Privacy Policy

Effective Date: April 2, 2026

Last Updated: April 2, 2026

This Privacy Policy describes how 2D Data Solutions, Inc. (“Company”, “we”, “us”) collects, uses, shares, and protects information when you use TaplyPOS (“Service”). This policy applies to merchants who use our point-of-sale software and to customers whose data merchants collect through the Service.

1. Information We Collect

1.1 Merchant Account Information

Data TypeExamplesPurpose
Account credentialsEmail address, password (hashed)Authentication
Business informationStore name, address, phone, tax IDService operation, receipts
Payment credentialsStripe account ID (no card numbers)Payment processing
Staff informationNames, roles, PINs (hashed)Access control
Device informationDevice model, OS version, app versionDebugging, compatibility

1.2 Transaction Data

Data TypeExamplesPurpose
Sales recordsItems, prices, quantities, totalsBusiness operations, reporting
Payment recordsPayment method (cash/card), last 4 digits, amountTransaction tracking
Refund recordsRefund amount, reason, timestampFinancial records
Audit logsActions performed, timestamps, staff memberSecurity, compliance

1.3 Customer Data (Collected by Merchants)

Data TypeExamplesPurpose
Contact informationCustomer name, email, phoneCRM, receipts
Purchase historyVisit count, total spentLoyalty tracking

We never collect or store credit card numbers, CVVs, or full card data.

All payment card information is processed exclusively by Stripe and never passes through our servers or is stored on your device.

1.4 Information We Do NOT Collect

  • Credit or debit card numbers
  • Bank account numbers
  • Social Security numbers
  • Biometric data (Face ID/Touch ID is processed on-device by Apple only)
  • Location data (only used for one-time address auto-fill during setup, not tracked)

2. How We Use Information

  • Service operation: Processing transactions, generating receipts and reports
  • Account management: Authentication, authorization, staff access control
  • Cloud sync: Synchronizing data between your device and our cloud infrastructure
  • Customer support: Responding to support requests
  • Service improvement: Analyzing usage patterns to improve the Service (aggregated, anonymized)
  • Legal compliance: Meeting regulatory and legal obligations

3. How We Store and Protect Information

3.1 Data Storage

  • Local storage: Transaction data is stored locally on your device in encrypted files for offline functionality
  • Cloud storage: Data syncs to Supabase (hosted on AWS) with PostgreSQL database, encrypted at rest
  • Region: US-West-2 (Oregon)
  • Retention: Data is retained for the life of your account plus 30 days after deletion

3.2 Security Measures

  • All data transmitted via HTTPS/TLS encryption
  • Database encrypted at rest (AES-256)
  • Row Level Security (RLS) ensures merchants can only access their own data
  • Staff PINs stored as SHA-256 hashes with unique salts
  • Tamper-evident audit logs with hash chains
  • JWT-based authentication with token refresh
  • Payment credentials stored in Stripe’s PCI-compliant infrastructure, not our database

4. Information Sharing

We do not sell your personal information. We share information only as follows:

RecipientData SharedPurpose
Stripe, Inc.Business info, transaction amountsPayment processing
Supabase (AWS)All account and transaction dataCloud storage and sync
Apple (Sign in with Apple)Authentication tokensAccount authentication
Google (Google Sign-In)Authentication tokensAccount authentication
NetlifyContact form submissionsWebsite form processing
Law enforcementAs required by lawLegal compliance

5. Your Rights

5.1 All Users

  • Access: View all your data through the app
  • Correction: Update your information in Settings
  • Deletion: Delete your account and all associated data through Settings > Legal & Privacy > Delete Account
  • Export: Export transaction data via CSV through Analytics and Tax Report screens

5.2 California Residents (CCPA)

Under the California Consumer Privacy Act, you have the right to:

  • Know what personal information we collect, use, and disclose
  • Request deletion of your personal information
  • Opt out of the sale of personal information (we do not sell personal information)
  • Non-discrimination for exercising your rights

To exercise these rights, contact support@taplypos.com.

5.3 EU/EEA Residents (GDPR)

Under the General Data Protection Regulation, you have the right to:

  • Access, rectify, or erase your personal data
  • Restrict or object to processing
  • Data portability
  • Withdraw consent at any time
  • Lodge a complaint with a supervisory authority

Our legal basis for processing is: (a) performance of a contract (providing the Service), (b) legitimate interests (improving the Service), and (c) consent (optional features like marketing).

6. Merchant Obligations Regarding Customer Data

As a merchant using TaplyPOS, you act as the data controller for your customers’ personal information. You are responsible for:

  • Obtaining appropriate consent from your customers before collecting their data
  • Informing your customers how their data will be used
  • Complying with applicable privacy laws in your jurisdiction
  • Responding to your customers’ data access and deletion requests

We act as a data processor on your behalf and process customer data only as necessary to provide the Service.

7. Children’s Privacy

The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child under 13, we will delete it promptly.

8. Data Breach Notification

In the event of a data breach affecting your personal information, we will notify you within 72 hours of becoming aware of the breach, in accordance with applicable laws (including GDPR Article 33).

9. Account Deletion

When you delete your account:

  • Your account credentials are immediately deactivated
  • All business data (transactions, products, customers, staff) is permanently deleted within 30 days
  • Your Stripe connected account remains active (managed directly with Stripe)
  • Backup copies are purged within 90 days
  • Aggregate, anonymized analytics data may be retained

10. Cookies and Tracking

The TaplyPOS mobile app does not use cookies or third-party tracking. Our website (taplypos.com) does not use cookies for tracking or advertising purposes. We use privacy-friendly analytics for basic service metrics which do not track individual users.

11. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes by updating the “Last Updated” date and providing notice through the app or email. Continued use constitutes acceptance.

12. Contact

For privacy questions, data requests, or complaints:

2D Data Solutions, Inc.
Privacy Team
Email: support@taplypos.com
Website: taplypos.com