Privacy Policy
Premia is a loyalty platform for restaurants operated by Greenfield AI Tech. This policy explains what data we collect, why we collect it, who we share it with, and what rights you have over it. It is written in plain language because we do not believe legal terms should be obscure.
If all you want to know is who is allowed to message you and how to switch it off, go straight to section 4.
If you have questions or want to exercise your rights, write to us at privacy@premia.vip.
1. Who we are
Premia is a Greenfield AI Tech product. The venue you buy from — the operator — is the one who decides what it sends you and what it collects about its own customers: it is the controller of that data. Premia runs the platform on the venue’s behalf and on its instructions: we are the processor.
One part of it is ours. Your Premia account — your number, your language, your devices, and the fact that you belong to several programs at once — sits above any one venue, and there Greenfield AI Tech is a controller too. No venue sees another venue’s data, or the list of programs you belong to.
Exactly where one role ends and the other begins depends on the law that applies to you, and a lawyer can draw that line more finely than we can. What we can tell you precisely is who decides what, and that is what we just wrote.
2. What data we collect
2.1 If you are a venue’s customer (member)
- Identification: your WhatsApp number in E.164 format is your primary identity. Optionally: name, email, language, birthday.
- Transactions: each receipt you scan (photo + amount + merchant + date + items detected by the AI), points credited, redemptions made, current tier.
- Orders and reservations: what you ordered, how many people you booked for, at what time, and at which table. The venue sees this, because it is the one cooking it and seating you (section 5).
- Communications: the messages we send you via WhatsApp / SMS / email / push notification, their delivery status, and whether you opened them (where applicable). Also the messages you write to us on WhatsApp or in chat, including receipt photos.
- Your permissions: which programs you joined, when, under which version of the terms, and whether promotions are switched on or off. We keep that history because it is the proof that your permission exists and when you changed it.
- Session: if you sign in to the
/meportal, we store a signed httpOnly cookie for 30 days. We do not use third-party tracking cookies without your consent. - Device: if you install the app, we store the notification token your phone issues so we can send you an alert. That token belongs to the phone, not to a program — which is why a notification from any of your programs arrives on the same handset.
- Location, only to confirm you are at the venue: when you share live location on WhatsApp or check in from the app, we compare that point against the venue’s coordinates. Within about 150 metres it counts as a visit (300 metres for requesting a song at a bar). We store only the last known position, not a history of your movements, and we do not track you between visits.
2.2 If you are a venue operator
- Identification: email, name, role within the organization.
- Configuration: restaurants, rewards, points rules, templates, segments, branding.
- Audit: every administrative action (create a reward, adjust points, change a role) is recorded in the log with your identity, IP, and timestamp. The log is append-only and retained indefinitely for compliance.
2.3 If you are a courier (Premia Repartos app)
- Identity: name, phone, vehicle, and the access code you sign in with. No email or password required.
- Location while on shift: while your shift is open and the app is on screen, your position is sent every 30 seconds.
- Background location: only while you are carrying a delivery — it starts when you mark the order picked up and stops when you deliver it or close your shift. Your location is never tracked with the shift closed, nor during a shift in which you are not carrying an order. On Android a visible notification is shown the whole time it is active.
- Why: so dispatch can assign you the closest delivery and know where you are, and so the customer can see where their order is. A customer sees your dot only while their own order is on the way: never before, never after, and never for someone else's order.
- How long we keep it: position history is deleted automatically every month (only the current and previous month are kept). Separately we store your last known position, overwritten on every update.
- Deliveries and cash: the orders you carried, the (optional) delivery photos you take, and your cash movements (float received, collected, settled). The cash ledger is append-only because it is the account between you and the operator.
3. What we use it for
- Operate the loyalty program (earn points, redeem rewards).
- Handle what you asked for: take your order or your booking, tell you how it is going, send you the code to sign in, answer you when you write.
- Send you promotions and news from the venue you joined, for as long as you keep that permission switched on (section 4).
- Generate aggregate predictions for the operator (churn risk, LTV, next visit). The models are heuristic and are not shared outside the organization.
- Detect fraud (duplicate receipts, fake numbers).
- Meet the operating venue’s legal and tax obligations.
4. Your permission to message you
Premia sends two very different kinds of message, and the permission each one needs is different too. This section explains which is which, because it is what almost everyone actually wants to know.
4.1 Joining a program is the permission
When you join a venue’s loyalty program — by scanning its QR code, sending its join code on WhatsApp, or signing up in the app — that venue is allowed to send you its announcements and its promotions. It is not a buried permission: you are shown it as you join, before you join, and it is recorded together with the date and the version of the terms you accepted. The current version is 2026-09-10.
The permission is per program. Joining one venue’s program does not let any other venue write to you, even if both use Premia and even if the messages arrive on the same WhatsApp number.
4.2 Ordering or booking does not make you a member
If all you did was place an order or book a table, you are not a member for marketing purposes. You get the messages about that order or that booking — the confirmation, the status, the reminder — and nothing else. Nobody is going to send you a promotion because you ordered once. If you later want to join the program and start earning points, that is your call.
4.3 As a member you have two settings, not a long list
- «Notices about my orders and bookings» — always on. These are the replies to something you did: the code to sign in, the confirmation of your table, the status of your order, the points credited to you. It is not a toggle because switching it off would mean booking a table and never finding out whether you got it. If you do not want these messages, the way to not get them is not to place the order or the booking.
- «Promotions and news» — you control this one. Switch it on and off whenever you like, from your profile or from WhatsApp. Switching it off does not remove you from the program: you keep your points, your tier, and your coupons.
4.4 BAJA and ALTA on WhatsApp
Send BAJA (or STOP) on WhatsApp and we switch promotions off. Notices about your orders and bookings keep coming. Send ALTA and promotions come back on.
When the message arrives on Premia’s shared number, a BAJA applies to every program that number belongs to at that moment, and an ALTA switches them all back on the same way. Nobody should have to write BAJA four times because they eat in four different places.
4.5 What that switch stops, and what it does not
Switching «Promotions and news» off stops:
- the campaigns a venue sends to its customers;
- its automated rules, including the birthday greeting and we-miss-you messages;
- double-points alerts and other points promotions;
- congratulations for reaching a new tier;
- achievement nudges;
- the coupons and gifts a venue decides to grant you.
It does not stop — so these keep coming:
- sign-in codes;
- your booking confirmations and reminders;
- the status of your orders;
- points credited for a receipt or a visit;
- your points coming back when a coupon expires before you use it;
- the answer to something you wrote to us.
If what you want is for us to stop writing to you altogether and delete your account, you can ask for that at premia.vip/en/delete-account.
5. Who we share your data with
Premia runs as a layer on top of several external services. Each one has its own policy and processes data only for the function described.
- Twilio (US): sends and receives WhatsApp messages and SMS. This is the primary WhatsApp path. Receives your number and the message content.
- Meta / WhatsApp Cloud API (US/IE): a second, legacy WhatsApp path with the same data. Subject to WhatsApp’s policies.
- Google (US): reads your receipt photo. The image is sent to the Gemini model (
gemini-2.5-flash) through the Generative Language API, and the service returns the extracted text. - Google (US) and/or Anthropic (US): the conversational assistant you chat with. Which of the two answers depends on how the platform is configured, so we name both. It receives the text of the conversation and the data the assistant needs to answer you (your points balance, for example).
- Expo (US): delivers push notifications to the Premia apps. Receives your device token and the content of the notification.
- Resend (US): sending transactional and campaign emails.
- n8n self-hosted (Greenfield AI Tech): orchestrates the communications dispatcher. Data does not leave our infrastructure.
- Supabase (PostgreSQL, US — Oregon): our database. Isolated per organization via Row Level Security.
- Vercel (US): application hosting.
- Sentry (US/EU): error monitoring. Receives only stack traces and technical metadata — not message content or phone numbers.
- Venue integrations: if the operator configured outbound webhooks, events such as
transaction.validatedare sent to their system (for example, their POS or CRM). They only see events relating to their own organization.
What the venue sees. The venue you ordered from or booked with sees who is coming, for how many people, and what they ordered: that is the information the kitchen and the host work from. If you are a member of its program, it also sees your activity inside that program — points, redemptions, visits, receipts — and nothing you do at any other venue.
We never sell your data. We never share it with advertisers or marketing agencies. The only exceptions are legal obligations (court order, tax requirement).
6. How long we keep it
- While you are active: your data is kept while your account is active in any program.
- If you switch promotions off: we delete nothing. Your account, your points, and your tier stay as they are, and notices about your orders and bookings keep working. We do store the date you switched it off — precisely so we do not write to you again.
- If you ask us to delete your account: you can ask at premia.vip/en/delete-account or by email. We delete your data within 30 days, keeping only what tax law requires (for example, aggregate transaction amounts without personal identifiers).
- Audit: append-only logs are kept for 5 years for compliance requirements.
7. Your rights
You have the right to:
- Access: request a copy of all the data we hold about you.
- Rectification: correct incorrect data from your profile or by emailing us.
- Erasure: request that we delete your data (subject to legal exceptions), at premia.vip/en/delete-account.
- Portability: ask us for your data in a format you can open and take with you. Write to us and we will send it.
- Withdraw consent: switch «Promotions and news» off whenever you like, from your profile or by sending BAJA on WhatsApp (section 4).
- Object: object to processing based on legitimate interest (for example, profiling for predictions).
To exercise any of these rights, write to us at privacy@premia.vip from the email associated with your account, or from the WhatsApp number you joined with. We respond within 30 days.
8. Cookies
We use three types of cookies:
- Necessary (always on): session cookies (httpOnly), language preference, sidebar collapse state.
- Analytics (opt-in): help us understand which features are used. Anonymized. No individual tracking.
- Marketing (opt-in): we do not use any currently. Reserved for future integrations with explicit consent.
You can review and adjust your preferences from the banner that appears the first time you visit the site, or from the “Cookies” link in the footer. The cookie-by-cookie detail is in the cookie policy.
9. Security
- All connections use TLS 1.2+.
- Passwords and tokens are stored with SHA-256 + unique salts (argon2id reserved where applicable).
- Access to your data is limited to authorized staff of your organization, via RLS (Row Level Security) at the database level.
- No servers in countries that do not meet minimum standards (all in US/EU).
- Continuous auditing of administrative changes.
If we detect a security breach that affects you, we notify you within 72 hours, per GDPR article 33.
10. Minors
Premia is not directed at minors under 16. If we discover that a member is a minor without verifiable parental consent, we delete the account without delay.
11. International transfers
Almost all of our processors (Twilio, Meta, Google, Anthropic, Expo, Resend, Supabase, Vercel, Sentry) are in the United States. Where applicable, transfers are made under the EU’s Standard Contractual Clauses (SCCs).
12. Changes to this policy
If we change the policy, we notify you through your active channel (WhatsApp by default if you are a customer, email if you are an operator) with 30 days’ notice when the change is material.
This policy goes hand in hand with the terms of service, which carry a version. The current one is 2026-09-10, and when you join a program we record which version was in force at that moment — so it is always possible to say what exactly you accepted, and not only what today’s text says.
13. Contact and supervisory authority
Questions or complaints: privacy@premia.vip. If you are not satisfied with our response, you can escalate to the data protection authority in your country (in Costa Rica, PRODHAB; in Mexico, INAI; in the EU, your national authority). Nicaragua has no functioning data protection authority today, so if you are there, write to us first.