JUSTO Systems
Privacy Policy
Effective 19 July 2026
This policy explains what personal data JUSTO collects when you use the JUSTO app and this website, why we collect it, and the rights you have over it. We keep it plain and we only collect what running the service needs.
1. Who we are
The controller of your data is JUSTWIN UNLIMITED S.R.L., a company registered in Romania (CUI 46690910; not registered for VAT - neplatitor de TVA), Bucharest, Romania - the operator of JUSTO smart coffee systems.
For any privacy question or to exercise your rights, contact us at [email protected].
2. What we collect and why
We collect only what a coffee order and account need:
- Your account. Your email address and display name, as provided by your sign-in provider (Google, and Apple in future), and a reference id from that provider. We never see or store a password.
- Your taste profile. The answers you give to the optional taste quiz, used to recommend drinks. You can skip the quiz and delete the profile at any time.
- Your allergen profile - only if you choose to give it, and it is health data. If you tell the app which of the 14 EU-declarable allergens you need to avoid, we store that list on your account and the timestamp of your consent. We use it for one thing: warning you before you order a drink that contains, or may contain, one of them. It is special-category data under Article 9 of the GDPR, so we ask for it as an explicit, separate choice - never as a side effect of a settings toggle - and you can withdraw it in one tap, which deletes it. It is never written into our operational logs, never shown on any staff or dashboard screen, never shared with anyone, and never used to profile or market to you. Your order records only THAT you acknowledged a warning, never which allergens you declared.
- Your saved drinks. The recipes (drink settings) you choose to save to your account.
- Your orders. The drink, price, machine, times, and order status. If you ask for a named invoice you may provide your CNP; otherwise none is collected.
- Payments. A payment reference from our processor. Your card details are entered on the payment provider's own page and never reach our systems.
- Invoices. The fiscal invoice we are legally required to issue for each sale.
- Sessions. A secure, hashed sign-in token so you stay logged in. We store only the hash, never the token itself.
- Machine and service data. Operational events from the machines (order events, brew progress, stock, faults). These are keyed to machines and orders; no name or email is written into them.
- Shared drinks. If you share a saved drink, we store a copy of that drink's name and settings behind a random link. The link reveals only the drink, never your identity.
- Your location - only if you allow it, and it stays on your phone. The "Find a machine" map asks for your position so it can centre the map on you and list machines nearest first. Your coordinates are used on the device only: they are never sent to JUSTO's servers and we never store them. Say no and the map still works - it simply shows every machine instead of sorting by distance. The map itself is drawn by your phone's map service (Google Maps on Android, Apple Maps on iOS), which will see your position and what part of the world you are looking at, under its own privacy policy. You can withdraw the permission at any time in your phone's settings.
3. Why we are allowed to use it (legal bases)
- To provide the service (your account, orders, saved drinks, taste recommendations) - performance of our contract with you.
- To meet legal obligations - issuing and keeping fiscal invoices under Romanian accounting and tax law.
- Our legitimate interests - running, maintaining and securing the machines and the service (operational telemetry, preventing abuse). These events are about machines and orders, not your browsing.
- Your explicit consent - the allergen profile, and only that. It is health data, so consent is the only lawful basis we rely on for it (Article 9(2)(a)), we record when you gave it, and withdrawing it is as easy as giving it (Article 7(3)): clearing the list in the app withdraws it and deletes the data. Withdrawing affects nothing else about your account, and stops only the warnings.
4. Sign-in
You sign in with Google (Apple later). Your provider confirms your identity to us and we issue our own session; we receive your email and name from them and nothing more. Passwords do not exist anywhere in JUSTO.
5. Payments
Card payments are handled by our payment processor (NETOPIA Payments, a Romanian company) on their own secure page. We receive only a transaction reference and the result - we never receive, store or process your card number, so JUSTO is outside the scope of card-data handling.
6. Invoices and e-Factura
Each sale gets a fiscal invoice, issued through our invoicing provider (FGO, a Romanian company) and reported to the Romanian tax authority (ANAF) through the e-Factura system, as the law requires. A CNP is not required for an individual; when none is given the invoice carries an anonymized code.
7. Who we share it with
We do not sell your data or use it for advertising. We share it only with the service providers (processors) that make JUSTO work, each under a data processing agreement:
| Provider | What they handle | Where |
|---|---|---|
| Render | Hosting (servers, database) | EU (Frankfurt) |
| Cloudflare | Network, security, access | Global |
| Sign-in identity | US | |
| Google Maps (Android) | Drawing the machine map; sees your position while the map is open. Not shared with us. | US |
| Apple Maps (iOS) | Drawing the machine map; sees your position while the map is open. Not shared with us. | US / EU |
| NETOPIA | Card payments | Romania (EU) |
| FGO | Fiscal invoicing | Romania (EU) |
International transfers. Your account and order data are stored in the EU (Render's Frankfurt region). Some providers (Cloudflare, Google) may process data outside the European Economic Area, for example in the United States. Where they do, the transfer is covered by appropriate safeguards - Standard Contractual Clauses and/or the EU-US Data Privacy Framework.
8. How long we keep it
- Account, taste profile, saved drinks: for as long as your account exists. Delete your account and they are removed.
- Allergen profile: until you clear it or delete your account, whichever comes first. It is included in your data export.
- Sessions: expire and are deleted automatically.
- Orders: kept as long as Romanian accounting and tax law requires, even after you delete your account - but then unlinked from you, with your account, your name and any CNP removed from them.
- Invoices: a fiscal invoice already issued cannot be changed or withdrawn. Where one carries your name, email or CNP, that copy stays with our invoicing provider and with ANAF for the retention period the law sets, because we are legally obliged to keep it (GDPR art. 17(3)(b)). We keep only the invoice number.
- Machine/operational data: kept for as long as it is useful to run and secure the fleet, then aged out.
9. Your rights
Under the GDPR you can, at any time:
- Get a copy of your data - use "Export my data" in the app profile, which downloads everything we hold about you as one file.
- Delete your account - use "Delete account" in the app profile. This erases your account, sessions, saved drinks and taste profile, and unlinks your past orders. Fiscal invoices already issued are the exception: the law obliges us to keep them and they cannot be altered after issue, so where one names you it stays on file for the statutory period. See "How long we keep it" above.
- Correct your data, object to processing based on our legitimate interests, or restrict it - contact us at [email protected].
You also have the right to lodge a complaint with the Romanian data protection authority, the ANSPDCP (dataprotection.ro).
10. Personalized recommendations (profiling)
The taste quiz builds a preference profile that we use to suggest drinks. This is profiling in the GDPR sense, so we tell you plainly - but it is only a coffee suggestion: there is no automated decision that has a legal or similarly significant effect on you. The quiz is optional, and you can retake or delete the profile whenever you like.
11. Security
We verify sign-ins against the provider's own keys, store session tokens only as SHA-256 hashes, encrypt traffic with TLS, keep the operations panel behind both a login wall and a token, and self-host our fonts so viewing our pages does not send your IP address to a font CDN.
12. Children
JUSTO is not directed at children and is not intended for anyone under 16. We do not knowingly collect data from children.
13. Cookies and tracking
The JUSTO app does not use advertising or tracking cookies. This website uses only what is technically necessary to serve and secure the pages. We do not track people who merely walk past a machine.
14. Changes to this policy
If we change how we handle data, we will update this page and its effective date. Material changes will be made clear.