Legal
Privacy Policy
Last updated: 25 June 2026
VenueCore Ltd (“VenueCore”, “we”) provides a hospitality operations platform used by venues to run service, take payments and manage staff. This policy explains what personal data we process, why, and the rights individuals have under UK GDPR and EU GDPR.
1. Who is the data controller?
For data about venue owners, venue staff and platform visitors, VenueCore is the controller. For data about guests of a venue (reservations, loyalty, receipts, allergens, dietary notes), the venue is the controller and VenueCore is the processor acting on the venue’s documented instructions under a Data Processing Agreement (see /dpa).
2. What we collect
- Account data — name, work email, hashed password, role, venue membership.
- Operational data — orders, payments, tips, cash-ups, shifts, KDS tickets, audit logs.
- Guest data (processor) — guest name, contact, reservation history, loyalty balance, allergens, marketing consent state.
- Payment data — handled by Stripe; VenueCore stores only references (last4, brand, intent id), never full PAN or CVV.
- Technical data — IP, browser/device, error logs, uptime checks, anonymous analytics.
3. Why we process it (lawful bases)
- Contract — to deliver the platform to subscribed venues.
- Legal obligation — VAT records, fiscal receipts, tax retention (typically 6 years UK / 10 years EU member-state).
- Legitimate interests — security monitoring, fraud prevention, product analytics, service reliability.
- Consent — marketing emails, optional cookies, AI-assisted diagnostic chat (Copilot).
4. Where data is stored
Primary application data is hosted in the European Union (Frankfurt) on a managed Postgres cloud. Payments are processed by Stripe in the EU/UK with global redundancy. AI diagnostic prompts (Copilot) may be sent to Google (Gemini) via the Lovable AI Gateway, with transfers covered by the EU–US Data Privacy Framework and Standard Contractual Clauses where applicable; do not paste PII into Copilot. Full vendor list at /subprocessors.
5. Retention
- Account & venue data: lifetime of the contract + 90 days, then purged.
- Financial records (orders, payments, VAT): 6 years (UK statutory).
- Audit logs & security events: 1 year.
- Guest reservations: per venue’s configured retention (default 24 months of inactivity).
- Marketing contacts: until unsubscribe.
6. Your rights
Under UK/EU GDPR you can request access, rectification, erasure, restriction, portability, and object to processing. Guests should contact the venue first (they are the controller). Staff and venue owners can email support@venuecore.solutions. We respond within 30 days. You also have the right to lodge a complaint with the UK ICO or your local EU supervisory authority.
7. Security
TLS 1.2+ in transit; AES-256 at rest. Row-level security isolates every tenant. Passwords are hashed (bcrypt) and screened against the Have I Been Pwned database. Admin actions, money movement and authentication events are audited. Suspected incident? Email support@venuecore.solutions.
8. Cookies
We use strictly-necessary cookies for authentication and session continuity, and optional analytics cookies once you consent. You can change consent at any time via the cookie banner.
9. Contact
VenueCore Ltd, support@venuecore.solutions.