Data Collection Policy

Last updated: 10 September 2026

This document details every category of data PourPOS handles, where it lives, how long it is kept, and how it is removed. See the Privacy Policy for the companion overview.

Data inventory

CategoryExamplesWhere storedRetention
IdentityName, email, roleCloudflare D1Until account deletion
Work recordsSessions, tastings, sales, people counters, ratingsCloudflare D1Tenant audit trail (kept; deleted on company deletion)
SchedulingShifts, shift acceptance, unavailabilityCloudflare D1Until deletion by tenant
Venue dataLocation name/address, sign-in QR URL, venue coordinates (captured once on-site)Cloudflare D1Until tenant deletion
PhotosStock estimation photos, brand logosTransient processing / D1 metadataPhotos are used for estimation and are not retained as user media
PasskeysCredential ID + public key + counterCloudflare D1Until credential or account deletion
PaymentsStripe customer/payment IDs, Apple transaction IDs, invoicesCloudflare D1 + Stripe/AppleTax-invoice retention period (7 years, AU)
CommunicationsTeam messages, booking threads, notification historyCloudflare D1 + ResendUntil tenant deletion
TelemetryError reports (Sentry, PII-scrubbed)Sentry90 days
Transient locationDevice GPS at venue-match timeMemory only — not storedNot retained

On-device data (iOS app / PWA)

Cross-border processing

Cloudflare D1 primary regions and edge delivery may process data in Australian and United States data centres. Resend, Stripe, Apple and Sentry process data under their own regional policies. We do not transfer data to advertisers — ever.

Deletion paths

Payment data

We never receive or store card numbers. Stripe stores payment methods (PCI DSS Level 1). Apple In-App Purchases are verified via App Store Server Notifications v2; we retain only transaction identifiers and credit amounts.

Contact

Data protection questions: pourpos.app/help

Privacy Policy · Terms of Service