Privacy Policy
Last updated: October 6, 2026
The short version. We collect what we need to run PintDeck: your account and brewery details, what you put into the app, and how the app is used. We use PostHog to understand how people use PintDeck, which includes recording some sessions in the signed-in web app, and Sentry to find and fix errors. We don't sell personal information, and we don't use it for advertising. Information about your guests belongs to you, and we process it on your behalf. You can ask us to see, correct, export, or delete your data at any time. This summary isn't the whole policy; the sections below are.
1. Who We Are and What This Policy Covers
PintDeck is operated by Digitally Simple LLC, an Idaho limited liability company ("PintDeck," "we," "us," or "our").
This policy explains how we handle personal information in PintDeck Business, which includes:
- the PintDeck Business web app at business.pintdeck.io and our website at pintdeck.io;
- the PintDeck Business iPhone and Apple Watch apps;
- the PintDeck apps for Fire TV and other TV devices; and
- the menus, screens, embeds, QR codes, and other public pages that breweries publish with PintDeck.
PintDeck Taste, our app for beer drinkers, will get its own privacy policy. Until then, Section 6 summarizes what Taste collects and what breweries can see.
2. Our Role
When we decide how data is used. For information about the people who use PintDeck Business (account details, billing, support, and how the app is used), PintDeck decides how that information is used. We're its "controller" under laws like the GDPR, and a "business" under U.S. state privacy laws.
When we process data for a brewery. Breweries use PintDeck to keep information about their guests, such as club members, ticket buyers, tournament entrants, and their Square customers. For that information, the brewery decides how it's used, and PintDeck processes it on the brewery's behalf as a "processor" or "service provider." If you're a guest and want to see, correct, or delete what a brewery keeps about you, contact the brewery. You can also contact us and we'll help, or pass your request to the brewery.
3. Information We Collect
3.1 Information You Give Us
- Account details. Your name, email address, password (stored only in hashed form), and profile photo, if you add one. If you continue with Apple or Google, we receive your name, email address, and an account ID from them. Apple may give us a private relay email address instead of your real one.
- Your brewery's details. Its name, address, phone number, website, time zone, hours, logo, size, and the check-in area you draw on a map.
- Your team. The names and email addresses of people you invite, and their roles.
- Billing details. The plan you choose and the billing contacts you add. Stripe collects your payment method and billing address at checkout (see Section 3.4). We don't receive or store full card numbers.
- Content. Everything you add to the app, such as beers, menus, recipes, kegs, inventory, events, images, club perks, and messages.
- Information about your guests that you or your staff add or import (see Section 5).
- AI prompts. The descriptions you write when you use AI image generation.
- Forms and support. What you send us through our start, contact, and waitlist forms, such as your name, email, brewery, phone number, city, point-of-sale system, and notes, and anything you send to support.
- Choices. Your email preferences, including whether you want product updates. Product update emails are off unless you turn them on.
3.2 Information Collected Automatically
- Sign-in and security data. When you sign in, we record your IP address, browser or device, and the time, to keep your account secure and to prevent abuse such as repeated failed sign-ins.
- Product analytics (PostHog). On our website and in the web app, we collect the pages you view, what you click and tap, how long you stay, the features you use, your browser, device, and operating system, the page that referred you, and your IP address. We use the IP address to estimate your approximate location (such as city and country). When you're signed in, this data is linked to your user ID, name, email address, and brewery.
- Session recordings (PostHog). After you sign in to the PintDeck Business web app, we may record your session. A recording captures what appears on the screen and how you move through it, such as clicks, scrolls, and pages, along with page load and network timings and browser console messages. We hide what you type into form fields, email addresses and phone numbers anywhere on screen, and all text on the screens that list your guests, such as club members, ticket buyers, and tournament entries. We don't record our marketing website, sign-in pages, or the menus and pages breweries publish. We use recordings only to fix problems and improve PintDeck, and we keep them for 30 days.
- Errors and performance (Sentry and PostHog). When something breaks, we collect technical details such as the error, the page or screen, your browser or device, the app version, and how long requests took. Sentry reports identify you only by your user ID. We set Sentry not to collect cookies, IP addresses, or request contents, and we remove links that grant access, such as invite and ticket links, before a report is sent.
- iPhone and Apple Watch apps. Screens viewed, when the app is opened and closed, the features you use, your device model, operating system, app version, and crash reports. We don't record your screen in the apps. If you allow notifications or Live Activities, we store a push token so we can send them. The camera is used only to scan QR codes, and scanning happens on your device. Photos you choose to upload are stored with your content.
- TV apps and screens. For each screen, we collect a device identifier, device model, operating system and app version, which menu or playlist it shows, and whether it's online, so you can see your screens' status.
- Cookies and similar technologies. See Section 8.
3.3 Information About Visitors to Breweries' Public Pages
When someone opens a menu, embed, or other public page that a brewery publishes with PintDeck, such as a club, ticket, or tournament page, we count the visit without using cookies or local storage to recognize the visitor's browser. We collect the page viewed and the browser and device. The IP address is used only to tell visits apart for one day, together with the browser details, and isn't stored with the visit (see Section 8). We don't record sessions or track clicks on these pages. We use this to run the pages, count how often menus are seen, and improve PintDeck. Some public pages load fonts from Google Fonts, which means your browser sends your IP address to Google.
3.4 Information From Other Sources
- Stripe. Stripe sells and bills PintDeck subscriptions as the merchant of record. It sends us your subscription status, plan, billing period, and receipts, and lets us show limited card details, such as the card brand and last four digits, in the Billing tab. Stripe handles your payment information under its own privacy policy.
- Connected accounts. If you connect Square or Stripe to take payments or run your club, we receive data from those accounts as needed for the features you use, such as your locations, catalog, customers, orders, payments, and subscriptions.
- Your organization. An owner or admin may add you to their organization's workspace by inviting your email address.
- PintDeck Taste. Taste members can choose to share information with your brewery (see Section 6).
4. How We Use Information
We use personal information to:
- provide the Service: create and secure accounts, sign you in, run your workspace, publish your menus and screens, send what you ask us to send, and connect the services you choose;
- process subscriptions, trials, and plan changes (with Stripe);
- send service emails, such as verification, sign-in links, password resets, invitations, receipts, billing alerts, and notices about changes to the Service or these policies;
- send product updates, if you've turned them on;
- understand how PintDeck is used and improve it, including by testing new features and offers with some customers;
- find and fix bugs and performance problems;
- provide support and respond to requests;
- detect and prevent fraud, abuse, and security incidents;
- create aggregated or de-identified data that doesn't identify anyone; and
- comply with the law and enforce our Terms of Service.
We don't sell personal information, and we don't use it for targeted advertising. We don't allow advertising networks to collect information through PintDeck.
Legal Bases (EEA, UK, and Switzerland)
Where the GDPR or a similar law applies, we rely on:
| Purpose | Legal basis |
|---|---|
| Providing the Service, billing, service emails, support | Performance of our contract with you |
| Analytics, session recordings, improving the Service, security, fraud prevention | Our legitimate interests in running, securing, and improving PintDeck |
| Product update emails | Your consent, which you can withdraw at any time |
| Keeping records, responding to lawful requests | Legal obligations |
5. Information About Your Guests
Breweries can use PintDeck to keep information about their guests, including:
- Club members: name, email, phone number, birthday (month and day only), membership level and status, perks, punch cards, visit and purchase history at that brewery, notes staff add, and email preferences. Members can join through a brewery's join page, through Taste, or when staff add them, including at a Square register.
- Ticket buyers and attendees: name, email, phone number, the tickets they bought, and limited payment details (card brand, last four digits, and receipt link). Payments go through the brewery's own Stripe or Square account.
- Tournament entrants: name, email address, and phone number.
- Private event contacts: name, email, phone number, and company, entered by staff.
- Square data: when a brewery connects Square, we store order details (totals, items, and quantities) to count visits and purchases and to build sales reports. We link orders to a customer only when that customer is a club member. We also receive Square's customer update notifications, which can include details of the brewery's other Square customers; we delete them after 90 days.
We process this information to provide the Service to the brewery, as described in Section 2. Each brewery is responsible for having the right to collect it, for messages it sends, and for honoring its guests' choices. Every club email and follower update has a link to stop them. You can also contact the brewery or us.
6. PintDeck Taste and What Breweries Can See
This section is a summary until Taste has its own privacy policy.
What Taste collects. Your account details, username and photo, and your date of birth, which we use to confirm you're 21 or older; your beer logs, ratings, notes, wishlist, and collections; the breweries you follow and events you plan to attend; your clubs, tickets, and tournament entries; your notification settings and push token; and analytics and error data like that described in Section 3.2. When you check in, we collect your device's precise location to confirm you're at the brewery.
What breweries can see. Breweries never see the date of birth on your Taste account or your exact location. They can see:
- Follows and plans to attend: only how many people follow them or plan to come, not who.
- Beer feedback: combined ratings for their beers, and tasting notes you haven't made private, without your name.
- Your logs on their TV screens: your name, photo, and note appear only if you turn on showing your logs on screens. Otherwise, if the brewery allows it, a log may appear as "A Taste member" with the beer and rating.
- Club membership: when you join a brewery's club, it sees the details you gave when joining (such as your name, email, phone number, and birthday). If your Taste account is linked to the membership, it also sees your Taste username, photo, and email; the days you visited; the beers you've tried there; your recent public logs and ratings of its beers; and the events and challenges you took part in at that brewery.
- Tickets and tournaments: your name, email, and phone number, and what you bought or entered.
Apple Wallet. If you add a membership card to Apple Wallet, the pass contains your name, member number, level, perks, and the brewery's location, so it can appear when you're nearby.
7. How We Share Information
We share personal information only as follows:
- With our service providers (subprocessors), who process it on our behalf under contracts that require them to protect it:
| Provider | What they do for us | Location |
|---|---|---|
| Supabase | Database, authentication data, file storage | United States |
| Vercel | Website and app hosting, server functions, logs | United States and global edge network |
| PostHog | Product analytics, session recordings, feature flags, error tracking | United States |
| Sentry | Error and performance monitoring | United States |
| Resend | Sending email | United States |
| Stripe | Subscription billing as merchant of record; payments on breweries' own Stripe accounts | United States |
| Square | Point-of-sale, loyalty, and payments for breweries that connect it | United States |
| OpenAI | AI image generation (receives the prompt you write) | United States |
| Mapbox | Address search and maps | United States |
| Apple | Sign in with Apple, push notifications and Live Activities, Apple Wallet passes | United States |
| Sign in with Google, web fonts | United States | |
| Cloudflare | DNS and network services | United States and global edge network |
- Within your organization. Team members in your organization's workspace can see its content, your name and email, and who made some changes.
- With breweries, at a Taste member's choice, as described in Section 6.
- With the services you connect, such as Square and Stripe, when you ask us to.
- For legal reasons, when we believe in good faith that the law requires it, or to protect the rights, property, or safety of PintDeck, our users, or others.
- In a business transfer, such as a merger, acquisition, or sale of assets, in which case the information stays subject to this policy.
- With your consent or at your direction.
We'll update the table above, and email account owners at least 30 days before we add a subprocessor that handles personal data in a materially different way.
8. Cookies, Local Storage, and Similar Technologies
| Type | What it does | Examples |
|---|---|---|
| Essential | Keep you signed in and secure your session. The Service doesn't work without them. | PintDeck sign-in cookies (names starting with pintdeck) |
| Preferences | Remember settings on your device, such as how a table or view is set up. | Browser local storage |
| Analytics | Recognize your browser between visits so we can understand how PintDeck is used, and record sessions in the signed-in app (Section 3.2). Not used for the visits described under "Visits we count without cookies." | PostHog cookies and local storage (names starting with ph_ or __ph_) |
| Payments | Help Stripe prevent fraud during checkout. | Stripe cookies on checkout pages |
We don't use advertising cookies, and we don't allow ad networks to place cookies through PintDeck.
Visits we count without cookies. We don't use cookies or local storage to recognize your browser when you visit the menus and pages breweries publish, PintDeck Taste's web pages, or our public website when your browser sends a Global Privacy Control signal or you appear to be in the European Economic Area, the UK, or Switzerland (we go by your device's time zone). We still collect the usage data described in Sections 3.2 and 3.3 for these visits. To tell visits apart, PostHog uses a one-way code made from your IP address and browser details, mixed with a value that changes every day, so a visit can't be linked to the same browser on another day. The IP address isn't stored with these visits, so they aren't given an approximate location. Once you sign in to PintDeck Business, analytics work as described in Section 3.2, because they're part of how we run and support the Service.
Your choices. You can block or delete cookies in your browser, but you'll need essential cookies to sign in. Browser extensions that block analytics will also stop PostHog from collecting data.
Do Not Track and Global Privacy Control. We don't sell personal information or share it for targeted advertising, so these signals have nothing to opt you out of under U.S. state privacy laws. We still honor Global Privacy Control on our public website by counting your visits without cookies, as described above. We don't change anything in response to Do Not Track.
9. How Long We Keep Information
| Information | How long |
|---|---|
| Account details | While your account is open. If you ask us to delete your account, we delete it within 30 days, except what we must keep by law. |
| Your organization's content and guest data | Until the brewery deletes it, or until the organization is deleted. A deleted organization can be restored for 30 days; then we permanently delete it from our production systems. |
| Backups | Deleted data can remain in encrypted backups for up to 90 days. |
| Session recordings | 30 days |
| Square notifications about customers | 90 days |
| Error reports | Up to 90 days |
| Product analytics events | Up to 7 years, the retention period our analytics provider sets. When you delete your account, or ask us, we delete the analytics profile linked to you. |
| Server and security logs | Generally up to 30 days |
| Billing records | Kept by Stripe as long as tax and accounting laws require |
| Support emails | While your account is open, and up to 2 years after our last contact |
| Waitlist and form submissions | Until you ask us to remove them, or 2 years after our last contact |
| Email unsubscribes | As long as needed to honor them |
| Records of legal notices we emailed you | While your account is open |
Some data is kept by the providers in Section 7 under their own retention schedules after we delete our copy.
10. How We Protect Information
We use safeguards that fit the sensitivity of the data, including:
- encryption in transit (TLS) for everything sent between your browser or device and PintDeck;
- encryption at rest for our database and file storage;
- database access rules that keep each organization's data separate from other organizations';
- hashed passwords, and encryption of the access tokens for services you connect, such as Square; and
- access to production data limited to the PintDeck staff who need it to run and support the Service.
No system is perfectly secure. If a breach affects your personal information, we'll notify you, and regulators where required, without undue delay and within the time the law requires.
11. Your Choices and Rights
In the app. You can update your account details, change your email preferences, remove team members, disconnect integrations, export some data (such as club member lists and reports), and, if you're an owner, delete your organization.
By request. Wherever you live, you can ask us to:
- tell you what personal information we have about you and give you a copy;
- correct it;
- delete it;
- give it to you in a portable format; and
- stop sending you product update emails.
Email support@pintdeck.io with the subject "Privacy request." We'll respond within 30 days, or sooner if the law requires. We may ask you to verify your identity, and we may need to keep some information to meet legal obligations. You can use an authorized agent, who must show proof that you authorized them.
U.S. state privacy rights. Residents of California, Colorado, Connecticut, Virginia, and other states with privacy laws have the rights above, plus the right to opt out of the sale of personal information, sharing for targeted advertising, and certain profiling. We don't do any of those. If we deny your request, you can appeal by replying to our decision, and if we deny the appeal, you can contact your state attorney general. We won't treat you differently for using your rights.
EEA, UK, and Swiss residents also have the right to object to processing based on our legitimate interests, to restrict processing, to withdraw consent at any time, and to complain to your local data protection authority.
Guests of a brewery should send requests about a brewery's guest data to the brewery (see Section 2).
12. Children
PintDeck Business is for adults running a business, and PintDeck Taste is only for people 21 and older. We don't knowingly collect personal information from anyone under 18, or from anyone under 21 through Taste. If you believe a minor has given us personal information, contact us and we'll delete it.
13. International Transfers
PintDeck and our providers are based in the United States, and we store and process information there. If you use PintDeck from outside the U.S., your information will be transferred to the U.S., which may have different data protection laws. Where required, we rely on safeguards such as the European Commission's Standard Contractual Clauses.
14. Changes to This Policy
We may update this policy. If a change is material, we'll email the address on your account before it takes effect, and we may also show a notice in the app. The "Last updated" date at the top shows when this policy last changed.
15. Contact
Questions about privacy, or a request about your data:
Digitally Simple LLC (PintDeck)
3400 W Lost Rapids Dr, Unit D102
Meridian, ID 83646
Email: support@pintdeck.io (subject: "Privacy request")