← Back to app

Privacy Policy for VenueCore Inventory

Effective Date: August 5, 2026

This “Privacy Policy” explains how VenueCore (“Company”, “we”, or “our”) collects, uses, discloses, and otherwise processes personal data on behalf of our customers – typically, merchants (any, a “Merchant”) – in connection with our application, VenueCore Inventory, available at venuecoreinventory.com and through the Clover App Market. This Privacy Policy does not apply to Company’s privacy practices in any other context.

Merchants reach the application in one of two ways, and a few practices differ between them:

Company’s processing of personal data in connection with our application is governed by this Privacy Policy and our agreements with Merchants. In the event of any conflict between this Privacy Policy and a customer agreement, the customer agreement will control to the extent permitted by applicable law.

This Privacy Policy is not a substitute for any privacy policy that a Merchant may be required to provide to their customers, personnel, or other individuals.

Information we collect

We may collect personal data from or on behalf of Merchants. Merchants determine the scope of the personal data transferred to us or that we collect, and the information we receive may vary by Merchant. Typically, the information we collect on behalf of Merchants includes:

Information that we collect when a customer for a Merchant makes a payment

When a customer makes a payment via a Clover POS, the Clover platform collects information about the transaction. VenueCore Inventory does not store payment card numbers, cardholder names, or any cardholder financial data. The transaction details we receive are limited to the data necessary for ingredient deduction, namely:

We do not collect additional payment-time data beyond what is described above.

Additional information that customers of the Merchant provide through the Clover POS ancillary to a payment

VenueCore Inventory does not collect or process customer-ancillary data such as customer email addresses, phone numbers, marketing preferences, loyalty program activity, customer addresses, birthdates, interests, reviews, or feedback. Our application does not interact with the Clover Customers, Loyalty, or Marketing surfaces.

Information that we collect about personnel of a Merchant

VenueCore Inventory does not collect information about Merchant personnel (such as clock-in/clock-out times or tips earned). Our application does not request the Employees permission and does not interact with employee records.

Account information for Direct Merchants

When a Merchant creates an account directly with us (rather than installing from the Clover App Market), we collect:

POS connection credentials

To read sales from a Merchant’s POS we store connection credentials: for App Market Merchants, the Clover OAuth access and refresh tokens; for Direct Merchants who connect themselves, the merchant-generated API token the Merchant creates in their own POS dashboard and pastes into the application. These credentials are encrypted at rest (see “Security”), are used only to read the Merchant’s own POS data and to write back stock counts, and are deleted immediately when the Merchant disconnects or uninstalls. A Merchant may also revoke the token directly in their POS dashboard at any time.

Billing information for Direct Merchants

Where a Direct Merchant subscribes to a paid plan, payments are processed by Stripe, Inc. Card details are collected by Stripe on its own hosted pages and are never received or stored by us. We store only the non-sensitive billing metadata Stripe returns to us — a customer and subscription identifier, plan status, trial and renewal dates, and the outcome of billing events — so we know whether an account is active. Stripe’s handling of payment data is governed by Stripe’s privacy policy at https://stripe.com/privacy.

Additional information that Merchants provide to us about their customers or personnel

Merchants do not provide us with information about their customers or personnel through our application. The Merchant-provided data we process is limited to the operational records the Merchant creates inside the application, including:

How we use the information we collect

We use the personal data we collect for or on behalf of Merchants, to provide our services and the functionality of our application:

We may also use personal data for related internal purposes, including:

In addition, Company may use personal data as we believe necessary or appropriate to (a) comply with applicable laws and lawful requests and legal processes, such as to respond to subpoenas or requests from government authorities; (b) enforce the terms and conditions that govern our application; (c) protect our rights, privacy, safety or property, and/or that of you or others; and (d) protect, investigate and deter against fraudulent, harmful, unauthorized, unethical or illegal activity.

How we share information

We may share personal data that we collect with:

Company may disclose personal data to government or law enforcement officials or private parties as required by law, and disclose and use such information as we believe necessary or appropriate to (a) comply with applicable laws and lawful requests and legal processes, such as to respond to subpoenas or requests from government authorities; (b) enforce the terms and conditions that govern our application; (c) protect our rights, privacy, safety or property, and/or that of you or others; and (d) protect, investigate and deter against fraudulent, harmful, unauthorized, unethical or illegal activity.

Company may sell or transfer some or all of its business or assets, including personal data we process for Merchants, in connection with a business transaction (or potential business transaction) such as a merger, consolidation, acquisition, reorganization or sale of assets or in the event of bankruptcy, in which case we will make reasonable efforts to require the recipient to honor this Privacy Policy.

Data retention and deletion

We retain Merchant data for as long as the Merchant maintains an account or has the application installed. Deletion works as follows:

We may retain a minimal record of billing transactions where required for tax, accounting, or legal-compliance purposes, and may retain de-identified aggregate statistics that cannot be linked back to a Merchant or individual.

For disaster recovery we keep encrypted database backups in S3-compatible object storage (currently Cloudflare R2). Backups are encrypted, are never used for any purpose other than restoring service, and are automatically deleted on a rolling thirty (30) day schedule — so residual copies of deleted Merchant data age out of backups within thirty (30) days of the live-data deletion.

Security

We store all data in an encrypted PostgreSQL database. POS credentials — Clover OAuth access and refresh tokens, and merchant-generated API tokens — are encrypted at rest using AES-256-GCM with keys held only by the application server. Account passwords are stored only as salted one-way hashes and are never recoverable in readable form. The opaque session tokens issued to Merchant users are stored on our servers only as keyed HMAC-SHA-256 hashes; the raw token is held in the user’s browser (in session storage and, where the Merchant uses multi-location switching, in local storage) and is cleared on sign-out. All traffic between the Merchant’s browser, our servers, and third-party APIs is protected with TLS. Access to production systems is limited to personnel who need it, requests are rate limited, and security-sensitive actions are recorded in an audit log. Database backups are encrypted and are deleted on a rolling thirty (30) day schedule.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a breach affecting a Merchant’s personal data, we will notify the affected Merchant, and any regulator where required, without undue delay and consistent with applicable law.

Children’s data

The application is a business tool intended for use by businesses and their authorized personnel. It is not directed to children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.

Cookies and browser storage

The application does not use advertising cookies, analytics cookies, or any third-party trackers. We use browser storage only to operate the application: the session token that keeps a Merchant user signed in (held in session storage and, where the Merchant uses multi-location switching, in local storage), the user’s theme preference, and similar functional settings. These values are not used to track individuals across other sites or services, and can be removed at any time by signing out or clearing browser storage.

Your rights and choices

Data subject rights

To the extent that applicable law provides individuals with rights pertaining to their personal information, such as to review and request changes to their personal information, individuals should contact the Merchant with any requests pertaining to the Merchant’s use of our application. To the extent that Clover is responsible for responding to data subject rights requests under applicable law, individuals may contact Clover with applicable requests as explained in Clover’s Privacy Notice, https://www.clover.com/privacy-policy. Company will assist a Merchant, or Clover, as applicable, in responding to such requests subject to our contract with a Merchant or Clover.

Complaints

If you have a complaint about our handling of personal data, you may contact us via the contact information provided below.

Updates

We reserve the right to modify this Privacy Policy at any time. We will notify you of updates by updating the date of this Privacy Policy.

Contact us

You may contact us with any questions, comments, or complaints about this Privacy Policy or our privacy practices via:

Additional information for Merchants located in Europe

Controller

Company is a data processor acting for and on behalf of the Merchant that has installed our application on their Clover POS. That Merchant is the controller of personal data that we process on its behalf. Clover is also a controller of personal data in some circumstances. Clover’s Privacy Notice is available at https://www.clover.com/privacy-policy.

Legal basis for processing

Company processes personal data as directed or permitted by the Merchant that uses our application. The Merchant is responsible for establishing a legal basis for our processing of personal data for or on behalf of the Merchant.

Cross-border data transfer

When we transfer personal data outside of Europe (or the UK) to countries not deemed by the European Commission to provide an adequate level of protection for personal data, we make the transfer pursuant to one of the following transfer mechanisms:

You may contact us with questions about our transfer mechanism.

Data retention

Subject to our agreement with a Merchant, Company retains personal data for as long as necessary to (a) provide our products and services; (b) comply with legal obligations; (c) resolve disputes; and (d) enforce the terms of any agreement we may have with a Merchant. You may contact us for additional information about our data retention practices in connection with the application.

Data subject rights

Under certain circumstances, data subjects in Europe and the UK have certain rights relating to their personal data, which include the rights to request from the Controller (a) access to the data subject’s personal data; (b) correction of incomplete or inaccurate personal data; (c) erasure of personal data; (d) restriction of processing concerning the data subject; and (e) that the controller provide a copy of the data subject’s personal data that the data subject provided to the controller in a structured, commonly used and machine-readable format. Data subjects may also object to a controller’s processing of personal data under certain circumstances. Where processing is based on a data subject’s consent, the data subject has the right to withdraw consent at any time; however, the withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal. Data subjects may also file a complaint with a supervisory authority. You may view contact information for supervisory authorities at https://edpb.europa.eu/about-edpb/board/members_en. Data subjects in Europe or the UK should direct any rights request to the appropriate Controller.

Your California privacy rights

As a California resident, you have the rights listed below. However, these rights are not absolute, and we may decline your request as permitted by the CCPA.

Information. You can request the following information about how we have collected and used your Personal Information during the past 12 months: the categories of Personal Information we have collected; the categories of sources from which we collected Personal Information; the business or commercial purpose for collecting and/or selling Personal Information; the categories of third parties with whom we share Personal Information; whether we have disclosed your Personal Information for a business purpose, and if so, the categories of Personal Information received by each category of recipient; and whether we’ve sold your Personal Information.

Access. You can request a copy of the Personal Information that we maintain about you.

Deletion. You can ask us to delete the Personal Information that we maintain about you.

Nondiscrimination. You are entitled to exercise the rights described above free from discrimination. We will not penalize you for exercising your rights.

How to exercise your rights

You may exercise your California privacy rights by emailing [email protected] with the subject line “California Privacy Request”. The CCPA requires us to verify the identity of the individual submitting the request before providing a substantive response. A request must be provided with sufficient detail to allow us to understand, evaluate, and respond. The requester must provide sufficient information to allow us to reasonably verify that the individual is the person about whom we collected information. A request may also be made on behalf of a child under 13. California residents may empower an “authorized agent” to submit requests on their behalf; we may require the authorized agent to provide written authorization confirming that authority.

Sale of personal information

We do not sell, as defined under CCPA, your Personal Information to third parties.

In the preceding twelve (12) months, we have not sold any personal information.

Personal information that we collect, use and share

The chart below summarizes our collection, use, and sharing of Personal Information during the last 12 months before the effective date of this Privacy Policy.

Category (see glossary below) Do we collect? Do we share for business purposes?
Identifiers (e.g., merchant ID, store ID; for Direct Merchants also business name, account email address, and Google account identifier)YesYes
Online Identifiers (IP address and browser user-agent in security audit logs; functional browser-storage values described under “Cookies and browser storage”)YesNo
Account credentials (salted one-way password hash; POS API credentials, encrypted at rest)YesNo
Protected Classification CharacteristicsNoNo
Commercial Information (e.g., transaction line items)YesYes
Biometric InformationNoNo
Internet or Network InformationNoNo
Geolocation DataNoNo
Sensory InformationNoNo
Professional or Employment InformationNoNo
Education InformationNoNo
InferencesNoNo
Financial Information (billing status and subscription identifiers only; card details are collected and held by Stripe, never by us)LimitedYes
Medical InformationNoNo

Glossary


VenueCore Inventory · Contact: [email protected]