Legal

Privacy Policy

Effective: · Last reviewed: (product draft — not counsel-approved)

Draft pending legal counsel review. Not legal advice — do not treat as final production language. This page does not claim PCI Level 1, HIPAA, or any other certification.

Disclaimer

This document is a draft and has not been approved by legal counsel. It does not constitute a PCI certification (including PCI DSS Level 1), HIPAA compliance attestation, or any other regulatory certification. Do not rely on this document for legal compliance until it has been reviewed and approved by a qualified attorney.

1. Who we are

LYNKSpay ("LYNKSpay," "we," "us") provides a browser-based point of sale for restaurants and retail businesses. Contact: hello@lynkspay.app.

This draft Policy applies to lynkspay.app, related marketing pages, and the authenticated LYNKSpay application. It is not legal advice and is pending counsel review before production reliance. Related: Terms of Service (including the 14-day free trial).

2. Intended audience & children (COPPA)

The Service is intended for businesses and users who are at least 18 years old. We do not knowingly collect personal information from children under 13. The Service is not directed to children under 13 and is not intended to be subject to the Children's Online Privacy Protection Act (COPPA). We do not offer child-directed communities or social features.

If you believe a child under 13 has created an account, contact hello@lynkspay.app and we will delete the account and related personal information promptly. Merchant employees under 18 who use a terminal do so under the merchant's account and workplace policies — the account owner must be an adult authorized to bind the business.

3. Information we collect

We collect account, business, staff, transaction, and technical information needed to run the POS, including during any free trial period described in our Terms:

  • Account data: email address, password (hashed by our auth provider), and profile name; if you use Google sign-in, identifiers and email from Google.
  • Business & staff data: organization and location names, staff display names, roles, and terminal PIN hashes (PINs are hashed; we do not store plaintext PINs).
  • Operational data: menus/catalog, tickets/checks, payments metadata (amounts, method, Stripe PaymentIntent IDs), tips, cash drawer sessions, and related audit logs.
  • Technical data: IP address, device/browser type, app version, and error diagnostics when reporting is enabled. Session tokens may be stored in browser localStorage.
  • Cookies: we use first-party functional cookies (for example, UI state). We do not use advertising pixels or third-party ad trackers on the site today.

We do not intentionally collect sensitive government IDs, precise geolocation for marketing, or full payment card PANs/CVVs through the LYNKSpay application UI. Card data entered for payments is handled by Stripe under Stripe's terms; we do not claim a specific PCI DSS merchant level in this draft.

4. How we use information

  • Provide, secure, and improve the Service (including free trials)
  • Authenticate users and authorize staff terminals
  • Process payments via Stripe and reconcile tickets
  • Provide support and respond to requests
  • Send service-related notices (security, billing when enabled)
  • Comply with law and enforce our Terms

We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising.

5. Processors & sharing

We share data with service providers who process it on our instructions — not to sell it or share it for ads:

  • Supabase — authentication, database, and related hosting
  • Stripe — card and Terminal payment processing. Stripe processes card data; LYNKSpay does not store full primary account numbers (PAN) or CVV on our servers
  • Google — optional OAuth sign-in
  • Hosting / CDN / fonts — infrastructure and font delivery
  • Error monitoring — when enabled (for example, Sentry), limited diagnostic data to diagnose outages and bugs

We may disclose information if required by law, to protect rights and safety, or in connection with a merger, acquisition, or asset sale (with notice where required).

6. Retention

We retain account and operational records for as long as your account is active and as needed for tax, accounting, dispute, and legal obligations. Soft-deleted records may remain for a limited period before permanent deletion. Trial-only accounts that never convert may still retain data until you request deletion or we purge inactive accounts under our operational policies. You may request deletion as described below; some records may be retained where law requires.

7. Your privacy rights (including CCPA)

Depending on where you live, you may have rights to access, correct, delete, or export personal information, and to appeal a denial.

California (CCPA/CPRA): You may request to know, delete, or correct personal information we hold about you. We do not sell or share personal information as those terms are defined for cross-context behavioral advertising. You will not be discriminated against for exercising privacy rights.

CCPA / privacy contact: email hello@lynkspay.app with "Privacy request (CCPA)" in the subject line. We may verify your identity before fulfilling a request. Authorized agents may submit requests as permitted by law; we may require proof of authorization.

8. Security

We use industry-standard controls appropriate to a multi-tenant POS, including encrypted transport (HTTPS), hashed credentials and staff PINs, and row-level access controls separating merchant data. Card payments rely on Stripe's infrastructure; this Policy does not assert a PCI DSS Level 1 (or any numbered level) certification for LYNKSpay. No method of transmission or storage is 100% secure.

9. International transfers

We primarily serve businesses in the United States. If you access the Service from another country, your information may be processed in the United States or other locations where our providers operate.

10. Changes

We may update this Policy from time to time. Material changes will be highlighted on this page or by email to account owners when appropriate. The Effective and Last reviewed dates at the top of this page will be updated when we publish a new draft.

Related: Terms of Service.