// LEGAL
Privacy Policy
// LAST UPDATED: AUGUST 31, 2026
// WHAT WE COLLECT
At threedeep, we respect your privacy. When you use threedeep to order drinks, we collect the information necessary to process your order and operate the service. Depending on how you use threedeep, this includes:
Account & orders. Your name, email address, password (stored as a salted hash), order history, Bar TAB Credit balance and transactions, and the name you enter at checkout.
Payments. Payment details are processed by our PCI-compliant payment processor (Stripe); threedeep never stores full card numbers. We retain transaction identifiers and a card fingerprint (a non-reversible identifier Stripe derives from the card) used for fraud prevention and order attribution.
Location. If you grant location permission, we collect your device's precise location while you use the app and store your last known location to show nearby bars and, if you opt in, to send nearby-bar notifications. We do not track your location in the background.
Notifications. If you enable push notifications, we store your device push tokens and subscription endpoints, your notification preferences, and any bars you watchlist.
Sign-in security. If you enable biometric sign-in, we store a WebAuthn public-key credential identifier and signature counter. We never receive your fingerprint or face data — only a cryptographic confirmation that your device authenticated you.
Sessions & analytics. Session records include IP address and browser user agent. Our own analytics record page paths, referrers, timestamps, and a persistent random visitor identifier — we do not use third-party advertising trackers.
// HOW WE USE IT
We use this information solely to facilitate transactions, provide customer support, prevent fraud, and help venues and bartenders fulfill orders efficiently. We do not sell, rent, or trade your personal information to third parties. Your data is used exclusively to operate and improve the threedeep platform and to support the venue where you are placing your order.
// PAYMENT SECURITY
Payment information is handled by secure, PCI-compliant payment processors, and threedeep does not store full credit card numbers. We may share limited information with service providers only as necessary to deliver the service (such as payment processing or messaging providers), and only under strict confidentiality obligations.
// DATA PROTECTION
We implement reasonable administrative, technical, and physical safeguards to protect your information, consistent with the New York SHIELD Act. Access to personal data is restricted to server-side systems using credentialed service roles.
// RETENTION & DELETION
We keep account, order, and transaction records for as long as your account exists and as required for tax, accounting, and dispute-handling obligations. Push tokens are deleted when the device unsubscribes or the token is reported dead. Location is limited to the most recent known position and is overwritten as it updates. You may request access to, correction of, or deletion of your personal data by emailing hello@threedeep.io; we will delete data not subject to a legal retention requirement within 30 days.
// SERVICE PROVIDERS
We share limited information with service providers only as necessary to deliver the service — payment processing (Stripe), email delivery (Resend), push-notification delivery (Apple Push Notification service and web-push providers), and our database/hosting infrastructure (Supabase, Vercel) — each under confidentiality obligations. We do not sell, rent, or trade your personal information.
// YOUR CONSENT
By using threedeep, you consent to the collection and use of information as described in this policy, which may be updated periodically to reflect improvements in our services or changes in legal requirements.