berthcast
Pricing Contact Sign in
Legal

Privacy Policy

Last updated: 10 July 2026 · Effective: 10 July 2026
On this page
  1. Who we are
  2. Data we collect
  3. How we use your data
  4. Who we share data with
  5. Cross-border transfers
  6. How long we keep data
  7. Security
  8. Your rights
  9. Cookies and tracking
  10. Children's data
  11. Changes to this policy
  12. Contact and Data Protection Officer

1. Who we are

berthcast ("we", "us", "our") provides an inventory analysis service to food distribution and similar businesses. This Privacy Policy explains what personal data we collect when you use the Service, how we use it, who we share it with, and the rights you have over it.

This policy applies to personal data of users of the Service (account holders, employees of customer organisations) and of individuals whose data appears in customer-uploaded files (for example, contact persons in a supplier list).

2. Data we collect

2.1 Account data

  • Email address (used to create your account and send verification, password resets, and service notifications)
  • Company name and role (so we can tailor the Service to your organisation)
  • Password (stored as a hashed value; we never see your plain password)
  • Plan tier and usage counters

2.2 Data you upload

When you use the Service, you upload business data including:

  • Inventory reports (SKUs, stock levels, units of measure)
  • Sales records (transaction history, quantities, revenue)
  • Purchase orders (supplier interactions, lead times)
  • Supplier listings (which may include supplier company names, contact persons, addresses, payment terms)
  • Customer listings, where you choose to provide them (which may include customer company names and contact persons)

Some of this data may include personal data of third parties (for example, a supplier's contact email). By uploading it, you confirm that you have a lawful basis under the PDPA (or equivalent law applicable to you) to share that data with us for the purpose of running the Service.

2.3 Usage and technical data

  • Server logs: IP address, browser type, requested pages, and timestamps — kept for error tracing and security monitoring (for example, blocking repeated failed sign-ins)
  • Approval, dismissal, and outcome actions on recommendations — stored as part of your organisation's records so your team can see its own decision history

We do not run third-party analytics, advertising trackers, or session-recording tools anywhere in the Service.

2.4 Contact form

If you contact us through the website's contact form (with or without an account), we collect the name, email address, company name, and message you submit. We use this data solely to respond to your enquiry and to set up accounts you request, and we keep it for up to 12 months.

3. How we use your data

We use your data to:

PurposeExamples
Provide the Service Authenticate you, run analyses on your uploaded data, generate recommendations, save your approvals.
Communicate with you Send verification emails, password resets, critical-stock alerts, and (if you opt in) product updates.
Improve the Service Aggregated, anonymised statistics (for example, how many analyses run per week). We do not use your uploaded business data to train AI models — ours or anyone else's.
Keep the Service safe Detect abuse, fraud, and security incidents.
Comply with the law Respond to legitimate legal requests and meet our regulatory obligations under the PDPA and other applicable law.

4. Who we share data with

We share data only with sub-processors who help us run the Service. Each is contractually bound to confidentiality and limited use:

Sub-processorPurposeLocation
Anthropic, PBC AI model inference (Claude) used to generate recommendations from your data. United States
Render, Inc. Application hosting, database storage, log retention. United States (primary)
Google LLC (Gmail SMTP) Outbound transactional email (verification, password reset, alerts). Global
Cloudflare, Inc. Content delivery, TLS, and denial-of-service protection in front of the Service (proxies all traffic and therefore sees visitor IP addresses). Global
Google LLC (Google Fonts) Font files loaded when pages render (Google receives the visitor's IP address as part of serving the font). Global

We do not sell your personal data. We do not share your data with advertisers, data brokers, or for any purpose unrelated to providing the Service.

We may share your data in response to a valid legal request (court order, regulator subpoena, law enforcement requirement) where we are legally obliged to do so. We will notify you where we are lawfully permitted.

5. Cross-border transfers

The Service is operated from Singapore. Some of our sub-processors store and process data outside Singapore, primarily in the United States. Where data is transferred out of Singapore, we take reasonable steps under section 26 of the PDPA to ensure the recipient is bound by enforceable obligations to protect the data at a standard comparable to that under the PDPA.

6. How long we keep data

We retain your data for as long as your account is active and for a reasonable period afterwards to meet legal, accounting, and dispute-resolution obligations. Specifically:

  • Account records: kept while the account is active and for up to 12 months after closure.
  • Uploaded data and analyses: kept while your account is active. During your account's life, a verified deletion request is honoured within 30 days. After account closure, your data remains available for export on request for 30 days, then is deleted from the live system within a further 30 days (matching our Terms of Service).
  • Backups: encrypted database snapshots are kept on a rolling basis and age out automatically within approximately two weeks, so deleted data also leaves the backups within that window.
  • Server logs: retained for up to 90 days, then deleted or aggregated.
  • Billing records: retained for 7 years to meet Singapore tax and accounting requirements.

You may request earlier deletion by contacting us (see section 12). We will honour the request unless we are required by law to retain the data longer.

7. Security

We use commercially reasonable technical and organisational measures to protect your data, including:

  • Encryption in transit (HTTPS/TLS, enforced with HSTS) between your browser and our servers.
  • Encryption at rest for stored data on our hosting platform.
  • Hashed passwords and hashed password-reset tokens — neither is ever stored in plain text.
  • Automatic blocking of repeated failed sign-in attempts, request throttling on public forms, and security response headers on every page.
  • Strict separation between customer organisations: your team only ever sees your organisation's data.
  • Daily encrypted database backups, retained on a rolling basis.
  • Application logging of security-relevant events, and production access limited to berthcast's operator for legitimate operational reasons only.

No online service is fully secure. If we become aware of a personal data breach that is likely to result in significant harm to you or to the individuals whose data you have uploaded, we will notify you and the Personal Data Protection Commission as required by Singapore law.

8. Your rights

Under the PDPA, you have the right to:

  • Access the personal data we hold about you.
  • Correct any personal data that is inaccurate or out of date.
  • Withdraw consent to our processing of your personal data, subject to legal or contractual restrictions.
  • Request deletion of personal data we no longer have a lawful basis to hold.
  • Export your account data in a portable format on reasonable request.

To exercise any of these rights, contact us using the details in section 12. We will respond within 30 days. Where we cannot honour a request (for example, because we are legally required to retain the data), we will explain why.

9. Cookies and tracking

The Service uses a small number of cookies that are strictly necessary for it to function (for example, to keep you logged in). We do not use advertising cookies, third-party analytics that profile you across the web, or tracking pixels in marketing emails. If we add optional analytics in future, we will update this policy and provide a clear opt-in.

10. Children's data

The Service is a B2B tool not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Changes to this policy

We may update this Privacy Policy from time to time. When we make a material change, we will notify account holders by email or via the Service at least 14 days before the change takes effect. The "Last updated" date at the top of this page always reflects the current version.

12. Contact and Data Protection Officer

Questions about this policy, or any request to exercise your rights under the PDPA, can be sent through our contact page or emailed to admin@berthcast.com. Mark your message "Privacy request" so we route it correctly.

Our designated Data Protection Officer (DPO) under section 11(3) of the PDPA can be contacted directly at admin@berthcast.com.

© 2026 berthcast · Inventory operations for food distributors
Terms Privacy Contact