Privacy Policy
Last updated: 10 September 2026
PourPOS ("we", "us") provides a tasting and sales tracking platform for distilleries, breweries and wineries. This policy explains what personal data we collect, why, and the choices you have. It applies to our website (pourpos.app), our mobile tracker, and our iOS application.
1. Who we are
Your distillery or brewery (your employer or the business that invited you) is the controller of your workspace data — tasting records, staff lists and shifts. PourPOS processes that data on their behalf. For account-level data (your name and email) we act as the controller.
2. What we collect
- Account data: name, email address, role, and tenant (company) membership.
- Work data: tasting sessions, products tasted, sales recorded, people counters, session ratings, shift schedules, venue check-in details, booking messages, and team chat messages you send.
- Photos you upload: bottle stock photos (used to estimate stock levels) and brand logos.
- Passkeys: the public key of each credential you register. Biometric data (your fingerprint or face) never leaves your device and is never sent to us.
- Payment tokens: Stripe or Apple payment method identifiers used for credit purchases. Card numbers are handled by Stripe/Apple and are never stored on our servers.
- Diagnostic data: error reports via Sentry, scrubbed of cookies, auth tokens and email addresses.
- Location (transient): when you tap "nearest venue" or start geofenced session auto-pause, we use your device location at that moment to compute distance to a venue. We do not store or build a location history.
3. What we do NOT collect
- Biometric data (Face ID / Touch ID templates stay on your device).
- Stored location history or background tracking.
- Credit card numbers.
- Advertising identifiers; we run no ad networks and sell no data.
4. Why we process it (legal bases)
- Contract: to provide the service your company signed up for (sessions, shifts, reports, billing).
- Legitimate interests: security (rate limiting, abuse detection), product reliability (error monitoring).
- Consent: camera/location/photo access — requested per-use via iOS permission prompts; you can withdraw at any time in iOS Settings.
5. Third-party processors
- Cloudflare — hosting, D1 database, edge delivery (data stored in Australian/US edge regions).
- Resend — transactional email (magic links, shift notifications, invoices).
- Stripe — wallet payments and card management (PCI-compliant).
- Apple — In-App Purchase receipts, Sign in with Apple identity tokens, App Store services.
- Sentry — error diagnostics (PII scrubbed).
- Google — Places autocomplete for venue addresses.
6. Retention & deletion
Work records are kept as a historical audit trail for the tenant that created them. If you delete your account in-app (Settings → Delete Account), your credentials, recovery tokens and identifying details are removed and your user record is deactivated; historical session entries remain part of your employer's records. The last active member of a company can delete the company's entire dataset in the same flow.
You may also request deletion at any time via pourpos.app/help — we respond within 30 days.
7. Your rights
- Access, correction, and deletion of your personal data.
- Withdraw consent for device permissions in iOS Settings.
- Data portability on request (CSV exports are available to admins in-product).
- Complaint rights with your local regulator (OAIC in Australia).
8. Security
All traffic is encrypted (TLS). Authentication uses WebAuthn passkeys (no passwords) or Sign in with Apple. Sessions are HttpOnly, Secure cookies. Access to production data is restricted to authorised personnel.
9. Children
PourPOS is a business tool and is not directed at children. Because the product references the alcohol industry, it is rated 17+ and accounts are provisioned by employers.
10. Changes
We'll update this page when the policy changes and, for material changes, notify account admins by email.
← Back to Home · Terms of Service · Data Collection Policy