Last updated: 10 September 2026
This document details every category of data PourPOS handles, where it lives, how long it is kept, and how it is removed. See the Privacy Policy for the companion overview.
| Category | Examples | Where stored | Retention |
|---|---|---|---|
| Identity | Name, email, role | Cloudflare D1 | Until account deletion |
| Work records | Sessions, tastings, sales, people counters, ratings | Cloudflare D1 | Tenant audit trail (kept; deleted on company deletion) |
| Scheduling | Shifts, shift acceptance, unavailability | Cloudflare D1 | Until deletion by tenant |
| Venue data | Location name/address, sign-in QR URL, venue coordinates (captured once on-site) | Cloudflare D1 | Until tenant deletion |
| Photos | Stock estimation photos, brand logos | Transient processing / D1 metadata | Photos are used for estimation and are not retained as user media |
| Passkeys | Credential ID + public key + counter | Cloudflare D1 | Until credential or account deletion |
| Payments | Stripe customer/payment IDs, Apple transaction IDs, invoices | Cloudflare D1 + Stripe/Apple | Tax-invoice retention period (7 years, AU) |
| Communications | Team messages, booking threads, notification history | Cloudflare D1 + Resend | Until tenant deletion |
| Telemetry | Error reports (Sentry, PII-scrubbed) | Sentry | 90 days |
| Transient location | Device GPS at venue-match time | Memory only — not stored | Not retained |
Cloudflare D1 primary regions and edge delivery may process data in Australian and United States data centres. Resend, Stripe, Apple and Sentry process data under their own regional policies. We do not transfer data to advertisers — ever.
We never receive or store card numbers. Stripe stores payment methods (PCI DSS Level 1). Apple In-App Purchases are verified via App Store Server Notifications v2; we retain only transaction identifiers and credit amounts.
Data protection questions: pourpos.app/help