Privacy
What we store. Why we store it. Who never sees it.
Last updated 2026-09-03. Written to be readable, not to hide the answer.
En español
Privacidad, en resumen
Puedes leer el libro sin cuenta: no guardamos en nuestros servidores nada que te identifique. Tu punto de lectura y tus copas hechas viven en tu propio dispositivo. Si entras con tu correo, guardamos lo mínimo para recordar por dónde ibas en cualquier dispositivo y que ya has pagado.
No vendemos tus datos, no usamos rastreadores publicitarios y nunca vemos tu tarjeta. Si aceptas recibir novedades, puedes darte de baja cuando quieras.
El responsable del tratamiento es Kai Kran AS, Blokkaveien 1c, 0282 Oslo, Noruega. Puedes pedirnos que te enseñemos, corrijamos, exportemos o borremos lo que tenemos escribiendo a privacy@bartendercheatcode.com. Tienes todos los derechos que te da el RGPD, y puedes reclamar ante tu autoridad de protección de datos, que en España es la Agencia Española de Protección de Datos.
El texto completo está debajo, en inglés, y es el que tiene valor legal. Este resumen está aquí para que sepas lo que dice.
The short version
Read the book without an account and we store nothing that identifies you on our servers. Sign in with your email and we store the minimum needed to save your place across devices, and to remember that you paid. The course is different, and deliberately so: a credential has to carry a name, so enrolling on the course means giving us your name and email, and a passed examination is recorded against them. The section below says exactly what that means. We do not sell your data, we do not run advertising trackers, and we never see your card. If you choose to hear from us, we send occasional news and offers — and you can unsubscribe at any time.
Who is the data controller
Kai Kran AS, Blokkaveien 1c, 0282 Oslo, Norway, organisation number 998235065, VAT NO998235065MVA, is the data controller for the personal information the universe collects. Contact: privacy@bartendercheatcode.com.
What we collect, when
Reading without an account
- Nothing that identifies you is sent to our servers.
- Your reading position, your claimed drinks and your log live on the device you use, in local storage. Clearing site data on your browser erases them.
- On the course, your browser makes up one random string for itself and we record it against your seat, so we can see how many browsers a seat has been opened on. It is not a fingerprint and it says nothing about you, your device or where you are: it is a number we look at when a single seat is being shared widely. Clearing site data erases it, and your browser is then counted as a new one.
- Server logs may hold the usual technical breadcrumbs (IP address, browser, requested page) for a short window, for security and debugging. These are not tied to a person.
Once you sign in with a magic link
- Your email address, used as the account key.
- Your reading position, claimed drinks, coaster state, log and the fact that you paid (yes or no). This is the account row that lets your place follow you across devices.
- The timestamp of the last update to your account row.
- If you opt in to the supporters wall: a chosen username and your consent to that opt-in. Not your real name unless you type it as the username.
Once you buy
- The purchase record: transaction ID, amount, currency, country, purchase date, and the fact that you gave the required immediate-access consent at checkout. This lives on our side.
- Payment card details never touch our servers. Paddle handles the card end to end. We only see that a transaction completed.
The Bartender’s Cheat Code Course
The course cannot work the way the book does, because a credential with no name on it certifies nobody. From the moment you enrol we hold, on our servers:
- Your name and email, given at the course door. The name is the one that will appear on your credential. Lawful basis: performance of the contract, because the course is the issuing of a named credential and it cannot be delivered without a name.
- Your progress through the course, which stays on your device in local storage, exactly like the book.
- A record of every final examination you sit: your name, your email, the date, your score, whether you passed, an identifier for that particular paper, how long you spent on each question, and which attempt of the day it was. We keep this so a result can be reissued, checked, or corrected if it is ever disputed.
- If a venue bought your seat: the fact that the seat is held by your name and email, and the email address of the buyer, so the seat can be accounted for and so an unopened seat can be given to somebody else.
The credential is public, and that is the point
A pass issues a credential with a verification link. Anyone holding that link sees the name on the credential, the level, the date and the score. That is what makes it checkable by an employer, and it is the reason the credential is worth holding. It is published because you asked for a credential, which is the contract you entered.
The link carries no email address and no other personal detail. It is not indexed and not listed anywhere; it is found only by being given. If you would rather your credential were not reachable at all, write to us and we will withdraw it. Withdrawing it removes the credential; it does not undo the fact that you passed, and we will confirm your result to you privately on request.
The course does not talk to the guide
The in-app guide is part of the book. Nothing you type inside the course is sent to a model provider.
The guide's conversations
When you talk with the guide, the last few turns of the conversation are sent to the model provider so the guide can answer. We do not store the transcript on our side unless we tell you so on that page. The provider processes the turn to answer, and the standing rule with the provider is that your text is not used to train a model.
Marketing emails and the audience list
Separate from your account and the course, we keep an audience list — the people we may contact. Here is exactly how it works.
- When you buy, or ask us for something (such as the course offer from the venue quiz), we add your email to our contact list. On its own this is transactional only: a record of our relationship, and we do not send you marketing unless you opt in.
- Marketing goes only to people who opt in. Ticking the consent box is your consent, under GDPR Article 6(1)(a), to receive relevant industry information, news and offers from The Bartender’s Cheat Code and the Cocktail Club universe. In the EU, the UK, India and other countries that require it, that box is never pre-ticked; only where the law allows an opt-out model, such as the United States, may it be pre-ticked, and you can always untick it.
- The Cocktail Club is a separate company. The Cocktail Club universe is operated by Quenched AS, a separate Norwegian company founded by the same person as this site but with its own shareholders. If you opt in, your consent lets us share your contact details with Quenched AS so the Cocktail Club can send you relevant messages too. Quenched AS receives nothing unless you opt in, you can withdraw at any time, and neither company sells your data or shares it with advertising networks.
- You can stop at any time. Every marketing email carries an unsubscribe link, and you can unsubscribe whenever you like at bartendercheatcode.com/unsubscribe. It takes effect immediately; account and purchase emails still reach you. We keep a short suppression record of your unsubscribe so we never email you again by mistake.
- What we store for this: your email, your name if you gave it, the source and date, your consent state and when it was given, your country at the time (for the consent rules), and your unsubscribe state — nothing more.
Who we share it with, and why
- Supabase (EU region), for the account row, authentication and cross-device sync. Sub-processor.
- Paddle, as merchant of record for the sale, for the payment, receipt and tax. Sub-processor.
- Cloudflare Turnstile, for the sign-in bot check, when it is enabled. Sub-processor.
- Vercel, for hosting the pages. Sub-processor.
- Resend, for the emails we send you: your seat codes, the message that confirms you have passed, your sign-in link, and — only if you have opted in — our marketing emails. It receives the address it sends to and the contents of that message. Sub-processor.
- Quenched AS (the Cocktail Club), a separate company and its own data controller, for Cocktail Club marketing — and only if you have opted in to hear from the Cocktail Club universe.
- Model provider for the guide, when you talk to the guide. Sub-processor.
We do not sell your data. We do not share it with advertising networks. We do not run third-party trackers on the reading pages.
Where the data sits
The account row lives on Supabase, hosted in the EU (Stockholm). Paddle stores the transaction record in its own systems. Some sub-processors may process data outside the EU/EEA; where they do, they operate under standard contractual clauses or the equivalent legal safeguard.
How long we keep it
- Account row: for as long as your account exists. Delete the account and we delete the row.
- Purchase record: for as long as the law requires us to keep it for tax and accounting, typically several years.
- Examination record: for as long as the credential is meant to be checkable, so that a certificate someone shows can still be verified years later. Ask us to withdraw a credential and we mark it withdrawn and stop showing the name at its link.
- Seat record: for as long as the seat exists, so a venue can account for what it bought.
- Marketing contact: until you unsubscribe. After that we keep only a short suppression record, so we do not contact you again by mistake.
- Server logs: a short window measured in days, then rotated out.
Your rights (EU/EEA)
Under the GDPR you can ask us to:
- Show you what we hold about you.
- Correct anything that is wrong.
- Delete your account and personal data.
- Export the account row in a portable format.
- Object to any processing you disagree with.
- Withdraw your consent to marketing at any time — untick the box, use the unsubscribe link, or write to us. Withdrawing does not affect anything done before.
- Complain to your national data protection authority. In Norway that is Datatilsynet.
Ask any of the above by writing to privacy@bartendercheatcode.com. A person reads that inbox. For the course, that includes asking us to withdraw a credential so the name stops appearing at its verification link.
Cookies and local storage
We use local storage on your device to remember your reading position and your claims. That is not a cookie. Once you sign in, a Supabase session cookie is set on your device so the pages remember you across visits. Paddle sets its own cookies inside its checkout when it opens; those are governed by Paddle's own policy.
Children
The universe teaches cocktails. It is not for children, and it is not directed to anyone below the legal drinking age where they live.
Changes to this page
When we change what we do with your data in a way that matters, we update this page with a fresh date and email account holders whose accounts are still active.
Data controller