← Back to app

Privacy Policy for VenueCore Inventory

Effective Date: July 17, 2026

This “Privacy Policy” explains how VenueCore (“Company”, “we”, or “our”) collects, uses, discloses, and otherwise processes personal data on behalf of our customers – typically, merchants (any, a “Merchant”) – in connection with our application, VenueCore Inventory, which runs on the Clover Point of Sale system (“Clover POS”). This Privacy Policy does not apply to Company’s privacy practices in any other context.

Company’s processing of personal data in connection with our application is governed by this Privacy Policy and our agreements with Merchants. In the event of any conflict between this Privacy Policy and a customer agreement, the customer agreement will control to the extent permitted by applicable law.

This Privacy Policy is not a substitute for any privacy policy that a Merchant may be required to provide to their customers, personnel, or other individuals.

Information we collect

We may collect personal data from or on behalf of Merchants. Merchants determine the scope of the personal data transferred to us or that we collect, and the information we receive may vary by Merchant. Typically, the information we collect on behalf of Merchants includes:

Information that we collect when a customer for a Merchant makes a payment

When a customer makes a payment via a Clover POS, the Clover platform collects information about the transaction. VenueCore Inventory does not store payment card numbers, cardholder names, or any cardholder financial data. The transaction details we receive are limited to the data necessary for ingredient deduction, namely:

We do not collect additional payment-time data beyond what is described above.

Additional information that customers of the Merchant provide through the Clover POS ancillary to a payment

VenueCore Inventory does not collect or process customer-ancillary data such as customer email addresses, phone numbers, marketing preferences, loyalty program activity, customer addresses, birthdates, interests, reviews, or feedback. Our application does not interact with the Clover Customers, Loyalty, or Marketing surfaces.

Information that we collect about personnel of a Merchant

VenueCore Inventory does not collect information about Merchant personnel (such as clock-in/clock-out times or tips earned). Our application does not request the Employees permission and does not interact with employee records.

Additional information that Merchants provide to us about their customers or personnel

Merchants do not provide us with information about their customers or personnel through our application. The Merchant-provided data we process is limited to the operational records the Merchant creates inside the application, including:

How we use the information we collect

We use the personal data we collect for or on behalf of Merchants, to provide our services and the functionality of our application:

We may also use personal data for related internal purposes, including:

In addition, Company may use personal data as we believe necessary or appropriate to (a) comply with applicable laws and lawful requests and legal processes, such as to respond to subpoenas or requests from government authorities; (b) enforce the terms and conditions that govern our application; (c) protect our rights, privacy, safety or property, and/or that of you or others; and (d) protect, investigate and deter against fraudulent, harmful, unauthorized, unethical or illegal activity.

How we share information

We may share personal data that we collect with:

Company may disclose personal data to government or law enforcement officials or private parties as required by law, and disclose and use such information as we believe necessary or appropriate to (a) comply with applicable laws and lawful requests and legal processes, such as to respond to subpoenas or requests from government authorities; (b) enforce the terms and conditions that govern our application; (c) protect our rights, privacy, safety or property, and/or that of you or others; and (d) protect, investigate and deter against fraudulent, harmful, unauthorized, unethical or illegal activity.

Company may sell or transfer some or all of its business or assets, including personal data we process for Merchants, in connection with a business transaction (or potential business transaction) such as a merger, consolidation, acquisition, reorganization or sale of assets or in the event of bankruptcy, in which case we will make reasonable efforts to require the recipient to honor this Privacy Policy.

Data retention and deletion

We retain Merchant data for as long as the application is installed on the Merchant’s Clover account. When a Merchant uninstalls the application from the Clover App Market, or initiates a disconnect from within the application, the Merchant’s stored Clover OAuth tokens are deleted immediately, and we automatically schedule all remaining data we hold for that Merchant (including ingredients, recipes, inventory, transactions, sync logs, alerts, and security audit logs) for permanent deletion within thirty (30) days. Merchants may request immediate deletion at any time by contacting us at the address below.

For disaster recovery we keep encrypted database backups in S3-compatible object storage (currently Cloudflare R2). Backups are encrypted, are never used for any purpose other than restoring service, and are automatically deleted on a rolling thirty (30) day schedule — so residual copies of deleted Merchant data age out of backups within thirty (30) days of the live-data deletion.

Security

We store all data in an encrypted PostgreSQL database. Clover OAuth access and refresh tokens are encrypted at rest using AES-256-GCM with keys held only by the application server. The opaque session tokens issued to Merchant users are stored on our servers only as salted HMAC-SHA-256 hashes; the raw token is held in the user’s browser (in session storage and, where the Merchant uses multi-location switching, in local storage) and is cleared on sign-out. All traffic between the Merchant’s browser, our servers, and the Clover API is protected with TLS.

Cookies and browser storage

The application does not use advertising cookies, analytics cookies, or any third-party trackers. We use browser storage only to operate the application: the session token that keeps a Merchant user signed in (held in session storage and, where the Merchant uses multi-location switching, in local storage), the user’s theme preference, and similar functional settings. These values are not used to track individuals across other sites or services, and can be removed at any time by signing out or clearing browser storage.

Your rights and choices

Data subject rights

To the extent that applicable law provides individuals with rights pertaining to their personal information, such as to review and request changes to their personal information, individuals should contact the Merchant with any requests pertaining to the Merchant’s use of our application. To the extent that Clover is responsible for responding to data subject rights requests under applicable law, individuals may contact Clover with applicable requests as explained in Clover’s Privacy Notice, https://www.clover.com/privacy-policy. Company will assist a Merchant, or Clover, as applicable, in responding to such requests subject to our contract with a Merchant or Clover.

Complaints

If you have a complaint about our handling of personal data, you may contact us via the contact information provided below.

Updates

We reserve the right to modify this Privacy Policy at any time. We will notify you of updates by updating the date of this Privacy Policy.

Contact us

You may contact us with any questions, comments, or complaints about this Privacy Policy or our privacy practices via:

Additional information for Merchants located in Europe

Controller

Company is a data processor acting for and on behalf of the Merchant that has installed our application on their Clover POS. That Merchant is the controller of personal data that we process on its behalf. Clover is also a controller of personal data in some circumstances. Clover’s Privacy Notice is available at https://www.clover.com/privacy-policy.

Legal basis for processing

Company processes personal data as directed or permitted by the Merchant that uses our application. The Merchant is responsible for establishing a legal basis for our processing of personal data for or on behalf of the Merchant.

Cross-border data transfer

When we transfer personal data outside of Europe (or the UK) to countries not deemed by the European Commission to provide an adequate level of protection for personal data, we make the transfer pursuant to one of the following transfer mechanisms:

You may contact us with questions about our transfer mechanism.

Data retention

Subject to our agreement with a Merchant, Company retains personal data for as long as necessary to (a) provide our products and services; (b) comply with legal obligations; (c) resolve disputes; and (d) enforce the terms of any agreement we may have with a Merchant. You may contact us for additional information about our data retention practices in connection with the application.

Data subject rights

Under certain circumstances, data subjects in Europe and the UK have certain rights relating to their personal data, which include the rights to request from the Controller (a) access to the data subject’s personal data; (b) correction of incomplete or inaccurate personal data; (c) erasure of personal data; (d) restriction of processing concerning the data subject; and (e) that the controller provide a copy of the data subject’s personal data that the data subject provided to the controller in a structured, commonly used and machine-readable format. Data subjects may also object to a controller’s processing of personal data under certain circumstances. Where processing is based on a data subject’s consent, the data subject has the right to withdraw consent at any time; however, the withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal. Data subjects may also file a complaint with a supervisory authority. You may view contact information for supervisory authorities at https://edpb.europa.eu/about-edpb/board/members_en. Data subjects in Europe or the UK should direct any rights request to the appropriate Controller.

Your California privacy rights

As a California resident, you have the rights listed below. However, these rights are not absolute, and we may decline your request as permitted by the CCPA.

Information. You can request the following information about how we have collected and used your Personal Information during the past 12 months: the categories of Personal Information we have collected; the categories of sources from which we collected Personal Information; the business or commercial purpose for collecting and/or selling Personal Information; the categories of third parties with whom we share Personal Information; whether we have disclosed your Personal Information for a business purpose, and if so, the categories of Personal Information received by each category of recipient; and whether we’ve sold your Personal Information.

Access. You can request a copy of the Personal Information that we maintain about you.

Deletion. You can ask us to delete the Personal Information that we maintain about you.

Nondiscrimination. You are entitled to exercise the rights described above free from discrimination. We will not penalize you for exercising your rights.

How to exercise your rights

You may exercise your California privacy rights by emailing [email protected] with the subject line “California Privacy Request”. The CCPA requires us to verify the identity of the individual submitting the request before providing a substantive response. A request must be provided with sufficient detail to allow us to understand, evaluate, and respond. The requester must provide sufficient information to allow us to reasonably verify that the individual is the person about whom we collected information. A request may also be made on behalf of a child under 13. California residents may empower an “authorized agent” to submit requests on their behalf; we may require the authorized agent to provide written authorization confirming that authority.

Sale of personal information

We do not sell, as defined under CCPA, your Personal Information to third parties.

In the preceding twelve (12) months, we have not sold any personal information.

Personal information that we collect, use and share

The chart below summarizes our collection, use, and sharing of Personal Information during the last 12 months before the effective date of this Privacy Policy.

Category (see glossary below) Do we collect? Do we share for business purposes?
Identifiers (e.g., merchant ID, store ID)YesYes
Online Identifiers (IP address and browser user-agent in security audit logs; functional browser-storage values described under “Cookies and browser storage”)YesNo
Protected Classification CharacteristicsNoNo
Commercial Information (e.g., transaction line items)YesYes
Biometric InformationNoNo
Internet or Network InformationNoNo
Geolocation DataNoNo
Sensory InformationNoNo
Professional or Employment InformationNoNo
Education InformationNoNo
InferencesNoNo
Financial InformationNoNo
Medical InformationNoNo

Glossary


VenueCore Inventory v1.0.1 · Contact: [email protected]