Legal
Privacy policy
Effective 3 August 2026
1.Who we are
DeckPOS is the controller for the data described here. Contact privacy@deckpos.com.
2.What we collect, and why
If you visit this site: the pages you looked at and a cookie that remembers your consent choice. Nothing else unless you give it to us.
If you give us your email: that address, when you confirmed it, and when you opted in or out. We use it to send what you asked for, and we do not send anything to an address that has not confirmed itself.
If you operate a store: your name, email, role, the store you belong to, and a record of security-relevant actions — signing in, changing a permission, voiding a sale. That last one is kept because it is what makes an audit trail worth having.
3.What we never do
We do not sell personal data. We do not use your store’s data or your customers’ data to train models. We do not run advertising trackers on this site — the only cookie set without asking is the one that remembers you were asked.
4.How long we keep it
Marketing addresses until you unsubscribe, plus a record of the unsubscribe itself so we can prove we stopped. Operator accounts for as long as the store exists, then 30 days. Security audit records for two years, because their whole purpose is answering a question asked later.
5.Who else sees it
The infrastructure providers we run on, each under a contract that forbids them using it for anything else. They are listed, by name and purpose, on the subprocessors page.
6.Your rights
You can ask for a copy of what we hold, ask us to correct it, or ask us to delete it. Manage my data does all three without needing an account. We verify the address first — otherwise anybody could delete anybody.
Cookie choices can be changed at any time from cookie preferences, including withdrawing a consent you already gave.
Questions about any of this go to legal@deckpos.com. To see or delete what we hold about you, use Manage my data.