Legal

Privacy Policy

Last updated 4 September 2026

This policy explains what VenueTech collects, why we hold it, who we share it with, and what you can ask us to do about it. It covers the VenueTech portal, the VenueTech mobile apps, and this website.

Who this policy covers

VenueTech Systems LLC operates VenueTech, a platform venues use to run point of sale, payments, guest operations, and reporting. This policy applies to the VenueTech portal, the VenueTech mobile applications, and venuetech.us.

It describes two relationships, and the difference between them decides what we may do with a given record.

Venue staff and operators
People who hold a VenueTech account and sign in to run a venue. We decide how their account information is handled, so this policy governs it directly.
Guests of a venue
People who order, pay, or hold a stored value balance at a venue that runs VenueTech. We process that information on the venue’s instructions and for the venue’s purposes. The venue decides what is collected and how long it is kept, and its own privacy notice governs. Where this policy and a venue’s instructions differ on guest data, the venue’s instructions decide.

Information we collect

We collect the following categories. Not every venue uses every part of the platform, so not every category applies to every account.

Account and identity
Your name, work email address, telephone number where you give one, the venue or group you belong to, your role, and your permissions. This is the record that decides what you can see once you are signed in.
Information from Google sign in
If you sign in with Google, Google sends us your email address, whether that address is verified, your name, and your Google account identifier. We ask Google for three permissions and no others: your basic profile, your email address, and confirmation that you signed in. We never receive, see, or store your Google password, and we do not read your Gmail, your Drive, your Calendar, or your Contacts.
Information from Microsoft sign in
If you sign in with a Microsoft work account, Microsoft sends us the same three things: your email address, your name, and your account identifier. The same limits apply. We do not receive your password and we request no access to your mailbox or files.
Venue operational data
Orders, checks, menu configuration, staff and shift records, reservations and room charges where a venue connects its hotel system, stored value balances, and the reporting built on top of all of it. This is the venue’s data, held for the venue.
Payment information
Card payments are captured and authorised by the payment gateway, not by us. Full card numbers do not reach VenueTech systems and are not stored by us. What we hold is the result of a transaction: an amount, a date, an authorisation outcome, a card brand, the last four digits, and a token the gateway issues so a saved card can be charged again without us ever holding the number.
Device and usage data
IP address, browser and device type, operating system, the pages and screens you open, and the time you opened them. We use this to keep accounts secure, to trace faults, and to see which parts of the product are used.
Support communications
Messages you send us, the tickets they become, and the notes we add while resolving them.

How we use information

We do not sell personal information. We do not share it with advertisers, and we do not use it to build advertising profiles or to serve targeted advertising.

  • To sign you in, keep you signed in, and decide what your account is permitted to do.
  • To run the parts of the platform your venue has enabled: taking orders, taking payment, printing and sending receipts, managing menus, and producing reports.
  • To settle payments and to report on settlement and funding.
  • To answer support requests and to investigate faults you or your venue report.
  • To detect, investigate, and prevent fraud, abuse, and unauthorised access.
  • To meet legal, tax, and payment industry obligations.
  • To improve the product, using aggregated and de-identified figures wherever the question can be answered that way.

How we use information from Google sign in

This section is deliberately narrow, because signing in with Google is the only place VenueTech touches Google account data at all.

We use the email address Google gives us for exactly one thing: to find the VenueTech account that already carries that address and to open a session for it. If no VenueTech account matches, sign in fails and nothing is created. Signing in with Google does not register you, and it does not give you access to a venue you were not already granted.

Your name and Google account identifier are used to label that session and to write the sign in to our audit log, so a venue can see who signed in and when.

VenueTech’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to others except as needed to provide or improve this sign in feature, to comply with applicable law, or as part of a merger or acquisition. We do not use Google user data for advertising, and we do not allow humans to read it except with your explicit permission, for security purposes, to comply with applicable law, or where the data is aggregated and de-identified.

You can withdraw our access at any time from your Google account permissions page. Doing so stops future Google sign in and does not delete your VenueTech account, which continues to exist and can still be reached with your other sign in method.

Who we share information with

We share information only with the categories below, only where it is needed, and under contracts that require them to protect it and forbid them from using it for their own purposes.

The payment gateway and the processor
To authorise card transactions, to settle them, and to report on funding.
Cloud hosting and infrastructure providers
To run the servers, databases, and file storage the platform is built on.
Message delivery providers
To send email and text messages you or your venue asked for, including receipts and one time sign in codes.
Systems your venue connects
Where your venue links its own point of sale, its hotel system, its reservation system, or its accounting or reporting tools, we exchange the data that link requires. Your venue controls those connections and can end them.
Professional advisers
Auditors, lawyers, and accountants, where they are bound by professional confidentiality.
Authorities and legal process
Where we are required by law, court order, or a binding request from a regulator, and where we believe disclosure is necessary to prevent harm or to protect our rights.
A buyer or successor
If the business is sold or merged, under terms that hold the buyer to this policy until it is replaced by one you are told about.

How long we keep it

Account records are kept while the account is active and for as long afterwards as we need them to resolve disputes, meet tax and payment industry obligations, and enforce our agreements.

Venue operational data is kept for as long as the venue’s agreement with us requires, and is deleted or returned when that agreement ends, subject to any retention the law requires of us.

Audit and security logs are kept on a fixed schedule, because their value is that they cannot be edited after the fact.

How we protect it

No system is beyond compromise, and we do not claim otherwise. If a breach affects your information we will tell you and the relevant regulator within the time the law requires.

  • Traffic between your browser or app and our servers is encrypted in transit.
  • Sensitive fields are encrypted where they are stored.
  • Access is granted by role, so an account reaches only the venues and the functions it has been given.
  • Sign in issues a session that expires, and administrative sessions expire sooner than others.
  • Privileged actions are written to an audit log that records who acted, on what, and when.
  • Card numbers are held by the payment gateway rather than by us, which keeps the most sensitive field in the system out of our hands entirely.

Your choices and your rights

Depending on where you live, you may have the right to ask for a copy of the information we hold about you, to have it corrected, to have it deleted, to restrict or object to how we use it, and to receive it in a portable form. You also have the right to complain to your data protection regulator.

To make any of these requests, write to support@venuetech.us. We will ask you to verify your identity before we act, and we will answer within the period the law sets.

If you are a guest of a venue rather than a member of its staff, send your request to the venue. The venue decides what happens to guest data, and we act on its instructions. Tell us anyway if you cannot reach them and we will help route it.

You can disconnect Google or Microsoft sign in at any time from that provider’s account permissions page, without closing your VenueTech account.

Cookies and similar technologies

The portal sets cookies that are necessary for it to work: one that holds your signed in session, and one that holds short lived state such as which venue you are currently viewing. They are set to be read by the server only and are not readable by scripts running in your browser.

This website does not set advertising cookies and does not carry third party advertising trackers.

International transfers

We operate from the United States and our infrastructure providers may process information in other countries. Where information moves out of the country it was collected in, we rely on the transfer safeguards that the law of that country provides for, and we require the same protections downstream.

Children

The platform is a business tool and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has given us information, write to us and we will delete it.

Changes to this policy

When this policy changes we update the date at the top of the page. Where a change materially affects how we handle your information, we will tell account holders directly rather than relying on you to notice.

Contact us

Write to support@venuetech.us with any question about this policy or about the information we hold. VenueTech Systems LLC is the controller of the account information described here.