Privacy Policy
Your privacy is important to us. Learn how we collect, use, and protect your data.
Last updated: January 12, 2026
At SIDAMO Café & Roastery ("we," "our," or "us"), we are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our services. Please read this policy carefully to understand our practices regarding your personal data.
GDPR Compliance
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, this Privacy Policy also serves as our GDPR Privacy Notice. We process your personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
1. Information We Collect
We collect information that you provide directly to us, information automatically collected when you use our services, and information from third-party sources.
1.1 Personal Information
We may collect the following personal information:
- Name: To identify and communicate with you
- Email Address: For account creation, order confirmations, and communications
- Phone Number: For order updates and customer service
- Address: For order fulfillment and shipping
- Payment Information: Processed securely through third-party payment processors
- Account Credentials: Username and password for account security
- Business Information: Company name and tax ID (for business accounts)
1.2 Automatically Collected Information
When you visit our website, we automatically collect:
- IP address and device information
- Browser type and version
- Operating system
- Pages visited and time spent on pages
- Referring website addresses
- Cookies and similar tracking technologies
1.3 Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your experience, analyze site usage, and assist in our marketing efforts. You can control cookies through your browser settings, but disabling cookies may limit your ability to use certain features of our website.
2. How We Use Your Information
We use the information we collect for the following purposes:
- Account Creation and Authentication: To create and manage your account, verify your identity, and authenticate your access
- Order Processing and Fulfillment: To process, fulfill, and ship your orders
- Customer Service Communications: To respond to your inquiries, provide support, and communicate about your orders
- Legal Compliance and Account Security: To comply with legal obligations, prevent fraud, and ensure account security
- Marketing and Promotions: To send you marketing communications (with your consent) about our products, services, and promotions
- Website Improvement: To analyze website usage, improve our services, and enhance user experience
- Legal Requirements: To comply with applicable laws, regulations, and legal processes
Legal Basis for Processing (GDPR): We process your personal data based on (1) your consent, (2) the necessity to perform a contract with you, (3) compliance with legal obligations, (4) protection of vital interests, (5) our legitimate interests, and (6) your consent for marketing communications.
3. How We Share Your Information
We do not sell your personal information. We may share your information in the following circumstances:
- Service Providers: With third-party service providers who perform services on our behalf (payment processing, shipping, email services)
- Business Transfers: In connection with any merger, sale of assets, or acquisition
- Legal Requirements: When required by law, court order, or government regulation
- Protection of Rights: To protect our rights, property, or safety, or that of our users or others
- With Your Consent: When you have provided explicit consent for us to share your information
All service providers are contractually obligated to protect your information and use it only for the purposes we specify.
4. Data Security
We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- SSL/TLS encryption for data transmission
- Secure servers and databases
- Regular security assessments
- Access controls and authentication
- Employee training on data protection
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.
5. Your Rights (GDPR and CCPA)
Depending on your location, you may have the following rights regarding your personal data:
Right to Access
You have the right to request access to your personal data and receive a copy of the data we hold about you.
Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data.
Right to Erasure ("Right to be Forgotten")
You have the right to request deletion of your personal data under certain circumstances.
Right to Restrict Processing
You have the right to request restriction of processing of your personal data.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used format.
Right to Object
You have the right to object to processing of your personal data for direct marketing purposes.
Right to Withdraw Consent
You have the right to withdraw your consent at any time where we rely on consent to process your data.
To exercise any of these rights, please contact us using the contact information provided at the end of this policy. We will respond to your request within 30 days (or as required by applicable law).
6. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. Factors we consider when determining retention periods include:
- The nature and sensitivity of the data
- The potential risk of harm from unauthorized use or disclosure
- The purposes for which we process the data
- Legal and regulatory requirements
When we no longer need your personal data, we will securely delete or anonymize it in accordance with our data retention policies.
7. International Data Transfers
Your information may be transferred to and maintained on computers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ.
If you are located outside the United States and choose to provide information to us, please note that we transfer the data to the United States and process it there.
For users in the EEA, UK, or Switzerland, we ensure appropriate safeguards are in place for international transfers, including standard contractual clauses approved by the European Commission.
8. Children's Privacy
Our services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete such information.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
For material changes, we will provide additional notice through email or prominent notice on our website. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
10. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- SIDAMO Café & Roastery
- Email: info@lasidamo.com
- Phone: 3109903687
- Address: US
For GDPR-related requests, you also have the right to lodge a complaint with your local data protection authority if you believe we have not addressed your concerns satisfactorily.
By using our services, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of your information as described herein.