Privacy Policy
Esh Bros Pty Limited ABN 60 074 351 992 trading as LOYREW, operator of LoyalCup
Effective: 23 August 2026 · Version: 1.0
1. Who we are
LoyalCup is a loyalty system operated by Esh Bros Pty Limited (we, us, our). It combines an always-on counter display, a branded customer app and an owner dashboard.
In this policy:
- Client — a café, quick-service restaurant or hospitality business that subscribes to LoyalCup.
- Customer — a member of the public who joins a client’s loyalty programme through the branded app or counter display.
- Partner — a reseller or channel partner appointed by us.
- You — whichever of these applies to you, including a visitor to loyrew.com.
2. Our commitment and the law that applies
We handle personal information in accordance with the Privacy Act 1988 (Cth) (the Act) and the Australian Privacy Principles (APPs).
We are committed to complying with the APPs whether or not the Act currently binds us.
3. What this policy covers
This policy covers personal information we collect through:
- the LoyalCup website at loyrew.com, including enquiry forms and the newsletter;
- our sales tools (the client landing page, the ROI calculator and the client demo);
- the LoyalCup platform — the counter display, the branded app and the owner dashboard;
- our dealings with clients, partners and prospective investors.
4. What we collect, and from whom
4.1 Website visitors and enquirers
When you submit an enquiry, request a demo, apply as a reseller, or contact us as an investor, we collect:
- your name;
- your email address;
- your business name;
- your phone number, where you provide it;
- the content of your message and any answers you give in our sales tools (for example, weekly cup volumes entered into the ROI calculator);
- the type of enquiry (client, reseller or investor);
- the page or tool the enquiry came from, and the date and time it was submitted.
If you subscribe to our newsletter, we collect your email address and the audience type you select (client, reseller, or other), together with your consent to receive email updates.
4.2 Clients
For businesses that subscribe, we collect business contact details, the names and contact details of nominated staff users, site and location details for each venue, and configuration data for the loyalty programme (branding, stamp rules, rewards and promotions).
4.3 Customers
When a member of the public joins a client’s loyalty programme, the platform collects:
- identifying details provided at enrolment — typically a first name and an email address or mobile number, generally using your opted in credentials of your Apple or Google store credentials.
- loyalty activity, such as stamps earned, visit dates and times, rewards issued and redeemed, and scratch-card outcomes;
- device and app data necessary to operate the app, including a device identifier and push-notification token;
- approximate location, but only where a customer has enabled location permissions for geo-push notifications, if the client chooses to use such a feature and if it is permitted to be used by you.
We collect this information as a service provider to the client. See section 9.
4.4 Everyone
We collect standard technical information such as IP address, browser and device type, referring page and pages viewed through our website analytics.
5. What we do not collect
We do not process payments through our website or the platform. Subscription fees, hardware charges and partner commissions are invoiced and settled separately, outside the platform.
Accordingly, we do not collect or store credit card numbers, debit card numbers, CVV codes or bank account details through the website or the platform. If you provide payment details to us for invoicing, that happens outside these systems and is handled under our ordinary accounting arrangements.
We do not knowingly collect sensitive information as defined in the Privacy Act such as health, racial or ethnic origin, political opinions, sexual orientation, or biometric data.
6. Location data and push notifications
The branded app can send a customer a notification when they are near a participating client.
This works only if the customer grants location permission to the app on their device. The permission can be withdrawn at any time in the device’s settings, and withdrawing it stops geo-push notifications without affecting the rest of the loyalty programme.
We do not store such information, even if it is granted.
7. The counter display
The LoyalCup counter display is a screen in a public place inside a client’s premises.
This means limited personal information may be briefly visible to other people standing at the counter. We limit what appears to a first name and loyalty progress, and the display does not show email addresses, phone numbers or transaction history. Customers who would prefer their name not to appear can ask the client, or us, to turn this off for their account.
8. How we use personal information
| Purpose | Applies to |
| Responding to enquiries and arranging demonstrations | Enquirers |
| Sending an automated acknowledgement of your enquiry | Enquirers |
| Assessing reseller applications and managing partnerships | Partners |
| Providing, configuring and supporting the LoyalCup platform | Clients |
| Operating loyalty programmes — issuing stamps, rewards and offers | Customers |
| Sending geo-push notifications where permission is given | Customers |
| Producing dashboard analytics on visit frequency and retention | Clients |
| Identifying lapsing regulars and generating the monthly health digest | Clients |
| Sending our newsletter, where you have consented | Subscribers |
| Improving the website and understanding how it is used | Visitors |
| Meeting our legal, tax and record-keeping obligations | Everyone |
We do not sell personal information.
9. Customer data — who controls it
A client’s customer list belongs to that client, not to us.
We hold and process customer information on behalf of the client, under our agreement with them. The client decides what its loyalty programme offers and how it communicates with its own customers. A client can export its customer list at any time as long as their subscription is active.
If you are a customer and you want your information accessed, corrected or deleted, you can contact either the client whose loyalty programme you joined or us at the address in section 17. We will act on the request and, where appropriate, refer it to the client.
10. Who we disclose personal information to
We disclose personal information to:
- the relevant client, in respect of its own customers;
- our service providers, who are permitted to use it only to provide services to us as listed in the table below:
| Category | Used for | Provider |
| Website and application hosting | Running the site and platform | Azure, Microsoft |
| Customer relationship management (CRM) | Enquiry records and follow-up | ZOHO or as relevant (we will update this from time to time) |
| Automation / integration | Passing enquiries to the CRM | ZOHO or as relevant (we will update this from time to time) |
| Email delivery and marketing | Acknowledgements and newsletter | ZOHO or as relevant (we will update this from time to time) |
| Website analytics | Traffic and engagement measurement | Google Analytics, ZOHO or as relevant (we will update this from time to time) |
| Live chat | Website enquiries | ZOHO or as relevant (we will update this from time to time) |
| Push notification delivery | App notifications | ZOHO or as relevant (we will update this from time to time) |
| Professional advisers | Accounting, legal, insurance | As required |
- others, where you consent, or where we are required or authorised by law.
We do not disclose personal information to third parties for their own marketing purposes.
11. Overseas disclosure
Some of our service providers may store or process personal information outside Australia.
Where we disclose personal information overseas we take reasonable steps to ensure the recipient handles it consistently with the APPs, including through contractual terms.
12. Cookies, analytics and tracking
Our website uses cookies and similar technologies to keep the site working, remember your preferences, and measure how the site is used.
We use cookies from our analytics and tag manager service providers. These set cookies that record pages viewed, time on site and interactions such as button clicks and video plays. IP anonymisation is enabled in our Google Analytics configuration.
Non-essential cookies are not set until you accept them. You can decline non-essential cookies, and you can block or delete cookies in your browser at any time. Declining will not stop you using the site, though some features may not work as well.
13. Direct marketing
We send marketing email only where you have opted in, in accordance with the Spam Act 2003.
Every marketing email we send identifies us as the sender and contains a working unsubscribe link. Unsubscribing takes effect promptly and, in any event, within five business days. You can also unsubscribe by emailing us.
14. Security
We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. These include transport encryption (HTTPS), access controls limiting staff access to what their role requires, and dashboard access restricted to authorised users of each client.
Sales tool links are issued per prospect with a unique key and can be revoked. QR codes are generated locally in the browser, so no third-party service receives your links.
No system is completely secure, and we cannot guarantee the security of information transmitted to us over the internet.
15. Data breaches
We maintain a data breach response plan. If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act.
Where a breach affects customer information, we will also notify the relevant client promptly so it can meet its own obligations.
16. How long we keep information
| Information | Retention |
| Enquiries that do not become clients | 24 months from last contact |
| Client records | For the term of the agreement and retained as required for tax and legal purposes |
| Customer loyalty data | For as long as the client’s subscription continues, then deleted within 2 years. |
| Newsletter subscribers | Until you unsubscribe, then suppression-list only |
We destroy or de-identify personal information when it is no longer needed for any purpose for which it may be used or disclosed and we are not required by law to retain it.
17. Access, correction and complaints
Access and correction. You may request access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. Contact us at the address below. We will respond within 30 days. There is no charge for making a request; we may charge a reasonable cost for providing access in some circumstances, and will tell you before we do. If we refuse access or correction we will explain why in writing and tell you how to complain.
Complaints. If you believe we have breached the APPs, please contact us first at the address below. We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner.
18. Children
The LoyalCup platform is not directed at children. A client’s loyalty programme is intended for adult customers, and clients should not enrol a person under 16 or any relevant local legal age as relevant, without the consent of a parent or guardian. If you believe we hold information about a child collected without consent, contact us and we will delete it.
19. Changes to this policy
We may update this policy from time to time. The current version is always available at loyrew.com/privacy/, with the effective date at the top. Where a change is significant we will take reasonable steps to notify clients and, where appropriate, other affected individuals.
20. Contact us
Privacy Officer
Esh Bros Pty Limited trading as LOYREW
Email: privacy@loyrew.com
Post: 7 Dunbil Court Bangor NSW 2234 Australia