Pocketful

Privacy policy

Last updated: 2026-09-24

Who we are

Pocketful AI, Inc. (pocketful.ai), a Delaware corporation, builds software for restaurants and businesses: digital menus, loyalty cards, a customer link page and Pocket, an AI assistant for owners. Contact: hello@pocketful.ai.

What we collect

Business accounts: name, email, password (hashed) or Google/Apple sign-in, and the business data you enter (menus, prices, addresses, campaigns). Customers of our businesses: what they give when joining a loyalty program (name, email or phone), Wallet pass and web-push identifiers, and menu visit logs. WhatsApp: when you message Pocket on WhatsApp we receive your phone number, profile name and the messages you send, so we can answer. Website: basic analytics and the contact form contents.

How we use it

To provide the service you asked for: answer your questions, show your sales data, run your loyalty program and send the notifications you or the business set up. We may also use de-identified or aggregated data to improve Pocketful, including our machine learning and statistical models. We do not sell personal data and do not use it for advertising.

Who processes it

Hosting on Amazon Web Services (United States); AI answers by our language-model provider, which receives the conversation to generate a reply; messaging by Meta (WhatsApp Cloud API) and Apple (Wallet); error monitoring by Sentry; email by Amazon SES and Google. Each processes data only to provide its part of the service. Because these services are in the United States, your data is transferred outside your country; by using Pocketful you consent to that transfer.

How long we keep it

While your account or the business's program is active. Conversations and logs may be kept up to 12 months for support and security, and backups for 30 days.

Your rights

You can ask to access, correct or delete your data, or unlink your WhatsApp number, by writing to hello@pocketful.ai. We answer within 30 days. Customers of a business may also ask that business directly.

Security

Data travels encrypted (HTTPS), credentials are hashed or encrypted at rest, and access is limited to the people who operate the service.

Changes

If this policy changes we will update this page and the date above.