Skip to content

Privacy

Your data, and what we do with it

Uze helps a venue recognise its regulars and make their usual in a tap. That only works if a small amount of information about a person is held with care. This policy explains what we collect, why we hold it, who can see it, and the choices you have at any time.

Effective 30 July 2026

01Who we are

Uze is a product of de:volt Pty Ltd, an Australian company based in Melbourne, Victoria, Australia. When this policy says “we” or “Uze”, it means de:volt Pty Ltd.

For anything about your personal information, write to privacy@getuze.com. We answer privacy requests within a reasonable time, and always within the limits the law sets.

02The two roles data plays here

A venue runs Uze on top of its own point of sale. For a venue’s members — its regulars — the venue decides what it keeps and why, and Uze holds that information on the venue’s behalf. In privacy terms the venue is the controller and Uze is its processor.

For the account a venue holds with us, and for billing, Uze is the controller. Both roles are covered below so you can see the whole picture in one place.

03What we collect

We keep the information a counter needs to know someone, and little else:

  • Who you are. your name, and a pronoun or greeting if you share one.
  • How to reach you. an email or phone number, when you choose to add one.
  • Your usual. the orders you save, and notes a venue keeps so your visit runs smoothly.
  • Your visits. when you tap in, at which venue, and what you spent — the history that makes recognition work.
  • Allergies and dietary needs. only if you choose to record them. This is health information, and we treat it as sensitive — see section 5.
  • Technical basics. a session so you stay signed in, and the standard request logs any web service keeps to stay secure and reliable.
  • Whether you opened a venue’s email. emails a venue sends you carry a small tracking image, so they can see how many people opened one. It applies only to emails from a venue, never to your receipts, card notices, or sign-in links. Turn off that venue’s emails and it stops with them.

04Why we hold it, and our lawful basis

We only use your information for the reasons it was given. Under the Australian Privacy Principles and, where it applies, the GDPR, each use rests on a clear basis:

  • Recognition. to show a venue who has arrived and their usual — with your consent when you join, and to deliver the service you asked for.
  • Running the venue. to help staff serve you and understand their regulars — the venue’s legitimate interest in serving its customers well.
  • Allergies. to keep you safe — only with your explicit consent.
  • Messages from a venue. with your consent, given one of two ways: you turn on emails for that venue in your preferences, or you tell them at the counter and they record it. Either way it is per venue, and every email they send carries a link that stops it in one click.
  • Billing and security. to run our own business and keep the service safe — our legitimate interest and legal obligations.

05Allergies and other sensitive information

Allergy and dietary information is health information. We collect it only when you enter it yourself, and only after you agree to us storing it and showing it to the venues you choose. It is off by default: nothing about your health is shared with a venue unless both you and that venue turn it on.

You can remove it at any time from your preferences, and ask a venue to clear what it holds.

06Who can see your information

Your details are visible to the venues you have tapped in at, to the extent you have chosen to share. We do not sell personal information, and we do not share it for anyone else’s advertising.

A few trusted providers help us run the service, and only handle data to do so on our instructions:

  • Supabase. Database, authentication and realtime hostingSydney, Australia (ap-southeast-2).
  • Amazon Web Services (SES). Sending email on a venue's behalf and oursSydney, Australia (ap-southeast-2).
  • Square. Point-of-sale, catalogue and order processingUnited States.
  • Stripe. Billing and payment for what venues pay UzeUnited States.
  • Vercel. Application hosting and deliveryUnited States / global edge.

07Where your data lives

Member information is stored in Australia, in Supabase’s Sydney region. Some of the providers above operate in the United States, so running the service can involve sending data overseas. When we do, we take reasonable steps to keep it protected to Australian standards, and for anyone in the EU or UK we rely on Standard Contractual Clauses for the transfer.

08How long we keep it

We keep information for as long as it serves the reason it was collected. Visit history is kept while your profile is, and removed with it. If you close your Uze account, or a venue removes you, your personal information is deleted, keeping only what the law requires us to retain (for example, records tied to billing, with your identity removed). Short-lived operational data leaves on a schedule a venue can see in its settings.

09Your choices and rights

You are in control of your information. At any time you can ask to:

  • See it. get a copy of what a venue, or Uze, holds about you.
  • Correct it. fix anything that is wrong or out of date.
  • Take it with you. receive it in a portable, machine-readable form.
  • Delete it. have your profile or your whole Uze account removed.
  • Change your mind. withdraw a consent, or stop messages, without affecting what came before.

Copies and removal run from your preferences: download your data or have a copy prepared, remove yourself from one place, or remove your whole account. A removal waits seven days so you can change your mind, every request carries a deadline we track, and you can also fix your name and pronouns there. For corrections beyond that, or anything else, email privacy@getuze.com and we will action it against the same tracked process.

10Cookies and tracking

We keep this simple. Uze sets one essential cookie so you stay signed in. We run no third-party analytics and no advertising trackers. If that ever changes, we will ask for your consent before anything non-essential loads, and update this policy first.

11Keeping it safe

Access to member data is walled by venue, secrets are encrypted, and every change to a record is logged. No system is perfect: if a breach ever put your information at real risk, we would act quickly to contain it and notify you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires. You can reach our security team at security@getuze.com.

12Changes, and how to complain

When we make a material change we will update the effective date above and, where it matters, ask you to agree again. If you are ever unhappy with how your information has been handled, tell us first at privacy@getuze.com. You can also complain to the Office of the Australian Information Commissioner at oaic.gov.au, or, in the EU or UK, to your local data-protection authority.