Skip to main content
DrinkLync
WebsiteCustomer app
Privacy policy

DrinkLync Privacy Policy

DrinkLync LLC (“DrinkLync”, “we”, “us”) operates a mobile drink-ordering platform used by customers, venues, bartenders, gatekeepers, managers, owners, and brand partners. This policy explains what personal data we collect, why we collect it, how long we keep it, who we share it with, and the rights you can exercise. It applies to our web app at app.drinklync.com, our iOS / Android apps, our marketing site, and any related services we operate.

Effective 2026-05-21 · Version 1.0

The short version
  • We collect what we need to run ordering, pickup, and payments; you control analytics and marketing via the cookie banner.
  • We never sell your personal information.
  • Payments are tokenized; we never store raw card numbers.
  • You can export or delete your data from Settings at any time.
  • Age checks at the bar are performed by the venue's licensed staff; DrinkLync provides the supporting software.

The full text below is what applies; this summary is here to help you find your way around it.

1. Who we are and how to contact us

Controller: DrinkLync LLC, a Tennessee limited liability company.

Primary support and privacy contact: help@drinklync.com.

Postal mail: address on request via help@drinklync.com.

If you are in the EEA / UK and prefer a written DPO-style channel, send your request to help@drinklync.com with subject line “Privacy request”.

2. Purpose of this policy

This policy describes the personal data we collect when you use DrinkLync, the purposes we use it for, and the choices you have. It complements the in-app cookie banner (which governs analytics and marketing telemetry) and the Data Processing Addendum we offer to venue and brand partners.

3. Categories of data we collect

  • Account profile: name, email, phone number, optional profile photo, password hashes, MFA factors.
  • Identity / age verification: date of birth, optional ID-on-file artifacts collected by venue gatekeepers (stored encrypted and retained only as long as legally required).
  • Order and transaction history: drinks ordered, venue, timestamps, item modifiers, refunds, tips.
  • Payment metadata: card-brand, last4, tokenized payment-method ID. We do not store raw card data; payments are tokenized by our PCI-compliant processor.
  • Device + telemetry: device model, OS version, app version, IP address, coarse location (when permission granted), push tokens, crash and performance signals.
  • Venue + staff data: shift, role, station assignment, login events (for bartender / gatekeeper / manager / owner personas).
  • Support records: messages you send to help@drinklync.com, in-app Lync conversations, bug reports.
  • Marketing preferences: cookie consent state, email subscription state, referral source.

4. Sources of data

  • Directly from you (account creation, in-app forms, support).
  • Automatically as you use the app (telemetry, device signals, fraud signals).
  • From the venue you order at (manager-uploaded staff records, station assignments).
  • From integrated payment + identity processors when you authorize a transaction.
  • From referral and ad-attribution partners when you click a campaign link.

5. Lawful bases under GDPR / UK GDPR

  • Performance of a contract: to operate the ordering, pickup, payment, and account flows you ask us to provide.
  • Legal obligation: to meet tax, accounting, alcohol-licensing, fraud-prevention, and consumer-protection duties.
  • Legitimate interest: to keep the platform secure, prevent abuse, debug crashes, and protect venue staff.
  • Consent: for analytics and marketing cookies, push notifications, optional location, and marketing emails. You can withdraw consent at any time without affecting prior lawful processing.

6. How we use your data (purposes)

  • Operate ordering, payment handoff, pickup verification, and customer support.
  • Support the venue's age and identity verification where required by alcohol-licensing law.
  • Protect the platform from fraud, abuse, account-takeover, and security incidents.
  • Maintain transaction, tax, refund, dispute, and audit records.
  • Improve reliability, performance, launch readiness, and venue operations (analytics-consent gated).
  • Send marketing or re-engagement messages (marketing-consent gated).
  • Respond to legal requests, subpoenas, and lawful regulator inquiries.

7. Cookies, analytics, and similar technologies

DrinkLync uses three cookie / telemetry categories:

  • Essential: sign-in, payment session, fraud-prevention, order delivery. Cannot be disabled because the service does not function without them.
  • Analytics: product analytics, performance monitoring, feature usage. Off by default. Opt in via the cookie banner.
  • Marketing: campaign attribution, re-engagement signals. Off by default. Opt in via the cookie banner.
  • You can change your choice at any time at /legal/cookie-preferences, reachable from the “Cookie preferences” link in the footer of every page.

8. Who we share data with

  • Payment processors (Stripe and successors): tokenized payment data.
  • Cloud infrastructure providers (Amazon Web Services): storage, compute, observability.
  • Identity verification providers: when a venue requires ID-on-file or wristband issuance.
  • Email / SMS / push providers: transactional and (with consent) marketing messages.
  • Analytics + crash-reporting providers: only when analytics consent is granted.
  • The venue you are ordering at: the bartender / gatekeeper / manager sees order content, station + handoff status, and the minimum identity fields needed to deliver the order.
  • Law enforcement and regulators: when legally compelled or where there is a good-faith basis to do so.

9. International transfers

Our primary processing happens in the United States (AWS us-east-1). If you are in the EEA / UK and your data is transferred to the US, the transfer relies on Standard Contractual Clauses or the EU-U.S. Data Privacy Framework where applicable. Contact help@drinklync.com to request a copy of the transfer safeguards.

10. Retention

  • Account profile: retained while the account is active and for 12 months after closure unless legally retained for longer.
  • Order + transaction records: retained for at least 7 years (US tax / accounting / dispute) and as long as venue/brand contracts require.
  • Payment metadata: retained for the longer of (a) the processor’s retention requirement or (b) chargeback / dispute window.
  • Telemetry: retained for 13 months in raw form and longer in aggregated form.
  • Support tickets: retained for 24 months after last contact.
  • Cookie consent records: retained for 24 months for audit trail.

11. Your rights

Depending on your jurisdiction (GDPR / UK GDPR / CPRA / state privacy laws), you have some or all of the following rights:

  • Right of access: a copy of the personal data we hold about you.
  • Right to rectification: correction of inaccurate data.
  • Right to erasure (“right to be forgotten”): deletion subject to retention duties.
  • Right to restrict or object to processing, especially for marketing or analytics.
  • Right to data portability: a machine-readable export.
  • Right to withdraw consent for any consent-based processing.
  • Right to non-discrimination for exercising privacy rights.
  • Right to opt out of the “sale” or “sharing” of personal information (CCPA/CPRA and similar state laws). DrinkLync does not sell your personal information; you can record an opt-out from any sharing for cross-context targeted advertising at /do-not-sell.
  • Right to lodge a complaint with your supervisory authority (e.g., ICO in the UK, your national DPA in the EEA).
  • How to exercise: email help@drinklync.com, use the in-app account-deletion and data-deletion pages, or visit /do-not-sell for the sale/share opt-out. We respond within 30 days (60 in complex cases).
Responsibility for age checks

Age verification at service is performed and owned by the venue

Every alcoholic drink ordered through DrinkLync is sold, poured, and handed over by the venue's licensed staff. Verifying that the person receiving a drink is 21 or older (or the local legal drinking age) at the point of service is the venue's legal responsibility under its alcohol license and local law.

DrinkLync provides software tooling that supports the venue's checks (account age attestation, order and pickup verification, optional ID-on-file features). DrinkLync does not itself perform age verification at service and does not assume the venue's responsibility for it.

12. Children’s data

DrinkLync is an alcohol-ordering platform restricted to users 21 years of age or older (or the local legal drinking age, whichever is higher). We do not knowingly collect data from anyone under that age. If you believe a minor has used DrinkLync, contact help@drinklync.com and we will delete the account.

Age verification at the point of service is performed and owned by the venue; DrinkLync provides supporting tooling only (see the callout above).

13. Automated decision-making

DrinkLync uses automated systems for fraud-prevention, anomaly detection, and capacity / pricing telemetry. We do not make decisions with legal or similarly significant effect on you solely by automated means without human review (e.g., a permanent account ban). Where automated decisioning is used in a way that materially affects you, you can request human review at help@drinklync.com.

14. Security

  • Transport encryption (TLS 1.2+) on every endpoint.
  • Encryption at rest for primary stores (AWS KMS).
  • MFA enforced on manager / owner / admin accounts.
  • Least-privilege IAM roles for every Lambda and operator role.
  • Continuous security review via audit-logger and a security-regression test suite.
  • Incident response playbook in our internal runbook library; we will notify affected users where law requires.

15. Changes to this policy

We may update this policy as DrinkLync evolves. Material changes will be announced in-app + by email at least 14 days before they take effect. The current version + effective date is always shown at the top of this page.

16. Contact and complaints

All privacy questions, requests, or complaints: help@drinklync.com.

If we cannot resolve a complaint, you may also contact your local supervisory authority (e.g., ICO, CNIL, AEPD) or your state attorney general’s office.

DrinkLync LLC support and privacy links
Support contact: help@drinklync.com
Privacy PolicyTerms of ServiceAccessibilityCookie PreferencesAccount DeletionData DeletionData Processing Addendum