Privacy Policy
Effective Date: April 2, 2026
Last Updated: April 2, 2026
This Privacy Policy describes how 2D Data Solutions, Inc. (“Company”, “we”, “us”) collects, uses, shares, and protects information when you use TaplyPOS (“Service”). This policy applies to merchants who use our point-of-sale software and to customers whose data merchants collect through the Service.
1. Information We Collect
1.1 Merchant Account Information
| Data Type | Examples | Purpose |
|---|---|---|
| Account credentials | Email address, password (hashed) | Authentication |
| Business information | Store name, address, phone, tax ID | Service operation, receipts |
| Payment credentials | Stripe account ID (no card numbers) | Payment processing |
| Staff information | Names, roles, PINs (hashed) | Access control |
| Device information | Device model, OS version, app version | Debugging, compatibility |
1.2 Transaction Data
| Data Type | Examples | Purpose |
|---|---|---|
| Sales records | Items, prices, quantities, totals | Business operations, reporting |
| Payment records | Payment method (cash/card), last 4 digits, amount | Transaction tracking |
| Refund records | Refund amount, reason, timestamp | Financial records |
| Audit logs | Actions performed, timestamps, staff member | Security, compliance |
1.3 Customer Data (Collected by Merchants)
| Data Type | Examples | Purpose |
|---|---|---|
| Contact information | Customer name, email, phone | CRM, receipts |
| Purchase history | Visit count, total spent | Loyalty tracking |
We never collect or store credit card numbers, CVVs, or full card data.
All payment card information is processed exclusively by Stripe and never passes through our servers or is stored on your device.
1.4 Information We Do NOT Collect
- Credit or debit card numbers
- Bank account numbers
- Social Security numbers
- Biometric data (Face ID/Touch ID is processed on-device by Apple only)
- Location data (only used for one-time address auto-fill during setup, not tracked)
2. How We Use Information
- Service operation: Processing transactions, generating receipts and reports
- Account management: Authentication, authorization, staff access control
- Cloud sync: Synchronizing data between your device and our cloud infrastructure
- Customer support: Responding to support requests
- Service improvement: Analyzing usage patterns to improve the Service (aggregated, anonymized)
- Legal compliance: Meeting regulatory and legal obligations
3. How We Store and Protect Information
3.1 Data Storage
- Local storage: Transaction data is stored locally on your device in encrypted files for offline functionality
- Cloud storage: Data syncs to Supabase (hosted on AWS) with PostgreSQL database, encrypted at rest
- Region: US-West-2 (Oregon)
- Retention: Data is retained for the life of your account plus 30 days after deletion
3.2 Security Measures
- All data transmitted via HTTPS/TLS encryption
- Database encrypted at rest (AES-256)
- Row Level Security (RLS) ensures merchants can only access their own data
- Staff PINs stored as SHA-256 hashes with unique salts
- Tamper-evident audit logs with hash chains
- JWT-based authentication with token refresh
- Payment credentials stored in Stripe’s PCI-compliant infrastructure, not our database
4. Information Sharing
We do not sell your personal information. We share information only as follows:
| Recipient | Data Shared | Purpose |
|---|---|---|
| Stripe, Inc. | Business info, transaction amounts | Payment processing |
| Supabase (AWS) | All account and transaction data | Cloud storage and sync |
| Apple (Sign in with Apple) | Authentication tokens | Account authentication |
| Google (Google Sign-In) | Authentication tokens | Account authentication |
| Netlify | Contact form submissions | Website form processing |
| Law enforcement | As required by law | Legal compliance |
5. Your Rights
5.1 All Users
- Access: View all your data through the app
- Correction: Update your information in Settings
- Deletion: Delete your account and all associated data through Settings > Legal & Privacy > Delete Account
- Export: Export transaction data via CSV through Analytics and Tax Report screens
5.2 California Residents (CCPA)
Under the California Consumer Privacy Act, you have the right to:
- Know what personal information we collect, use, and disclose
- Request deletion of your personal information
- Opt out of the sale of personal information (we do not sell personal information)
- Non-discrimination for exercising your rights
To exercise these rights, contact support@taplypos.com.
5.3 EU/EEA Residents (GDPR)
Under the General Data Protection Regulation, you have the right to:
- Access, rectify, or erase your personal data
- Restrict or object to processing
- Data portability
- Withdraw consent at any time
- Lodge a complaint with a supervisory authority
Our legal basis for processing is: (a) performance of a contract (providing the Service), (b) legitimate interests (improving the Service), and (c) consent (optional features like marketing).
6. Merchant Obligations Regarding Customer Data
As a merchant using TaplyPOS, you act as the data controller for your customers’ personal information. You are responsible for:
- Obtaining appropriate consent from your customers before collecting their data
- Informing your customers how their data will be used
- Complying with applicable privacy laws in your jurisdiction
- Responding to your customers’ data access and deletion requests
We act as a data processor on your behalf and process customer data only as necessary to provide the Service.
7. Children’s Privacy
The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child under 13, we will delete it promptly.
8. Data Breach Notification
In the event of a data breach affecting your personal information, we will notify you within 72 hours of becoming aware of the breach, in accordance with applicable laws (including GDPR Article 33).
9. Account Deletion
When you delete your account:
- Your account credentials are immediately deactivated
- All business data (transactions, products, customers, staff) is permanently deleted within 30 days
- Your Stripe connected account remains active (managed directly with Stripe)
- Backup copies are purged within 90 days
- Aggregate, anonymized analytics data may be retained
10. Cookies and Tracking
The TaplyPOS mobile app does not use cookies or third-party tracking. Our website (taplypos.com) does not use cookies for tracking or advertising purposes. We use privacy-friendly analytics for basic service metrics which do not track individual users.
11. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes by updating the “Last Updated” date and providing notice through the app or email. Continued use constitutes acceptance.
12. Contact
For privacy questions, data requests, or complaints:
2D Data Solutions, Inc.
Privacy Team
Email: support@taplypos.com
Website: taplypos.com