Legal

Privacy Policy

Last updated: August 10, 2026

This policy covers pourpar.com and the PourPar app, run by Pour Thoughts L.L.C., a District of Columbia limited liability company. It says what we collect, why we hold it, who else touches it, and how long it stays. There are no dark corners in here and no clever exceptions at the bottom.

1

The short version

  • We collect an email address so you can sign in, a billing record so we can charge the subscription, and whatever you choose to put in your book.
  • Your book is stored so we can compute your numbers for you. We do not mine it.
  • We count anonymous page visits and a handful of product milestones, so we can see where setup loses people. Those counts are tallied on our own servers and by Vercel, the company that already hosts this site. Neither sets a cookie, and neither carries anything out of your book.
  • We never sell or share your data, never run advertising trackers, and never train AI models on your book.
  • You can export everything anytime, and you can ask us to delete it.
2

What we collect

Account. Your email address, and if you sign in with Google, the basic profile Google hands back (name, email, profile image). Passwords, where you use one, are handled by Clerk and never reach us in readable form.

Your book. Everything you enter or import: recipes, ingredients, pack sizes and prices, inventory counts, sales figures, prep and par settings, distributors and rep contacts, orders, schedules, and staff records including the names, emails, phone numbers, and hourly wages you choose to enter.

Billing. Stripe holds the card. What reaches us is a customer id, a subscription id, its status, the email on the subscription, and a referral code if one came along with the checkout. We never see or store full card numbers.

Operational logs. Our hosting provider records ordinary request logs (IP address, timestamp, path, browser user agent) as part of running the site. We use them to keep the service up and to stop abuse, and for nothing else.

Product analytics. We count how the site and the app get used, in our own database, using no outside analytics company at all. That is one count per page you open, plus six named moments: the demo being opened, guided setup starting, a step of setup being reached, a first recipe saved, a trial started, and a subscription paid. Each count carries the name of the moment, the route it happened on, a random number identifying the browser tab, and the campaign or partner tag from the link you arrived through if there was one. It carries nothing out of your book: no recipe or ingredient names, no prices, costs or wages, no venue name, no email address, and nothing you typed into any field. That is enforced by a list of permitted fields in the code rather than left to care — anything not on the list is never read, so it cannot be sent even by accident. It is enforced a second time by the table those counts are stored in, which has no column for a name, an address, an account or a figure.

Those counts record no location, no IP address, no browser or device details, and nothing tying one of them to your account. Alongside them, Vercel — the company that already hosts this site and carries every request to it — tallies anonymous, cookieless page counts for us (Vercel Web Analytics). Those counts identify pages, not people: no cross-site profile, no advertising use, and nothing from your book. We do not run advertising trackers, we do not follow you to any other website, and we do not buy information about you from anybody.

3

Why we hold each thing

Identity so you can sign in. The book so the app can compute your costs, pars, and orders. Billing data so we can charge the subscription and answer a billing question. Logs so the service stays up and secure. That is the whole list. If we ever want to use something for a new purpose, this page changes first and we tell you.

4

Staff information: you are the controller

When you enter your employees’ names, contact details, and wages, that data is yours and it is about your people. You decide what to collect and why. We hold and process it only to give you the features you use, on your instructions. In data protection language, you are the controller and we are the processor. In practice: tell your staff what you keep, keep it accurate, and take people off when they leave. We will delete individual records on your instruction, and all of it when you ask us to delete the book.

5

Where the data lives

Everything runs in the United States. We use a short list of vendors, called subprocessors, and nobody else:

  • Vercel
    Hosting and delivery of the site and its API.
  • Neon
    The Postgres database where your book is stored, keyed to your account.
  • Clerk
    Accounts, sign-in, and sessions.
  • Stripe
    Payments, subscriptions, and the billing portal.
  • Anthropic
    AI parsing of sheet text, only at the moment you ask for it.
  • CloudMailin
    Receiving mail sent to a private inbound address, where that feature is turned on.

Each of them is bound by its own contract to handle data on our instructions and not for their own purposes. If we add one, this list changes before the vendor starts handling anything.

6

AI parsing, in detail

Dropping a sheet and choosing to have it read sends the text of that sheet to Anthropic’s API, at that moment, so a model can extract the rows. What comes back is a preview. You approve it before anything saves, and if you discard it nothing was written. We do not send your book to a model for any other purpose, there is no background processing, and Anthropic does not use API data to train its models. If you would rather nothing leave the app at all, the plain CSV import reaches the same place without a model.

7

Inbound email, where it is turned on

An account can be issued a private address for forwarding sheets. Mail sent there is received by CloudMailin and stored as a pending item holding the sender address, the subject, the file name, and the extracted sheet text. Pending items are deleted 30 days after they arrive, whether or not you used them, and you can delete one immediately. Applying an item is always a deliberate action on your part; nothing writes itself into your book.

8

What sits on your device

The app keeps a working copy of your book in your browser’s local storage so it stays fast and survives a bad connection. That copy lives on your device, and clearing your browser data clears it. The demo bar runs entirely on your device and stores nothing on our servers.

Two much smaller things sit beside it. If you arrived through a partner or campaign link, that tag is kept in local storage so the credit still lands if you subscribe next week. And a random number identifying the current browser tab is kept in session storage, which the browser erases when you close the tab. Neither is a cookie, neither is sent to anyone but us, and neither says anything about who you are.

9

Cookies

Essential only. Clerk sets the session cookie that keeps you signed in, along with the cookies it needs to protect that session. There are no advertising cookies and no cross-site trackers anywhere on the site, and nothing here follows you to another website. The usage counting in section 2 is cookieless: our own counts go to our own servers, and the page counts Vercel tallies as our host set no cookie either and build no profile of you. That is why this site has never asked you to accept anything. Separately, if you arrive through a partner or campaign link, we keep that code in your browser’s local storage so the credit lands if you subscribe later.

10

How long we keep things

  • Your book: for as long as the account is open. After cancellation we keep it 90 days so a returning customer finds their work waiting, then it is deleted on our schedule. Ask and we delete it sooner, normally within 30 days.
  • Pending email items: 30 days from arrival, then deleted automatically.
  • Account and billing records: while the account is open, plus the period tax and accounting rules require us to keep invoices and payment records.
  • Operational logs: short lived, on our hosting provider rolling schedule.
  • Usage counts: one year in our own database, then deleted automatically. They are tallies of events, not records about a person, and deleting your account does not need to touch them because none of them names you.
11

What we never do

We do not sell your data. We do not share it with advertisers or data brokers. We do not use your book to train AI models, ours or anyone else’s. We do not use an outside analytics company, so no part of your book, and no record of your visit, is sent to one. We do not let our vendors use it for their own purposes. The only ways your data leaves the set of vendors listed above are: you export it, you ask us to send it somewhere, or a valid legal order requires it, and in that last case we will tell you unless the law forbids us from telling you.

12

Security

Data is encrypted in transit, and our database and hosting providers encrypt it at rest. Access to production data is limited to the people who need it to run the service, which today is a very short list. Card numbers never touch our systems at all. No system is perfect: if a breach ever affects your data we will tell you promptly and plainly, with what we know and what you should do about it.

13

Your choices

  • Export the whole book to a file from Settings, anytime.
  • Correct anything by editing it in the app.
  • Delete your account and its data by writing to us from the account email. We confirm when it is done.
  • Ask for a copy of the account data we hold, or ask a question about any of this, at the same address. We answer within 30 days.

Depending on where you live you may have further rights over your personal data. We apply the choices above to everyone rather than sorting people by where they live.

14

Children

PourPar is a business tool and it is not for anyone under 18. We do not knowingly collect data from children. If a venue enters staff records for a minor employee, that record is the venue’s to justify and manage under section 4.

15

Where we operate

The United States only, for now. If that changes, this page changes before we open anywhere else.

16

Changes to this policy

We will post the new version on this page with a new date at the top, and email account holders about anything material at least 30 days before it takes effect.

17

How to reach us

Privacy questions, data requests, and deletion requests all go to support@pourpar.com, and a person answers them.

Pour Thoughts L.L.C.

support@pourpar.com

1220 Potomac Avenue SE #5, Washington, DC 20003, United States