Legal

Privacy Policy

Effective Date: September 23, 2026. Version 1.0. This Privacy Policy describes how BevMatrx AI, Inc. handles information in connection with bevmatrx.ai, the BevMatrx platform and the BevMatrx mobile application.

I. Scope of This Policy

BevMatrx AI, Inc., a Delaware corporation (“BevMatrx,” the “Company,” “we,” “us” or “our”), provides beverage inventory and analytics software to hospitality businesses. This Privacy Policy applies to the bevmatrx.ai website (the “Site”), the BevMatrx web application (the “Platform”) and the BevMatrx mobile application (the “App,” and together with the Site and the Platform, the “Services”). Where a provision applies to only one of them, this Policy says so.

By using the Services you acknowledge the practices described in this Policy. Your use of the Services is also governed by our Terms of Service.

II. The Capacities in Which We Act

We handle information in two distinct capacities, and the distinction determines your rights.

  • As a controller. Information collected through the Site, and the account records of the individuals who use the Platform and the App, are handled by us for our own purposes as described in this Policy.
  • As a processor. Operational records that a customer organization connects or uploads — point of sale transactions, supplier invoices, inventory counts, recipes, purchase orders and associated photographs (collectively, “Customer Data”) — are processed by us on that organization’s instructions and on its behalf. The customer determines the purposes of that processing. If you are an employee of a BevMatrx customer, direct requests concerning Customer Data to your employer, which we will support.

III. Information We Collect

A. Information You Submit Through the Site

When you complete a form on the Site, we collect the information you provide, which may include your name, business email address, telephone number, organization name, number of venues, job role, point of sale system, current inventory tool and any additional message you choose to include. We also record the marketing campaign, referring article or other attribution parameters associated with your visit.

B. Account Information

To use the Platform or the App, an authorized administrator of a customer organization issues you an account. In connection with that account we collect your name, business email address, an authentication credential and your assigned role. For personnel in roles that perform work on the floor of a venue, we also collect a mobile telephone number, which is used to contact that individual about the account and, where that method is enabled, to deliver one-time sign-in codes by text message. Authentication credentials are held by our authentication provider in hashed form and are not readable by us.

C. Customer Data

The Platform and the App receive the operational records described in Section II, including data retrieved from a point of sale or accounting system that a customer has authorized us to connect. Customer Data may incidentally identify individuals, for example the employee who recorded a count or approved an order.

D. Information Collected Through the Mobile Application

The App requests access to the device camera, and uses it in two distinct ways:

  • Barcode scanning. When you scan a barcode, the image is decoded on the device and discarded. That image is not transmitted to us and is not retained.
  • Photographs you deliberately capture. A photograph of a shelf attached to a count, a page of a supplier invoice, or a bottle label submitted for identification is uploaded to our systems and retained with the record to which it relates, so that colleagues and reviewers within your organization can examine it. Invoice pages are processed by Amazon Textract and bottle labels by Amazon Rekognition, in each case on our instructions as described in Section VI.

The App stores a copy of recent records on the device so that it remains usable on an unreliable connection. Signing out or removing the App deletes that copy.

The App does not request access to your location, your microphone, your contacts or your photo library. It contains no advertising, analytics or attribution software development kits. It does not send push notifications. It does not track you across applications or websites owned by other companies, and it does not request permission to do so.

E. Information Collected Automatically

Our servers and those of our hosting providers record technical information incidental to the delivery of the Services, including internet protocol address, device and browser type, operating system, referring page, and the date, time and nature of requests. This information is used to operate, secure and troubleshoot the Services.

IV. How We Use Information

We use the information described above to:

  • provide, operate, maintain and improve the Services;
  • create and administer accounts and authenticate users, including the delivery of invitations, sign-in links and one-time codes;
  • perform the processing a customer has instructed, including reading invoices, reconciling counts, calculating variance and producing reporting;
  • respond to inquiries submitted through the Site and communicate with prospective and current customers about the Services;
  • send administrative and transactional messages, including service notices, alerts you have configured and scheduled reports;
  • monitor, detect and prevent fraud, abuse, security incidents and other unlawful activity;
  • comply with legal obligations and enforce our agreements; and
  • analyze which of our published materials and tools are useful to operators, in aggregate.

We do not sell Personal Information, we do not share Personal Information for cross-context behavioral advertising, and we do not use Customer Data to train artificial intelligence models for the benefit of any other party.

V. How We Disclose Information

We disclose information only as follows:

  • To service providers. To the vendors identified in Section VI, each of which is bound to use the information solely to provide services to us.
  • Within your organization. To other authorized users of your organization’s account, according to the permissions your administrator has assigned.
  • At your direction. To a third-party system you have instructed us to connect.
  • For legal reasons. Where we believe in good faith that disclosure is required by law, subpoena or other legal process, or is necessary to protect the rights, property or safety of BevMatrx, our customers or the public.
  • In a corporate transaction. As described in Section XV.

We do not disclose one customer organization’s data to another.

VI. Service Providers

We engage the following providers, each with access limited to what its function requires:

ProviderFunction and information accessed
Amazon Web Services, Inc.Hosting, storage and processing of the Site, the Platform and all Customer Data, including photographs. Amazon Textract extracts data from invoice pages and Amazon Rekognition analyzes bottle labels, in each case on our instructions.
Supabase, Inc.Authentication. Holds email addresses, hashed credentials and, where provided, mobile telephone numbers.
Resend, Inc.Delivery of transactional email, including invitations, alerts and scheduled reports.
HubSpot, Inc.Customer relationship management. Receives inquiries submitted through the Site.
Slack Technologies, LLCInternal notification that an inquiry has been received.
Google LLCBusiness email and productivity, and therefore any correspondence you send to us directly.

VII. Cookies and Similar Technologies

The Site stores marketing attribution parameters in your browser’s session storage so that, if you submit a form, we know which page brought you. That information remains in your browser and is transmitted only if you submit a form, and it is discarded when you close the tab. The Platform and the App use storage on your device to maintain your authenticated session. We do not set advertising cookies and we do not permit third parties to set cookies on the Site for advertising purposes.

VIII. Retention

We retain inquiries submitted through the Site for as long as we are in contact with you and thereafter as our business records require. We retain Customer Data, including photographs, for the term of the customer organization’s agreement with us and delete it thereafter on request, subject to any longer period required by law. We retain technical logs for a limited period for security and diagnostic purposes.

IX. Security

We maintain administrative, technical and physical safeguards designed to protect information against unauthorized access, disclosure, alteration and destruction, including encryption of data in transit, access controls and segregation of each customer’s data. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. You are responsible for safeguarding your authentication credentials and for notifying us promptly at hello@bevmatrx.ai if you believe your account has been compromised.

X. Deleting Your Account and Your Information

You may have your BevMatrx account and the personal information associated with it deleted, whether you use the Platform, the App or both. Either method is available to you:

  • Through your administrator. The administrator of your organization may remove you from the organization, which terminates your access immediately.
  • By written request to us. Send a request to hello@bevmatrx.ai from the email address associated with your account, stating that you wish your account to be deleted. We will complete the deletion within thirty (30) days and confirm in writing when it is done.

Deletion removes your authentication credentials, your name and your contact details. Operational records produced in the course of your work — a count you performed, an invoice you photographed — constitute Customer Data belonging to your employing organization rather than to you. Those records are retained under that organization’s agreement with us and cease to be attributed to you by name. A customer organization may request deletion of its entire account and all associated Customer Data by the same method.

XI. Your Privacy Rights

Subject to applicable law and to the capacities described in Section II, you may request that we disclose the personal information we hold about you, correct inaccurate information, delete information, or provide a portable copy. You may also withdraw consent where processing is based on consent, and opt out of marketing communications at any time; administrative and transactional messages relating to your account will continue.

Residents of California have the rights conferred by the California Consumer Privacy Act, as amended, including the rights to know, delete, correct and limit the use of sensitive personal information. We do not sell or share personal information as those terms are defined in that statute, and we have not done so in the preceding twelve months. Residents of other states with comprehensive privacy statutes have the equivalent rights those statutes confer. Individuals in the European Economic Area and the United Kingdom have the rights of access, rectification, erasure, restriction, portability and objection, and may lodge a complaint with their supervisory authority.

To exercise any right, write to hello@bevmatrx.ai. We will verify your identity by reference to the account or correspondence in question and respond within the period the applicable law allows. We will not deny you goods or services, charge you a different price, or provide you a different level of service because you exercised a privacy right.

XII. Where Information Is Processed

BevMatrx is established in the United States and the Services are hosted in the United States. If you access the Services from another jurisdiction, you understand that your information will be transferred to, stored in and processed in the United States, where data protection law may differ from that of your own jurisdiction. Where required, we rely on the European Commission’s standard contractual clauses or another lawful transfer mechanism.

XIII. Children’s Privacy

The Services are intended for use by licensed hospitality businesses and their personnel. They are not directed to children, and we do not knowingly collect personal information from any individual under the age of sixteen. If we learn that we have done so, we will delete that information promptly. A parent or guardian who believes we hold such information should contact us at the address below.

XIV. Third-Party Websites

The Services may contain links to websites operated by others. We do not control those websites and are not responsible for their privacy practices. We encourage you to read the privacy policy of any website you visit.

XV. Business Transfers

If BevMatrx is involved in a merger, acquisition, financing, reorganization, bankruptcy or sale of all or part of its assets, information held by us may be transferred as part of that transaction, subject to applicable law and to commitments materially consistent with this Policy.

XVI. Changes to This Privacy Policy

We may revise this Policy from time to time. The Effective Date at the top of this page indicates when it was last revised. If we make a material change, we will provide notice through the Services or by email to account holders before the change takes effect. Your continued use of the Services after the effective date of a revision constitutes acceptance of it.

XVII. How to Contact Us

Questions, requests and complaints regarding this Policy should be directed to:

BevMatrx AI, Inc.
Attn: Privacy
28 Smith Street, Box 918
Shelter Island, New York 11964
United States
hello@bevmatrx.ai