Last updated: 11 April 2026
Privacy Policy
Effective Date: 25 September 2026 Last Updated: 25 September 2026
BTLR (“we”, “our”, “us”) operates a lifestyle personalisation and guest experience platform. You tell BTLR what you like; BTLR helps venues, butlers and experiences serve you accordingly, and only ever on terms you control.
This policy explains what we collect, why, who sees it, and what you can do about it. It applies to the BTLR mobile app and the services behind it (the “Service”).
1. Who we are
BTLR is the controller of the personal data described here. For anything in this policy, including data-subject requests, contact Admin@btlr.vip.
Where a venue (“Space”) uses your data for its own purposes beyond serving you through BTLR, that venue is a separate controller and its own privacy notice applies.
2. What we collect
2.1 Account and identity
Name, preferred name, salutation, email address, phone number, country of residence and country of birth, date of birth, language preferences, your BTLR tag, and a profile photo if you add one.
Alias profiles. You may create additional personas under one account. An alias has its own name, photo, tag and preferences, and is protected by a PIN. Aliases let you keep contexts separate; they are not anonymity from us, and they inherit your account’s email, country and date of birth.
2.2 Preferences and the preference graph
The things you tell us you like, dislike, need or avoid — food, drink, hospitality, travel, entertainment, home, accessibility needs and so on. You can provide these by typing or speaking to the in-app assistant, by uploading photographs, or by accepting suggestions.
We store these as a structured graph rather than free text, so that a venue can be told “seafood, no shellfish” without being handed your conversation.
2.3 Special category data
Some preferences reveal information that data-protection law treats as sensitive — for example dietary requirements that imply a religion, allergies or health conditions, accessibility needs, or preferences that imply sexual orientation.
We process this only with your explicit, separate consent, which you give and can withdraw in the app at any time. Withdrawing it stops further processing and queues the erasure of the affected data from our systems, including the AI knowledge graph. See §4.
2.4 Location, Bluetooth and presence
With your permission, the app uses Bluetooth beacons and geofences to detect when you arrive at, move around within, and leave a participating venue.
Concretely, this means we collect: the identifiers of BTLR beacons your device detects and their signal strength, your device’s approximate position when a detection occurs, which touchpoint (bar, spa, reception, table area) you are at or near, and the times you arrive and leave.
This is the core of how BTLR works — it is what lets a venue know you have arrived without you announcing yourself. You can refuse or revoke location and Bluetooth permission at any time in iOS Settings. Venue detection stops; the rest of the app continues to work.
We do not track your location when you are not near a participating venue, and we do not build a general movement profile of you.
2.5 Communications
Messages you exchange with the in-app AI assistant, with a butler, with venue staff, and — if you use SocialMatch — with other guests. Also voice input you choose to record, which is transcribed on your device.
Messages are not end-to-end encrypted. We analyse the content of your conversations to extract preferences, because that is the product. They are encrypted in transit and at rest, and access is restricted as described in §5.
2.6 Bookings and payments
Butler bookings, subscriptions, gifts, tips and their history.
Card details are collected and stored by Stripe, our payment processor. We never see or store your full card number. We retain the transaction record, amount, currency, and Stripe’s reference.
2.7 Device and technical data
Device type, operating system version, app version, a device identifier used to bind your session, push-notification tokens, IP address, and diagnostic logs (access times, errors, feature usage).
3. Why we use it, and our legal basis
| What we do | Legal basis (UK/EU GDPR) |
|---|---|
| Create and run your account | Performance of a contract |
| Store your preferences and build your preference graph | Performance of a contract |
| Process special category preferences | Explicit consent (Art. 9(2)(a)) |
| Detect your presence at a venue via beacons | Consent (device permission), then contract |
| Share preferences with a venue or butler you are engaging | Performance of a contract, on your instruction |
| Introduce you to other guests via SocialMatch | Consent — off by default |
| Take payment, bill subscriptions, issue refunds | Performance of a contract |
| Send service and booking notifications | Performance of a contract |
| Send marketing | Consent, withdrawable at any time |
| Keep the platform secure and prevent fraud | Legitimate interests |
| Improve the Service and fix faults | Legitimate interests |
| Meet legal, tax and accounting obligations | Legal obligation |
Where we rely on consent, you can withdraw it at any time without affecting processing already carried out.
4. Automated processing and AI
BTLR uses artificial intelligence to read what you tell it and turn it into structured preferences, to summarise your preferences for a venue or butler, and to suggest experiences.
- Your content is processed by AI models operated by us and by third-party model providers acting as our processors under contract.
- We do not make decisions with legal or similarly significant effects about you by automated means alone. Nothing in BTLR decides your credit, your employment, or your access to a service without a human involved.
- Summaries shared with venues use a pseudonymous identifier, not your name. Your real name is revealed only where you are dealing with that venue or butler directly.
You can ask us for a human review of any automated summary that you think misrepresents you, and you can edit or delete any individual preference.
5. Who we share it with, and what they see
Venues (Spaces) you engage with. When you are at, or booked into, a participating venue, it may see the preferences relevant to serving you and the fact of your presence. It sees a pseudonymous identifier and the preferences you have shared — not your whole graph. You choose what is shared, per venue, and can change it.
Butlers. A butler you have booked can see the preferences relevant to your session and can exchange messages with you. A butler’s access is limited to the booking: before the session starts they can message you and nothing more; the wider view of your engagements opens only once the session begins, and closes when it ends.
Other guests, via SocialMatch only. SocialMatch is off unless you turn it on. When on, other guests at the same venue may be shown that you share an interest, and may be introduced to you. They see the persona you are using and what you have agreed to share — never your contact details.
Service providers (processors). Cloud hosting and databases, AI model providers, Stripe for payments, push-notification delivery, email delivery, error monitoring. They act on our instructions under contract.
Others. Where the law requires it, to protect rights and safety, or as part of a merger or acquisition (we will tell you if that happens).
We do not sell your personal data, and we do not share it for third-party advertising.
6. Children and young people
BTLR is not intended for children under 13, and we do not knowingly collect their data.
Users under the age of majority in their jurisdiction are treated as minors in the Service. A minor cannot enable SocialMatch without the verified approval of an adult guardian, given through the app. Certain features are restricted for minors regardless of consent.
If you believe a child has given us personal data, contact Admin@btlr.vip and we will delete it.
7. How long we keep it
| Data | Retention |
|---|---|
| Account and profile | While your account is open |
| Preferences and preference graph | While your account is open, or until you delete them |
| Special category data | Until you withdraw consent, then queued for erasure |
| Venue engagement and presence records | Condensed into summaries after a rolling window, then deleted |
| Chat messages | Retained for the conversation’s lifetime, then archived or deleted per the surface |
| Inactive alias profiles | Deleted after a period of non-use; we warn you first and you can keep it |
| Bookings, payments, invoices | As required by tax and accounting law (typically 7 years) |
| Diagnostic logs | Short rolling window |
When you close your account we delete or irreversibly anonymise your personal data, except where we must keep records by law — financial records in particular.
8. Your rights
Depending on where you live, you have the right to: access your data; correct it; delete it; restrict or object to processing; withdraw consent; receive your data in a portable format; and complain to your data-protection authority (in the UK, the ICO; in the EU, your national authority).
Most of these you can exercise directly in the app — view and edit preferences, control per-venue sharing, withdraw special-category consent, delete an alias, or close your account. For anything else, contact Admin@btlr.vip. We respond within one month.
9. Where your data is held
BTLR operates regionally. Your data is held in the region associated with your country of residence wherever we can do so.
Some processing necessarily crosses borders — for example when you travel and engage a venue in another region, or where a processor operates globally. Where that happens we rely on appropriate safeguards, such as UK/EU standard contractual clauses, and we minimise what crosses by sharing pseudonymised summaries rather than raw data wherever possible.
10. Security
Encryption in transit and at rest; row-level access controls in the database so one account cannot read another’s; restricted and audited staff access; device-bound sessions; and support for passkeys instead of passwords.
No system is perfectly secure. If a breach affects your rights we will notify you and the relevant authority as the law requires.
11. Changes to this policy
We will update this policy as the Service changes. Where a change is material we will tell you in the app before it takes effect. The “Last Updated” date above always reflects the current version.
12. Contact
Email: Admin@btlr.vip Web: www.btlr.vip
If you are in the UK or EU and are unhappy with our response, you may complain to your data-protection authority.