Last Updated: October 8, 2026
Effective Date: October 2, 2026
1. Introduction
Carpe Vende Consulting Corp. ("Company," "we," "us," or "our") operates the Avēre application and website at getavere.com (the "Service"). This Privacy Policy describes how we collect, use, disclose, and protect your personal information when you use the Service.
The Service is intended for use within the United States only. By using the Service, you consent to the data practices described in this Privacy Policy.
2. Information We Collect
2.1 Information You Provide
- Account Information: email address and your first and last name when you create an account. Other members see only your first name and last initial (for example, "Sean H."), on the leaderboard and when you are a venue's mayor
- Profile Information: any additional profile details you choose to provide, including your date of birth, which is optional and never shown to other members
- Age Confirmation: your confirmation that you are 21 or older, and when you gave it
- Reports and Hidden Members: content you report, the reason you give, and any members whose content you choose to hide
- Invitations: if you join using a friend's invitation, the link between your account and theirs
- Venue Submissions: venue names, addresses, happy hour details, menu descriptions, and photos you submit
- Ratings and Reviews: your 5-dimension ratings (price, service, quality, vibe, and menu variety) of venues
- Photos: menu photos or other images you upload to the Service
- Communications: messages you send to us, including support requests and feedback
2.2 Social Media Login Data
If you register or log in using a third-party social media account (such as Google or Apple), we receive certain profile information from that provider. This typically includes your name, email address, and profile picture. We use this information only for the purposes described in this Privacy Policy. We do not control how social media providers use your data; please review their privacy policies.
2.3 Information Collected Automatically
- Precise GPS Location Data: when you use the check-in feature, we collect your device's precise GPS coordinates to verify your proximity to a venue (within approximately 150 meters). Location data is collected only when you actively initiate a check-in. We do not track your location continuously or in the background.
- Non-Precise Location Data: approximate location derived from your IP address
- Venue Interaction Data: we record interactions such as venue card views, direction taps, menu taps, website taps, phone taps, saves, and unsaves. These events include a session identifier.
- Device and Usage Information: device type, operating system, browser type and version, IP address, referring URLs, pages visited, access timestamps, device identifiers, and hardware model
- Cookies and Similar Technologies: we use cookies and local storage for session management and authentication. See Section 11 for details.
2.4 Mobile Application Data
If you use our mobile application, we may also collect:
- Mobile Device Data: device ID, model, manufacturer, operating system version, mobile carrier, and system configuration
- Camera Access: if you grant permission, to upload menu photos. We access your camera only when you actively initiate a photo upload.
- Push Notifications: if you grant permission, we send notifications about flash deals, check-in reminders, and account updates. You may opt out at any time through your device settings.
All personal information you provide must be true, complete, and accurate. You must notify us of any changes to your personal information.
2.5 Information Derived from Your Activity
- Points and Badge Data: calculated from your check-ins, ratings, submissions, and referral activity
- Mayor Status: determined by your check-in frequency at specific venues
- Leaderboard Rankings: derived from your cumulative activity
- Inferences: preferences and characteristics inferred from your usage patterns, such as preferred cuisines, neighborhoods, price ranges, and dining frequency
- Aggregated Insights: anonymized and aggregated data derived from collective user activity, such as venue popularity trends, neighborhood traffic patterns, and check-in volumes
2.6 Google API
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Verify check-ins through GPS location comparison
- Calculate and display points, badges, mayor status, and leaderboard rankings
- Process and moderate venue submissions, ratings, and community edits
- Personalize your experience (such as venue recommendations based on your preferences)
- Display venue analytics to participating venue operators (see Section 4.2 for details)
- Create aggregated, anonymized, or de-identified data products for analytics, market research, and technology partnerships
- Communicate with you about the Service, including account notifications and promotional communications
- Send you push notifications (if you have opted in) about flash deals, venue activity, and account updates
- Detect, prevent, and address fraud, abuse, and security issues (including GPS spoofing detection)
- Analyze usage patterns to improve the Service and develop new features
- Comply with legal obligations
- When available, process membership payments and manage subscriptions
4. How We Share Your Information
4.1 Public Information
The following information is visible to other users of the Service:
- Your display name
- Your check-in activity (venue and timestamp)
- Your ratings and the calculated Happy Hour Score for venues you have rated
- Your points total, badge level, and leaderboard position
- Mayor status at venues
- Venue submissions you have made (after approval)
4.2 Venue Operators
Participating venue operators may access analytics about their venues. The following categories of data are shared with venue operators:
Shared in aggregate (no individual user identification):
- Total venue card views, direction taps, menu taps, website taps, phone taps, and saves
- Check-in counts (total, unique visitors, and new visitors)
- Daily, weekly, and monthly traffic trends
- Happy Hour Score and rating averages
- Flash deal claim counts
Not shared with venue operators:
- Individual user names, email addresses, or contact information
- Individual user GPS coordinates
- Individual user browsing or interaction history beyond their own venue
- Individual user points, badges, or leaderboard data
4.3 Third-Party Service Providers and Technology Partners
We share information with the following third-party service providers that help us operate the Service:
| Provider | Data Shared | Purpose |
|---|---|---|
| Google Maps Platform (Google LLC) | Venue coordinates, place searches, map interactions | Map display, venue location rendering, place autocomplete for submissions |
| Supabase (Supabase Inc.) | All user data, including account info, check-ins, ratings, GPS coordinates, and photos | Database hosting, user authentication, file storage, real-time data delivery |
| Vercel (Vercel Inc.) | IP address, request metadata | Application hosting and content delivery |
When payment processing becomes available, we will use Stripe (Stripe Inc.) to process payments. Stripe will receive payment card details, billing address, and transaction information. We will update this Privacy Policy before activating payment processing.
We may engage additional technology partners, analytics providers, advertising platforms, and service providers from time to time. When we do, we will update this Privacy Policy to reflect those partnerships.
4.4 Aggregated and De-Identified Data
We may share, license, or sell aggregated, anonymized, or de-identified data that does not identify you personally. This data may be shared with venue operators, technology partners, market research firms, advertising platforms, and other third parties for purposes including analytics, trend analysis, market research, and business development.
4.5 Sale and Sharing of Personal Information
We do not sell your individual personal information. We do not share your personal information for cross-context behavioral advertising.
Some of our disclosures of personal information to technology partners may be considered "sharing" under the California Consumer Privacy Act (CCPA). If applicable, this includes identifiers and internet activity information shared with analytics providers.
If our data sharing practices change materially, we will update this Privacy Policy, provide you with notice, and offer opt-out mechanisms as required by applicable law, including a "Do Not Sell or Share My Personal Information" mechanism.
4.6 SMS and Mobile Information
No mobile information (including SMS/text message originator opt-in data and consent) will be shared with third parties or affiliates for marketing or promotional purposes. Sharing with subcontractors in support of service operations (such as customer support) is permitted.
4.7 Legal Requirements
We may disclose your information if required to do so by law or in response to valid legal process, including subpoenas, court orders, or government requests. We may also disclose information when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.
4.8 Business Transfers
If we are involved in a merger, acquisition, bankruptcy, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change by posting a notice on the Service or by email.
4.9 With Your Consent
We may share your information for other purposes with your explicit consent.
5. Categories of Personal Information (CCPA Disclosure)
The following table describes the categories of personal information we have collected in the past twelve (12) months, as defined by the California Consumer Privacy Act:
| Category | Examples | Collected |
|---|---|---|
| A. Identifiers | Name, email address, display name, IP address, unique device identifiers, account name | YES |
| B. Personal information per Cal. Civ. Code 1798.80(e) | Name, email address, date of birth (if you provide it) | YES |
| C. Protected classification characteristics | Not collected | NO |
| D. Commercial information | Membership tier, transaction history (when payments are active) | NO (future) |
| E. Biometric information | Not collected | NO |
| F. Internet or similar network activity | Venue interaction data (views, taps, saves), browsing activity within the Service, search and filter usage | YES |
| G. Geolocation data | Precise GPS coordinates (check-in only), approximate location from IP address | YES |
| H. Sensory data | Photos uploaded by users (menu photos) | YES |
| I. Professional or employment-related information | Not collected | NO |
| J. Education information | Not collected | NO |
| K. Inferences drawn from personal information | Preferred cuisines, neighborhoods, price ranges, dining frequency, venue recommendations | YES |
| L. Sensitive personal information | Precise geolocation, account login credentials | YES |
We only collect sensitive personal information as permitted by applicable law and for the purposes disclosed in this Privacy Policy. We do not use sensitive personal information to infer characteristics about you.
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. Specific retention periods:
- Account data (email, display name, profile): retained until you delete your account
- Check-in records (venue, timestamp, GPS coordinates): retained indefinitely to maintain venue analytics and community verification integrity
- Ratings: retained indefinitely as part of the venue's aggregate rating
- Venue interaction events (views, taps, saves): retained for 3 years for analytics purposes
- Points ledger: retained as an append-only audit trail for the life of the account
- Communications and support requests: retained for 3 years after last interaction
- Photos: retained until you delete them or your account is deleted
How to delete your account: in the app, open the menu and choose Delete account. Deletion is immediate and covers accounts created with Apple, Google, Facebook or email. If you can't access the app, email legal@carpevende.com and we will delete it for you.
After account deletion:
- We will delete or anonymize your personal information within 30 days, except as required by law
- Ratings and check-ins may be retained in anonymized form (stripped of user identity) to preserve venue analytics integrity
- Aggregated data derived from your activity is retained indefinitely
- Some information may be retained in backup archives; if so, it will be securely isolated from further processing until deletion is possible
7. Your Privacy Rights
7.1 All Users
You may:
- Access your account information through the Service
- Update your display name and profile information
- Delete your account in the app (menu → Delete account) or by contacting us at legal@carpevende.com
- Disable location services on your device to prevent GPS data collection (this will limit functionality)
- Opt out of promotional communications by using the unsubscribe mechanism in any promotional email
- Opt out of push notifications through your device settings
7.2 California Residents (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to Know: you may request the categories and specific pieces of personal information we have collected about you, the sources of collection, the business purpose for collection, and the categories of third parties with whom we share it
- Right to Delete: you may request that we delete the personal information we have collected from you, subject to certain exceptions
- Right to Correct: you may request correction of inaccurate personal information
- Right to Opt Out of Sale/Sharing: we do not sell your personal information. If this changes, we will provide a "Do Not Sell or Share My Personal Information" mechanism. If we begin selling or sharing personal information for targeted advertising in the future, we will honor Global Privacy Control (GPC) signals as a valid opt-out request.
- Right to Limit Use of Sensitive Personal Information: we collect precise GPS location data, which is considered sensitive personal information under the CCPA. We use this data only for the purposes disclosed in this Privacy Policy (check-in verification). You may limit our use of sensitive personal information by disabling location permissions on your device.
- Right to Non-Discrimination: we will not discriminate against you for exercising your privacy rights
- Authorized Agents: you may designate an authorized agent to submit privacy requests on your behalf. We may require verification of the agent's authority.
Financial Incentive Disclosure: Our rewards program (points, badges, mayor status) may constitute a "financial incentive" under the CCPA. The value of personal information collected in connection with the program is reasonably related to the value of the rewards. You may opt out by deleting your account.
To exercise these rights, contact us at legal@carpevende.com. We will verify your identity before processing your request. We will respond within 45 days, as required by law.
7.3 Texas Residents (TDPSA)
If you are a Texas resident, you have rights under the Texas Data Privacy and Security Act (TDPSA):
- Right to Access: you may confirm whether we are processing your personal data and access that data
- Right to Correct: you may request correction of inaccurate personal data
- Right to Delete: you may request deletion of your personal data
- Right to Data Portability: you may obtain a copy of your personal data in a portable format
- Right to Opt Out: you may opt out of processing for targeted advertising, sale of personal data, or profiling that produces legal or similarly significant effects. We do not currently engage in these activities.
To exercise these rights, contact us at legal@carpevende.com. You may appeal a denial of your request by contacting us at the same address. If your appeal is denied, you may contact the Texas Attorney General.
7.4 Other U.S. State Privacy Laws
If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may have the right to:
- Request access to and receive details about the personal information we maintain about you and how we have processed it
- Correct inaccuracies in your personal information
- Request deletion of your personal information
- Obtain a copy of your personal information in a portable format
- Opt out of targeted advertising, data sales, and profiling that produces legal or similarly significant effects
- Withdraw previously given consent
Oregon residents may request a list of specific third parties that have received their personal data.
To exercise your rights under any applicable state privacy law, contact us at legal@carpevende.com. We will process your request in accordance with applicable law.
7.5 Nevada Residents
We do not sell your personal information as defined under Nevada law. If you are a Nevada resident and wish to submit an opt-out request, contact us at legal@carpevende.com.
8. Data Security
We implement reasonable technical and organizational measures to protect your personal information, including:
- Row-level security policies implemented on database tables
- Authentication-gated access to personal data
- Server-side verification of GPS coordinates for check-ins
- HTTPS encryption for all data in transit
- Access controls limiting employee access to personal data
No method of transmission or storage is completely secure. We cannot guarantee absolute security of your information. Although we do our best to protect your personal information, transmission of personal information to and from our Service is at your own risk. If we become aware of a security breach affecting your personal information, we will notify you and the relevant authorities as required by applicable law.
9. Children's Privacy
The Service features alcohol, is for adults 21 and over, and is not directed to anyone under the age of 21. We do not knowingly collect, solicit data from, or market to anyone under 21 years of age. By using the Service, you represent that you are at least 21 years of age. If we learn that we have collected personal information from a person under 21, we will deactivate the account and take reasonable measures to promptly delete that information from our records.
If you believe a person under 21 has provided us with personal information, please contact us at legal@carpevende.com.
10. Location Data
GPS location data is a core component of the Service's check-in verification system. Important details about our location data practices:
- When collected: only when you actively tap the "Check In" button at a venue
- How used: compared against the venue's known coordinates to verify proximity (within approximately 150 meters)
- Not collected: we do not track your location in the background, continuously, or when you are not actively using the check-in feature
- Storage: check-in GPS coordinates are stored as part of your check-in record
- Sharing: individual GPS coordinates are not shared with venue operators or third parties, except as required by law
- Sensitive data: precise GPS location is classified as sensitive personal information under the CCPA. We use it only for the purposes disclosed in this Privacy Policy.
- Opting out: you may disable location permissions for the app at any time through your device settings. This will prevent you from using check-in and rating features.
- Where the app is opened from: once a day, we record the approximate city the app is opened from, taken from your network address or from your device location rounded to about 7 miles. This record is anonymous (it holds no account, device identifier or IP address) and is used only to decide where Avēre opens next.
- Nearby happy hours: while the app is open and location is allowed, your device location is used on your device to show the market you are in and sort places by distance. It is not stored for this purpose.
- Google Maps: when we use Google Maps Platform APIs, Google may use GPS, Wi-Fi, and cell towers to estimate your location. You may revoke consent by disabling location permissions on your device.
11. Cookies, Local Storage, and Tracking Technologies
11.1 What We Currently Use
- Authentication cookies: maintaining your login session
- Local storage: storing your filter and display preferences
11.2 What We Do Not Currently Use
- Third-party advertising cookies
- Cross-site behavioral tracking pixels
- Third-party analytics cookies
11.3 Future Use
We may introduce analytics cookies, performance monitoring tools, advertising pixels, or other tracking technologies in the future to improve the Service and support advertising. If we do, we will update this Privacy Policy to reflect those changes and provide appropriate notice and opt-out mechanisms where required by law.
To the extent any online tracking technologies are deemed a "sale" or "sharing" under applicable U.S. state laws, you can opt out as described in Section 7.
You can control cookies through your browser settings. Disabling cookies may affect the functionality of the Service.
12. Do Not Track and Global Privacy Control
Some browsers offer a "Do Not Track" (DNT) signal. We do not currently respond to DNT signals because no uniform technology standard for recognizing and implementing DNT signals has been finalized.
We do not currently sell or share personal information for targeted advertising, so there is nothing to opt out of today. If that changes, we will honor Global Privacy Control (GPC) signals as a valid opt-out request under applicable state privacy laws, including the CCPA.
13. Modification of Data Practices
We reserve the right to modify our data collection, use, and sharing practices at any time. Material changes will be communicated through updates to this Privacy Policy, posted on the Service with a revised "Last Updated" date. Where required by law, we will provide additional notice (such as email notification) for material changes to data practices.
Your continued use of the Service after any changes constitutes your acceptance of the updated practices, subject to your rights under applicable state privacy laws, which cannot be waived by contract.
14. Third-Party Links
The Service may contain links to third-party websites, including venue websites, social media profiles, and map/navigation applications. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.
15. International Users
The Service is operated from and intended for use within the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States, which may not offer the same level of data protection as your country of residence. By using the Service from outside the United States, you consent to this transfer. We make no representations that the Service complies with the privacy laws of any jurisdiction outside the United States.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on the Service with a revised "Last Updated" date. Your continued use of the Service after any changes constitutes your acceptance of the updated policy.
17. Contact Us
For questions about this Privacy Policy or to exercise your privacy rights, contact us at:
Carpe Vende Consulting Corp.
Email: legal@carpevende.com
For privacy-related complaints, you may also contact your state's Attorney General.