Last updated: September 13, 2026
Bruu Solutions LLC ("Bruu Solutions," "we," "us") provides the Bruu Loyalty Engine, a loyalty and rewards service that connects to the point-of-sale and online store systems of participating merchants, currently the Bruu Cafe locations and the companies that operate them ("Merchants"). This policy explains what information the Bruu Loyalty Engine receives, how we use and share it, and the choices available to Merchants and their customers.
This policy covers the Bruu Loyalty Engine, including our Clover app and our Shopify integration. The Bruu Rewards mobile app is covered by our App Privacy Policy, and the Bruu Print Service by its own privacy policy.
Our role
When we receive information from a Merchant's Clover or Shopify account, we process it on the Merchant's behalf, as its service provider, to run the Merchant's loyalty program. Merchants decide how their loyalty program works and are responsible for their own privacy notices to their customers. When a customer joins the Bruu Rewards program, we also keep that member's loyalty account so points can be earned and redeemed at any participating location.
Information we receive from Clover
When a Merchant installs our Clover app, we receive the following, limited to the permissions the Merchant approves:
Merchant information: business name, address, time zone, and settings.
Orders: order number, date and time, items, prices, discounts, taxes, totals, status, and refunds.
Payments: amount, tender type, status, and the device and employee recorded on the payment. Clover may include the card brand and the last four digits of the card. We do not receive full card numbers, expiration dates, or security codes.
Customer records attached to an order: the Clover customer ID and, where the Merchant has collected them, name, phone number, and email address.
Employee records: employee names and IDs, used to show who recorded an order or fulfilled a reward.
Items: item names, categories, and prices, used to apply rewards and show menus.
Information we receive from Shopify
For Merchants that connect a Shopify store: order number, items, totals, discounts, refunds, and the Shopify customer ID, name, email address, and phone number on the order. When a member redeems a reward online, we create a single-use discount code in the store.
Information about loyalty members
To run a member's loyalty account we keep:
Contact and account details: phone number (used to sign in), name, email address, and birthday if provided.
Loyalty activity: points earned, redeemed, adjusted, and expired; rewards claimed; and the location where each happened.
Linked purchase identifiers: the Clover or Shopify customer IDs connected to the member's account. When a member scans a receipt or orders in the app, we may link the Clover customer ID tied to the card used for that purchase, so later purchases with the same card at a participating location earn points automatically. Members can ask us to remove this link at any time.
Communication preferences: consent to marketing email and text messages, and app notification tokens.
Balances transferred from the Merchant's previous loyalty provider.
How we use information
We use this information to award points for purchases and remove points for refunds; show members their balances and activity and let them redeem rewards, including by creating reward orders or discount codes in the Merchant's Clover or Shopify account; send transactional messages, such as reward codes and notices about points earned, refunded, or expiring; send marketing email and text messages only to members who have agreed to receive them; calculate points activity between participating locations so Merchants can settle rewards with each other; provide support, prevent fraud and abuse, keep the service secure, and fix problems; and meet legal, tax, and accounting obligations.
We do not sell personal information, share it for cross-context behavioral advertising, or use a Merchant's customer data for any other company.
How we share information
With Merchants: each Merchant sees the orders, rewards, and loyalty activity for its own locations. Because points can be used at any participating location, staff at any participating location can look up a member to honor a reward. Settlement reports between Merchants use totals, not individual customer details.
With Clover and Shopify: to read orders and to create reward orders or discount codes, as the Merchant has authorized.
With service providers that process data for us under confidentiality obligations: Amazon Web Services (hosting and email delivery), Twilio (text messages), Google Firebase Cloud Messaging (app notifications), and Klaviyo (marketing email and text messages to members who have opted in).
For legal reasons: when required by law or court order, or to protect the rights, safety, or property of members, Merchants, us, or others.
In a business transfer: as part of a merger, acquisition, or sale of assets, subject to this policy.
Retention
Member accounts are kept while the account is active. If a member has had no loyalty activity for 2 years, or asks us to delete the account, we delete or de-identify the member's personal information.
Points and reward records are kept for 2 years after the activity. After that, or when an account is deleted, we keep only de-identified totals needed for accounting.
Order and payment details received from Clover and Shopify are kept for up to 90 days, then reduced to the order identifiers and totals the loyalty record needs.
System logs are kept for up to 30 days.
When a Merchant uninstalls our app, we stop receiving its data and delete its order data within 90 days, except records we must keep under this section.
Security
Data is encrypted in transit and stored in access-controlled systems in the United States. Clover and Shopify access credentials are kept in a secrets manager, and access is limited to people who need it to run the service. No method of transmission or storage is completely secure. We will notify affected Merchants of a security incident as required by law.
Your choices and privacy rights
Members can update their details in the Bruu Rewards app, turn off notifications in their device settings, unsubscribe from marketing email using the link in any email, and reply STOP to marketing text messages.
Members can ask to access, correct, or delete their information, or to remove a linked card, by emailing support@bruusolutions.com. We respond within 30 days.
California residents have the right to know what personal information is collected, to access, correct, and delete it, and not to be discriminated against for using these rights. We do not sell or share personal information as those terms are defined in California law.
If a request concerns information we process for a Merchant, we may refer it to that Merchant and help the Merchant respond.
Children
The Bruu Loyalty Engine is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has given us information, contact us and we will delete it.
Where the service is offered
The Bruu Loyalty Engine is offered to Merchants in the United States and stores data in the United States.
Changes to this policy
We may update this policy. We will post the new version on this page with a new "Last updated" date and notify Merchants of material changes by email or in the app.
Contact
Bruu Solutions LLC
420 Nichols Rd, 2nd Floor, Kansas City, MO 64112
support@bruusolutions.com