Legal

Privacy Policy

Last updated: August 18, 2026

This Privacy Policy explains how DSCVR (“we,” “us”) handles information when you use dscvr.beer — including discovery, credits, venue POS, brewery tools, and future shop and gacha / vending features.

It works with our Terms of Service. We do not sell your personal information.

01Who this covers

It covers visitors, wallet users, reviewers, gift senders/claimers, POS customers, and brewery / bar / ambassador partners. It does not control partner taprooms, wallet apps, Solana, or USDC issuers — those have their own policies.

Controller contact: partnerships@dscvr.beer.

02What we collect

You give us. Age-gate and Terms acknowledgements; optional display name; brewery/bar intake (business name, address, phone, contact name); reviews and private notes; shop shipping name and address when you order; support emails.

Wallet and account. Connected Solana public key; role if you are on the admin team; timestamps for last seen, age verify, and Terms accept. We do not collect seed phrases or private keys.

Activity. Check-ins (brewery, coarse distance, coordinates used to validate radius); outbound link clicks (URL kind); favorites; ratings and badge progress; points and daily counters; beer-credit balances and ledger (redeem, purchase, send, claim, buyback, POS burn); POS session metadata (cart, payer wallet, USDC paid, transaction signature); gacha pulls and prize fulfillment records when that feature is live; shop orders.

Media. Brewery logos and beer images uploaded to our storage; any photos you attach to a future profile or return claim.

Device and logs. IP address, browser, approximate region, pages viewed, and error logs from our hosting and database providers. We may use analytics cookies or similar tools.

We do not collect. Government ID unless a future high-risk fulfillment step requires it; full payment-card numbers (we do not take cards today — USDC is signed in your wallet); health data.

03How we use information

  • Operate discovery, points, credits, POS, shop, and gacha
  • Enforce legal drinking age and these policies
  • Prevent farming, double-spend of tabs, and fraud
  • Pay buybacks and settle USDC against the right wallet
  • Show public catalog, aggregates, and (if you opt in) activity
  • Fulfill merch, kits, recipes, and physical gacha prizes
  • Coordinate with partner breweries on listings and volume
  • Improve the product and communicate about the Service
  • Comply with law and protect users, partners, and DSCVR

Legal bases (where GDPR/UK GDPR apply): contract (running the Service you asked for), legitimate interests (security, product, public catalog), consent (age gate, optional marketing, analytics where required), and legal obligation.

04Blockchain is public

USDC transfers, memos (which may include your wallet and a compact cart), and any future on-chain mints are written to Solana. Anyone can read them. We cannot delete a confirmed transaction. Treat your public key as identifiable if you have linked it elsewhere.

05Who we share with

  • Infrastructure: Google Firebase (Firestore, Storage) and Google Cloud (including Cloud Run for purchase and buyback). Project region and subprocessors follow those vendors.
  • Chain: Solana validators and public explorers; USDC as issued by its circle of trustees — not us.
  • Wallets and RPC: your wallet app and our RPC provider see requests you sign or we make to confirm payments.
  • Partners: a brewery or bar may see that a DSCVR tab was paid at their venue (cart, time, truncated wallet) so they can pour. We do not sell marketing lists of drinkers.
  • Fulfillment: carriers and kit suppliers get the shipping data needed to deliver shop or prize orders.
  • Law and safety: we disclose when required by valid process or to prevent harm.
  • Corporate events: a merger or asset sale may transfer records under this policy.

Staff with God / Sub / Ambassador roles can see operational data needed for their job. Ambassadors do not run POS.

06Cookies, local storage, location

The age gate uses browser local storage (dscvr_age_verified). Wallet adapters store connection preferences. We may use session or persistent cookies for load balancing and analytics.

Check-in asks for device location to confirm you are within the published radius (currently 0.5 miles) of a brewery. We store the check-in result and distance; we do not continuously track you in the background. You can deny location; you simply will not check in.

You can clear site data in your browser. That may log you out of the age gate and wallet adapter until you confirm again.

07Retention

We keep wallet profiles, ledgers, and POS/gacha/shop records as long as needed to operate balances, prevent abuse, and meet tax or legal holds — typically the life of the account plus a reasonable archive period. Support mail is kept as long as the thread is useful. Backups expire on our vendors’ cycles.

Public on-chain data is not ours to erase. Off-chain reviews and favorites can be removed on request where the law allows and where we do not need them for a live dispute.

08Your rights

Depending on where you live (including California, other US state privacy laws, and the EEA/UK), you may have rights to access, correct, delete, export, or restrict certain personal information, and to opt out of “sale” or “sharing” for cross-context ads. We do not sell personal information and do not share it for cross-context behavioral advertising as those terms are typically defined.

Identity on DSCVR is a wallet. To make a request, email partnerships@dscvr.beer from a reachable address and include the Solana public key. We may ask you to sign a message from that wallet so we know it is you. We will not transfer credits to a different wallet just because an email asked.

Nevada residents may email the same address with subject “Nevada Do Not Sell Request.” We do not sell covered information.

Authorized agents may submit requests with proof of authority. We will not discriminate for exercising privacy rights.

09Children

The Service is 21+ in the US and legal drinking age elsewhere. We do not knowingly collect personal information from children or from anyone under legal drinking age. If you believe we have, write to us and we will delete access and associated profile data we control.

10Security

We use vendor-managed access controls, HTTPS, and least-privilege admin roles. No method is 100% secure. You must protect your wallet. Treasury keys for buybacks are held in cloud secret storage used only by our payment services — never asked of you.

11International transfers

We are oriented around the United States. Firebase, Cloud Run, and RPCs may process data in the US and other countries. If you use the Service from elsewhere, you understand those transfers. Where required, we rely on vendor standard contractual clauses or similar mechanisms.

12Changes

We will post updates here and change the date above. Continued use means you accept the revised policy, except where the law requires a new consent.

Questions: partnerships@dscvr.beer. Related: Terms · Privacy.