Privacy Policy
How TheApp collects, uses, and protects personal data (placeholder pending counsel review).
Pending counsel review. This document is a placeholder. The binding policy ships with the post-counsel revision and a customer notice. Until then this stub describes our current operating posture in plain language; it is not a contract.
What we collect
We collect what we need to deliver the Service: account information (name, email, role), business information you put into the platform (catalog, customers, orders), and operational telemetry (logs of actions you take inside the app). Payment information is collected by Stripe or Square, never by us.
How we use it
To run the Service, to bill you, to provide support, and to keep the platform secure. We do not sell your data. We do not train AI models on the contents of merchant accounts. We do not share data with third parties except the sub-processors required to deliver the Service (see /legal/sub-processors).
Where it lives
Operational data is hosted in Canadian regions of our infrastructure provider. Backups are encrypted and replicated across two regions. Access by TheApp staff is logged at the database level on an append-only audit trail.
How long we keep it
For as long as your account is active and as long as required by law, tax obligations, or operational integrity (audit logs of money events are retained per the schedule on the trust page). On account closure you can request deletion of your operational data; logs required by law are retained for the legally required period only.
Your rights
You can request access to, correction of, or deletion of personal data we hold about you. Requests go to privacy@theapp.com. We respond within 30 days. EU/UK residents have the rights set out in the GDPR/UK GDPR; Canadian residents have the rights set out in PIPEDA; California residents have the rights set out in the CCPA.
Contact
privacy@theapp.com.