CheekyBook is inventory management software for bars, operated by TinyRatchet LLC, doing business as CheekyBook ("CheekyBook," "we," "us," or "our"). This Privacy Policy explains what information we collect when you use our iOS app, web app, and related services (the "Service"), how we use it, and the choices you have.
By using the Service, you agree to the practices described here. If you do not agree, please do not use the Service.
1. Who this policy applies to
This policy applies to people who sign up for an account, staff members invited to an organization, and anyone who interacts with our websites or apps. If you are an employee of a bar using CheekyBook, your employer is the organization that controls your account and the inventory data it contains; we process that data on their behalf.
2. Information we collect
Account information
When you or your organization administrator creates an account, we collect your email address, your name (if provided), and the role you've been granted (administrator, buyer, or standard user). If your organization uses our single sign-on provider, we receive a unique identifier from that provider in place of a password. Where a password is used, we never store it in readable form — it is hashed before storage.
Organization and inventory data
To operate the Service, we store the data you or your team enter: your bar or organization name, subscription tier, inventory locations, categories, items, par levels, unit costs, distributor contact information, inventory counts, purchases, depletions, shopping cart entries, and invoice scans. This is operational business data — it belongs to your organization.
Device and usage information
When you use the Service we automatically log technical information such as your IP address, the time of each request, the action performed, and the resource affected. We keep these audit logs to secure the Service, investigate problems, and provide an activity history to account administrators.
Camera access (iOS app)
The iOS app requests camera access for two purposes only: scanning barcodes to look up items, and photographing delivery invoices so the line items can be extracted. Images you capture for invoice scanning are sent to our server and to the OCR provider described below. The camera is not used for any other purpose, and we do not access your photo library, location, microphone, contacts, or health data.
What we do not collect
We do not use advertising identifiers, cross-site trackers, or third-party analytics. We do not build a marketing profile about you. The web app does not set tracking cookies.
3. How we use your information
- To provide and maintain the Service — authenticating you, showing your organization's inventory, syncing between iOS and the web, and running reports.
- To process delivery invoices using image recognition so that line items can be extracted automatically, subject to your review.
- To secure the Service — detecting abuse, investigating incidents, and keeping audit logs.
- To communicate with you about your account, service changes, and customer support.
- To comply with legal obligations and enforce our terms.
4. How we share information
We do not sell your personal information, and we do not share it for advertising. We share information only in the limited circumstances below.
Service providers we use
- WorkOS — user authentication and organization management. Account emails and sign-in events are handled by WorkOS.
- Anthropic — invoice image recognition. When you scan a delivery invoice on iOS, the image is sent to Anthropic's API so line items can be extracted. Anthropic does not use this content to train its models in the manner we use the API.
- Slack — internal operational notifications (for example, new-organization signups) sent to our own workspace. Customer inventory data is not sent to Slack.
- Hosting and database infrastructure — the servers and managed PostgreSQL database that store your data.
These providers act on our instructions and are bound by confidentiality and data-protection obligations.
Within your organization
Information you enter into CheekyBook is visible to other members of your organization according to their role. Administrators can see user accounts and activity within the organization.
Legal and safety
We may disclose information if we believe in good faith that doing so is required by law, necessary to protect the rights, property, or safety of CheekyBook, our users, or the public, or necessary to enforce our terms.
Business transfers
If CheekyBook is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a different privacy policy.
5. Data retention
We retain account and inventory data for as long as your organization maintains an active account. If an account is closed or an organization cancels, we retain the associated data for a limited period to allow recovery, handle disputes, and meet legal or accounting obligations, after which it is deleted or anonymized. Audit logs are retained on a rolling basis for security and troubleshooting.
You can request deletion of your individual user account at any time (see "Your choices" below). Organization administrators can delete inventory records, distributors, locations, and invoice scans directly in the product.
6. How we protect your information
- Passwords (when used) are hashed with bcrypt before storage.
- API traffic is served over HTTPS; authentication uses signed tokens validated against our identity provider.
- On iOS, authentication tokens are stored in the device Keychain.
- The web app applies Content Security Policy headers and sanitizes user-generated content to defend against common web attacks.
- Webhooks are verified with HMAC signatures so we can trust the source of events.
- Access to production systems is limited to personnel who need it.
No system is perfectly secure. If we learn of a security incident that affects your information, we will notify you as required by law.
7. Your choices and rights
- Access and correction. You can view and update your profile and inventory data directly in the app. If you need help, contact us.
- Export. Organization administrators can export inventory data from the reports and counts screens.
- Deletion. You can delete your own user account from the account settings (a confirmation is required). Deleting your user account removes your sign-in credentials; inventory records you contributed to the organization remain with the organization. Organization administrators can request deletion of an entire organization by contacting us.
- Opt out of service email. Account and security email is required while your account is active. We do not send marketing email without consent.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA/CPRA), including the right to know what personal information we have collected, the right to request deletion, the right to correct inaccurate information, and the right not to be discriminated against for exercising these rights. We do not "sell" or "share" personal information as those terms are defined under the CCPA.
8. Children's privacy
CheekyBook is a business tool intended for adult users operating licensed establishments. It is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
9. International users
CheekyBook is operated from the United States and our servers are located in the United States. If you access the Service from outside the U.S., your information will be transferred to, stored, and processed in the U.S.
10. Third-party links
Distributor websites, documentation, and other links surfaced in the Service are operated by third parties with their own privacy practices. This policy does not apply to those sites.
11. Changes to this policy
We may update this policy from time to time. When we make material changes we will update the "Effective" date at the top and, where appropriate, notify you in the app or by email. Continued use of the Service after an update means you accept the revised policy.
12. Contact us
If you have questions, concerns, or requests related to this policy or your information, contact us at: