Skip to main content
bartendersNow

Legal

Privacy Policy

Effective:
Last updated:
Jurisdiction:
United States

1. INTRODUCTION

Midnight Logic, Inc. ("Company," "we," "us," or "our") operates the bartendersNow™ platform, a marketplace connecting professional bartenders with event hosts. We are committed to protecting your privacy and being transparent about how we collect, use, and share your personal information.

This Privacy Policy explains how we handle personal information when you use our progressive web application, website, and related services (collectively, the "Platform").

California Residents: This policy includes specific information about your rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA). See Section 12 for details.


2. INFORMATION WE COLLECT

2.1 Personal Information You Provide

Account Information:

  • Name, email address, phone number
  • Date of birth (used to confirm you meet the minimum age for the services you request and, for bartenders, to verify your identity with our payments and identity-verification provider)
  • Residential or mailing address, and the ZIP code you provide at sign-up
  • Profile photo and biography
  • Location and service area information
  • Professional credentials and certifications
  • Payment information (processed securely through Stripe)

For Bartenders:

  • Identity verification documents (via Stripe Identity)
  • Professional licenses and certifications (RBS, etc.)
  • Business information and tax identification
  • Service rates, availability, and preferences
  • Professional experience and references

Documents you upload (Documents Hub): Bartenders may upload documents to their Documents Hub, including certificates of insurance (which may contain a policy number and, in some cases, a business or home address), professional certifications, and background-check or fingerprinting-clearance records (for example, a California LiveScan clearance letter or result). We store these documents so that you can keep them in one place and choose to share them with specific hosts. We do not ask for, and you should not upload, a raw fingerprint image or fingerprint card. bartendersNow does not review, verify, endorse, or independently confirm any document you upload.

Identity Verification & Biometric Processing: Identity verification is conducted by our third-party service provider (Stripe, Inc.), which may collect and process biometric verification data pursuant to Stripe's Privacy Policy. Midnight Logic, Inc. does not receive, store, or have access to raw biometric templates. This government-issued ID and biometric verification data is classified as Sensitive Personal Information under the California Privacy Rights Act; see Section 12.2 (Categories of Personal Information) for the detailed disclosure.

For Hosts:

  • Event details (date, location, guest count, duration)
  • Beverage preferences and service requirements
  • Property and venue information
  • Special requests and accessibility needs

Communications:

  • Messages sent through our platform
  • Customer service interactions
  • Feedback and survey responses
  • Review and rating content

2.2 Information Collected Automatically

Platform Usage:

  • IP address, browser type, and device information
  • Platform navigation and interaction patterns
  • Feature usage and preferences
  • Session duration and frequency of use

Location Information:

  • Geographic location for service matching
  • GPS coordinates when using mobile features
  • Service area and travel preferences

Performance Data:

  • Algorithm performance and optimization data
  • Search queries and filtering preferences
  • Booking success rates and completion data
  • The Stock List usage and effectiveness metrics

First-Party Analytics (Firebase Analytics / GA4): We use Firebase Analytics (Google Analytics 4) as first-party product measurement (session tracking, booking funnels, and sign-ins) strictly for internal platform operation. This first-party operational analytics falls under the CCPA/CPRA Business Purpose Exception (Cal. Civ. Code § 1798.140(e)) and does not require a consent gate or opt-out.

This measurement includes coarse location: the state, the city, and the first three digits of a ZIP code. We use it to understand where our services are being requested — including areas where we are not yet available — so that we can plan where to operate. We do not send Google Analytics your full ZIP code, your street address, or precise device location such as GPS coordinates. We do not use this measurement for advertising or for cross-context behavioral advertising, and Google processes it for us as our service provider.

2.3 Information from Third Parties

Identity Verification (Stripe Identity):

  • Government-issued ID verification
  • Identity verification results
  • Financial account verification
  • Risk assessment data

Payment Processing:

  • Transaction history and payment methods
  • Fraud prevention and security data
  • Financial verification information

Integration Partners:

  • Google Maps: Location and mapping data
  • Twilio: SMS delivery and communication data
  • SendGrid: Email delivery and engagement data

2.4 Information from Non-Users

Some people give us personal information without ever creating an account. If you send us a copyright complaint, a trademark concern, a child-safety report, or another legal or abuse report, we collect the information you provide in that report. Depending on the type of report, this can include your name, the organization you represent, your email address, your postal address, your telephone number, your electronic or physical signature, and the contents of your report. For copyright complaints, federal law (17 U.S.C. § 512(c)(3)) requires us to collect several of these items before we can act on your notice.

How we use this information. We use information from non-user reports only to evaluate the report, take any action it calls for, notify the people affected by it (see Section 4.3), administer our repeat-infringer policy, keep the records the law requires us to keep, comply with our legal obligations, and establish, exercise, or defend legal claims.

Your rights still apply. If you are a California resident, you have the privacy rights described in Section 12 with respect to the personal information in your report, even though you do not have an account with us. Section 12.5 explains how to make a request and how we verify it when you have no account. Please note that some of this information is subject to the retention periods and legal exceptions described in Sections 5.1 and 12.1.

Launch-Notification Requests. If you do not have an account and you ask us to notify you when bartendersNow™ becomes available in your area — for example, by using the "Notify me" option we show when no bartenders are available near you — we collect the email address you provide and the city or area you asked about. We use this information solely to send you a notification when we launch bartending services in that area, and for related email-deliverability and abuse-prevention purposes. We do not add this address to any other marketing or promotional list, and we do not use it for any other purpose, without your separate consent.


3. HOW WE USE YOUR INFORMATION

3.1 Platform Operations

Core Services:

  • Facilitate connections between Hosts and Bartenders
  • Process bookings and coordinate services
  • Generate The Stock List recommendations
  • Calculate optimal staffing with Smart Staffing Calculator
  • Enable Captain Service coordination features

Account Management:

  • Create and maintain user accounts
  • Verify identity and credentials
  • Provide customer support
  • Process payments and handle refunds

3.2 Safety and Security

Platform Integrity:

  • Verify user identities and prevent fraud
  • Monitor for suspicious activity
  • Enforce platform policies and terms
  • Screen images you upload for explicit or violent content, using automated tools, before they are displayed publicly
  • Investigate safety incidents and disputes

Legal Compliance:

  • Comply with applicable laws and regulations
  • Respond to legal requests and court orders
  • Protect rights and interests of all parties
  • Maintain records as required by law

3.3 Improvement and Optimization

Algorithm Enhancement:

  • Improve The Stock List accuracy through feedback loops and usage data
  • Optimize Smart Staffing Calculator recommendations
  • Enhance matching algorithms for better connections
  • Analyze platform performance and user satisfaction

Product Development:

  • Develop new features and services
  • Test and implement platform improvements
  • Personalize user experience
  • Conduct research and analytics

3.4 Communications

Platform Communications:

  • Send booking confirmations and updates
  • Provide service notifications and reminders
  • Share important safety and policy information
  • Deliver customer support messages

Marketing Communications (with consent):

  • Share platform updates and new features
  • Provide educational content and tips
  • Send promotional offers and incentives
  • Conduct user surveys and feedback requests

Launch-Notification Communications (non-users):

  • If you asked us to notify you when we become available in your area, we use the email address you provided to send that notification. That is the only use we make of the address unless you later give us separate consent. Every such message includes a way to unsubscribe, and you may opt out at any time. Once you opt out, we suppress your address from further messages even if you do not have an account with us.

4. HOW WE SHARE YOUR INFORMATION

4.1 Between Platform Users

Public Profile Information:

  • Bartender profiles visible to potential Hosts
  • Professional credentials and certifications
  • Reviews, ratings, and feedback
  • Service offerings and availability

Booking Information:

  • Contact details shared after booking confirmation
  • Event logistics and coordination information
  • Payment and service completion data

Bartender-Directed Document Sharing. Documents in a bartender's Documents Hub are private by default. A document is shared with a host only when the bartender expressly chooses to share that specific document with that specific host, and only with a host the bartender has a confirmed booking or an open booking request with. When a document is shared, the host can open it through a temporary link that expires after 15 minutes; we do not give the host a permanent copy or a downloadable link, and the host's access is re-checked against a live booking relationship each time the host opens the document. A bartender can stop sharing a document at any time. Once sharing is stopped, or the booking relationship ends, the host can no longer open the document — although a link the host already opened may keep working for up to 15 minutes. We do not make sharing decisions on a bartender's behalf, we do not verify any document, and we do not provide documents to hosts, background-check companies, or anyone else except at the bartender's direction or as described in Sections 4.2 and 4.3.

4.2 Service Providers and Partners

We share information with the third-party service providers ("Sub-processors") identified in the sub-processor table in Section 11.1, which names each provider, its function, the data categories it processes, and its role. The generic categories below correspond to that named table:

Payment Processing (see the named sub-processors in Section 11.1):

  • Stripe: Payment processing, identity verification, fraud prevention
  • Financial institutions: Transaction processing and verification

Communication Services (see the named sub-processors in Section 11.1):

  • Twilio: SMS notifications and communication
  • SendGrid: Email delivery and management
  • Phone service providers: Voice communication support

Technology Services (see the named sub-processors in Section 11.1):

  • Google Maps: Location services and mapping
  • Automated content screening: Screening images you upload for explicit or violent content before public display
  • Cloud hosting providers: Data storage and platform operation
  • Analytics providers: Platform performance and optimization

4.3 Legal and Safety Requirements

Legal Compliance:

  • Law enforcement: When required by law or court order
  • Regulatory authorities: For compliance and investigation purposes
  • Legal counsel: For legal advice and representation

Safety and Security:

  • Emergency services: In case of safety incidents
  • Insurance providers: For claims processing and verification
  • Identity verification provider (Stripe Identity): Government-ID identity verification (we do not conduct background checks)

Copyright counter-notifications: If your content is removed after a copyright complaint and you send us a counter-notification to dispute the removal, the Digital Millennium Copyright Act (17 U.S.C. § 512(g)(2)(B)) requires us to send a copy of your counter-notification to the person who filed the original complaint. Your counter-notification must contain your name, address, and telephone number, and a statement consenting to the jurisdiction of a federal court. We are legally required to disclose that information to the complaining party, and we cannot redact it. Please read Section 5 of our DMCA & Copyright Policy before filing a counter-notification so that you understand what will be shared and with whom.

4.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the new entity, subject to the same privacy protections.


5. DATA RETENTION

5.1 Retention Periods

Active Accounts:

  • Personal and account information: Retained while account is active
  • Transaction records: 7 years for financial and tax purposes
  • Communications: 3 years for dispute resolution and support
  • Analytics and product-usage records: Individual event records are linked to your account and device identifiers while we hold them — they are not anonymized — and are scheduled for deletion 90 days after they are recorded. Aggregated counts derived from them, which contain no account, device, or session identifier, are kept indefinitely.

Inactive Accounts:

  • Personal information: Deleted after 2 years of inactivity
  • Essential records: Retained as required by law
  • Analytics data: The same 90-day schedule described above applies; whether your account is active does not change it

Documents you upload (Documents Hub). We keep a document you upload for as long as you keep it in your Documents Hub and your account is active. When you delete a document, we delete the document record and the underlying file. We also delete documents you have not removed yourself when you have had no interaction with your account for three (3) years, and we delete a document that has never been shared with a host, and that you have not updated, after twelve (12) months. We do not keep a deleted document except where a legal hold, audit, investigation, or legal claim requires us to.

Background-check and fingerprinting-clearance records (heightened sensitivity). Because these records are especially sensitive, we apply the schedule above to them without exception, we store them only so that you can share them with hosts you choose, and we never use them to identify you. This paragraph, together with Section 5.2, is our written retention-and-destruction schedule for these records. We permanently destroy such a record when you delete it, when you delete your account, when you have not shared it for twelve (12) months, or within three (3) years of your last interaction with us — whichever happens first — except where a law requires us to keep it longer.

Legal Requirements:

  • Tax records: 7 years as required by law
  • Safety incidents: As required for legal proceedings
  • Regulatory compliance: As mandated by applicable authorities
  • Compliance and legal acknowledgment records: Where you accept a legal acknowledgment, attestation, or certification on the platform (for example, a bartender's independent-contractor and responsible-service acknowledgments, or a host's event-compliance attestation), we retain a record of that acceptance — the date and time, the identifier of the version of the terms you accepted, and the responses you gave — for eight (8) years following the end of your relationship with bartendersNow™, or longer where a legal hold, audit, investigation, or legal claim requires it. This retention is necessary for us to comply with our legal obligations and to establish, exercise, or defend legal claims.

Copyright, Trademark, and Abuse Reports: When someone sends us a copyright complaint, a trademark concern, or another abuse report, we retain that report and the reporter's identity and contact information for three (3) years from the date the matter is finally resolved. A matter is finally resolved on the latest of: the date we remove or restore the content; the close of the counter-notification waiting period; or the close of any appeal window and our decision on the appeal.

After that three-year period, we automatically redact the reporter's personal contact information and keep only a de-identified record of the report — for example, the date, the content involved, the work claimed, our determination, and the action we took. We keep this de-identified record for the life of the reported user's account and for three years after the account is closed or terminated.

Strikes do not expire. Retaining a copyright notice for three years is not the same as a strike expiring. A strike we issue under our repeat-infringer policy remains on the account for as long as the account is open. If we terminate an account under that policy, we keep a permanent, de-identified record of the termination — with no readable personal information — because federal law (17 U.S.C. § 512(i)) requires us to reasonably implement a policy for terminating repeat infringers, and we cannot do that if a terminated user can erase the record by deleting and re-registering.

All of the periods above are suspended, and no information is deleted or redacted, while a legal hold, subpoena, preservation request, audit, investigation, or legal claim requires us to keep it.

Launch-Notification Requests (non-users): We retain an email address submitted through a launch-notification request until 90 days after we send the launch notification, or 24 months from the date you submitted it if we have not yet launched in your area, whichever occurs first — after which we delete it. If you unsubscribe or ask us to delete it sooner, we honor that request and keep only the minimum suppression record needed to ensure you stay unsubscribed.

5.2 Deletion Process

When information is deleted:

  • Data is removed from active databases within 30 days and purged from disaster-recovery backups in accordance with our standard automated backup retention cycles
  • We keep aggregated analytics counts — totals that contain no account, device, or session identifier and cannot be traced back to you — after the underlying records are deleted. We do not otherwise keep an anonymized copy of information you asked us to delete.
  • We maintain these aggregated counts only in aggregated form, we do not attempt to re-identify any individual from them, and we require anyone who receives them from us to do the same.
  • Documents you upload. When you delete a document from your Documents Hub, we delete both the document record and the stored file. When you ask us to delete your account, or make a verified request to delete your personal information under Section 12, we delete the documents in your Documents Hub and the underlying files as part of fulfilling that request, within the response times described in Section 12.5. A temporary access link a host already opened may continue to work for up to 15 minutes after you stop sharing or delete a document.
  • When we keep a document you asked us to delete. We will keep a document only where a law, a legal hold, an audit, an investigation, or a legal claim requires us to. If that happens, we will tell you which document we kept and why when we respond to your request, as described in Section 12.1.

6. DATA SECURITY

6.1 Security Measures

Technical Safeguards:

  • Encryption in transit: every connection to the Platform uses HTTPS with TLS, and we require it (HTTP Strict Transport Security)
  • Encryption at rest: information stored in our cloud database and file storage is encrypted at rest using AES-256 keys managed by our cloud provider
  • Payment cards: your card details are handled and tokenized by Stripe under the PCI Data Security Standard, and we never store your full card number
  • Restricted access: access to systems holding personal information is limited by role, and access to the content of your messages additionally requires an open, linked abuse report and is written to an audit log

What this does not mean. The Platform is not end-to-end encrypted. Encryption in transit and at rest protects your information from outsiders and from other users; it does not put your information beyond our own reach. We can access the content of messages in the limited, role-restricted, logged circumstances described above, and we will do so where the law requires it — including our mandatory reporting obligations relating to suspected child sexual exploitation.

Administrative Safeguards:

  • Access to personal information is limited to what a person needs to do their work
  • Personnel and contractors with access to personal information are subject to confidentiality obligations and access controls, and we conduct background screening of such personnel where appropriate and permitted by law
  • We keep a record of administrative access to message content, as described above

Infrastructure:

  • The Platform runs on Google Cloud Platform. The physical security of the facilities where your information is stored — restricted access, environmental controls, and secure disposal of storage media — is provided by that cloud provider under its own security programme, not by us directly.

6.2 Your Security Responsibilities

Account Protection:

  • Use strong, unique passwords
  • Enable two-factor authentication when available
  • Immediately report suspected unauthorized access
  • Keep your contact information current for security notifications

Safe Platform Use:

  • Verify identity of other users before sharing personal information
  • Report suspicious activity or safety concerns
  • Follow platform safety guidelines and best practices

7. YOUR CHOICES AND CONTROLS

7.1 Account Settings

Profile Management:

  • Update personal information and preferences
  • Control visibility of profile information
  • Manage communication preferences
  • Download your data in portable format

Privacy Controls:

  • Opt-out of marketing communications
  • Control sharing of certain information
  • Manage cookie preferences via your browser and, for California residents, at /legal/do-not-sell
  • Request account deletion

7.2 Communication Preferences

Email Communications:

  • Transactional emails: Cannot be disabled (booking confirmations, safety notices)
  • Marketing emails: Can be disabled via unsubscribe or account settings
  • Newsletter and updates: Optional subscription

SMS Communications:

  • Booking notifications: Can be managed in account settings
  • Security alerts: Cannot be disabled for safety reasons
  • Marketing messages: Opt-in required, easy opt-out

7.3 Data Access and Portability

Access Your Data:

  • View all personal information we have about you
  • Download your data in machine-readable format
  • Request copies of specific categories of information

Data Portability:

  • Export your profile information
  • Download transaction history
  • Receive data in commonly used formats (CSV, JSON)

8. COOKIES AND TRACKING TECHNOLOGIES

8.1 Types of Cookies

Essential Cookies:

  • Authentication and security
  • Platform functionality and features
  • Shopping cart and booking persistence
  • Load balancing and performance

First-Party Analytics Cookies:

  • First-party product measurement via Firebase Analytics (Google Analytics 4)
  • Used strictly for internal platform operation under the CCPA/CPRA Business Purpose Exception
  • No cross-context behavioral advertising trackers. On the marketing website only, a consent-gated first-party Google Ads conversion-measurement tag (advertising storage denied by default; measurement only, never ad personalization), with Google acting as our service provider — see Section 11.1

Marketing/Advertising Cookies:

  • In the bartendersNow™ web application: none — no marketing or advertising cookies, advertising pixels, or cross-context behavioral advertising trackers. On our marketing website: a first-party Google Ads conversion-measurement tag, consent-gated with advertising storage denied by default (no advertising cookie or identifier without your affirmative opt-in), used solely for conversion measurement and never for ad personalization or cross-context behavioral advertising, with Google acting as our service provider. See Cookie Policy §2.3 and §11.1.

8.2 Cookie Management

Browser Controls:

  • Most browsers allow you to manage cookie preferences
  • You can block or delete cookies, but this may affect platform functionality
  • Private/incognito browsing modes limit cookie tracking

Platform Controls:

  • California residents may exercise Do Not Sell or Share options at /legal/do-not-sell
  • Browser-level Global Privacy Control (GPC) signals are honored by default
  • Regular review and update of cookie policies

8.3 Third-Party Tracking

In the bartendersNow™ web application we use no third-party advertising pixels or cross-context behavioral advertising trackers. On our marketing website we use a first-party Google Ads conversion-measurement tag, consent-gated with advertising storage denied by default; it measures advertising effectiveness only and is never used for ad personalization, remarketing, or cross-context behavioral advertising, and no advertising cookie or identifier is set without your affirmative opt-in. The platform does not sell personal information or share personal data for cross-context behavioral advertising. First-party product analytics are provided by Firebase Analytics (Google Analytics 4) for internal platform operation, as described in Section 2.2.


9. CHILDREN'S PRIVACY

9.1 Age Restrictions

Platform Access:

  • You must be at least 21 years old to create an account or use the platform, whether as a Host or as a Bartender. This is the eligibility requirement set out in Section 3.1 of our Terms of Service, and it applies to the whole platform, not only to alcohol service.
  • We do not knowingly collect information from anyone under 13, and the platform is not directed to children.

9.2 Parental Rights

If we discover we have collected information from a child under 13:

  • We will delete the information immediately
  • We will terminate the account
  • We will notify parents if contact information is available

Parents can contact us to:

  • Review information collected from their child
  • Request deletion of their child's information
  • Refuse further collection of their child's information

10. INTERNATIONAL DATA TRANSFERS

10.1 Data Location

Primary Storage:

  • United States (Google Cloud Platform)
  • Subject to U.S. privacy laws and regulations
  • Enhanced protection for California residents under CCPA/CPRA

Cross-Border Transfers:

  • May occur for service provision and support
  • Adequate safeguards implemented for international transfers
  • Compliance with applicable international privacy frameworks

10.2 Safeguards

Transfer Mechanisms:

  • Standard contractual clauses
  • Adequacy decisions where applicable
  • Binding corporate rules for service providers

11. THIRD-PARTY SERVICES

11.1 Authorized Sub-Processors

To support delivery of our services, bartendersNow engages third-party service providers ("Sub-processors") that may access or process certain user data:

Sub-processorPurpose / FunctionData Categories ProcessedLocation / Role
Stripe, Inc.Payment processing, host/bartender payouts, identity verification (Stripe Identity).Financial/card data, payout details, Government ID & Biometric Data (Sensitive PI).USA (Service Provider / Independent Controller)
Google Cloud Platform / FirebaseCore cloud hosting, Firestore database, user authentication, push notifications, and automated screening of images you upload for explicit or violent content before they are displayed publicly (Cloud Vision SafeSearch). §Account profile data, booking history, internal identifiers, device tokens, and profile photographs and other images you upload.USA (Service Provider)
Google Maps PlatformAddress autocomplete, geocoding, event location rendering.Search queries, physical event addresses, geolocation data.USA (Service Provider)
Google Analytics 4 / Firebase AnalyticsProduct analytics, user-interaction tracking, and service-area coverage measurement.Usage telemetry, device details, clickstream data, coarse location (state, city, 3-digit ZIP prefix), first-party analytics identifiers, account identifiers and role, internal event and booking identifiers, anonymized IP.USA (Service Provider)
Google Ads (Google LLC)Advertising conversion measurement on the marketing website (measuring whether an ad interaction led to a contact-form lead); measurement only, not ad personalization or remarketing.Truncated IP address, page/interaction data, conversion events; a first-party conversion identifier only after affirmative opt-in.USA (Service Provider — Restricted Data Processing)
Twilio Inc.Operational SMS alerts about your bookings, where SMS alerts are enabled.Mobile phone numbers, SMS delivery logs.USA (Service Provider)
Twilio SendGridTransactional email delivery, account notifications, and delivery of the one-time codes used to verify your email address.Email addresses, one-time verification codes, email interaction logs, message content.USA (Service Provider)
Vercel Inc.Marketing website hosting and web form handling.Visitor IP address, web request headers, contact form entries.USA (Service Provider)
Cloudflare, Inc. (Turnstile)Bot protection and automated abuse prevention on web forms.Visitor IP address, browser telemetry, interaction metrics.USA (Service Provider)

† Implemented for bot protection upon feature activation.

‡ Active on the marketing website only, governed by Google Consent Mode v2 with advertising storage denied by default. Advertising storage is enabled only after you accept the "Marketing & Advertising" category; ad personalization and ad-user-data remain denied in all states, and Google processes the data as our service provider under Restricted Data Processing. Not used in the bartendersNow™ web application.

§ Automated image screening classifies an image for explicit or violent content only. It does not identify anyone, does not analyze facial geometry, and does not create or store any biometric template. Under the provider's published terms, images sent for this screening are not used to train the provider's models and are deleted after processing; we retain only the screening outcome. A photo the automated screen flags is reviewed by a person before any decision is made.

11.2 Third-Party Responsibilities

We are not responsible for:

  • Privacy practices of third-party services
  • Data collection by external websites or applications
  • User interactions outside our platform

We encourage you to review privacy policies of all services you use.


12. CALIFORNIA PRIVACY RIGHTS (CCPA/CPRA)

12.1 California Consumer Rights

We Do Not Sell or Share Your Personal Information: We do not sell your personal information. We use a first-party Google Ads conversion-measurement tag on our marketing website solely to measure advertising effectiveness; we do not use it for ad personalization or remarketing, and Google processes this measurement data on our behalf as a service provider under Restricted Data Processing, not for its own cross-context behavioral advertising. On that basis we do not "share" personal information for cross-context behavioral advertising as defined by the CPRA, and we have not sold or shared personal information in the preceding twelve (12) months. Because we do not sell or share personal information, we do not offer a "Do Not Sell or Share My Personal Information" opt-out mechanism, and none is required. You can still decline this tag at any time by rejecting the "Marketing & Advertising" category in our cookie banner or through the "Manage cookies" control, and we honor Global Privacy Control (GPC) signals by default. This statement is provided in accordance with the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and its implementing regulations.

Right to Know:

  • Categories of personal information collected
  • Sources of personal information
  • Business purposes for collection and sharing
  • Categories of third parties who receive information

Right to Delete:

  • Request deletion of personal information we have collected
  • Exceptions for legal requirements and business operations, as permitted by California Civil Code Section 1798.105(d). In particular, we will retain records of legal acknowledgments, attestations, and certifications you accepted, together with transaction and tax records, where retention is necessary to comply with a legal obligation or to establish, exercise, or defend legal claims. We will tell you which categories we have retained and why when we respond to your request.
  • Confirmation of deletion upon completion

Right to Opt-Out:

  • We do not sell your personal information, so there is no sale for you to opt out of.
  • We do not share your personal information for cross-context behavioral advertising — our Google Ads conversion tag is measurement-only and Google processes that data as our service provider — so there is no sharing for you to opt out of.
  • We do not use automated decision-making technology to make decisions that produce legal or similarly significant effects concerning you. We do use automated tools to screen images you upload for explicit or violent content; a photo the automated screen flags is reviewed by a person before any decision is made, and no automated tool decides whether you may use the platform, appear in search, be booked, or how much you are paid. If we ever use automated decision-making for a decision of that kind, we will give you notice and a way to opt out before we do.

Right to Correct:

  • Request correction of inaccurate personal information
  • Update your information through account settings
  • Contact us for assistance with corrections

Right to Limit:

  • Limit use and disclosure of sensitive personal information
  • Control sharing of sensitive categories of data
  • Manage permissions for specific data uses

Right to Non-Discrimination:

  • We will not discriminate against you for exercising your rights
  • Same service quality regardless of privacy choices
  • No denial of services for exercising rights

Limitation on Sensitive Personal Information: We collect Sensitive Personal Information (including government-issued ID and precise geolocation) solely for necessary platform operational purposes, identity verification via Stripe, and service fulfillment. We do not use or disclose Sensitive Personal Information for purposes that require a "Right to Limit" opt-out under California law.

12.2 Categories of Personal Information (CCPA)

Identifiers:

  • Name, email, phone number, IP address
  • Date of birth
  • Residential or mailing address and ZIP code
  • Government-issued ID for verification
  • Device identifiers and account numbers
  • For non-account holders who submit a launch-notification request, the only personal information we collect is an email address and the general area (such as a city) you asked us to notify you about.

Commercial Information:

  • Transaction history and payment records
  • Service preferences and booking history
  • Reviews and feedback provided

Biometric Information:

  • Identity verification is conducted by our third-party service provider (Stripe, Inc.), which may collect and process biometric verification data pursuant to Stripe's Privacy Policy. Midnight Logic, Inc. does not receive, store, or have access to raw biometric templates.

Internet/Network Activity:

  • Platform usage and navigation data
  • Search queries and interaction patterns
  • Device and browser information

Geolocation Data:

  • Current location for service matching
  • Service area preferences
  • Travel and availability patterns

Professional Information:

  • Bartending licenses and certifications
  • Professional experience and references
  • Business information and credentials

Sensitive Personal Information:

  • Government-issued ID for verification
  • Biometric identity-verification data processed by Stripe Identity (see below)
  • Financial account information for payments
  • Precise geolocation when using mobile features
  • Information contained in background-check or fingerprinting-clearance records you choose to upload

Identity Verification and Biometric Sensitive Personal Information (Stripe Identity). For bartender onboarding and fraud prevention, our third-party provider Stripe, Inc. ("Stripe Identity") collects and processes government-issued identification and facial/biometric verification data. Under the California Privacy Rights Act (Cal. Civ. Code § 1798.140(ae)), this constitutes Sensitive Personal Information. We use and permit the processing of this information solely for identity verification, fraud prevention, and compliance with applicable legal and regulatory obligations. Stripe processes this data as an independent service provider and controller under its own privacy policy; Midnight Logic, Inc. does not receive, store, or have access to raw biometric templates, and we do not use, sell, share, or otherwise disclose this Sensitive Personal Information for any commercial purpose or for cross-context behavioral advertising. As described in Section 12.1, we do not use this information for purposes that would trigger a "Right to Limit" opt-out under California law.

Background-check and fingerprinting-clearance records (Documents Hub). If you upload a background-check or fingerprinting-clearance record to your Documents Hub, any government identification number, biometric identifier, or health information that record contains is Sensitive Personal Information under the California Privacy Rights Act (Cal. Civ. Code § 1798.140(ae)). We store the record solely to keep it available to you and to enable the sharing you direct, as part of the service you requested. We do not use it to identify you, we do not use or disclose it for any commercial purpose or for cross-context behavioral advertising, and, consistent with Section 12.1, we do not use it for purposes that would trigger a "Right to Limit" opt-out under California law. Sharing a document with a host you have chosen is a disclosure you direct and that is necessary to provide the sharing service you requested.

12.3 Business Purposes for Collection

Service Provision:

  • Facilitate marketplace connections
  • Process bookings and payments
  • Provide customer support and communication
  • Respond to launch-notification requests from non-account holders by sending the availability notification they asked for
  • Store documents you upload to your Documents Hub and deliver them to hosts you choose to share them with

Security and Fraud Prevention:

  • Verify user identities and credentials
  • Monitor for suspicious activity
  • Protect platform integrity and safety
  • Screen uploaded images for explicit or violent content before they are displayed publicly

Internal Operations:

  • Improve platform features and algorithms
  • Conduct analytics and research
  • Maintain and optimize platform performance
  • First-party operational analytics via Firebase Analytics (Google Analytics 4) for session tracking, booking funnels, and sign-ins, under the CCPA/CPRA Business Purpose Exception (Cal. Civ. Code § 1798.140(e))

Legal Compliance:

  • Comply with applicable laws and regulations
  • Respond to legal requests and investigations
  • Protect rights and interests of all parties

12.4 Sources of Personal Information

Direct from You:

  • Account registration and profile creation
  • Booking requests and service coordination
  • Communications and feedback
  • Launch-notification requests submitted by people who do not have an account
  • Documents you upload to your Documents Hub

From Your Platform Use:

  • Device and browser information
  • Usage patterns and preferences
  • Location and interaction data

From Third Parties:

  • Identity verification services (Stripe)
  • Payment processing partners
  • Government-ID identity verification via Stripe Identity (we do not use background check providers)

12.5 How to Exercise Your California Privacy Rights

Submitting Requests: To exercise your Right to Know, Delete, Correct, or Opt-Out, please submit a verifiable consumer request to us via:

  • Email: privacy@bartendersnow.com (Subject: "CCPA Privacy Request")
  • In-App Settings: Registered users may also manage account data and download profile information directly within their account settings.

Verification Process: To protect your privacy, we must verify your identity before we act on your request. How we verify depends on whether you have an account with us.

  • If you have an account: We verify your request by matching the email address and profile details you provide against the information in your account.
  • If you do not have an account (for example, because you sent us a copyright, trademark, or abuse report): We verify your request by matching at least three data points you provide against the information in the report you sent us. For a request to access specific pieces of personal information, we will also ask you to provide a signed declaration, under penalty of perjury, that you are the person you claim to be. We apply this heightened standard because the personal information in a report could be sought by someone trying to identify the person who filed it.

We will never ask you to send us a government-issued identification document or a photograph of one to verify a privacy request.

Response Timeline: We will acknowledge receipt of your request within 10 business days and provide a substantive response within 45 calendar days of receipt. When reasonably necessary — for example, because of the complexity or volume of your request — we may extend that period by up to an additional 45 calendar days, for a total of up to 90 calendar days. If we need the additional time, we will notify you of the extension, and the reason for it, within the first 45-day period.

12.6 Authorized Agents

You may designate an authorized agent to exercise your rights on your behalf:

  • Provide written authorization for the agent
  • Verify your identity and the agent's authority
  • Agent must follow our verification procedures

13. NEVADA PRIVACY RIGHTS

Nevada residents have the right to opt-out of the sale of their personal information. We do not currently sell personal information as defined by Nevada law. If our practices change, we will update this policy and provide opt-out mechanisms as required.


14. UPDATES TO THIS POLICY

14.1 Policy Changes

We may update this Privacy Policy to reflect:

  • Changes in our information practices
  • New features or services
  • Legal or regulatory requirements
  • Industry best practices and standards

14.2 Notice of Changes

Material Changes:

  • Email notification to registered users
  • Prominent notice on our platform
  • 30 days' notice before changes take effect

Minor Changes:

  • Updated policy posted on platform
  • "Last Updated" date revised
  • Continued use constitutes acceptance

14.3 Review and Consent

We encourage you to review this policy periodically. Your continued use of our platform after policy updates constitutes acceptance of the changes.


15. CONTACT INFORMATION

15.1 Privacy Questions

For questions about this Privacy Policy or our privacy practices:

Email: privacy@bartendersnow.com
Subject: Privacy Policy Inquiry
Response Time: Within 5 business days

15.2 Privacy Rights Requests

To exercise your California privacy rights:

Email: privacy@bartendersnow.com
Subject: CCPA Rights Request
Include: Full name, account email, specific request details

15.3 Privacy Team

Email: privacy@bartendersnow.com
Role: Privacy compliance and data protection oversight
Availability: Monday-Friday, 9 AM - 5 PM PST

15.4 Company Information

Midnight Logic, Inc.
650 Nuttman St, Ste 114
Santa Clara, CA 95054
Email: legal@bartendersnow.com
Phone: (888) 548-9469


16. EFFECTIVE DATE AND ACKNOWLEDGMENT

This Privacy Policy is effective as of July 20, 2026 and applies to all information collected from that date forward.

By using the bartendersNow™ platform, you acknowledge that you have read, understood, and agree to this Privacy Policy and the collection, use, and disclosure of your personal information as described herein.


This Privacy Policy was last updated on September 7, 2026 and reflects current California and federal privacy laws. We are committed to maintaining the privacy and security of your personal information and will continue to update our practices as laws and technologies evolve.