Privacy
Privacy, in plain language.
How StoreRounds handles data today, what a future production pilot is designed to read, and the promises that will bind that pilot. Written to be read by an owner, not just a lawyer.
Last updated 2026-07-15 · storerounds.com/privacy
A licensed privacy attorney is reviewing the formal Privacy Policy and Data Processing Addendum that will stand behind this page. Until that review completes, this page states our working practice in plain language, and we do not accept payment against these terms. If anything here changes, this page changes first, in plain sight.
한국어 요약
StoreRounds는 현재 사전 제작 단계이며 실제 매장 POS에 연결된 운영용 어댑터는 없습니다. 이 웹사이트의 신청서는 이메일과 필수 매장 수 구간을 수집하고, Cloudflare는 쿠키 없는 방문 통계를 처리하며, Kit은 신청 이메일을 보관합니다. 데이터 내보내기 또는 삭제는 [email protected]으로 요청할 수 있습니다. 정식 개인정보처리방침과 데이터 처리 부속서(DPA)의 변호사 검토가 끝나기 전에는 결제를 받지 않습니다.
이 한국어 요약은 이해를 돕기 위한 안내이며, 법적 효력을 갖는 정식 문서는 영문본입니다. 한국어로 궁금하신 점은 [email protected]으로 편하게 문의해 주세요.
What this page covers
This page covers this website (storerounds.com), founding-cohort applications, and the intended StoreRounds product: a read-only connector, briefing service, and phone capture feature. It is the formal companion to the Trust and Security page, which separates lab-proven controls from production launch gates.
One status line, stated plainly: StoreRounds is pre-production. Its core flow has been exercised with simulated data, but no named POS adapter has passed the production proof gate and no real non-canary chain is connected. The product sections below state the rules for a future approved pilot, not a description of a live customer deployment.
What this website collects today
The only measurement on these pages is cookieless and privacy-first: Cloudflare Web Analytics counts visits and page views with no cookies, no cross-site tracking, no personal profiles, and no advertising pixels. Cloudflare already serves this site, so no new company sees your traffic, and nothing about your visit is sold or shared. The only external request you trigger yourself is the form you choose to submit.
- The founding-cohort application collects your email address, a required store-count band, and, if you arrived from a campaign, the tags on the link you clicked. That is all.
- Application data is stored with our email service provider (Kit) and used for the confirmation and pilot communications you requested. No spam, ever, and you can unsubscribe with one click in any email.
The data an approved production pilot would handle
What the pilot is designed to handle
- Business data: aggregated daily sales totals that a validated, read-only adapter would read from a narrow, named set of point-of-sale tables.
- Capture data you submit during a pilot: photographs of deposit slips, check deposits, and invoices, and the amounts read from them. These can carry bank account and routing numbers, and sometimes a name.
- Account data: names and email addresses of approved pilot users.
What we deliberately do not
- Payment card numbers. Never read, at all.
- Your employee or customer records. Not in the connector's read set.
- No payment processor receives data today. If payments later open, billing details will go directly to the named processor and not to StoreRounds.
- A full copy of your database. Only aggregated totals leave the store.
The planned capture path is the sensitive one and we say so at full volume: photographed slips can carry bank and personal details, the exact class of data the connector is designed not to touch. Before any real document enters a pilot, that path must use login attribution rather than biometrics and meet the stricter controls in the capture section of the Security page.
How we use data, and the promises that bind that use
- Today we use application data to review and contact founding-cohort applicants. In an approved pilot, customer data would be used only to run, secure, and support that customer's service and build its account-walled Chain Memory.
- Never sold. We do not sell or share application data as those terms are used under privacy law, and a future pilot would carry the same rule for customer data. We do not give data to brokers, advertisers, or competitors. The intended business model is paid software, but no paid plan is active today.
- Never trains a shared model without consent. Application data is not used to train a shared model. No StoreRounds Index is active. If a cross-chain benchmark program is built later, it would remain off by default and require explicit, written, revocable owner consent. Withdrawing consent would stop future inclusion, though it could not un-compute a benchmark already published; that limit would be disclosed before consent.
- Where we ever publish aggregated figures, we use the words "aggregated and de-identified," not "anonymized," unless the legal de-identification standard is actually met.
Your rights and controls
- You own your data. Until self-serve controls ship, email us with an export or deletion request at [email protected]. The founder will confirm the request's scope and completion timeline.
- A pilot connection would remain locally revocable. If a connector is installed for an approved pilot, the owner can stop new reads by dropping its read-only database credential or removing the connector, without waiting for a support ticket.
- State privacy rights. Depending on your state (California and a growing list of others), you may have rights of access, deletion, correction, and opt-out. Write to us and we will honor them; the counsel-reviewed policy will spell out the formal process, including California's coverage of workforce data.
- Pilot application: every email has a one-click unsubscribe, and you can ask us to delete your application record entirely.
Security, retention, and breach
- The prototype has exercised TLS in transit, encryption at rest, read-only least-privilege database access, protected credential storage, and server-enforced account and store boundaries with simulated data. Each named POS adapter still has to pass production proof before real customer use.
- Each data type is kept only as long as the service needs it or the law requires. Capture images are retention-limited to the reconciliation window, not kept forever.
- If a security incident affects your data, we will notify you without undue delay, consistent with applicable breach-notification law. Captured bank and routing numbers are treated as the highest-sensitivity trigger in that plan.
The full technical model, including what you can audit yourself, is on the Trust and Security page.
Subprocessors
Current infrastructure vendors are Cloudflare (site hosting, cookieless Web Analytics, and prototype object storage), Railway (prototype application hosting), Neon (prototype database hosting), Resend (prototype transactional email), and Kit (founding-cohort application emails). No payment processor receives data today. Before any customer connects a store, this list will state exactly which vendors can touch that pilot's data.
Today, website visitor or application data touches Cloudflare for hosting and cookieless analytics, and Kit for application emails. The other named vendors support preconnected product infrastructure; no real non-canary chain is connected.
Contact
Questions about privacy, or a rights request: [email protected]. It reaches the founder.