SS
StoreSenz

Privacy Policy

Effective date: July 15, 2026

This policy explains what information StoreSenz collects, how we use it, who we share it with, and what controls you have over it.

1. Who we are

StoreSenz Inc. (“StoreSenz”, “we”, “us”, or “our”) provides a retail intelligence and automation platform for independent retail stores. We are the “data controller” (or equivalent under applicable law) for the information described in this Privacy Policy.

This policy applies to our website at storesenz.com, our web dashboard, and all related services (collectively, the “Service”). It does not apply to third-party websites or services we link to.

2. Information we collect

Information you provide directly

  • Account registration: name, email address, business name, store address, phone number;
  • Payment information: handled by Stripe — we receive only a tokenised reference, never raw card numbers;
  • Store configuration: vendor details, product overrides, employee names, operating hours;
  • Support communications: emails or messages you send to our team.

Information from your POS system

When you install the Data Sync Agent, it reads data from your POS database and transmits it to the Service. The specific fields synced depend on the modules you have enabled and may include:

  • Sales transactions (date, items, quantity, price, tax);
  • Inventory levels and product catalog;
  • Customer phone numbers and purchase history (for engagement features);
  • Employee clock-in/out records (for time tracking);
  • Vendor and purchase order history.

We do not sync or store POS passwords or card payment data. See Section 4 for more detail on the sync agent.

Usage and technical data

  • Log data: IP address, browser type, pages visited, timestamps;
  • Feature usage: which modules and features you use and how often;
  • Device information: browser version, operating system;
  • Error and crash reports.

3. How we use information

We use the information we collect to:

  • Provide the Service — process transactions, generate forecasts, surface analytics, manage orders;
  • Billing and payments — charge subscription fees, send invoices, handle payment failures and grace periods;
  • Transactional communications — send alerts, reminders, order confirmations, and billing notices that are necessary to deliver the Service;
  • Customer support — respond to your questions and resolve issues;
  • Product improvement — analyse usage patterns to improve features (using aggregated, anonymised data);
  • Security and fraud prevention — detect and investigate suspicious activity;
  • Legal compliance — comply with applicable laws, regulations, and legal process.

We will not send you marketing emails without your explicit consent, and you may opt out of any marketing communications at any time.

4. POS data & sync agent

The StoreSenz Data Sync Agent is a lightweight application installed on a computer within your store’s local network. It operates with the following privacy properties:

  • Read-only access: the Sync Agent only reads from your POS database; it never writes to or modifies it;
  • Credentials stay local: your POS database credentials are stored only on your store PC and are never transmitted to StoreSenz servers;
  • Minimal transmission: only the fields required by your enabled modules are transmitted — not your entire POS database;
  • Encrypted in transit: all data sent from the Sync Agent to StoreSenz is encrypted using TLS 1.2+;
  • Offline resilience: if connectivity is lost, the agent resumes from the last known checkpoint — no data loss, no duplicate transmission.

POS data is stored in our cloud infrastructure (Google Cloud Platform) in encrypted form. Access is restricted to authorised StoreSenz systems and personnel with a demonstrated need.

5. AI processing

Several StoreSenz features use third-party AI models to generate insights. When you use these features, relevant data excerpts are sent to the AI provider selected for your account:

FeatureData sent to AI
Demand forecastingAggregated sales history (no customer PII), product names, seasonal context
Invoice extractionInvoice document content (vendor name, line items, amounts)
Festival planningHistorical sales during past festivals, product catalog
Voice ordering agentCaller utterances (audio transcribed by Deepgram), product catalog, store hours
AI purchase suggestionsInventory levels, sales velocity, vendor lead times

We never send complete customer records, payment card data, or employee personal information to AI providers. AI providers process data under their own privacy policies and data processing agreements with StoreSenz. You can select which AI provider is used for your account (Anthropic Claude, OpenAI, or Google Gemini) in your dashboard settings.

6. Payment data

Your subscription payments are processed by Stripe, Inc. StoreSenz does not store raw card numbers, CVVs, or full bank account details. Stripe stores your payment method securely and provides StoreSenz with a payment method token and status information only.

Your customers’ payments(for orders placed through your online store or WhatsApp) are processed directly by your connected Stripe account via Stripe Connect. StoreSenz receives transaction metadata (order ID, amount, status) but never handles or stores your customers’ card data.

For bank cash-inflow data (if you enable the Plaid integration), Plaid reads your bank account balance and transaction history in read-only mode. StoreSenz stores only the daily cash totals needed for your financials dashboard — not your full bank credentials.

7. WhatsApp & messaging

If you enable WhatsApp features (order parsing, customer engagement campaigns), we integrate with the Meta WhatsApp Business API using your store’s dedicated WhatsApp Business number.

Messages you receive from customers are stored in StoreSenz to enable order parsing and campaign tracking. Customer phone numbers are treated as personally identifiable information and are handled with appropriate safeguards.

Outbound messagessent through StoreSenz (order confirmations, engagement campaigns) are delivered via Meta’s API and subject to Meta’s WhatsApp Business policies. Recipients may opt out by replying “STOP” or using the unsubscribe link included in campaign messages.

You are responsible for ensuring you have valid consent from your customers before sending them marketing messages through the platform, in compliance with applicable messaging laws (TCPA, GDPR, etc.).

8. Third-party providers

We use the following sub-processors to deliver the Service. Each is bound by appropriate data processing agreements:

ProviderPurposeLocation
Google Cloud PlatformCloud hosting, database, storage, networkingUSA (us-central1 / us-west2)
StripeSubscription billing and Connect paymentsUSA
PlaidBank cash-inflow (read-only)USA
AnthropicAI forecasting & suggestions (optional)USA
OpenAIAI forecasting & suggestions (optional)USA
Google (Gemini)AI forecasting & suggestions (optional)USA
Meta (WhatsApp)WhatsApp Business messagingUSA / Global
BrevoTransactional and marketing emailsEU
LiveKitVoice agent real-time audio infrastructureUSA
DeepgramSpeech-to-text for voice orderingUSA
CartesiaText-to-speech for voice agentUSA
TelnyxPhone number provisioning and SIP routingUSA

9. When we share data

We do not sell your data. We share information only in these circumstances:

  • Service delivery: with the sub-processors listed in Section 8, strictly to provide features you have enabled;
  • Legal obligation: when required by law, court order, or governmental authority;
  • Protection of rights: when we believe disclosure is necessary to prevent harm or to protect the rights, property, or safety of StoreSenz, our customers, or the public;
  • Business transfers: in connection with a merger, acquisition, or sale of assets, with notice to you and the acquirer being bound by equivalent data protection obligations;
  • With your consent: for any other purpose with your explicit consent.

10. Data retention

We retain your data for as long as your account is active, or as needed to:

  • Provide the Service;
  • Comply with legal obligations (e.g., tax and financial records);
  • Resolve disputes and enforce agreements.

After account deletion or termination, we delete Customer Data within 30 days, except where retention is required by law. Anonymised, aggregated analytics data may be retained indefinitely.

You may request deletion of your data at any time by contacting privacy@storesenz.com. Please note that we may need to retain certain records for legal compliance even after a deletion request.

11. Security

We take security seriously and implement the following measures:

  • Encryption in transit: all data between your browser, the Sync Agent, and our servers uses TLS 1.2+;
  • Encryption at rest: databases and cloud storage are encrypted at rest using AES-256;
  • Field-level encryption: particularly sensitive fields (API keys, WhatsApp tokens, payment credentials) are additionally encrypted at the application layer before storage;
  • Secret management: credentials and API keys are managed via GCP Secret Manager — never stored in source code or environment files in production;
  • Access controls: internal access to production data is restricted to authorised personnel and logged via audit trails;
  • Rate limiting: API endpoints are rate-limited to mitigate abuse;
  • Webhook integrity: all incoming webhooks (Stripe, Meta, etc.) are verified using HMAC signatures.

Despite these measures, no system is 100% secure. If you discover a security vulnerability, please report it responsibly to security@storesenz.com.

12. International data transfers

StoreSenz is based in the United States. Our primary infrastructure runs on Google Cloud Platform in the US (regions us-central1 and us-west2). If you are accessing the Service from outside the United States, your data will be transferred to and processed in the US.

Some sub-processors (notably Brevo) process data in the European Union. Where data is transferred internationally, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions.

13. Your rights

Depending on where you are located, you may have the following rights regarding your personal information:

  • Access: request a copy of the personal data we hold about you;
  • Correction: request correction of inaccurate or incomplete data;
  • Deletion: request deletion of your personal data (subject to legal retention requirements);
  • Portability: receive your data in a machine-readable format;
  • Objection / restriction: object to or restrict certain processing activities;
  • Opt-out of marketing: unsubscribe from marketing communications at any time via the link in any email we send, or by emailing us.

To exercise any of these rights, contact privacy@storesenz.com. We will respond within 30 days. We may need to verify your identity before processing certain requests.

California residents (CCPA/CPRA): you have additional rights under California law, including the right to know the categories of personal information collected and the right to opt out of sale (we do not sell personal information). Contact us at the address above to exercise California-specific rights.

14. Cookies

The StoreSenz dashboard uses the following types of cookies and local storage:

  • Authentication: a JWT token is stored in browser local storage to keep you logged in. This is strictly necessary for the Service to function;
  • Preferences: theme (light/dark mode) and UI preferences are stored in local storage;
  • Analytics: we may use privacy-respecting analytics to understand how the marketing site is used (no cross-site tracking).

We do not use third-party advertising cookies. You can clear browser storage at any time, though this will log you out.

15. Children’s privacy

The Service is not directed to children under the age of 13 (or 16 where required by applicable law). We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us at privacy@storesenz.com and we will delete it promptly.

16. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by email and/or by displaying a notice in the dashboard at least 14 days before the changes take effect.

The “Effective date” at the top of this page shows when the policy was last updated. We encourage you to review this policy periodically.

17. Contact

If you have questions, concerns, or requests related to this Privacy Policy or your personal data, please contact us:

StoreSenz Inc. — Privacy Team

Email: privacy@storesenz.com

For legal matters, see our Terms of Service or email legal@storesenz.com.