Privacy Policy
Draft — written for an early pilot, not yet reviewed by a lawyer. Treat this as a starting point, not a finished legal document, before relying on it commercially.
What we collect
Business account info (organization name, owner email, a hashed password), location data (shop names, hashed staff PINs), inventory data you enter (items, counts, deliveries, suppliers, waste, recipes), and staff names attached to each stock update, sale, or waste entry for your own audit trail.
What we don't collect
No payment details are collected by this app today. We don't sell data to third parties, and we don't use your inventory data to train anything outside your own account.
Where it lives
Data is stored in a hosted Postgres database (Supabase) with row-level security enabled — application access goes only through this app's own servers, never a public API key.
Staff names
A staff member's typed name is stored against each scan, sale, or waste entry so an owner can see who did what. This is intended for the owner's own accountability records, not shared outside your organization.
Deleting your data
An owner can delete a location from Settings, which permanently removes its items, scans, purchases, and devices. To delete an entire organization's account, contact whoever set up your account.