Privacy Policy
Entity: YodaCom LLC, a Colorado limited liability company, d/b/a BeerZap ("BeerZap," "we," "us," or "our")
Governing law / venue: Colorado
Contact: legal@beerzap.com
Version 1.0 — Effective July 24, 2026
This policy covers everyone who interacts with BeerZap — attendees (who use the Service without creating an account), organizers, and vendors/brewers. Where practices differ by role, this policy says so.
1. Information We Collect
1.1 Attendees — geolocation, front and center
BeerZap's core mechanic is a "capture": you scan a QR code at a vendor station, and your device's precise GPS location is checked against that station's location to confirm you are physically present. When a capture succeeds, that GPS reading — latitude, longitude, and accuracy — is saved as a permanent part of your capture record, tied to a persistent anonymous identifier for your device/session (see Section 1.2). This location data is used to verify the scan at the moment it happens and to resolve a dispute later if one comes up (for example, if an organizer needs to confirm whether a capture was genuine). We do not track your location at any other time, and there is no continuous or background location tracking.
1.2 Attendees — no account, but not "anonymous" in every sense
BeerZap does not ask for your name, email address, or a password. You use the Service through an anonymous session tied to your device. That said, this anonymous session uses a persistent identifier — a durable token that stays associated with your captures across a single event (and, in some cases, across events) even though it is never linked to your name or contact information. We describe this precisely because it would be inaccurate to say BeerZap has no data trail about your activity — we do not know who you are, but we can distinguish your captures from another attendee's captures using this identifier.
1.3 Organizers and vendors
When you sign up as an organizer or claim a vendor/brewer login, we collect your name, email address, business/organization name, and payment information (processed by our payment processor, Stripe — we do not store full card numbers ourselves).
1.4 Usage and device data
Standard technical data (device type, browser, IP address, timestamps) collected automatically as part of operating the Service.
2. How We Use Information
We use the information described above to: operate the Service (verify captures, run leaderboards, process payments); communicate with organizers and vendors about their accounts and events; resolve disputes (for example, a "someone says they were there but weren't" capture dispute); improve the Service; and comply with legal obligations.
3. Geolocation Retention
Current practice: capture location data is retained for as long as the associated event and account records exist in our systems. As of this policy's effective date, we do not operate an automatic deletion schedule for capture records — they are retained indefinitely by default, similar in shape to how many location-based apps in this category operate. We recognize this is a meaningful retention choice, not a neutral default, and we are evaluating a defined retention/deletion schedule as the product matures. In the meantime, you may request deletion of your capture history at any time by contacting legal@beerzap.com with the event and approximate date/time of your capture; we will honor verified deletion requests.
4. Sharing of Information
4.1 The organizer/vendor data boundary — an affirmative claim, not just a promise
Vendors participating in your event cannot access your individual attendee data. Vendor accounts see only aggregate figures — leaderboard rank, average rating, total redemption counts — never your name, location history, or individual capture record. This is enforced technically at the database level through row-level security policies that restrict vendor access to narrow, aggregate-only functions. We believe this is a meaningfully stronger privacy boundary than the industry norm, where event platforms commonly hand attendee data to event organizers wholesale; we do not do that with vendors.
Event organizers can see capture-level data for their own event (this is necessary to resolve disputes and manage the event), but organizers do not receive data from other organizers' events, and vendors do not receive organizer-level data.
4.2 We do not sell your geolocation data
In the preceding twelve (12) months, BeerZap has not sold or shared (as those terms are defined under the CCPA/CPRA) any geolocation data or other personal information to any third party, and we do not intend to do so. If this changes in the future, we will update this policy and provide any notice and opt-out required by law before doing so.
4.3 Service providers
We share information with service providers who help us operate the Service (for example, our hosting provider and payment processor), under contractual obligations limiting their use of that information to providing services to us.
4.4 Legal requirements
We may disclose information if required to do so by law or in a good-faith belief that disclosure is necessary to comply with legal process, protect our rights, or protect the safety of any person.
5. Your Privacy Rights (CCPA/CPRA and Similar State Laws)
If you are a California resident, or a resident of another state with a comparable privacy law, you have the right to: know what personal information we have collected about you; delete that information; correct inaccurate information; and not be discriminated against for exercising these rights. Because we do not sell or share personal information with third parties, a request to opt out of sale or sharing has no additional practical effect beyond what we already do — but if you submit such a request, we will honor it and treat it the same as any other privacy-rights request under this policy, including recognizing a Global Privacy Control (GPC) browser signal as a valid request where technically detectable.
To exercise any of these rights, contact legal@beerzap.com.
Note on scope: this policy addresses federal-level (CCPA/CPRA-style) privacy rights. Some states have their own additional geolocation-specific privacy statutes not separately surveyed here.
6. Children's Privacy
BeerZap is not directed to children, and we do not knowingly collect personal information from anyone under 13. Additionally, attendees participating in any alcohol-related prize or reward must meet the legal drinking age described in our Acceptable-Use & Prize-Promotion Terms.
7. Data Security
We use commercially reasonable technical and organizational measures designed to protect information from unauthorized access, use, or disclosure — including the row-level-security architecture described in Section 4.1. No system is completely secure, and we cannot guarantee absolute security.
8. Data Retention — Organizer and Vendor Accounts
We retain organizer and vendor account information for as long as the account is active, and for 90 days after account closure or 7 years of account inactivity, whichever comes first, after which it is deleted or anonymized, except where we are required to retain it longer by law (for example, tax or payment records).
9. Cookies and Similar Technologies
We use cookies and similar technologies for essential Service functionality (for example, keeping your anonymous session active during an event) and, where applicable, basic analytics. We do not use these technologies to sell or share your information with third parties.
10. Changes to This Policy
We may update this Privacy Policy from time to time. For a change we determine to be material, we will provide at least 14 days' advance notice by email and/or in-app notice before the change takes effect.
11. Contact Us
Questions about this policy, or a privacy-rights request, can be sent to legal@beerzap.com.