Patron
Sign in

Privacy Policy

Last updated: 26 August 2026

1. Who is responsible for what

Patron is a tool businesses use to record their own guest relationships. For the account data of the business and its team, we act as controller. For the guest records, ratings, notes and evidence files a business uploads, that business is the controller and we act as its processor, handling the data only to run the Service.

2. Data we collect

  • Account data: email address, password hash, business name, and the establishments you create.
  • Guest data your team enters: name, company, email, phone, tags, star ratings, free-text notes, items ordered and comped, and any evidence files attached to a rating.
  • Derived data: average ratings, comp percentages and the risk score calculated from the entries above.
  • Technical data: push notification device tokens, delivery logs, network activity audit entries, and basic security/diagnostic logs.

3. How we use it

To provide the roster, ratings, comp and risk features; to deliver notifications you opt into; to share guest history with partner establishments you explicitly connect with; to keep audit trails for accountability; and to secure, support and improve the Service. We do not sell personal data and do not use guest records for advertising.

4. Storage and security

Data is stored in our managed cloud database with row-level security so each business can only reach its own records. Evidence files live in a private storage bucket and are served only through short-lived signed links. Access by our staff is limited to what is needed to operate and support the Service.

5. Sharing across the partner network

When a business accepts a partnership with another establishment, guest history matched by email or phone becomes visible to that partner — including ratings, comp percentages and, where opened, linked evidence. Nothing is shared until a partnership is accepted, every sharing event is written to the network activity log, and either side can end the partnership at any time, which stops future sharing.

6. Other recipients

We use service providers to host the database, storage and application, and to deliver push notifications. They process data on our instructions only. We may disclose data where the law requires it, or to protect the rights and safety of users.

7. Retention

Guest records are kept for as long as the business keeps them in its account. Deleting a record removes it from the live Service and it ages out of backups on our normal cycle. Delivery and audit logs are kept for a limited period for troubleshooting and accountability. Closing an account removes its data after a short export window.

8. Rights of guests and users

Individuals may have rights to access, correct, delete, restrict or object to processing of their data, and to data portability. Because guest records belong to the business that entered them, requests about a guest should be directed to that business; we will support them in responding. Team members can contact their account owner about their own account data.

9. Cookies

We use a small number of cookies and similar storage. See the Cookie Policy for the full list and your choices.

10. Contact

Privacy questions can be sent to the account owner's registered contact address for your workspace, who can escalate to us on your behalf.