Effective Date: August 24, 2026 · Version 1
THE BEVBRIDGE GROUP LLC ("BevBridge," "we," "us," or "our") provides websites, a business-to-business platform, applications, support, and related services that help beverage-industry participants manage RFPs and related business workflows (collectively, the "Service").
This Privacy Policy explains how we collect, use, disclose, and retain personal information when someone visits or uses the Service, receives a Service communication, or interacts with us. If you use the Service for a company or other organization (a "Company"), that Company may separately control information in its workspace and have its own privacy responsibilities.
This Policy applies to the BevBridge public website, authenticated platform, registration and invitation processes, support channels, and Service communications.
BevBridge generally determines how personal information is used for account administration, security, billing, direct support, website operation, and our own business activities. For RFPs, product catalogs, submissions, reviews, comments, files, and other Company-provided content, BevBridge often processes information to provide the Service under the Company's instructions. Companies and other authorized participants may independently determine how they use information they receive through the Service.
If a privacy request concerns information controlled by a Company, we may refer the request to that Company or coordinate with it.
The information depends on how the Service is used and may include:
The Service is intended for ordinary business information. Please do not submit unnecessary sensitive personal information, such as government identification numbers, personal financial credentials, health information, information about children, or payment-card credentials in free-text fields, uploads, or support materials.
We receive information:
We use personal information as reasonably necessary to:
We may disclose personal information:
Authorized recipients may download, export, print, or otherwise retain information. After an authorized disclosure, the recipient controls its external copies. BevBridge cannot retrieve those copies merely because platform access is later revoked or information is deleted from the Service.
We may use and disclose aggregated or de-identified information that is not reasonably capable of identifying a Company, User, RFP, submission, or other person. We do not attempt to re-identify information maintained as de-identified except to test de-identification or as required by law.
BevBridge does not sell personal information or share it for cross-context behavioral advertising. We do not use advertising pixels or session-replay tools in the Service as currently configured. The operational disclosures described above are not sales or targeted advertising.
The platform uses cookies needed for authentication and security. It also uses browser storage for preferences and temporary workflow state. Blocking or clearing these technologies may prevent login, reset preferences, or remove in-progress state.
Our public website infrastructure and anti-bot tools may collect limited device, visitor, performance, and error information needed to operate and protect the site. We do not use a separate advertising or cross-site behavioral-tracking system. Where applicable law requires consent for a nonessential technology, we will provide an appropriate choice before using it.
Service emails may include technologies that record delivery, opens, and link clicks. We use those records for message administration, troubleshooting, engagement measurement, security, and workflow support. Optional marketing communications will include any opt-out required by law, but necessary account, security, billing, and transactional messages may continue.
The Service does not currently include a production feature that routinely sends Customer content to a generative-AI provider. Separately, authorized personnel may use approved AI-assisted tools for limited internal purposes such as drafting, analysis, support, meeting review, and software development. We seek to minimize personal and confidential information used for these purposes and prohibit submission of credentials, full payment-card information, or other unnecessary sensitive data.
We do not use identifiable Customer content to train an unrelated general-purpose AI model, or permit an AI provider to use it for that provider's own model training, without separate authorization. We will provide additional notice and obtain any authorization required by law or contract before introducing materially different AI processing of Customer content.
We retain personal information for as long as reasonably necessary for the purposes described in this Policy, taking into account the type and sensitivity of the information; the status of the Account, Company, RFP, submission, or transaction; security and audit needs; legal, accounting, and contractual requirements; dispute preservation; and technical feasibility.
Some operational email, session, and audit records are routinely deleted on shorter schedules. Other information-such as account and Company records, Terms acceptance, billing history, RFPs, submissions, comments, support records, and files-may remain while needed for the Service or the purposes above. Residual copies may remain temporarily in backups or provider systems until overwritten or deleted through ordinary processes.
Deactivation stops future access but does not necessarily erase historical actions or shared business records. A complete deletion request may require manual work across multiple systems and may be limited by legal obligations, security needs, another Company's records, or copies previously received by authorized recipients. We may de-identify information instead of deleting it where lawful and appropriate.
We use reasonable administrative, technical, and organizational measures designed to protect personal information in our control. These include access controls, protected authentication methods, logging, and safeguards appropriate to the nature of the Service. Authorized personnel may access information when reasonably necessary to operate, secure, troubleshoot, or support the Service.
No method of storage, transmission, or access control is completely secure. Users and Companies should use secure devices and networks, protect authentication links, verify recipients and permissions, remove access promptly when no longer authorized, avoid unnecessary sensitive information, and report suspected misuse through the Service's support channel.
Depending on your role, you may be able to review or update profile information and communication preferences in the Service. Necessary transactional and security messages may continue even when optional notifications are disabled.
You may request access to, correction of, deletion of, or a portable copy of personal information. Depending on applicable law, you may also have rights to use an authorized agent, appeal a decision, or opt out of certain processing. Submit a request through the contact form on the BevBridge website, the support channel in the Service, or the mailing address below. We may verify identity, residency, account association, and authority before responding.
Rights are subject to applicable definitions, thresholds, exceptions, and verification requirements. We may deny or limit a request where permitted by law, including when information is controlled by a Company, needed for another person's rights, required for security or legal compliance, part of an authorized business record, or not reasonably separable from an RFP, submission, audit, billing, or legal-evidence record. We may keep a limited record of the request and response.
Because we do not sell personal information or share it for cross-context behavioral advertising, we do not currently provide a separate "Do Not Sell or Share" mechanism. We will update this Policy and provide any required choice before beginning such a practice.
The Service is intended for business Users who are at least 18 years old. It is not directed to children, and we do not knowingly collect personal information from anyone under 18.
The Service is primarily intended for use in the United States. We and our service providers may process information in the United States and other locations where they operate. Those locations may have privacy laws different from the laws where you live. Additional contractual terms or notices may apply if the Service is intentionally offered in another jurisdiction.
We may update this Policy as the Service, law, or our practices change. We will post the revised version with a new effective date and provide additional notice of material changes through the Service, by email, or another appropriate method. We will request consent only when required by law. Users generally acknowledge receiving this Policy as notice; they do not "accept" it as a contract merely by using the Service.
For privacy questions or requests, security reports, or general support, use the applicable support or contact function in the Service or on the BevBridge website, or write to:
Effective: August 24, 2026 · BevBridge Legal