← Back

Privacy Policy

Draft — written for an early pilot, not yet reviewed by a lawyer. Treat this as a starting point, not a finished legal document, before relying on it commercially.

What we collect

Business account info (organization name, owner email, a hashed password), location data (shop names, hashed staff PINs), inventory data you enter (items, counts, deliveries, suppliers, waste, recipes), and staff names attached to each stock update, sale, or waste entry for your own audit trail.

What we don't collect

No payment details are collected by this app today. We don't sell data to third parties, and we don't use your inventory data to train anything outside your own account.

Where it lives

Data is stored in a hosted Postgres database (Supabase) with row-level security enabled — application access goes only through this app's own servers, never a public API key.

Staff names

A staff member's typed name is stored against each scan, sale, or waste entry so an owner can see who did what. This is intended for the owner's own accountability records, not shared outside your organization.

Deleting your data

An owner can delete a location from Settings, which permanently removes its items, scans, purchases, and devices. To delete an entire organization's account, contact whoever set up your account.