Now rolling out across Australia & New Zealand — cafés and resellers welcome. Book a demo

Privacy Policy

Esh Bros Pty Limited ABN 60 074 351 992 trading as LOYREW, operator of LoyalCup

Effective: 23 August 2026 · Version: 1.0

1. Who we are

LoyalCup is a loyalty system operated by Esh Bros Pty Limited (we, us, our). It combines an always-on counter display, a branded customer app and an owner dashboard.

In this policy:

  • Client — a café, quick-service restaurant or hospitality business that subscribes to LoyalCup.
  • Customer — a member of the public who joins a client’s loyalty programme through the branded app or counter display.
  • Partner — a reseller or channel partner appointed by us.
  • You — whichever of these applies to you, including a visitor to loyrew.com.

2. Our commitment and the law that applies

We handle personal information in accordance with the Privacy Act 1988 (Cth) (the Act) and the Australian Privacy Principles (APPs).

We are committed to complying with the APPs whether or not the Act currently binds us.

3. What this policy covers

This policy covers personal information we collect through:

  • the LoyalCup website at loyrew.com, including enquiry forms and the newsletter;
  • our sales tools (the client landing page, the ROI calculator and the client demo);
  • the LoyalCup platform — the counter display, the branded app and the owner dashboard;
  • our dealings with clients, partners and prospective investors.

4. What we collect, and from whom

4.1 Website visitors and enquirers

When you submit an enquiry, request a demo, apply as a reseller, or contact us as an investor, we collect:

  • your name;
  • your email address;
  • your business name;
  • your phone number, where you provide it;
  • the content of your message and any answers you give in our sales tools (for example, weekly cup volumes entered into the ROI calculator);
  • the type of enquiry (client, reseller or investor);
  • the page or tool the enquiry came from, and the date and time it was submitted.

If you subscribe to our newsletter, we collect your email address and the audience type you select (client, reseller, or other), together with your consent to receive email updates.

4.2 Clients

For businesses that subscribe, we collect business contact details, the names and contact details of nominated staff users, site and location details for each venue, and configuration data for the loyalty programme (branding, stamp rules, rewards and promotions).

4.3 Customers

When a member of the public joins a client’s loyalty programme, the platform collects:

  • identifying details provided at enrolment — typically a first name and an email address or mobile number, generally using your opted in credentials of your Apple or Google store credentials.
  • loyalty activity, such as stamps earned, visit dates and times, rewards issued and redeemed, and scratch-card outcomes;
  • device and app data necessary to operate the app, including a device identifier and push-notification token;
  • approximate location, but only where a customer has enabled location permissions for geo-push notifications, if the client chooses to use such a feature and if it is permitted to be used by you.

We collect this information as a service provider to the client. See section 9.

4.4 Everyone

We collect standard technical information such as IP address, browser and device type, referring page and pages viewed through our website analytics. 

5. What we do not collect

We do not process payments through our website or the platform. Subscription fees, hardware charges and partner commissions are invoiced and settled separately, outside the platform.

Accordingly, we do not collect or store credit card numbers, debit card numbers, CVV codes or bank account details through the website or the platform. If you provide payment details to us for invoicing, that happens outside these systems and is handled under our ordinary accounting arrangements.

We do not knowingly collect sensitive information as defined in the Privacy Act such as health, racial or ethnic origin, political opinions, sexual orientation, or biometric data.

6. Location data and push notifications

The branded app can send a customer a notification when they are near a participating client.

This works only if the customer grants location permission to the app on their device. The permission can be withdrawn at any time in the device’s settings, and withdrawing it stops geo-push notifications without affecting the rest of the loyalty programme.

We do not store such information, even if it is granted.

7. The counter display

The LoyalCup counter display is a screen in a public place inside a client’s premises. 

This means limited personal information may be briefly visible to other people standing at the counter. We limit what appears to a first name and loyalty progress, and the display does not show email addresses, phone numbers or transaction history. Customers who would prefer their name not to appear can ask the client, or us, to turn this off for their account.

8. How we use personal information

PurposeApplies to
Responding to enquiries and arranging demonstrationsEnquirers
Sending an automated acknowledgement of your enquiryEnquirers
Assessing reseller applications and managing partnershipsPartners
Providing, configuring and supporting the LoyalCup platformClients
Operating loyalty programmes — issuing stamps, rewards and offersCustomers
Sending geo-push notifications where permission is givenCustomers
Producing dashboard analytics on visit frequency and retentionClients
Identifying lapsing regulars and generating the monthly health digestClients
Sending our newsletter, where you have consentedSubscribers
Improving the website and understanding how it is usedVisitors
Meeting our legal, tax and record-keeping obligationsEveryone

We do not sell personal information.

9. Customer data — who controls it

A client’s customer list belongs to that client, not to us.

We hold and process customer information on behalf of the client, under our agreement with them. The client decides what its loyalty programme offers and how it communicates with its own customers. A client can export its customer list at any time as long as their subscription is active.

If you are a customer and you want your information accessed, corrected or deleted, you can contact either the client whose loyalty programme you joined or us at the address in section 17. We will act on the request and, where appropriate, refer it to the client.

10. Who we disclose personal information to

We disclose personal information to:

  • the relevant client, in respect of its own customers;
  • our service providers, who are permitted to use it only to provide services to us as listed in the table below:
CategoryUsed forProvider
Website and application hostingRunning the site and platformAzure, Microsoft
Customer relationship management (CRM)Enquiry records and follow-upZOHO or as relevant (we will update this from time to time)
Automation / integrationPassing enquiries to the CRMZOHO or as relevant (we will update this from time to time)
Email delivery and marketingAcknowledgements and newsletterZOHO or as relevant (we will update this from time to time)
Website analyticsTraffic and engagement measurementGoogle Analytics, ZOHO or as relevant (we will update this from time to time)
Live chatWebsite enquiriesZOHO or as relevant (we will update this from time to time)
Push notification deliveryApp notificationsZOHO or as relevant (we will update this from time to time)
Professional advisersAccounting, legal, insuranceAs required
  • others, where you consent, or where we are required or authorised by law.

We do not disclose personal information to third parties for their own marketing purposes.

11. Overseas disclosure

Some of our service providers may store or process personal information outside Australia.

Where we disclose personal information overseas we take reasonable steps to ensure the recipient handles it consistently with the APPs, including through contractual terms.

12. Cookies, analytics and tracking

Our website uses cookies and similar technologies to keep the site working, remember your preferences, and measure how the site is used.

We use cookies from our analytics and tag manager service providers. These set cookies that record pages viewed, time on site and interactions such as button clicks and video plays. IP anonymisation is enabled in our Google Analytics configuration.

Non-essential cookies are not set until you accept them. You can decline non-essential cookies, and you can block or delete cookies in your browser at any time. Declining will not stop you using the site, though some features may not work as well.

13. Direct marketing

We send marketing email only where you have opted in, in accordance with the Spam Act 2003.

Every marketing email we send identifies us as the sender and contains a working unsubscribe link. Unsubscribing takes effect promptly and, in any event, within five business days. You can also unsubscribe by emailing us.

14. Security

We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. These include transport encryption (HTTPS), access controls limiting staff access to what their role requires, and dashboard access restricted to authorised users of each client.

Sales tool links are issued per prospect with a unique key and can be revoked. QR codes are generated locally in the browser, so no third-party service receives your links.

No system is completely secure, and we cannot guarantee the security of information transmitted to us over the internet.

15. Data breaches

We maintain a data breach response plan. If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act.

Where a breach affects customer information, we will also notify the relevant client promptly so it can meet its own obligations.

16. How long we keep information

InformationRetention
Enquiries that do not become clients24 months from last contact
Client recordsFor the term of the agreement and retained as required for tax and legal purposes
Customer loyalty dataFor as long as the client’s subscription continues, then deleted within 2 years.
Newsletter subscribersUntil you unsubscribe, then suppression-list only

We destroy or de-identify personal information when it is no longer needed for any purpose for which it may be used or disclosed and we are not required by law to retain it.

17. Access, correction and complaints

Access and correction. You may request access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. Contact us at the address below. We will respond within 30 days. There is no charge for making a request; we may charge a reasonable cost for providing access in some circumstances, and will tell you before we do. If we refuse access or correction we will explain why in writing and tell you how to complain.

Complaints. If you believe we have breached the APPs, please contact us first at the address below. We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days.

If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner.

18. Children

The LoyalCup platform is not directed at children. A client’s loyalty programme is intended for adult customers, and clients should not enrol a person under 16 or any relevant local legal age as relevant, without the consent of a parent or guardian. If you believe we hold information about a child collected without consent, contact us and we will delete it.

19. Changes to this policy

We may update this policy from time to time. The current version is always available at loyrew.com/privacy/, with the effective date at the top. Where a change is significant we will take reasonable steps to notify clients and, where appropriate, other affected individuals.

20. Contact us

Privacy Officer

Esh Bros Pty Limited trading as LOYREW

Email: privacy@loyrew.com

Post: 7 Dunbil Court Bangor NSW 2234 Australia