Privacy Policy
This Privacy Policy explains how Brew Scan collects, uses, stores and
protects personal information when people visit our website, scan a
Brew Scan-enabled QR code, use our directory, claim a brewery listing,
create an account or use our services.
Effective date:
12 July 2026
Privacy at a glance
We collect only the information reasonably needed to operate Brew Scan,
provide brewery profiles and QR services, produce scan analytics,
administer customer accounts, process enquiries and improve our website.
We do not sell personal information. We do not knowingly collect
sensitive personal information through QR-code scans, and we do not use
ordinary scan information to identify individual drinkers by name.
1 Who we are
Brew Scan provides QR-code-enabled digital experiences, brewery
directory listings, product information pages, customer engagement
services and scan analytics for breweries and related businesses.
For the purposes of applicable data protection law, the organisation
responsible for deciding how and why personal information is processed
is:
Legal business name: Crafti Beer Ltd
Trading name: Brew Scan
Registered address: 39 Blackfriars Avenue, Droitwich, WR9 8RH, United Kingdom
Privacy email:
Info@brewscan.com
Company number: 10321894
In this policy, “Brew Scan”, “we”, “us” and “our” refer to the business
identified above.
In some circumstances, Brew Scan acts as a data controller,
meaning we decide why and how personal information is used. In other
circumstances, such as when processing information solely on a brewery
customer’s documented instructions, we may act as its
data processor.
2 Scope of this policy
This policy applies to personal information processed through:
- the Brew Scan website and associated webpages;
- Brew Scan brewery directory listings;
- listing claim and verification processes;
- customer registration and login areas;
- private client file and report areas;
- QR-code scans and associated analytics;
- beer, brewery, taproom, stockist and campaign pages;
- contact forms, demonstrations and register-interest forms;
- customer support and business communications;
- subscriptions, purchases and billing administration;
- email newsletters and permitted business marketing; and
- our interactions with prospective and existing business customers.
This policy does not govern the independent privacy practices of a
brewery, retailer, payment provider, social network or other third party.
Those organisations may process information under their own privacy
notices.
3 Information we collect
Information you provide directly
Depending on how you interact with us, this may include:
- your name and job title;
- brewery or business name;
- business and billing address;
- email address and telephone number;
- account username and encrypted password credentials;
- information supplied when claiming or verifying a listing;
- messages, enquiries, feedback and support correspondence;
- subscription, order and transaction information;
- files, logos, photographs and content uploaded to an account;
- beer, product, ingredient, allergen and stockist information;
- marketing preferences; and
- any other information you choose to give us.
Information collected automatically
When someone visits our website or scans a QR code, we and our authorised
service providers may automatically collect technical and usage
information such as:
- Internet Protocol address;
- approximate country, region or town inferred from network information;
- date and time of the visit or scan;
- browser type and version;
- device type, operating system and screen characteristics;
- referring webpage or campaign source;
- pages viewed and links selected;
- QR code, brewery, beer or campaign identifier;
- general interaction and performance information;
- login, security and error logs; and
- cookie and consent preferences.
Information obtained from other sources
We may obtain business information from:
- publicly available brewery and company websites;
- public business directories and registers;
- map and location-data providers;
- social-media pages operated by the relevant business;
- Companies House or comparable public registers;
- commercial partners and referral sources;
- the brewery, brand owner or an authorised representative; and
- information submitted by visitors for correction or verification.
Where information obtained from a public source identifies an individual,
such as a named brewery contact or a personal business email address, it
may constitute personal information and will be handled in accordance
with this policy.
Payment information
Payments may be processed by an independent payment provider. Brew Scan
does not ordinarily receive or store complete payment-card numbers.
We may receive limited transaction information, such as payment status,
amount, date, billing name and a payment reference.
Sensitive information
Brew Scan does not intend to collect special-category or sensitive
personal information through ordinary QR scans, directory listings or
website use. Please do not send health, biometric, financial-account,
government-identification or other highly sensitive information unless
we have specifically requested it for a legitimate and lawful reason.
4 QR-code scan analytics
When a person scans a Brew Scan-enabled QR code, technical information
may be collected so that we can direct the person to the correct content,
protect the service and provide aggregated analytics to the relevant
brewery or business customer.
Scan reports may include:
- total and unique or estimated unique scans;
- scan dates and times;
- approximate geographic areas;
- device, browser and operating-system categories;
- the particular QR code, beer, product or campaign scanned;
- traffic and referral information; and
- aggregated trends and comparisons.
We do not ordinarily use a QR-code scan to identify the person
who scanned it by name. Location information is intended to be
approximate and should not represent a person’s precise live location.
A person may choose to provide additional information after scanning,
for example by completing a competition, survey, mailing-list form or
contact form. In that case, the form will explain what information is
requested and how it will be used.
Depending on the service arrangement, a brewery customer may receive
aggregated scan statistics. We do not intend to provide breweries with
raw personal identifiers unless this is necessary, lawful, appropriately
disclosed and covered by the relevant service agreement.
5 Brewery directory information
Brew Scan may create an initial brewery listing using information supplied
by the brewery or obtained from legitimate public and commercial sources.
This helps us provide a useful brewery directory and allows an authorised
representative to claim and manage the listing.
Initial directory information may include:
- brewery or trading name;
- public business address and map location;
- public telephone number and general business email address;
- official website and social-media links;
- business category and publicly stated services;
- taproom or visitor information;
- publicly available product information; and
- the source and date on which information was checked.
An unclaimed listing does not mean that the brewery endorses, subscribes
to or is commercially associated with Brew Scan. We aim to identify
unclaimed listings clearly.
Brewery representatives may contact us to claim, update, correct or
request removal of information. We may request reasonable evidence that
the person is authorised to act for the business.
We may retain a minimal suppression record where necessary to prevent
removed or disputed information from being unintentionally re-imported.
6 How we use personal information
We may use personal information to:
- operate, maintain and secure our website and services;
- create and administer customer and brewery accounts;
- verify and process brewery listing claims;
- provide private files, reports and QR-code materials;
- create, manage and redirect dynamic QR codes;
- generate scan analytics and customer reports;
- display and maintain brewery and product listings;
- process subscriptions, purchases, renewals and refunds;
- respond to enquiries and provide customer support;
- send service, security and account notifications;
- detect fraud, misuse, unauthorised access and technical problems;
- improve website performance and user experience;
- understand service demand and usage patterns;
- contact relevant business prospects where permitted by law;
- send marketing where consent or another lawful basis applies;
- establish, exercise or defend legal claims;
- comply with tax, accounting and legal obligations; and
- protect Brew Scan, our customers, users and the public.
We will not use personal information for a materially incompatible new
purpose without providing appropriate notice and, where required,
obtaining consent.
7 Our lawful bases
Where UK or European data protection law applies, we rely on one or more
of the following lawful bases:
| Lawful basis | When it may apply |
|---|---|
| Contract | To create an account, provide purchased services, manage QR codes, produce reports, process payments and fulfil our agreement with a customer. |
| Legitimate interests | To operate and secure Brew Scan, maintain business records, improve services, produce proportionate analytics, administer business directory listings, prevent misuse and conduct appropriate business-to-business communications. |
| Consent | For optional marketing, non-essential cookies and other activities where consent is required. Consent may be withdrawn at any time. |
| Legal obligation | To comply with tax, accounting, regulatory, court or lawful government requirements. |
| Vital interests | In the rare event that processing is necessary to protect somebody’s life or physical safety. |
| Legal claims and substantial public interest | Where applicable law permits or requires the processing of particular information for legal claims, fraud prevention or another recognised public-interest purpose. |
Our legitimate interests
Where we rely on legitimate interests, those interests may include
running a sustainable business, providing useful brewery information,
developing and improving Brew Scan, communicating with relevant
businesses, securing our systems, understanding service performance and
preventing fraud or misuse.
We consider whether the processing is necessary and balance our interests
against the rights and reasonable expectations of the individuals
affected.
9 Technology and service providers
Brew Scan operates using WordPress and may use third-party services and
plugins to provide its website, directory, private file portal, payments,
QR-code management, security, communications and analytics.
These may include providers in the following categories:
- WordPress website hosting and domain services;
- Directorist directory functionality;
- User Private Files or comparable secure client-file functionality;
- WooCommerce and associated payment services;
- QR-code generation and scan-analytics services;
- Google services, where enabled, such as Maps, Places or Analytics;
- email delivery and customer relationship management services;
- website backups, firewalls, spam filtering and security monitoring;
- consent-management and cookie-control services; and
- accounting, invoicing and business administration services.
Brew Scan actually uses. Remove categories you do not use and consider
naming important providers in a separate cookie policy or supplier list.
Some third-party features may collect information directly under their
own terms and privacy policies. For example, an embedded map, payment
page or social-media link may connect the visitor to that provider.
10 International data transfers
Brew Scan is based in the United Kingdom, but some service providers may
process information in the United States, European Economic Area or other
countries.
Where personal information is transferred outside the United Kingdom or
another relevant jurisdiction, we seek to use an appropriate transfer
mechanism where required. This may include:
- a UK or European adequacy decision;
- the UK International Data Transfer Agreement;
- the UK Addendum to approved contractual clauses;
- European Commission Standard Contractual Clauses;
- another legally recognised certification or transfer framework; or
- a limited statutory exception where legally permitted.
You may contact us for further information about the safeguards relevant
to your personal information.
11 How long we retain information
We retain personal information only for as long as reasonably necessary
for the purpose for which it was collected, including legal, accounting,
security and dispute-resolution requirements.
| Information category | Typical retention approach |
|---|---|
| Enquiries from non-customers | Normally up to 24 months after the last meaningful contact, unless a longer period is reasonably required. |
| Customer account and contract information | For the duration of the customer relationship and normally up to six years afterwards for legal and contractual records. |
| Invoices, payments and tax records | Normally six years or for any longer period required by tax or accounting law. |
| Private reports and customer files | For the active subscription or service period and for a limited period afterwards, subject to the customer agreement, backup cycles and legal requirements. |
| QR scan and technical analytics | Detailed information is retained only for the period needed to provide analytics and security. Aggregated or anonymised reports may be retained for longer. |
| Directory listing information | While the listing remains relevant, subject to periodic review, correction, objection and removal requests. |
| Marketing preferences and suppression records | Until consent is withdrawn or an objection is received. A minimal suppression record may then be kept to honour the request. |
| Security and access logs | Normally for a limited period appropriate to security, investigation and fraud-prevention needs. |
These periods are guidelines and may be shortened or extended according
to the nature of the information, contractual commitments, unresolved
disputes, legal holds, backup schedules and applicable law.
When information is no longer required, we will delete, anonymise or
securely isolate it as appropriate.
12 How we protect information
We use proportionate organisational and technical measures intended to
protect personal information against accidental loss, misuse,
unauthorised access, alteration or disclosure.
Measures may include:
- encrypted HTTPS connections;
- controlled user accounts and role-based permissions;
- private-file access restrictions;
- strong passwords and administrative access controls;
- software, theme and plugin updates;
- website security monitoring and firewalls;
- malware, spam and abuse prevention;
- backups and service-recovery procedures;
- restricted access to customer information;
- provider due diligence and contractual safeguards; and
- procedures for responding to suspected personal-data breaches.
No internet transmission or storage system can be guaranteed to be
completely secure. Users are responsible for keeping their account
credentials confidential and should contact us immediately if they
suspect unauthorised access.
14 Marketing communications
We may contact relevant businesses and business representatives about
Brew Scan where permitted by applicable law. We may rely on consent or
legitimate interests depending on the communication method, recipient
and circumstances.
We may use publicly available business contact details only where we
believe the use is relevant, proportionate and within the reasonable
expectations of the recipient.
You have the right to object at any time to the use of your
personal information for direct marketing.
You may unsubscribe using the link in a marketing email or contact us
using the details at the end of this policy. We will stop the relevant
marketing, although we may retain a minimal suppression record so that
we do not contact you again accidentally.
Service messages about an account, payment, security issue, QR code or
active customer service are not normally marketing and may continue where
necessary.
15 Your privacy rights
Depending on your location and the circumstances, you may have the right
to:
- be informed about how your personal information is used;
- request access to personal information we hold about you;
- ask us to correct inaccurate or incomplete information;
- request deletion of personal information;
- ask us to restrict particular processing;
- object to processing based on legitimate interests;
- object absolutely to direct marketing;
- receive certain information in a portable format;
- withdraw consent without affecting earlier lawful processing;
- complain to an appropriate data-protection regulator; and
- receive information about significant decisions made solely by
automated means, where applicable.
These rights are not absolute and may depend on the reason for processing,
applicable law and relevant exemptions.
Making a request
To exercise a privacy right, contact us using the details in Section 20.
Please describe your request clearly and identify the relevant account,
listing, QR interaction or correspondence where possible.
We may request proportionate information to verify your identity and
authority. We will not ask for more verification information than is
reasonably necessary.
We aim to respond within the timeframe required by applicable law. Under
UK and EU data protection law this is normally one month, although the
period may be extended for a particularly complex or numerous request
where legally permitted.
Privacy requests are generally handled without charge. A reasonable fee
may be permitted where a request is manifestly unfounded, excessive or
repetitive, or where additional copies are requested.
Complaints in the United Kingdom
We would appreciate the opportunity to resolve your concern directly.
You also have the right to complain to the UK Information Commissioner’s
Office if you believe your personal information has been handled
unlawfully.
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
United Kingdom
Telephone: 0303 123 1113
Website:
ico.org.uk
People in the European Economic Area or another jurisdiction may also
have the right to complain to their local data-protection authority.
16 California and other US residents
Privacy laws in certain US states may provide eligible residents with
rights regarding access, correction, deletion and disclosure of personal
information, as well as rights to opt out of certain sales, sharing,
targeted advertising or profiling.
Brew Scan does not sell personal information for money and does not
knowingly use personal information for cross-context behavioural
advertising.
Where an applicable US state privacy law gives you a right, you may submit
a request using the contact details in Section 20. We will verify and
respond to eligible requests as required by the relevant law.
You will not be unlawfully discriminated against for exercising an
applicable privacy right.
Categories of information
The categories potentially collected are described in Section 3 and may
include identifiers, internet or electronic activity, approximate
geolocation, commercial information and professional or employment-related
business-contact information.
The business purposes, source categories and recipient categories are
described elsewhere in this policy.
Authorised agents
Where permitted by law, an authorised agent may submit a request on your
behalf. We may require evidence of the agent’s authority and may need to
verify the request directly with you.
Appeals
Where applicable state law provides an appeal right, you may appeal a
decision by replying to our response and stating that you wish to appeal.
17 Children’s privacy
Brew Scan’s commercial services are directed primarily at breweries,
retailers and adults of legal drinking age. Our services are not designed
to encourage children to purchase or consume alcohol.
We do not knowingly collect personal information directly from children
under 13, or under a higher minimum age where required by local law,
without appropriate authorisation.
Certain beer or alcohol-related content may be subject to an age notice or
age-gating measure. Age confirmation does not necessarily require us to
retain a person’s full date of birth.
A parent or guardian who believes a child has provided personal
information to Brew Scan should contact us so that we can investigate and
take appropriate action.
18 Third-party websites and content
Brew Scan pages may link to brewery websites, retailers, stockists,
social-media platforms, maps, delivery services, competitions or other
third-party services.
When you leave Brew Scan or interact directly with a third party, that
organisation may collect information under its own terms and privacy
policy. We are not responsible for the independent privacy practices,
security or content of third-party services.
A link does not necessarily mean that Brew Scan endorses or controls the
third party.
19 Changes to this policy
We may update this Privacy Policy to reflect changes to our services,
technology, suppliers, business operations or legal obligations.
The latest version will be published on this page with a revised
effective date. Where a change is significant, we may also provide an
additional website, account or email notice where appropriate.
We encourage users and customers to review this policy periodically.
20. How to contact us
Questions, corrections, objections and privacy-right requests can be
sent to:
Craftibeer Limited
Trading as Brew Scan
39 Blackfriars Avenue, Droitwich, Worcestershire, WR9 8RH, United Kingdom
Email:
info@brewscan.com
Please use the subject line Privacy Request and do not
send passwords or unnecessary sensitive information by ordinary email.
