RetroVault Inc. ("RetroVault," "we," "us," or "our") operates a point-of-sale software platform for specialty retail stores. This Privacy Policy explains how we collect, use, share, and protect information when you use our Service.
We distinguish between two types of people in this policy:
For End Customers: your personal information is controlled by the retail store you transacted with, not directly by RetroVault. Please contact that store with privacy requests related to your purchase history.
| Type | Examples | Who provides it |
|---|---|---|
| Account information | Name, email, password, store name, phone, address | Subscriber |
| Billing information | Credit card details (processed by Stripe — we do not store card numbers) | Subscriber |
| Business data | Inventory records, pricing, categories, tax rates | Subscriber |
| Transaction data | Sales records, trade-in records, returns, payments | Subscriber |
| Customer records | Customer names, emails, phone numbers, purchase history, loyalty points | Subscriber (about End Customers) |
| Staff accounts | Names, email addresses, roles | Subscriber |
| Communications | Support emails, feedback, feature requests | Subscriber |
| Purpose | Legal basis |
|---|---|
| Providing and operating the Service | Contract performance |
| Processing subscription payments | Contract performance |
| Sending transactional emails (receipts, invoices, alerts) | Contract performance |
| Customer support and troubleshooting | Legitimate interest |
| Security monitoring and fraud prevention | Legitimate interest |
| Improving and developing the Service | Legitimate interest |
| Sending product updates and service announcements | Legitimate interest / consent |
| Complying with legal obligations | Legal obligation |
We do not sell your personal information or your customers' personal information to third parties. We do not use your business data or customer data for advertising purposes.
We share information only in the following circumstances:
We share data with trusted third-party providers who help us operate the Service:
All service providers are contractually required to protect your data and use it only for the purposes we specify.
We may disclose information if required by law, court order, or government authority, or if we believe disclosure is necessary to protect the rights, property, or safety of RetroVault, our users, or the public.
If RetroVault is acquired, merges with another company, or sells substantially all of its assets, your information may be transferred as part of that transaction. We will provide notice before your information is transferred and becomes subject to a different privacy policy.
We retain your data for as long as your account is active or as needed to provide the Service. Specifically:
You may request earlier deletion of your data by contacting us at [email protected].
We implement appropriate technical and organizational measures to protect your information, including:
No method of transmission or storage is 100% secure. If we become aware of a security breach that affects your data, we will notify you as required by applicable law.
Depending on your location, you may have the following rights regarding your personal information:
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
Note for End Customers: Requests related to purchase history or loyalty data held by a specific store should be directed to that store, as they are the data controller for that information.
The Service uses cookies and similar technologies for the following purposes:
We do not use advertising or tracking cookies. We do not share cookie data with advertisers.
The Service is intended for use by businesses and is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us immediately.
Your data is stored on servers located in the United States (via Supabase). If you are located outside the United States, your data will be transferred to and processed in the United States, which may have different data protection laws than your jurisdiction. By using the Service, you consent to this transfer.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
To submit a CCPA request, contact us at [email protected].
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through a notice in the Service at least 30 days before the changes take effect. The date at the top of this page reflects when the policy was last updated.
Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated policy.
If you have questions, concerns, or requests related to this Privacy Policy or our data practices, please contact us: