Privacy Policy
Effective Date: July 19, 2026 · Last Updated: August 19, 2026
This Privacy Policy describes how OSPOS ("we," "us," "our") collects, uses, and protects your information when you use the OSPOS mobile applications for iPhone, iPad, and Android and related services (the "Service"). We are committed to protecting your privacy and being transparent about our data practices.
1. Our Privacy Principles
OSPOS is built on a simple idea: your data is yours. We designed the app so that the Free Tier works entirely on your device with zero data leaving your phone. For Paid Tier users, we collect only what's necessary to provide cloud features. We never sell your data. Our source code is public at github.com/pzapzap/ospos so you can verify our claims.
2. Information We Collect
Free Tier (No Data Collection)
If you use the Free Tier, we collect nothing. All data — including your menu, orders, transaction history, and business settings — is stored locally on your device using SQLite. No data is transmitted to our servers. No account is required. No internet connection is needed.
Paid Tier (Account Required)
When you create an OSPOS account and use the Paid Tier, we collect:
| Data | Purpose | Storage |
| Email address | Account authentication, transactional notifications | Our servers |
| Password (hashed) | Account authentication (bcrypt, never stored in plaintext) | Our servers |
| Sign-in provider identifier | Apple, Google, or email account linkage | Our servers |
| Business name | Receipt branding, account identification | Our servers |
| Business settings | Tax rate, tip config, sync preferences | Our servers + device |
| Order history | Cloud sync, reporting, dispute evidence | Our servers + device |
| Transaction records | Cloud sync, reporting, receipts | Our servers + device |
| Customer phone or email | Receipt delivery only, entered per-transaction | Our servers (with order) |
| Stripe account identifier | Route card payments to your Stripe account | Our servers |
| Push notification token (optional) | Send you dispute alerts and account notices | Our servers |
Sign in with Apple
If you sign in with Apple, we receive only the information Apple provides based on your choices: your name (if you share it) and either your real email address or an Apple-generated private relay address. We use this solely for account creation and authentication.
Sign in with Google
If you sign in with Google (Android), we receive only the identity claims that Google's verified ID token provides: a stable Google identifier ("sub"), your email address, and optionally your name. We use this solely for account creation and authentication. We never receive or store your Google password.
Email & Password Sign-In
If you create an account with an email address and password, your password is immediately hashed with bcrypt on our servers. We never store, log, or transmit your password in plaintext, and we cannot recover it if lost.
3. Information We Never Collect
We never collect, store, process, or have access to:
- Credit card numbers, debit card numbers, PINs, CVVs, or any cardholder data
- Card data read via Tap to Pay on iPhone (NFC data is processed by Apple's ProximityReader framework and transmitted directly to Stripe, never touching our servers or your device's main app process)
- Your geographic location (Location permission is used only by the Stripe Terminal SDK for reader discovery, as required by Stripe's terms, and is never transmitted to us)
- Your contacts, calendar, messages, call logs, or browsing history
- Photos or videos other than menu-item images or dispute-evidence uploads that you explicitly choose to send
- Device advertising identifiers (IDFA on iOS, AAID on Android)
- Biometric data (Face ID, Touch ID, and Android biometrics are processed entirely on-device by the operating system)
- Screen recordings or keystrokes
All payment card data is handled exclusively by Stripe in accordance with PCI DSS standards.
4. Device Permissions
OSPOS requests certain device permissions only when you use the features that require them. We do not use these permissions for any other purpose.
- Bluetooth: Required by Stripe Terminal to communicate with external card readers and receipt printers, and by our optional two-device pairing feature to discover a nearby paired iPhone.
- Location (Fine, while in use): Required by Stripe Terminal to discover card readers, per Stripe's terms. We do not read or transmit your location.
- NFC: Used by Tap to Pay on iPhone. The card read is handled entirely by Apple's ProximityReader framework and Stripe; OSPOS never sees card data.
- Camera: Optional. Used only if you choose to add a photo to a menu item or upload dispute evidence.
- Photo Library: Optional. Same purpose as Camera.
- Local Network / Bonjour: Used only when you enable OSPOS's optional two-device mode, so a paired iPhone can be discovered on the same local network as your iPad. No data leaves your local network for this feature.
- Face ID / Biometrics: Optional. Used to confirm sensitive actions like refunds and account deletion. The authentication is performed by the operating system; we only receive a yes/no result.
- Push Notifications: Optional. Used to alert you to Stripe disputes and important account notices.
5. Two-Device Mode (iPad + iPhone)
OSPOS optionally lets you pair an iPad and an iPhone so the iPad displays the cashier interface and the iPhone acts as a customer-facing display and card reader. When you enable this feature:
- Both devices communicate directly with each other over Apple's MultipeerConnectivity framework (Bluetooth and local Wi-Fi). No data is sent to our servers by the pairing itself.
- The connection is encrypted by Apple's framework.
- Cart contents and charge amounts flow from the iPad to the iPhone in real time only for the duration of a session. Nothing is retained on either device beyond the current transaction.
- Card payments continue to be processed by Stripe Terminal and Apple's ProximityReader. OSPOS never sees card data on either device.
6. How We Use Your Information
We use your information solely to:
- Provide and operate the Service (account management, data sync, receipts, dispute handling)
- Send transactional emails (account verification, password resets, receipts, dispute alerts)
- Communicate service updates and important notices
- Improve the Service using aggregated, anonymized analytics
- Detect and prevent fraud and abuse
- Comply with legal obligations
We do not use your data for advertising, profiling, or marketing to third parties.
7. Third-Party Services
OSPOS integrates with the following third-party services, each with their own privacy policies:
- Stripe — Payment processing and Tap to Pay. Stripe receives transaction and business data necessary to process payments and handle disputes. See Stripe's Privacy Policy.
- Apple — Sign in with Apple and Tap to Pay on iPhone. See Apple's Privacy Policy.
- Google — Sign in with Google on Android, and advertising conversion measurement on our marketing website (see “Our website” below). See Google's Privacy Policy.
- Resend — Email receipt and account notification delivery. Resend receives customer email addresses only when an email receipt is sent, and your email address for account notifications. See Resend's Privacy Policy.
- Twilio — SMS receipt delivery (not currently enabled; pending A2P registration). When enabled, Twilio would receive customer phone numbers only when an SMS receipt is sent. See Twilio's Privacy Policy.
- Sentry — Error monitoring. Sentry receives anonymized crash reports and error data to help us fix bugs. Personally identifiable information such as emails, tokens, and phone numbers is automatically scrubbed before events are transmitted. See Sentry's Privacy Policy.
- Hetzner Online GmbH — Cloud hosting for our server. See Hetzner's Privacy Policy.
We do not share your data with any other third parties.
Our website (ospos.app)
This section covers our marketing website only — it does not describe the
OSPOS app. The website loads Google Ads conversion tracking, which sets cookies and
identifiers in your browser so we can tell whether an advertisement led to an app
download.
That tracking exists only on the website you are reading now. It is not
present in the OSPOS app, and it never has access to merchant accounts, menus, sales,
customers, or any transaction data. Visiting the website requires no account, and we do
not link website browsing to any OSPOS account. This does not change the commitment
above: we still do not use your data — your account, your sales, your
customers — for advertising, profiling, or marketing.
You can opt out at Google
Ads Settings, through your browser’s cookie controls, or with any tracking
blocker. None of these affect the app.
8. Data Security
We take reasonable measures to protect your data:
- In transit: All communication between the app and our servers uses TLS 1.2 or higher (HTTPS). Two-device pairing traffic is encrypted by Apple's MultipeerConnectivity framework.
- At rest: Server-stored data is protected by our provider's disk encryption. Local data on iOS is protected by Apple's filesystem encryption; local data on Android is protected by the platform's app-sandbox encryption.
- Authentication: Session tokens are stored in your device's secure store (Keychain on iOS, EncryptedSharedPreferences on Android), never in plaintext storage.
- Password storage: Passwords are hashed with bcrypt (cost factor 12) on our servers. We never store, log, or transmit your password in plaintext.
- Payment data: We never handle card data. Stripe manages all payment security in compliance with PCI DSS Level 1.
- Ongoing security: Our source code is public, and we have undergone independent security audits including MASVS-mobile and OWASP-Top-10 reviews.
9. Data Retention
- Free Tier: Data exists only on your device. Deleting the app deletes your data.
- Paid Tier: We retain your data for as long as your account is active. After account deletion (see Section 11), server-stored data is retained for 90 days to allow recovery, then permanently deleted.
- Legal obligations: We may retain certain records longer if required by law (e.g., tax records, fraud prevention, dispute records that Stripe requires us to preserve).
- Anonymized aggregates: We may retain aggregated statistics (such as total merchant counts and platform-wide transaction volume) indefinitely; these do not identify any individual user or business.
10. Your Rights
You have the right to:
- Access your data: Export your transaction data via CSV at any time from within the app (Settings → Export Data). Request a full data export by contacting us.
- Correct your data: Update your business information at any time through the app.
- Port your data: Export your data in CSV format for use with other services.
- Delete your data: See Section 11 below.
- Withdraw consent: Sign out of your account at any time; you can also revoke Stripe access from the app.
If you are located in the European Union, United Kingdom, or California, you may have additional rights under GDPR, UK GDPR, or CCPA respectively. Contact us to exercise these rights.
11. How to Delete Your Account
You can delete your OSPOS account and all associated server-stored data at any time:
- Open OSPOS on your device.
- Tap Settings.
- Scroll to the Account section and tap Delete Account.
- Confirm with Face ID, Touch ID, or your device passcode.
Deletion is immediate on our servers except for a 90-day recovery window during which the data is retained but not accessible. After 90 days it is permanently deleted. Stripe payment records may be retained by Stripe separately according to their policy.
If you cannot access the app (for example, if you have already uninstalled it), you may request deletion by emailing phil@ospos.app from the email address associated with your account. We process such requests within 30 days.
12. Children's Privacy
OSPOS is a business tool intended for merchants and business operators 18 years of age or older. We do not knowingly collect information from children under 13 (or under 16 in the EU). If you believe we have inadvertently collected such data, please contact us and we will promptly delete it.
13. International Data Transfers
Our servers are located in Germany (Hetzner Online GmbH), and our third-party subprocessors operate in the United States and other jurisdictions. If you use the Paid Tier from outside these regions, your data will be transferred to and processed in these locations. By using the Paid Tier, you consent to this transfer. We rely on Standard Contractual Clauses (SCCs) and equivalent safeguards for transfers of personal data from the EU/UK.
14. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will provide at least 30 days' notice via email (for Paid Tier users) or in-app notification. The most current version will always be available at ospos.app/privacy.
15. Contact Us
If you have questions about this Privacy Policy or want to exercise your data rights, contact us at:
OSPOS — TTTS Co.
Email: phil@ospos.app
Website: ospos.app
Source Code: github.com/pzapzap/ospos