PineappleOrangeJuice.com

Privacy Policy

Effective date: September 4, 2026  ·  Version: 1.5  ·  Controller: Pineapple Orange Juice, LLC (Delaware, USA)

This Privacy Policy explains how Pineapple Orange Juice, LLC collects, uses, shares and protects personal information in connection with PineappleOrangeJuice.com. It covers two different relationships, and which one applies to you determines your rights and who you should contact.

Which part applies to you?

If you booked an experience at a venue — the venue is the controller of your information and decides how it is used. We are its processor and act on its instructions. Read Section 3, then direct requests about your information to the venue. See Section 11.

If you run a business that subscribes to our software — we are the controller of your account, billing and support information. Read Section 2 and Section 11.

Contents
  1. Scope and roles
  2. Information we collect as controller
  3. Information we process as processor
  4. The AI Phone Operator
  5. Cookies and similar technologies
  6. How we use information
  7. US availability and processing roles
  8. Sharing and disclosure
  9. International transfers
  10. Retention
  11. Your rights
  12. US state privacy rights
  13. Children
  14. Security
  15. Data breaches
  16. Automated decision-making
  17. Changes
  18. Contact and complaints

1. Scope and roles

PineappleOrangeJuice.com is booking software licensed to experience businesses such as escape rooms (“Venues”). Each Venue has an isolated workspace.

SituationOur roleController
A Venue’s guest, booking, participant, waiver, message and call dataProcessorThe Venue
Venue account, staff logins, subscription and billing recordsControllerUs
Our marketing site, sales enquiries and support correspondenceControllerUs
Security, abuse-prevention and audit logs about use of the platformControllerUs

Where we act as processor, we process information under our agreement with the Venue and its documented instructions, subject to applicable law.

2. Information we collect as controller

2.1 Business account information

When a Venue registers we collect the business name, the owner’s name, a business email address and the business timezone. Within the workspace a Venue may add a business phone number, mobile number, website, postal address, locale and currency.

2.2 Staff account information

For each staff account: email address, display name, assigned role, active status, a securely hashed password (hashed with bcrypt — we never store passwords in readable form) and the date of last sign-in.

2.3 Subscription and billing information

Our payment processor Stripe collects and holds payment card details. We receive and store a Stripe customer identifier, a subscription identifier, subscription status, the current billing period end date, whether cancellation is scheduled, and a record of billing events we have processed. We do not receive or store card numbers, expiry dates or security codes.

2.4 Security and abuse-prevention records

We record sign-in attempts, password-reset requests and signup attempts. To avoid storing more identifying information than necessary, the email address or IP address involved is stored only as a keyed cryptographic hash, together with the outcome and timestamp.

2.5 Platform administration records

Lifecycle actions taken by our platform administrators — for example suspending or reactivating a workspace — are written to an audit log with the administrator identity, the workspace, the action, the reason and a timestamp.

2.6 Technical information

Our hosting provider and application logs record IP addresses, request paths, timestamps, user-agent strings and error diagnostics, generated automatically when you use the Service.

2.7 Correspondence

If you contact us for support, sales or legal reasons we keep the correspondence and its contents.

3. Information we process as processor for Venues

The categories below are determined by each Venue’s configuration. We hold them on the Venue’s behalf and do not use them for our own purposes.

3.1 Guest and booking records

3.2 Participant and waiver records

3.3 Payment records

We store the payment provider used, the amount and currency, the payment status, provider reference identifiers, refund records and any provider failure message. No payment card data passes through or is stored by the Service. Guests are redirected to the provider’s own hosted checkout page.

3.4 Communications

For each message sent we retain the recipient address, subject, a snapshot of the message body as sent, the scheduled and actual send times, the number of delivery attempts, delivery status and any error returned by the email provider. A Venue may also connect a marketing-audience provider. In that case, the booking form presents an optional, unchecked marketing-email consent box. If a guest affirmatively selects it, we retain the consent time, source and wording and may send that guest’s contact details to the provider selected by the Venue. We do not add guests who leave the box unchecked. Provider unsubscribe and cleaned-address notices are applied to the Venue’s guest record, and we do not automatically resubscribe a guest who has unsubscribed. This marketing choice does not affect booking, payment, security or other transactional messages.

3.5 Self-service links

Booking emails contain an expiring signed link that lets a guest view their bookings, update contact details, open waivers, reschedule and cancel within the deadlines the Venue sets. The link contains a cryptographically signed token, not a password. The link expires after 90 days. Anyone in possession of the link can use it until it expires, so guests should treat these emails as confidential.

3.6 Guest photos

Where a Venue enables Guest Photos, authorised staff may attach customer-approved photographs to a specific booking and customer history through the Venue workspace or the POJ Photos companion app. We process the image, caption, sharing choice, consent-confirmation time, uploader identity, file size and dimensions, and configured retention date on the Venue’s behalf. Photos selected for delivery are made available to the booking customer through a private, expiring gallery. The companion app stores its access token in the iOS Keychain and may keep a protected local copy of an image while an upload is pending; the app does not use photos for advertising or tracking.

3.7 Telephone records

See Section 4.

4. The AI Phone Operator

Venues may subscribe to an optional add-on that answers their telephone line with an automated conversational assistant. Where a Venue has enabled it:

4.1 Disclosure

Every call begins with a spoken disclosure that the caller is speaking with an automated booking assistant, before any information is collected. The time at which the disclosure was given is recorded.

4.2 We do not record call audio

We do not intentionally record or retain call-audio files.

Live audio is transmitted through our telecommunications and speech-processing providers so the call can operate and speech can be transcribed. We retain the written transcript and call records described below, not a playable audio recording. Provider processing is governed by our current service configurations and agreements.

4.3 What is stored about a call

DataDetail
Caller numberStored in masked form for display, and as a keyed cryptographic hash and a normalised lookup value used to match the caller to an existing booking. The full number is not displayed in the interface.
Written transcriptCaller and assistant turns with timestamps, capped at the most recent 64 entries. On a long call the earliest turns are not retained.
Call metadataStart, answer and end times, duration, status, outcome and disclosure timestamp.
Action auditA record of each action the assistant took or was refused, with minimised inputs: for example the last four characters of a booking reference, a masked callback number, or the verification method used.
Verification challengesWhere a caller verifies by email or text code, a keyed hash of the target and of the code, plus timestamps. The code itself is not stored in readable form.
Usage recordsBillable seconds and minutes per call.

4.4 The AI model provider

Conversation text is sent to an AI model provider to generate replies. We configure eligible requests to disable provider storage and model training where the provider supports those controls, and periodically verify the applicable configuration and contractual terms. We do not intentionally send payment-card data to the model, and the assistant is instructed never to collect or repeat payment-card details. Current provider information is available on request.

4.5 Emergencies

If a caller says something the system identifies as indicating an emergency, the assistant immediately ends the call and tells the caller to contact emergency services. That turn is written to the transcript. The Service is not an emergency service and must not be relied on to summon assistance.

4.6 Caller-identification verification

A Venue may optionally choose to treat a matching inbound caller ID as verification of a caller’s identity. Caller ID can be spoofed. Where a Venue enables this, it accepts responsibility for that decision, and it may permit a caller presenting a matching number to view limited booking details and perform certain changes without a one-time code.

5. Cookies and similar technologies

We use strictly necessary storage for the application. On our public marketing, signup and subscription-conversion pages, Google Tag Manager, Google Analytics and Google Ads measurement load with analytics and advertising storage denied by default. In that state, Google may receive cookieless measurements used for aggregate reporting and conversion modelling. With a visitor’s optional permission, Google analytics and advertising storage are enabled to measure visits, signup progress and advertising performance. We may then retain campaign parameters, the original landing page, referring domain, a Google Analytics client identifier and Google advertising click identifiers (such as GCLID, GBRAID or WBRAID) with a business signup so we can understand which advertising led to a trial or paid subscription.

CookiePurposeLifetime
staff_sessionKeeps a signed-in staff user authenticated. Marked HttpOnly, Secure and SameSite=Lax.8 hours
platform_sessionKeeps a platform administrator authenticated. Marked HttpOnly, Secure and SameSite=Strict, and scoped to the administration path only.4 hours

PineappleOrangeJuice platform advertising measurement is limited to our eligible marketing, signup and subscription-conversion pages and is not used to measure a Venue’s public booking pages, embedded booking widgets or tenant operations pages. We do not use guest booking data for our own advertising. Selecting “Use necessary only” or sending a recognised Global Privacy Control signal keeps Google analytics and advertising storage denied; POJ does not retain campaign identifiers in browser storage in that state. Cookieless aggregate measurements may still be sent from an eligible page. Visitors may reopen Privacy choices on an eligible page at any time.

Google may receive online identifiers and activity from an eligible page when optional tracking is allowed, and may receive cookieless measurement signals when storage remains denied. We do not sell personal information for money. Depending on applicable law and the enabled advertising configuration, this disclosure may be treated as sharing for targeted or cross-context behavioural advertising; where an opt-out right applies, the privacy choice and recognised browser signal are treated as an opt-out.

6. How we use information

As controller we use information to: create and administer accounts; authenticate users; take payment and manage subscriptions; provide support; secure the Service and prevent fraud and abuse; monitor and improve performance and reliability; measure which marketing campaigns lead to business trials and subscriptions; comply with legal obligations; and communicate service and billing notices. We may send product announcements to Venue owners; you may opt out of non-essential announcements at any time, but not out of service, security and billing notices while your account is active.

As processor we use information only to provide the Service to the Venue and on the Venue’s instructions: displaying availability, creating and managing bookings, taking payment through the Venue’s provider, sending the Venue’s notifications, generating waivers and reports, and operating the telephone assistant.

We do not sell personal information for money. We do not use guest data for our own marketing, and we do not use Venue or guest data to train our own machine-learning models.

7. US availability and processing roles

The Service is currently offered to businesses operating in the United States. We process Venue account data as described in this Policy and process Customer Data on the Venue’s documented instructions under the Terms of Service. A business must not use the Service for operations outside the United States or intentionally submit data subject to a non-US processor agreement unless we first agree in writing to the required contractual and transfer terms.

8. Sharing and disclosure

8.1 Sub-processors

We share personal information with service providers that support hosting, payment processing, transactional email delivery, tenant-selected marketing-audience management, telephony and AI-assisted conversations. A marketing provider receives guest contact information only when the Venue enables the integration and the guest has affirmatively opted in. We require providers to protect the information they receive and to process it only for the contracted service. Current information about these providers, their function and the categories of data they receive is available by contacting staff@pineappleorangejuice.com.

8.2 Between Venues

We do not share data between Venues. A guest who books at two Venues has two separate records, and neither Venue can see the other’s relationship with that person.

8.3 Legal and safety disclosures

We may disclose information where required by law, subpoena, court order or other legal process, or where we reasonably believe disclosure is necessary to protect the rights, property or safety of Pineapple Orange Juice, our customers or the public. Where we are legally permitted, we will notify the affected Venue before disclosing data we hold on its behalf, so it can seek protective relief.

8.4 Business transfers

If we are involved in a merger, acquisition, financing or sale of assets, information may be transferred as part of that transaction. We will give notice before personal information becomes subject to a materially different privacy policy, and the recipient will remain bound by commitments at least as protective.

8.5 What we never do

We do not sell personal information for money, disclose it to data brokers, use guest booking data for our own advertising, or permit one Venue to access another Venue’s Customer Data. Optional platform marketing disclosures are described in Section 5 and are controlled by the visitor’s privacy choice.

9. International transfers

We are based in the United States, and application data is hosted and processed in the United States. The Service is offered only to businesses operating in the United States and does not currently include an EEA, UK or other international data-processing addendum or regional storage option. We will establish the required contractual, subprocessor and transfer arrangements before authorising operations in additional countries.

10. Retention

Retention periods, and the limits of what the Service currently deletes automatically, are set out in full in our Data Retention Policy, which forms part of this Privacy Policy. In summary: security and rate-limiting records are kept for short fixed periods; password reset and verification codes expire in minutes; call transcripts are deleted on the schedule the Venue configures; and booking, customer, waiver and payment records are retained for as long as the Venue’s workspace is active, and then for a limited wind-down period; guest photos are deleted on the Venue-configured schedule; after closure, subject to legal retention requirements.

11. Your rights

11.1 If you booked at a Venue

The Venue is the controller of your information. Please contact the Venue directly to access, correct, delete, restrict, object to or port your data. If you contact us instead, we will use the information you provide to make a reasonable attempt to route the request to the appropriate Venue without exposing another Venue’s records. We cannot guarantee identification from incomplete information and cannot act on Customer Data without the controlling Venue’s instruction unless required by law.

11.2 If you are a Venue or a staff user

Subject to applicable law, you may ask us to: confirm whether we hold personal information about you and give you a copy; correct inaccurate information; delete information; restrict or object to processing; receive information in a portable format; and withdraw consent where processing is based on consent, without affecting prior processing.

11.3 How to exercise rights

Email staff@pineappleorangejuice.com. We will verify your identity, usually by requiring you to respond from the address on file or to confirm details only the account holder would know. We will respond within the period required by applicable law. For verified California requests to know, access, correct or delete, this is generally 45 calendar days, with a permitted extension and notice where applicable.

11.4 No discrimination

We will not deny service, charge a different price or provide a different quality of service because you exercised a privacy right.

12. United States state privacy rights

If you are a resident of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana or another state with a comprehensive privacy law, you may have rights to know, access, correct, delete, obtain a portable copy, opt out of sale or targeted advertising, and limit the use of sensitive personal information. Exercise them as described in Section 11.3.

Sale, sharing and targeted advertising. We do not sell personal information for money. If optional platform advertising technology constitutes sharing or targeted advertising under applicable law, you may opt out by selecting “Use necessary only” in Privacy choices or by using a recognised Global Privacy Control signal. POJ platform advertising tags are not used on Venue booking, embedded-booking or tenant operations pages.

Sensitive personal information. We do not use or disclose sensitive personal information for purposes beyond those permitted without a right to limit.

Categories. The categories of personal information we collect, the sources, purposes and categories of recipients are described in Sections 2, 3, 4, 6 and 8. Current provider details are available on request.

Authorised agents. You may use an authorised agent, who must provide proof of authorisation; we may also contact you to confirm.

Appeals. If we decline a request, you may appeal by replying to our decision with the word “Appeal”. We will respond within 45 days. Residents of some states may also contact their Attorney General.

13. Children

The Service is intended for use by businesses and by adults making bookings. We do not knowingly collect personal information directly from children.

The Service does allow a Venue to record participants who are minors on a booking roster, and to capture a guardian’s signature on a waiver. That information is provided by the booking adult or by the guardian, not collected from the child. Where we hold it, we hold it as processor for the Venue, which is responsible for having a lawful basis and any required parental consent, and for the content of its waiver.

If you believe a child’s information has been provided to us in a manner that requires deletion, contact staff@pineappleorangejuice.com and we will work with the relevant Venue to address it promptly.

14. Security

We maintain administrative, technical and organisational safeguards designed for the nature of the Service. These include access controls, tenant-scoped authorisation, encryption in transit, protected credential storage, rate limiting, webhook verification, audit logging, backups and recovery procedures. Implementation details may change as controls are improved and are tested and documented through our engineering and operations processes.

No system is completely secure. We cannot guarantee absolute security, and you are responsible for the strength and confidentiality of your credentials.

15. Data breaches

If we become aware of a personal data breach affecting information we hold as processor, we will notify the affected Venue without undue delay and provide available information reasonably needed for the Venue’s notification duties. Where we act as controller, we will notify affected individuals and regulators within the time and in the manner required by applicable law.

Report a suspected vulnerability or incident to staff@pineappleorangejuice.com. We will acknowledge it as soon as reasonably practicable. We will not pursue legal action against good-faith security researchers who report privately and do not access or alter data beyond what is necessary to demonstrate the issue.

16. Automated decision-making

The Service uses automated processing for scheduling rules, fraud and abuse controls, communications and optional AI-assisted conversations. POJ does not use these systems on its own behalf to make employment, credit, housing, insurance or other decisions intended to produce legal or similarly significant effects about individuals.

The AI Phone Operator uses an automated system to hold a conversation and, where the Venue has enabled it, to create or change a reservation. It operates within server-enforced limits: it can act only on a booking already verified during that call; it cannot take a reservation, reschedule, cancel or send a payment link without a caller’s separate explicit spoken confirmation; and it cannot access any other Venue’s data. A caller may ask to speak to a person at any time, and where the Venue has configured and enabled transfer during staffed hours, the call is transferred.

17. Changes to this Policy

We may update this Policy. We will change the effective date above and, for material changes, give notice by email to Venue owners and by notice in the workspace at least 30 days before the change takes effect. Previous versions are available by contacting staff@pineappleorangejuice.com.

18. Contact and complaints

Pineapple Orange Juice, LLC
8 The Green STE A, Dover, Kent County, DE 19901, United States
Privacy: staff@pineappleorangejuice.com
Security: staff@pineappleorangejuice.com

The Service is initially offered only to businesses operating in the United States. We will update this Policy, including any required regional contacts, before offering the Service in additional countries.