Bev Logo

Nitecapp Supplier Privacy Policy

Effective Date: January 16, 2026

Introduction

Nitecapp ("we", "us", or "our") respects your privacy and is committed to protecting the personal and business data of our suppliers. This Privacy Policy explains how we collect, use, store, and share information when beverage and food suppliers ("you" or "Supplier") use the Nitecapp platform (including our websites, apps, and related services specifically provided to suppliers). We focus here on supplier-related data practices – if you are also a user of other parts of Nitecapp (e.g., the consumer app or operator dashboard), please refer to any additional privacy notices relevant to those. By using Nitecapp as a supplier, you consent to the practices described in this Privacy Policy. We've written this policy in clear, straightforward language to be as transparent as possible. If you have any questions or concerns, please contact us at the information provided at the end.

1. Information We Collect

We collect various types of information from and about our supplier users and their content. This includes the categories outlined below.

1.1 Personal Information (Supplier Account Data)

When you create a supplier account, we collect personal and business-related details such as:

  • Contact Information: Your name, business email address, phone number, and job title. We use this to identify you, communicate with you, and verify your account.
  • Company Information: Your company or brand name, business address, website, and industry segment (e.g., winery, brewery, distillery, food producer). We may also request proof of affiliation (such as a company-domain email or documentation) as part of brand verification.
  • Login Credentials: Username and password (stored in encrypted form). If you use single sign-on or third-party authentication, we collect the necessary identifiers or authentication tokens from that provider.
  • Preferences and Settings: Account-level preferences such as notification settings, language, and time zone, which help tailor your experience.

1.2 Brand and Content Data

As you use Nitecapp to upload and manage content, we collect and store the information you provide, including:

  • Brand Profiles: Brand descriptions, product details, logos, images, and other information you add to brand or product pages.
  • Uploaded Media: Photos, videos, PDFs, recipes, and other files you upload. If you generate content using Nitecapp’s AI tools, we may store the generated output and the prompt used to create it.
  • Courses and Educational Content: Lesson text, quizzes, questions, answers, and other structured training materials you create.
  • Communication Content: Messages, comments, feedback, or support communications (such as emails or chats with our support team), which may be associated with your account for context.
  • Portfolio Data: Organizational metadata such as brand families, categories, tags, and naming conventions used to structure your content.

1.3 Usage Data (Analytics Information)

We automatically collect data about how you and your invited team members use the platform, including:

  • Log Data: IP address, device and browser type, operating system, pages viewed, actions taken, and timestamps. This helps with security, troubleshooting, and analytics.
  • Activity Data: Information about interactions within the platform (such as viewing analytics, publishing content, or using AI tools). This data may be linked to your account ID and is primarily used in aggregate or to provide usage insights to you.
  • Cookies and Similar Technologies: Used for session management, preferences, and analytics. Some cookies are essential for platform functionality, such as keeping you logged in.

1.4 Data from Operators and Frontline Interactions

As Nitecapp connects suppliers with hospitality operators and staff, we collect and present data about how those users engage with your content:

  • Engagement Analytics: Aggregated insights such as course completion counts, video views, quiz pass rates, and property-level participation. These analytics do not include personal details of individual staff unless consented to or required for certification records.
  • Operator Feedback or Communication: Messages, questions, ratings, or feedback submitted by operator users, which may include their name or role and are shared with you through the platform.
  • Brand Placement Data: Information about venues that carry or list your products within Nitecapp, including venue names, locations, and placement details, based on operator-provided data.

1.5 AI and Training Data

When you use AI-assisted features, we may collect:

  • AI Input Data: Prompts, descriptions, or instructions you provide to AI tools, which are required to generate results and help us improve feature quality.
  • AI Output Data: Generated text or images that you choose to save as part of your content. These outputs may also be retained in limited training or evaluation logs in accordance with this policy.

1.6 Information from Third Parties

In some cases, we receive information from third-party sources, including:

  • Verification Services: Confirmation or business verification details from third-party providers.
  • Analytics Providers: Aggregated or generalized usage and demographic insights (such as region-level statistics).
  • Operator Data: Information operators provide about your brand or content through their use of the platform.

We do not typically collect sensitive personal information (such as government IDs or financial account numbers) from suppliers. The platform is designed for business and training content, and we ask that you do not upload highly sensitive personal data to Nitecapp.

2. How We Use Your Information

We use the collected information to provide, maintain, and improve Nitecapp's services, and to support you in using the platform. Specifically:

2.1 Providing the Service:

We use your registration and account info to set up your account, verify your identity and brand affiliation, and allow you to log in. For example, your email and password let you access the supplier dashboard securely.

The content data (brand pages, courses, etc.) you provide is used to populate the platform and deliver that content to the intended audience. If you upload a product video and mark it public, we use the data to ensure it's distributed to hospitality staff and venues via our app. If you create a course, we use the info to present that course to learners and track their progress. Essentially, without using your content data in this way, the service wouldn't function.

Engagement and operator data (like who is using your content) is used to generate the analytics and insights you see on your dashboard. We crunch that data to present it back to you in meaningful ways – e.g., graphs of course completions, lists of top-viewed videos, etc. It's also used internally to gauge platform health (like overall adoption metrics).

2.2 Communications:

We use contact information (email, phone as needed) to communicate with you. This includes sending service-related announcements (e.g., confirmation emails, notices of new features, changes to terms or policies), responding to support inquiries, and sending occasional product tips or marketing communications. For example, we might email a newsletter with best practices or an invite to a webinar for suppliers. You can opt out of non-essential marketing emails at any time. However, you cannot opt out of critical service emails (like security alerts or major platform notices) as these are integral to using the service.

If you and an operator or user communicate via the platform (for example, through a Q&A on a course or a chat feature), we will route those messages accordingly and may monitor them for compliance or support.

2.3 Improving and Personalizing the Platform:

We analyze usage data (both at an individual and aggregate level) to understand how suppliers are using Nitecapp. This helps us spot trends and areas to improve. For instance, if we see that a majority of users never use the "supplier locations" feature, we might investigate why and enhance it. Or if the AI image generator is heavily used, we'll allocate more resources to it.

We might use your usage patterns to personalize your experience. For example, if you frequently use certain tools, we might surface those quicker or suggest tutorials relevant to your activity. If the system notices you haven't tried a new feature, it might highlight it on your dashboard ("Did you know you can create quizzes? Here's how.").

We use collected feedback and support queries to improve customer service. Knowing common pain points helps us create better help resources or fix bugs promptly.

2.4 Data Sharing and Distribution:

With Hospitality Operators and Staff: The very point of Nitecapp is to share your brand content with hospitality operators, their staff, and in some cases the public. So, by design, information you upload marked for distribution will be shared:

Your brand profiles, courses, videos, and recipes will be accessible to the appropriate users (for instance, all operators if public, or specific ones if you choose). Operators and frontline staff may see and use this data to train and educate themselves. If you mark content "private" for certain venues, we will restrict access accordingly. But generally, if content is public, any user on the platform can view it (and potentially consumers via certain features). We will not share your personal account info with them (they see the brand's info, not, say, your personal email). However, within content it might be implied or included who the brand contact is.

We share analytics about content usage within the platform as appropriate. For example, a venue manager might see how their staff performed on your course. We provide them those insights (since they need to manage their team). This is mutually beneficial: they see value in your content and you get distribution. We ensure that sharing is done in a way consistent with expectations – e.g., a manager will see their own staff's results, but not necessarily the details of staff at another company.

Public Discovery:If you consent to it (implicitly by uploading content intended for consumers or by not marking something private), we will share certain brand data publicly. As mentioned, Nitecapp will have consumer-facing discovery tools. For instance, if a user searches for your brand to see which bars carry it, we might show your brand name, logo, product description, and perhaps an image – basically a mini profile to inform the consumer. We might also show which venues have it (from operator data). This is a key part of "activation" – connecting brands with consumers. Rest assured, sensitive or internal content (like a training quiz or internal pricing info) will not be shown to consumers. Only the appropriate public-facing information (which is often similar to what you'd have on your own website or marketing materials) will be exposed, and only if you've provided it.

Within Your Organization:If you invite team members (Managers) to your supplier account, they will see the data in your account. That's obvious but just to state – your colleagues with permissions can see the brand content and any collected analytics. You control their access. We consider that internal sharing under your direction, not our doing.

2.5 Compliance and Enforcement:

We use information as needed to enforce our Terms and Conditions and other policies. For example, we may review content and communications if we suspect a violation (like someone uploading prohibited content). We also use data to detect and prevent fraud or misuse. If something flags in our systems (like unusual account activity that might indicate a compromised account or a bot), we might analyze logs to investigate.

We may use your contact and activity info to inform you of policy changes or seek consent for new uses of data if such need arises. For instance, if laws change requiring certain consent for AI usage of data, we might reach out.

If necessary, we use data to comply with legal obligations. This could mean retaining records of payments for tax purposes, or producing information in response to a lawful subpoena or request (explained in Section 4). We also keep certain logs to meet security and compliance standards (like maintaining audit trails for ISO 27001 etc.).

2.6 AI Training and Feature Improvement:

To help improve Nitecapp's AI-powered features, we may use limited portions of platform content in a responsible and privacy-conscious way. This allows us to make tools like search, recommendations, quizzes, and content creation smarter and more useful over time.

In practice, this means we may use anonymized or aggregated content to train and refine our models. For example, if we offer an AI feature that helps generate quiz questions, the system may learn from patterns across many courses to better understand how effective questions are structured. The AI learns general patterns—it does not memorize or reproduce individual content verbatim.

We take care to ensure this process does not expose sensitive, proprietary, or confidential information to other users. AI outputs are designed to be general and instructional, not to reveal specific internal materials, recipes, or business details.

By using the platform, you're allowing this limited use of content as part of normal service operations. This helps us continually improve the quality, accuracy, and usefulness of Nitecapp's AI features for everyone on the platform.

If you have specific concerns about how your content is used, you're welcome to reach out to us to discuss options.

Important note: We do not use personal data—such as names, contact details, or user identities—for AI training. AI learning is focused on educational and product-related content, and outputs are intended to remain generic and non-identifying.

2.7 Marketing and Testimonials:

With your permission, we might use your company's name and logo on our website or marketing materials (for example, listing you as a "Nitecapp Supplier" or including a case study about your successful use of the platform). If we want to quote you or share specifics, we will ask first. Also, we may send you information about Nitecapp events, new features, or partnership opportunities. You can opt out of promotional communications as mentioned.

We will not sell your personal information to third parties for their marketing. We also don't bombard you with irrelevant advertising – any marketing we do is mainly to inform you of platform-related opportunities.

3. Data Storage and Security

3.1 Data Storage Location and Duration

Location: Your data is stored on secure servers, primarily on Amazon Web Services (AWS) cloud infrastructure. Our servers (for now) are in the United States. If you are located in another country, be aware your information will be transferred to and stored in the U.S. under U.S. data protection standards. (We adhere to frameworks like Privacy Shield successor mechanisms where applicable for EU data, etc.) We choose AWS because of its robust security and compliance offerings, including ISO/IEC 27001 certification.

Duration (Retention):We retain your personal and brand data as long as your account is active and for a reasonable period thereafter. As a default, we keep data while you're using Nitecapp so you have an ongoing record and history (for example, older courses and analytics remain accessible). If you delete content or your account, we will initiate deletion of the associated data from our live databases. However, some data may remain in secure backups for a certain period (typically not more than 90 days, often shorter) before those backups are cycled out, or longer if required for legal reasons. We also may retain certain information even after account deletion if necessary for legal compliance or legitimate business interests – for instance, we might keep a record of the fact that you had an account and it was closed, to prevent fraud or if needed for auditing. But in general, when you say delete, we delete. And importantly, deleted data is not recoverable – so be sure before you remove things.

3.2 Security Measures

We take security extremely seriously – Nitecapp is built for enterprise-grade adoption, so we implement industry best practices to safeguard your data. Our measures include:

  • Encryption: All communications with the Nitecapp platform are encrypted via HTTPS/TLS. Any sensitive data (like passwords or certain personal fields) are stored encrypted or hashed. We also encrypt data at rest in our databases where feasible. For instance, files and backups on AWS are encrypted using strong algorithms.
  • Access Controls: Within our organization, we limit who can access supplier data. Only authorized personnel with a need (like support or engineering troubleshooting an issue) can access your data, and even then, they access the minimum needed. We have strict role-based access internally. Your content is also siloed so that other suppliers cannot access it (unless you deliberately share something).
  • ISO 27001 and Compliance: We follow a security management program aligned with ISO/IEC 27001 standards and others. AWS, our hosting provider, is ISO 27001 certified, which means the infrastructure meets rigorous security controls. We also enforce security best practices like regular security audits, penetration testing, and code reviews to catch vulnerabilities.
  • Monitoring and Incident Response: We have systems to monitor for suspicious activity on the platform. If an anomaly is detected (say, a sudden large export of data or repeated failed logins), our security team is alerted. We have an incident response plan – if anything were to occur (like a data breach or security incident), we will inform affected users as required by law and take immediate steps to mitigate.
  • Employee Training and Policies: All Nitecapp employees and contractors with system access undergo background checks and security training. We have confidentiality agreements and data handling policies in place. Our staff are educated about the sensitivity of supplier data (especially any competitive or proprietary info) and know to treat it with the utmost care.
  • Physical Security:Although we're cloud-based, any physical servers or offices are protected. AWS data centers have robust physical security controls. Our company offices use access control and secure networks for any on-site data handling.
  • Regular Backups: We perform regular backups of data to prevent loss. These backups are stored securely (encrypted) and tested for restorability. So, your data is not only protected from unauthorized access, but also from accidental loss or corruption.

Despite all these precautions, it's important to note that no system can be 100% secure. However, we are continually improving our security posture and will promptly address any vulnerabilities or incidents, should they arise.

3.3 ISO 27001 Compliance Note

We specifically mention ISO 27001 because it's an internationally recognized standard for information security management. By leveraging AWS's compliance and implementing our own controls, we align with those standards. This includes systematic risk assessment, controlling access, and continuous improvement of our security processes. Enterprise customers can request more details on our security architecture if needed (under NDA, perhaps). We want you to feel confident that Nitecapp is a safe repository for your content and data.

4. Sharing of Information

We treat your information with care and do not share it with third parties except in the circumstances described below.

4.1 With Your Consent or at Your Direction

If you explicitly instruct us to share data with a third party, we will do so. For example, if you integrate a third-party service or API with Nitecapp—such as connecting to a CRM or social media platform—we will share the necessary data at your direction.

With your permission, we may also feature your brand (such as your name or logo) in Nitecapp marketing materials. In that context, limited information is shared publicly only with your consent.

4.2 Service Providers (Processors)

We use trusted third-party companies to perform certain business functions on our behalf. These providers receive only the data necessary to perform their services and are contractually bound to protect it and use it solely for Nitecapp’s purposes.

Examples of service providers include:

  • Cloud Hosting & Storage: Our infrastructure is hosted on providers such as AWS (Amazon Web Services). While your data resides on their servers, access is strictly controlled by us and governed by their security and compliance commitments.
  • Email & Communication Tools: Services like SendGrid may be used to send invitations, notifications, or updates. These providers process recipient email addresses and message content solely to deliver communications.
  • Analytics & Monitoring: We use analytics and monitoring tools (such as Google Analytics with IP anonymization, Sentry, or Datadog) to understand usage and diagnose issues. These tools may process limited technical data like IP addresses or user IDs, which we strive to minimize.
  • AI Providers: Some AI-assisted features rely on third-party AI APIs (such as language or image generation services). When you use these features, relevant prompts or context may be sent to those providers to generate a response. We select reputable providers with strong data protection practices and will indicate in the UI when an external AI service is used.
  • Payment Processors: If paid features are offered, payments are handled by secure processors (such as Stripe). Payment details are collected and stored by the processor, not by Nitecapp, and they are required to comply with PCI-DSS standards.
  • Other Vendors: We may use customer support, marketing, survey, or feedback tools (such as Zendesk or Intercom) that process your contact information and correspondence to provide support or gather feedback.

All service providers are bound by confidentiality and data protection agreements, and we do not permit them to use your data for their own purposes.

4.3 With Other Users (Operators, Staff, Public)

As described elsewhere in this policy, when you upload content intended for sharing, it is shared with the relevant user groups by the nature of the service.

Public or broadly shared content may be accessible to operators, staff, or in some cases public consumers. Restricted content is shared only with the users you designate (for example, staff at a specific hotel group).

We do not share your personal contact information with other users except where you choose to include it (such as listing a contact email on a brand page). In some cases, your name, title, or role may appear as the author or responder to content to provide context and authenticity.

4.4 Business Transfers

If Nitecapp undergoes a merger, acquisition, sale of assets, or similar corporate transaction, user data may be transferred as part of that transaction. Any successor entity will be required to honor terms at least as protective as this policy.

We will notify you of any such change in ownership or use of your personal information and inform you of any choices you may have regarding your data.

4.5 Legal Obligations and Protection of Rights

We may disclose information if required by law or if we believe in good faith that disclosure is necessary to comply with legal obligations, protect our rights or property, investigate wrongdoing, prevent fraud or security issues, or protect the safety of users or the public.

Where permitted, we will attempt to notify you of such requests and will limit disclosures to what is reasonably necessary.

4.6 De-Identified or Aggregate Data

We may share aggregated or anonymized data that cannot reasonably be used to identify you. For example, we may publish high-level statistics about platform usage or engagement trends in marketing or industry reports.

To emphasize: we do not sell your personal information and do not share it with third-party advertisers. Any sharing is limited to your direction, essential service providers, or legal requirements.

5. Your Rights and Choices

We believe in transparency and giving you control over your data. Depending on your location and subject to applicable law, you have certain rights regarding the personal information we hold about you:

5.1 Access and Correction:

Access (Right to Know): You have the right to request a copy of the personal data we have about you. For supplier users, most of your data is readily accessible by logging into your account – you can see your profile info, content, and analytics. If you need a comprehensive export (including system logs, etc.), you can contact us. We will provide the information in a commonly used electronic format, subject to authentication of your identity.

Correction (Right to Rectification):If any of your personal or company information is incorrect or outdated, you have the ability to correct it. You can usually do this through your account settings (e.g., update your name, change your email, edit brand descriptions). For any fields you cannot change yourself (maybe verification info), you can ask our support and we will correct any inaccuracies. It's in everyone's interest that data is accurate, so we'll promptly address correction requests.

We will respond to access or correction requests as soon as possible, generally within 30 days or as required by law.

5.2 Deletion (Right to Erasure):

You can delete specific content you've uploaded at any time (as described in the User Guide and Terms). Once deleted, that content will no longer be visible to others. We will then proceed to remove it from our active systems (and eventually from backups).

If you wish to delete your entire account and all associated data, you can initiate that via the platform or by contacting us. As noted, account deletion is irreversible – all brand content, courses, analytics, etc. will be purged. We will warn you of this outcome and might require a confirmation step (since a mistaken deletion could be disastrous for your accumulated content). Upon confirmation, we will deactivate and delete the account data. Some minimal info might be retained (as mentioned in retention) but we won't keep anything beyond what's necessary. Deleted means deleted. Keep in mind, deletion of your account will mean operators and staff can no longer access your previously shared content, and it may impact those who were in progress on courses etc. (It will appear removed on their side too).

Important: If you have multiple team users, deleting an account may affect them all. Ensure that the person requesting deletion is authorized (likely the Admin). We may verify such a request to prevent accidental or malicious deletion.

5.3 Portability:

In many jurisdictions, you have the right to data portability – the right to obtain your personal data in a format that can be moved to another service. Practically, you can export much of your content and data from Nitecapp: for instance, you might download courses or reports. If you need assistance, we can provide your data in JSON, CSV, or another convenient format. Note that this covers data you provided (and some generated data like your analytics), not proprietary analysis. But we aim to be flexible. If you were to leave Nitecapp, we want you to be able to take your work with you (minus any Nitecapp-specific system info).

5.4 Opt-Out of Communications:

Marketing Emails: As mentioned, you can opt out of promotional or marketing emails at any time by clicking the unsubscribe link in those emails or adjusting your account email preferences. Note that you will still receive essential service communications (account alerts, important updates) even if you opt out of marketing.

Notifications:If our app sends push notifications or in-app notifications, you typically have controls within the app settings or your device settings to opt out or mute certain notifications. For example, you might toggle off a notification for "weekly tips" but keep "new message from operator". We try to provide granular control.

Cookies: You can control or delete cookies via your browser settings. Some cookies are necessary for login sessions, so blocking those might hinder your use of Nitecapp web. For analytics cookies, we may offer a cookie banner or settings to opt out of analytics tracking. Alternatively, tools like browser do-not-track signals or ad-blockers might limit some third-party analytics. We honor do-not-track where feasible for marketing, but since our usage analytics is more for feature use, we treat that as part of service operations. However, if you object, there might be an opt-out mechanism we can provide (like an opt-out cookie for Google Analytics).

5.5 Brand Ownership Changes:

If your company or brand gets a new owner or if you as the primary user leave the company, please coordinate with us to transfer the account or data rights appropriately. The data on Nitecapp is considered an asset of the brand, not the individual user. We can transfer the account to another authorized person (after verification). If the brand is acquired, the data (brand pages, courses, analytics) can be transferred to the new owner's Nitecapp account. We will facilitate this in a secure manner once proper documentation is provided. Important: We will not hand over your account to someone else without verification. Similarly, if you were managing multiple brands and one brand's ownership changes, we can help segregate and move just that brand's data to a new account for the new owner. We aim to be flexible so that the platform reflects real-world ownership. We might require a written request or legal documentation for significant transfers, just to ensure legitimacy. Once transferred, the new owner will have access to all that brand's historical data (e.g., the analytics of past usage) as if they had been the owner all along. If that's not desired, the alternative is for you to delete the brand's data before transfer, but that wipes history – usually not preferred. We generally suggest transferring so continuity is preserved (with appropriate agreements if needed between old/new owners).

5.6 California Privacy Rights (if applicable):

If you're a California resident, you have specific rights under the CCPA/CPRA, some of which overlap with the above: the right to know, delete, and opt-out of sale/sharing of personal info. We do not sell personal info as defined. If we ever consider use of data that could be construed as "sharing" for cross-context behavioral advertising, we'd provide opt-outs. You also have the right not to be discriminated against for exercising your privacy rights. We extend similar courtesy to all users. If you ever want to exercise California rights, just contact us via the methods below; we will verify your identity and process your request as required.

5.7 EU/UK Data Subject Rights (if applicable):

If you are in the EU/EEA or UK, GDPR grants rights to access, rectification, erasure, restriction of processing, objection to processing, and data portability, as well as the right to lodge a complaint with a supervisory authority. We cover most of these above. For objection: you can object to processing of your data for certain purposes (like direct marketing – which we allow opt-out) or if based on legitimate interest (we would review and honor if no overriding interest to continue). For restriction: if you contest accuracy or our right to process, you can request we limit use until resolved. We also handle that case-by-case.

To exercise any rights, or if you have questions, reach out to our support or privacy contact (see Contact section). We may need to verify identity for sensitive requests, especially for data access or deletion (we wouldn't want to accidentally give your data to an impostor). We will respond within the timeframe required by law (typically 30 days, can extend to 60 in complex cases, but we aim for sooner). There is generally no fee for these requests unless they are unfounded or excessive (in which case we might charge a reasonable fee or refuse, but we'd justify that).

Remember that even after deletion, some data (like aggregated insights that don't identify you, or minimal logs) might remain for reasons stated. Also, if your content was accessed by others, they might have retained copies (we cannot erase files someone already downloaded, etc.). But through the platform, it will be gone.

6. Use of Data in AI Tools & Opt-In

We want to be clear and transparent about how content on Nitecapp is used in connection with our AI-assisted features (such as recommendations, summaries, and search). This is an evolving area, and one we know users care deeply about.

6.1 AI Use of Content (No Model Training)

By uploading content to Nitecapp, you allow that content to be accessed and referenced by AI-assisted features within the platform to support education, discovery, and program execution. Nitecapp does not use your content to train general-purpose AI models or to improve models outside of your organization's intended use.

In practice, AI features may help surface, summarize, or organize content you have already chosen to make available to hospitality teams carrying your products. For example, if a supplier uploads cocktail recipes or tasting notes, AI tools may help staff quickly find that information, understand it, or receive relevant recommendations while working. This use is limited to making existing content easier to access and apply—it does not involve learning from your content or incorporating it into a broader training dataset.

6.2 Safeguards and Scope of Use

We handle AI-assisted content access carefully and with clear boundaries. AI features only reference content that is already visible to the relevant user, such as staff at properties that carry your brand. Content is not exposed to unrelated users, competitors, or external systems.

We do not use personal data (such as names, email addresses, phone numbers, or user identities) in AI features. The focus is strictly on educational and product-related materials, including brand stories, product attributes, recipes, menus, and training content. Any personal or internal-only information is outside the scope of AI-assisted use.

AI outputs are designed to be contextual and supportive, not verbatim reproductions of full documents. For example, an AI may summarize key tasting notes or highlight relevant pairing guidance, but it is not intended to reproduce proprietary materials wholesale.

6.3 Content Responsibility and Intended Sharing

Content uploaded to Nitecapp is assumed to be intended for training, education, and program execution by teams carrying or selling your products. If certain materials are confidential or not meant to be broadly shared, they should not be uploaded to shared areas of the platform. Nitecapp is not designed to store trade secrets or highly sensitive proprietary processes.

6.4 Transparency and Future Features

If we introduce new AI capabilities that materially change how content is accessed or referenced, we will update this policy accordingly. For example, if an AI feature allows staff to ask questions answered using supplier-provided content, we will ensure suppliers are informed about how their content may be referenced and that appropriate safeguards and attribution are in place.

6.5 No Sale of Data or External AI Training

We do not sell your content or data for AI purposes, and we do not provide your content to third parties to train their AI models. Any AI services used by Nitecapp are governed by agreements that restrict data usage to Nitecapp's functionality and explicitly prohibit external model training on your content.

In summary, AI on Nitecapp is designed to help the right people access and use the content you choose to share—nothing more. Our goal is to reduce friction in education and execution while respecting brand boundaries and data responsibility.

7. Children's Privacy

Nitecapp's platform is not intended for use by minors (for our industry, likely no one under 18 or 21 depending on alcohol laws). We do not knowingly collect personal data from anyone under the legal drinking age (21 in the U.S.) or under 16 in general (the stricter COPPA threshold). Supplier accounts are business accounts and should be used by adults. If we discover that an underage person has created a supplier account or provided personal info, we will take steps to delete that information promptly. If you, as a supplier, are uploading any content featuring minors (which would be unusual in an alcohol context), ensure you have appropriate rights and that it's used lawfully (e.g., maybe a soft drink brand featuring teens in a campaign – still, we'd advise caution).

But overall, minors shouldn't be using Nitecapp. The frontline app might have young employees (like an 18-year-old bartender in some region), but in supplier context, content is aimed at professional use. We instruct any underage individuals who somehow interact with us to refrain and have a guardian contact us if needed to remove their data.

8. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational reasons. When we make material changes (those that substantively affect how your data is used or your rights), we will notify you clearly – for example, by email (to the address on your account) or by placing a prominent notice on the supplier dashboard. We will also update the "Effective Date" at the top of the policy.

It's important you review such changes. If you continue to use Nitecapp after a revised Privacy Policy has become effective, that means you accept the updated terms (of course, within the bounds of law – if consent is required for something, we'll specifically seek it). If you do not agree with any changes, you should stop using the platform and may request your data deletion.

We encourage you to periodically review this Privacy Policy to stay informed about how we are protecting the information you entrust to us. Our commitment to your privacy won't change – any updates are generally to clarify or improve our policies, or adapt to new features.

9. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or the way we handle your data, please do not hesitate to contact us:

  • Email: teams@nitecapp.com
  • Website Contact Form:You can also reach out through our website contact page if needed, and mention it's privacy-related so it gets routed appropriately.

We will respond to your inquiries as soon as possible, typically within a few business days. If you need to escalate an issue or feel we haven't addressed your concern satisfactorily, you have the right to contact your local data protection authority (for EU/UK users) or other relevant regulatory body. But we genuinely prefer to resolve things directly and amicably.

Thank you for trusting Nitecapp with your data. We value your partnership and are dedicated to keeping your information secure and your privacy respected as we work together to build the global standard in food and beverage discovery, education, and activation.