Cette page n’existe qu’en anglais.
Fair and lawful
Only for your own organisation, no spam, no unlawful content.
Serve responsibly
Youth protection, cash register and taxes are the club's job – games never for money.
Stay secure
Personal logins, no bypassing of safeguards, report problems.
This Acceptable Use Policy describes how drinklist.app (web, web app, administration and app) may be used and what is not allowed. It supplements the terms and conditions of iqmeta GmbH, Am Sonnenhang 24, 71111 Waldenbuch, Germany ("iqmeta"), specifies in particular their § 7 (obligations of the customer) and is part of the contract of use. In the event of contradictions, the terms and conditions prevail.
Summary
- drinklist.app is for managing drinks, goods, accounts, cash register and billing of your own organisation (e.g. a club) – not for spam, resale or unlawful purposes.
- No unlawful, offensive or third-party content; no sensitive data (e.g. health, religion, ID or bank account numbers) in free-text fields.
- Emails, invitations and push notifications only to people who belong to the organisation; do not circumvent sending limits.
- Interfaces, automation and bots only within the documented scope; no security tests and no bypassing of safeguards.
- Youth protection, serving alcohol, cash register (TSE) and taxes are the club's responsibility. Games on the TV display are entertainment: no gambling for money, no encouraging excessive drinking, nothing involving alcohol for minors.
- Online payments only for the club's own goods and services – no prohibited goods, no money laundering, no abuse of chargebacks.
- Please report violations to support@drinklist.app. iqmeta may respond to violations in stages – from a notice to a suspension.
§ 1 Scope and responsibility
- This policy applies to everyone who uses drinklist.app: customers and their users with roles (owners, administrators, managers, cashiers, bartenders, bookers, readers), members with their own account or PIN, guests, as well as devices and programs accessing it via kiosk, TV display, order display, print proxy or interfaces.
- The customer (the organisation) ensures that its users, members and guests comply with this policy and is responsible for the content and use within its organisation. Owners, administrators and managers expressly accept the current version.
- Anyone acting for an organisation warrants that they are authorised to do so.
§ 2 Principle
drinklist.app may only be used lawfully and for its purpose: booking drinks and goods to accounts, cash register and cash sales, billing, payment, dunning, stock, reports, communication within the organisation and the related interfaces. The laws of the country in which the organisation operates and the terms of integrated services (e.g. payment providers) apply.
§ 3 Content
Content is everything users enter or upload – such as names of organisations, lists, accounts and products, news, polls, notes, additional fields, pictures, logos, support messages and data received via interfaces. Content is not allowed if it
- violates the law, in particular if it is a criminal offence (e.g. incitement to hatred, unconstitutional symbols, depictions of violence, threats),
- insults, defames, exposes, discriminates against or harasses others,
- is pornographic or harmful to minors,
- infringes third-party rights – copyright, trademark, name or personality rights, such as other people's photos without permission or profile pictures without the consent of the person shown,
- contains malware, phishing or misleading links, or advertises third parties unrelated to the organisation.
Sensitive data in free-text fields: notes, account names, additional fields, news and polls are not intended for special categories of personal data (Art. 9 GDPR, e.g. health, religion, political opinions, trade union membership) nor for ID, tax or bank account numbers, credit card data, passwords or PINs. Additional account fields are only used for information the club really needs to run the account.
§ 4 Emails, invitations, push notifications and news
- Invitations, news, PINs, guest cards, orders to suppliers, dunning letters and invoices by email as well as push notifications may only be sent to people who belong to the organisation or have a business relationship with it (members, guests, suppliers) and for whom the club has a legal basis. Purchased, harvested or third-party address lists are not allowed.
- drinklist.app is not a newsletter or advertising service. Advertising for third parties, chain letters and mass mailings unrelated to the organisation are prohibited.
- To protect all customers, sending limits apply (including a daily budget per organisation for emails to non-users, a maximum number of open invitations and limits per address). If an unusually high number of emails bounce or spam complaints are received, sending for the organisation is paused until iqmeta has reviewed and released it. These limits must not be circumvented – for example by using several organisations, logins or repeated invitations.
- Dunning letters must be factual; members must not be exposed publicly (e.g. lists of debtors on the TV display or in the news).
- Members' opt-outs and notification settings (e.g. push only with consent, email can be switched off per list) must be respected.
§ 5 Uploaded files and pictures
- Only files that the user is allowed to use and that serve the purpose may be uploaded: product pictures, profile pictures, logos and banners, receipts, import files and attachments to support tickets.
- drinklist.app is not a general file storage. Third-party or unrelated files, malware and files with active content (e.g. scripts in SVG logos) are not allowed.
- The technical limits on size, type and storage per organisation apply. iqmeta may remove files that evidently infringe third-party rights or violate this policy (§ 7 of the terms).
§ 6 Public links and devices
- Links and QR codes for the TV display, order display, kiosk, table QR ordering, event self-registration, digital receipts and device pairing must be treated like keys: use them only where intended, do not share them publicly on the internet, and revoke or renew them in the administration if misuse is suspected.
- Kiosk devices and tablets at the bar must be set up and supervised so that nobody books to other people's accounts. PINs belong to the respective account and are not passed on.
- Personal information on publicly visible displays (e.g. leaderboard, names in the horse race) is only shown with the consent of the persons concerned.
§ 7 Interfaces, automation and fair use
- Automated access is only allowed via the documented interface (API) with your own API keys and via webhooks. API keys are used only for your own organisation, granted with the minimum necessary rights and kept secret.
- In particular, the following are not allowed: reading the user interfaces with programs ("scraping"), automated logins, bots and scripts outside the API, solving or bypassing the bot check through third parties or programs, and circumventing request limits (rate limits), for example with several keys, logins or IP addresses.
- Webhooks may only point to your own systems or systems operated on your behalf.
- Use must remain within what is customary for the organisation. Load that impairs operation for other customers (e.g. mass requests, endless loops, extremely many accounts, bookings or files without corresponding club activity) is not allowed. Anyone with special requirements talks to iqmeta in advance.
§ 8 Security
- Logins with email and password are personal. They are not shared with others; roles and invitations exist for further people. Two-factor authentication is recommended for owners and managers.
- Not allowed are security tests, vulnerability or load scans and penetration tests without iqmeta's prior written consent, access to other organisations, accounts or data, and circumventing or defeating safeguards – such as login lockouts, the bot check, rights and roles, sending protection, plan limits or request limits.
- Anyone who finds a security vulnerability reports it confidentially to support@drinklist.app, does not exploit it and does not publish it before iqmeta has been able to fix it.
- Suspected misuse of logins, PINs, API keys or links must be reported to iqmeta without delay (§ 7 of the terms).
§ 9 Identity, logins and quotas
- Information given at registration, in the master data and in the billing address must be correct. Nobody may pretend to be iqmeta, another organisation or another person, or create the impression of a connection with iqmeta that does not exist.
- Each user has a quota of organisations they may create as owner (currently three; more on request). It must not be circumvented by additional logins, disposable addresses or front persons.
- The limits of the free plan and of the plans (accounts, lists, users, features) must not be deliberately circumvented – for example by splitting one organisation into several free organisations, by alternately archiving and restoring accounts or by tampering with the count. Shared accounts with a factual reason (e.g. "Guests" or a team kitty) are allowed.
- The activity rule for free organisations (§ 6a of the terms) is only met by an actual sign-in of an authorised person; automated sign-ins do not count.
§ 10 No resale
drinklist.app is used for your own organisation. Without a written agreement with iqmeta it is not allowed to resell, rent out or sublicense the service or logins, to offer it under your own name ("white label") or to operate it for other organisations against payment. Anyone acting on behalf of a club (e.g. as treasurer or service provider) works in that club's organisation with a granted role. Trademarks, logos, texts and the picture library of drinklist.app may only be used within the service; the service may not be replicated or reverse engineered beyond what the law permits.
§ 11 Sale of goods, alcohol, tobacco and youth protection
- Only goods and services whose sale is legally permitted may be booked and sold via drinklist.app. In particular, narcotics, prescription drugs, weapons and other prohibited goods, or goods that require a special permit if that permit is missing, are not allowed.
- The club alone is responsible for youth protection and the rules for serving alcohol. In Germany the Youth Protection Act applies in particular: beer, wine, sparkling wine and mixed drinks thereof not under 16, spirits and drinks containing spirits as well as tobacco products, e-cigarettes and similar products not under 18. In addition, licensing law or a required permit and the law of the respective country apply.
- The youth protection features (age check, alcohol flag on products, daily limits, approvals) support the club but do not replace checks on site. Dates of birth are only confirmed after checking an ID; flags and age limits must not be set incorrectly on purpose to defeat protective features.
- For guest cash sales at the kiosk, QR ordering and at the bar, the club ensures that alcoholic drinks and tobacco products are only handed out after an age check. Visibly drunk persons are not served further.
§ 12 Games and fun features
Lucky wheel, horse race, the drinking game "Hangover Hilde", "Bruchpilot", leaderboard, badges and similar features on the TV display or in the app are for entertainment. The following applies:
- No gambling: no stake or fee may be charged for taking part; there must be no playing for money, credit or prizes of monetary value and no betting on the outcome. Prizes and "penalties" are only symbolic and voluntary (e.g. applause, a title for the evening). Anyone who wants to offer prizes checks the legal requirements (e.g. gambling and prize competition law) themselves.
- No encouraging excessive drinking: games must not call for drinking alcohol quickly, competitively or in large quantities. Players may join in alcohol-free or sit out at any time without disadvantage or being exposed.
- Protection of minors: games related to alcohol (e.g. drinking games, races by number of drinks, leaderboards on alcohol) are not used at youth events or with minors taking part, and minors are not encouraged to drink alcohol.
- Names and rankings are only shown with the consent of the participants; nobody is shown up.
§ 13 Online payment and money flows
- Card payment (Stripe Connect, the club's own Stripe, SumUp or PayPal accounts, card readers), SEPA direct debit (via Stripe or GoCardless) and credit balances serve exclusively to pay for the club's goods and services to its members and guests. Payments flow directly between the club and the payment provider; iqmeta does not hold customer funds (§ 2 of the terms). In addition, the terms and lists of prohibited businesses of the respective payment providers apply.
- Not allowed are money laundering, terrorist financing, payments for prohibited goods or services, passing through third-party payments, sham bookings, paying out credit balances to third parties as a payment service, and top-ups that do not serve consumption or services within the club.
- Direct debits are only collected with a valid mandate and timely pre-notification. Chargebacks and refunds must not be abused – neither through unauthorised collections nor through systematic chargebacks of justified claims.
§ 14 Cash register, TSE and bookkeeping
- The club is responsible for proper cash management – in Germany in particular under the Fiscal Code (including § 146a AO), the Cash Register Security Ordinance (KassenSichV) and the GoBD, including issuing receipts, notifying the tax office of cash register systems and retention periods.
- Any manipulation is prohibited: bookings bypassing the TSE, subsequently altering or suppressing transactions, sham cancellations, test bookings in live operation or concealing outages. Corrections are only made via the intended cancellations and counter-bookings.
- The club backs up data that must be retained in good time via export (§ 6a and § 9 of the terms).
§ 15 Data protection for member data
- The club is the controller under the GDPR for the personal data of its members, guests and users; iqmeta processes it as a processor under the data processing agreement.
- The club only records data for which it has a legal basis, informs the data subjects, implements their rights (e.g. access, erasure) and uses exports and reports only for the purposes of the organisation. Exports must be stored securely.
- Data of other organisations or of people unrelated to the organisation is not recorded, collected or analysed.
§ 16 Reports
Violations of this policy, unlawful content, spam, security vulnerabilities and misuse can be reported at any time to support@drinklist.app or via "Help & support" in the app, web app and administration. Helpful are the organisation concerned, the place or link, the time and a short description. iqmeta reviews every report and treats the reporter's information confidentially as far as legally permitted.
§ 17 Consequences of violations
- iqmeta responds proportionately and takes the legitimate interests of the customer into account. Depending on the severity, the following measures in particular may be taken:
- a notice asking for remedy within a reasonable period,
- removing or blocking individual content (e.g. pictures, news),
- temporarily blocking individual features (e.g. pausing email sending, revoking API keys, webhooks or public links),
- temporarily suspending individual logins or the organisation,
- extraordinary termination under § 6 (3) of the terms as well as claims for damages and indemnification.
- In the event of serious violations or danger to operations, other customers or third parties, iqmeta may act immediately and then informs the customer without delay.
- Blocked data is retained unless otherwise required by law; data subject to statutory retention (in particular TSE and booking data) remains exportable.
- iqmeta only discloses data to authorities where there is a legal obligation or an official or court order, and may report criminal offences.
§ 18 Acceptance and changes
- This policy is accepted at registration together with the terms and conditions. Owners, administrators and managers of an organisation are asked in the app, web app and administration to accept the current version.
- Anyone who does not accept the policy can decline it there and state the reason; this creates a support ticket. Until it is resolved, the administration features cannot be used; data is retained and remains exportable, and acceptance can be given at any time. The right of termination remains unaffected.
- iqmeta may change this policy with effect for the future; the procedure under § 12 of the terms applies. Each version carries a version number (date).
- This policy is provided in German and English. The German version is legally binding.