Last updated: August 24, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between BevSync, LLC(“Processor”) and the Organization subscribing to the BevSync platform (“Controller”). It governs processing of personal data by BevSync on behalf of the Controller. It supplements our Terms of Service and Privacy Policy. On data-processing matters, this DPA controls.
1. Roles
- Controller — the Organization that determines the purposes and means of processing.
- Processor— BevSync, which processes personal data on the Controller's instructions.
- Sub-processor — a third party BevSync engages to process personal data.
2. Processing purposes
BevSync processes personal data only to provide the Service:
- Authenticating and managing user accounts
- Inventory, analytics, reporting, and POS sync
- Transactional and notification email
- Audit logs and customer support
Customer PII from POS transactions is stripped before storage. BevSync does not store end-consumer personal data.
3. Categories of personal data
- Account identity: email, name, optional phone (Users)
- Authentication: hashed passwords (Supabase Auth), session tokens
- Organization info: business name, billing email, phone, website
- Business contacts: distributor and brand names, emails, phones
- Team invitations: invitee email and role
- Audit and security: IP on unauthorized-access attempts, last login, audit trail
4. Sub-processors
Required: Supabase (auth, database, storage, US), Resend (transactional email, US), Netlify (hosting and functions, US).
Optional, only if the Controller connects them: Google Places (address autocomplete), Square, Toast, Clover, Omnivore (POS read-only sales and menu data).
Google Calendar Appointment Scheduling on Book A Demo is used by BevSync to schedule product demos with website visitors. That processing is described in our Privacy Policy. It is not processing of Controller (customer) personal data under this DPA.
BevSync will notify the Controller at least 30 days before adding a new sub-processor that processes personal data. The Controller may object; if unresolved, the Controller may terminate.
5. Security measures
- HTTPS in transit; encryption at rest
- AES-256-GCM for stored POS credentials
- Optional TOTP multi-factor authentication
- Tenant isolation and row-level security
- Role-based access and audit logging
- Automatic PII stripping from POS sales data
See also our Security page.
6. Assistance, deletion, and audits
BevSync will assist the Controller with data-subject requests, security incidents, and reasonable audits. After the 30-day cancellation grace period, Controller data is deleted as described in the Terms and Privacy Policy. The Controller may export data while the account is active.
7. Contact
BevSync, LLC14811 N Kierland Blvd #4008
Scottsdale, AZ 85254
Email: support@bevsync.net
Mailing address: 14811 N Kierland Blvd #4008, Scottsdale, AZ 85254. For an executed copy of this DPA, email support@bevsync.net.