StorePro

StorePro

Privacy Policy

Last updated: [DATE]

1. Who this covers

StorePro is hosted software for print, copy and shipping stores, operated by [LEGAL ENTITY NAME] (“we”, “us”). This policy explains what the Service stores, where, and for how long.

There are two different groups of people involved, and it matters which one you are:

[The controller / processor split above should be stated in the exact terms your jurisdiction uses, and may need a data processing agreement to back it.]

2. What we store

Everything held in our database, and why.
WhatWhy we hold it
Your account email address, and a securely hashed form of your password. We never store the password itself. To sign you in, to reset your password, and to contact you about billing, outages and changes to the Service.
Store details — store name, store number, location and branding, plus the admin code you chose for that store. To identify your stores and to set up each counter machine when you launch the calculator from the portal.
Your pricing configuration — every price and option you have changed from the defaults — and the most recent previous versions of it. So the same prices reach every counter machine on that store, and so you can see what changed and restore an earlier version if an edit went wrong.
Print-job records — job title and details, status, notes, assignee, due dates, and any customer name, email address and phone number your staff enter. So the job queue is shared across the store's counter machines rather than trapped on one of them.
Inventory — your categories and items, what is on the shelf, the supplier notes and unit costs you enter, and a history of every count: what changed, when, and the name whoever counted it typed in. So a count taken at one till is the count every till sees, and so the history can show what is actually being used up.
Feedback you send us — whichever of bug, feature or other you picked, your message, the reply address you gave, which store you sent it from, and — only if you tick the box — that browser's recent error log. So we can answer you, and so a report arrives with enough context that we do not have to ask you to reproduce it.
Billing status — your subscription's state, the number of stores it covers, its renewal date, and identifiers linking your account to our payment processor. No card numbers. To know what your account is entitled to, and to show it to you accurately.
Daily usage counts — per store, per day, per service: screen opens, quotes worked out, cart lines, and the total value quoted. Plus a heartbeat naming each counter machine and the version it is running. Counts and totals only — no customer details and no individual job. So the store's owner can see how their stores are being used, and so we can support the Service and know which version a machine is on. See section 3.
Recent error reports — the error message, the file and line it came from, the machine identifier and the version. Newest 100 per store. So a fault can be diagnosed from the error itself rather than over the phone. See section 3.
Technical logs kept by our hosting and database providers, which can include IP addresses and timestamps of requests. Security, abuse prevention and diagnosing faults. We do not use them to build a profile of anyone.

The print-job records deserve a specific warning to store owners: whatever your staff type into a job is stored. If they put a customer's phone number in the job details box, it is held the same as any other field. Tell your staff what is appropriate to record, and do not use the job queue for information you would not want held in a hosted system.

3. What the counter machine keeps, and what it reports

Some things the app keeps are stored in the browser on the machine itself and are not sent to us:

Two things that used to stay on the machine now also reach the store's account, so that the store's owner and we can see whether the software is working and being used:

Each counter machine is identified by a random identifier generated on that machine, so the owner can tell one till from another. It is not linked to a person, and staff are not identified.

Clearing the browser's site data on that machine erases everything held on the device, and generates a new machine identifier next time. The machine then has to be set up again through the portal. Counts and error reports already sent to the store's account are covered by section 7.

No advertising or analytics trackers. The Service loads no third-party analytics, advertising or tracking scripts, and sets no advertising cookies.

Two exceptions, and they are product images rather than tracking. The vendor gallery pages — signs, banners, apparel and the rest — show each product using the picture the wholesaler publishes, loaded from that wholesaler's own website rather than copied onto ours: 4over.com and signs365.com. Opening one of those pages therefore tells those two companies that a browser somewhere asked for the picture, which is what any image on any website does. Nothing about you, your store, your prices or your customers is sent with the request, and nothing else on the Service loads from anywhere but our own systems. The browser is instructed to send only our site's address, not the page you were on.

4. Where it is stored

Account details, store configuration, pricing and print-job records are stored in a PostgreSQL database hosted by Supabase, which also handles sign-in and password resets. The database region is us-west-1 (United States, Oregon).

Third parties that process data for us

Our sub-processors.
ProviderWhat it does
SupabaseDatabase hosting, authentication and password resets.
StripeSubscription payments — see section 5.
4over, signs365 Product photographs on the vendor gallery pages, loaded from their websites. They receive nothing but a request for a picture — see section 3.
Resend Delivering the email we send. That is the alerts a store has chosen to receive about its own work — a print job past its due date, a print job almost due, or an inventory item low or out — plus our own internal service notices. For a store alert, Resend receives the address that store entered, the store's name, and the job titles, due dates, item names, quantities and low-stock thresholds the alert is about. It never receives a customer's name, email address or phone number, and never a cost or supplier note. A store that has entered no address receives no alerts and nothing about it is sent.
[WEB HOST(S)] Serving the web pages themselves. Keeps standard access logs.
[EMAIL PROVIDER, if support email is hosted] Handling support email you send us.

[If data may be processed outside the country where your customers are — it usually is — the lawful transfer mechanism needs to be identified and named here.]

5. Payment information

Card numbers never reach our servers. Payments are handled entirely by Stripe: when you subscribe you are taken to Stripe's own checkout, and your card details go to Stripe directly. We never see, receive or store them.

What we receive back from Stripe is limited to what we need to run your account: an identifier for you as a Stripe customer, your subscription's status, the number of stores it covers, and when the current period ends. Stripe handles your payment details under its own privacy policy.

To change a card, view invoices or cancel, use the billing area of the portal — it hands you over to Stripe, which is the only place those details exist.

6. Who can see it

One account cannot read another account's data. That separation is enforced by the database itself on every single request, rather than by the app remembering to check — so a bug in a page cannot expose one store's pricing or print jobs to another store.

Within your own account, anyone who can sign in as you, or who has a store's admin code on a connected machine, can see that store's data. That is why the admin code matters and why it should be changed when someone who knew it leaves.

On our side, access is limited to the people who need it to operate and support the Service, and we look at your data only to fix a problem, to answer a request from you, or where the law requires it. [If you are asked to hand data to law enforcement, decide in advance whether you commit to notifying the customer first where you are legally able to.]

7. How long we keep it

8. We do not sell your data

We do not sell, rent or trade your information, or your customers' information, to anyone. We do not share it for advertising, and we do not use it to train anything. The only third parties who touch it are the providers listed in section 4, and only so they can do the job listed beside them.

9. Your choices and requests

If you are a store owner: you can see and change your store details, pricing and print jobs at any time from the portal and the app. To get a copy of your data, or to have your account and its data deleted, email us and we will do it.

If you are a store's customer and want to know what a store holds about you, or want it deleted, contact that store — they control the record and can delete it themselves from the print queue. If you cannot reach them, contact us and we will help.

[Depending on where your customers live, specific rights (access, correction, deletion, portability, objection, appeal) and response deadlines may apply and must be listed explicitly — GDPR, UK GDPR, CCPA/CPRA and others differ.]

[If a supervisory authority complaint route must be offered, name it here.]

10. Children

The Service is business software sold to stores. It is not directed at children, and we do not knowingly collect information from a child. If you believe a child's information has been entered into a store's print queue, contact that store, or us, and it will be removed.

11. Changes to this policy

If we change what we collect or who we share it with, we will update this page and change the date at the top. For a material change we will also email account holders. [Notice period, if you commit to one.]

12. Contact

Privacy questions, data requests, or anything on this page: support@REPLACE-WITH-DOMAIN.example

[Registered company name and postal address, and a named data protection contact or representative if one is required in your jurisdiction.]