact. Choose the privacy or data-rights subject
- Publisher
- The 7 Brews Menu, an independent consumer publication (https://the7brewsmenu.com)
- Acknowledgement
- Within 2 business days, with a substantive response inside 30 days
Related reading: the Cookie Policy for the per-cookie inventory, the Terms of Service for the rules governing use of the site, the Disclaimer for advertising and nutrition disclosures, and the Editorial Policy for how our data is researched and verified.
Our website includes a Community Q&A section and comment areas where visitors may submit questions, answers, and comments. This content is created by users and does not represent the views, opinions, or official guidance of The 7 Brews Menu or 7 Brew Coffee.
We collect the following information when you post community content: your chosen display name, email address (optional), the content of your submission, and your browser fingerprint (used solely to prevent duplicate voting). We do not require account registration. Email addresses, if provided, are stored in our database and are not shared with third parties or used for marketing purposes.
All user-generated content is moderated. We reserve the right to remove any content that violates our community guidelines, including content containing links, spam, profanity, or offensive material. By submitting content, you grant us a non-exclusive, perpetual license to display your contribution on our website.
Questions about this page
Talk to the people who wrote it
Corrections, data-rights requests, legal notices and licensing all go to the same inbox and are triaged by a named editor. Typical first reply: 2 business days.
The rest of our trust centre
Every policy is written in the same plain style and dated on the page.
- About Us Who publishes this guide, the experience behind it, and how the database is maintained.
- Contact Us Reach the editorial team for corrections, data questions, legal notices or partnerships.
- Editorial Policy How we research, source, model and fact-check every price, calorie and allergen figure.
- Cookie Policy Every cookie, pixel and local-storage key we use, plus how to switch each one off.
- Terms of Service The agreement covering permitted use, intellectual property, liability and disputes.
- Disclaimer & Ads Trademark notice, nutrition and allergen limits, and our full advertising disclosure.
- DMCA & Copyright Takedown notices, counter-notifications and how to license our original material.
- Accessibility Our WCAG 2.2 conformance target, the measures in place, and known limitations.
Plain-language note. This document is written to be read, not to be survived. It is general information about how The 7 Brews Menu operates and is not legal advice for your own situation. Where a translated version conflicts with this English text, the English text governs.