BrewpassPricing

Privacy Notice

Last updated: 10 August 2026

1. Who we are

Brewpass is operated by Bono Tech. For personal data processed through the Brewpass platform and website, Bono Tech acts as the data controller. Cafes that use Brewpass are separate controllers for the customer data they collect in their own workspace; for that data Bono Tech acts as their processor.

2. Personal data we collect and why

  • Account data (name, email, password hash, cafe name and role) — to create and secure your account and provide the Service. Legal basis: performance of a contract.
  • Cafe and menu content (address, phone, logo, menu items, images) — to publish your branded menu. Legal basis: performance of a contract.
  • Order and loyalty data (items ordered, order type, table number, points balance, WiFi voucher claims) — to operate ordering, loyalty and voucher features. Legal basis: performance of a contract.
  • Support messages — to answer your questions. Legal basis: legitimate interests.
  • Usage and technical data (device identifiers, IP address, log and error telemetry) — for security, fraud prevention, debugging and improving the product. Legal basis: legitimate interests.
  • Marketing communications, where you have opted in. Legal basis: consent, which you can withdraw at any time.

Payment card details are never collected or stored by Bono Tech — they are handled by our payment provider.

3. Who we share data with

  • Service providers / subprocessors — cloud hosting and database, email delivery, error monitoring and analytics tooling, acting on our instructions.
  • Paddle.com, our Merchant of Record, for the sale of subscriptions, subscription management, payments, invoicing and tax compliance.
  • Professional advisers such as legal and accounting advisers.
  • Authorities where required by law or to protect our legal rights.

We do not sell personal data.

4. International transfers

Some providers may process data outside your country, including outside the UK/EEA. Where that happens we rely on appropriate safeguards such as adequacy decisions or Standard Contractual Clauses.

5. Retention

We keep account and cafe data for as long as your account is active and for up to 12 months after closure, order and loyalty records for as long as needed to run the programme and meet accounting obligations, and log data for a short technical retention window. After that data is deleted or anonymised.

6. Your rights

Subject to the law that applies to you, you may request access to your data, correction, erasure, restriction, portability, and object to processing based on legitimate interests. Where we rely on consent you can withdraw it at any time. We respond within one month. If you are in the UK/EEA you may also complain to your local supervisory authority.

7. Security

We apply appropriate technical and organisational measures, including encryption in transit, row-level access controls in the database, role-based staff permissions, and server-side validation of orders, loyalty and voucher issuance.

8. Cookies and local storage

We use strictly necessary cookies and browser storage to keep you signed in and remember your language preference. Any analytics or marketing cookies are only set with your consent and can be managed through your browser settings.

9. Contact

To exercise a right or ask a privacy question, contact Bono Tech through the support channel in your dashboard.