Privacy Policy
Welcome to BrewStack ("we," "our," or "us"). We are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website (https://brewstack.in/), use our Point of Sale (POS) applications, Enterprise Resource Planning (ERP) systems, ZATCA-compliant e-invoicing integrations, and any related IT services (collectively, the "Services").
Please read this Privacy Policy carefully. By accessing or using our Services, you acknowledge that you have read, understood, and agree to the terms outlined herein. If you do not agree with the terms of this privacy policy, please do not access the site or utilize our services.
1. Regulatory Compliance
As an IT provider offering solutions tailored for businesses in the Kingdom of Saudi Arabia (KSA), BrewStack strictly adheres to local and international privacy regulations, including but not limited to:
The Saudi Arabian Personal Data Protection Law (PDPL) issued under Royal Decree No. (M/147).
ZATCA (Zakat, Tax and Customs Authority) regulations regarding data integrity and security for Phase 1 and Phase 2 electronic invoicing.
General Data Protection Regulation (GDPR) guidelines where applicable to international interactions.
2. Information We Collect
We collect information that identifies, relates to, describes, or could reasonably be linked, directly or indirectly, with a specific consumer, business, or device.
A. Personal and Business Data You Provide to Us
Contact Information: Name, corporate email address, phone number (+966 numbers or international equivalents), job title, and company name.
Account Credentials: Usernames, passwords, and security tokens used to access our ERP, POS, and dashboard environments.
Financial & Billing Information: Corporate bank details, billing addresses, and tax/CR (Commercial Registration) numbers required for contractual agreements and service provisioning.
Customer Support Data: Information you provide when submitting tickets, asking questions, or requesting a free consultation via our website or email (info@brewstack.in).
B. Technical and Usage Data (Collected Automatically)
When you interact with our website or applications, we may automatically log:
Device Metadata: IP address, browser type, operating system version, device type, and unique device identifiers.
Log and Usage Data: Access times, pages viewed, features used within our software platforms, crash logs, and website navigation paths.
Cookies and Tracking Technologies: Small files stored on your device to remember configurations, maintain secure sessions, and analyze web traffic patterns.
C. Merchant Client Data (Data Processor Capacity)
When business entities (restaurants, cafes, food service providers) utilize BrewStack’s POS and ERP systems, they input data belonging to their own end consumers and employees (e.g., customer phone numbers for loyalty programs, transaction details, employee shift times).
Important Note: In this context, BrewStack acts strictly as a Data Processor, and our merchant client acts as the Data Controller. We process this information solely on behalf of, and under the explicit instructions of, the merchant client in accordance with our system agreements and applicable laws.
3. How We Use Your Information
BrewStack processes personal and business data for legitimate business interests, including:
Providing and Maintaining Services: Activating your cloud ERP environment, syncing live inventory across your branches, and operating kitchen displays.
Ensuring Compliance: Generating ZATCA-compliant electronic invoices, embedding cryptographic stamps, and utilizing required QR code metadata.
Customer Support & Communication: Responding to inquiries, troubleshooting technical system errors, and sending system updates or structural advisories.
Security & Fraud Prevention: Monitoring system health, protecting our architecture against cyber threats, verifying user identities, and preventing unauthorized software access.
Improving Our Products: Analyzing usage metrics anonymously to refine user interfaces, build more efficient database structures, and develop new modules.
4. Disclosure and Sharing of Information
We do not sell, rent, or trade your personal data to third parties. We may share your information only under the following limited conditions:
To Third-Party Service Providers: We partner with trusted cloud hosting facilities (such as regional servers complying with KSA data residency requirements), database managers, and payment gateways who assist us in operating our infrastructure. These parties are contractually bound to safeguard your data.
For Legal and Regulatory Obligations: We will disclose data to government bodies, judicial authorities, or ZATCA if required by statutory laws, audits, or structural Phase 2 clearance compliance framework requirements.
Business Transfers: If BrewStack undergoes a merger, acquisition, restructuring, or asset sale, your data may be transferred to the successor entity under the same privacy safeguards.
5. Data Residency and Global Storage
In strict alignment with the Saudi Arabian PDPL requirements for critical infrastructure and financial processing:
All corporate, transactional, and electronic invoicing data processed through our local KSA systems is securely hosted and stored within data servers physically located inside the Kingdom of Saudi Arabia, unless explicit regulatory exemptions apply.
Data transmission outside the Kingdom is restricted and heavily scrutinized, occurring only through highly encrypted transit protocols under legally accepted cross-border data transfer mechanisms.
6. Data Security
We implement robust administrative, technical, and physical security measures designed to protect your personal and business data.
Encryption: Data is encrypted both in transit (using SSL/TLS frameworks) and at rest within our server environments.
Access Control: Access to your data is strictly confined to authorized BrewStack personnel who require it to perform their core technical or administrative duties.
Vulnerability Assessments: We continuously monitor our systems for potential software bugs, security vulnerabilities, or unauthorized access attempts.
While we take rigorous steps to secure your information, no transmission over the internet or cloud architecture can be guaranteed 100% secure. Therefore, we encourage users to maintain secure login credentials and notify us immediately if any unauthorized account activity is suspected.
7. Data Retention
We retain your personal data only as long as your business contract remains active or as required to fulfill the objectives specified in this policy.
Accounting and Tax Records: In compliance with Saudi Arabian tax regulations and ZATCA statutory laws, electronic invoices and related metadata are securely retained for a minimum mandatory period of six (6) years (or as mandated by local laws).
Account Logs: Operational logs and basic contact information are purged or anonymized when they are no longer necessary for customer service or system diagnostics.
8. Your Privacy Rights
Under the Saudi PDPL and global privacy standards, you hold specific structural rights regarding your personal data. These include:
Right to Information/Awareness: The right to know why your data is collected, how it is handled, and who it is shared with (as outlined in this policy).
Right of Access: The right to request copies of the personal data we hold about you.
Right to Correction/Rectification: The right to demand the modification or update of inaccurate, out-of-date, or incomplete data.
Right to Destruction/Erasure: The right to request the deletion of your personal data when it is no longer required for the purposes it was collected, subject to prevailing regulatory retention periods (such as ZATCA tax rules).
Right to Withdraw Consent: Where data processing relies entirely on your explicit consent, you have the right to withdraw that consent at any moment.
To exercise any of these rights, please contact our data compliance team at info@brewstack.in.
9. Changes to This Privacy Policy
BrewStack reserves the right to update or modify this Privacy Policy at any time to reflect changing technological requirements, operational updates, or revisions in local laws. When updates are published, the "Last Updated" date at the top of this page will change. We recommend checking this page periodically to remain informed about how we protect your data.
10. Contact Us
If you have any questions, complaints, or feedback regarding this Privacy Policy or our data management operations, please reach out to us at:
Company Name: BrewStack Technologies
Website: https://brewstack.in
Email Address: info@brewstack.in
Contact Number: +966 532602174