Privacy Policy

Effective September 3, 2026 · Last updated September 3, 2026

If you just checked in somewhere: the venue hosting your event asked for that information, and the venue decides what happens to it. AcePOS is the software they use to collect and store it. We hold it for them. We never sell it, never use it for advertising, and never let one venue see another venue's guests. To see, correct, or delete your information, contact the venue you visited. If you can't reach them, write to us at [PRIVACY@YOURDOMAIN.COM]and we'll help.

1. Two different roles

This policy covers two kinds of information, and our responsibilities differ for each. The distinction matters, so it comes first.

  • Guest information: what you enter on a check-in form at an event. Here the venue is in charge. They chose the questions, they decide how the answers are used, and they are the ones to ask about access or deletion. We only process it on their behalf, under contract. In legal terms they are the controller or “business”; we are the processor or “service provider.”
  • Account information: what a business gives us when it signs up for AcePOS. Here we are in charge, and this policy describes what we do with it directly.

2. What we collect

From guests, on behalf of a venue

Venues build their own check-in forms, so the exact fields vary. The form always shows you what it is asking before you submit it. Across all venues the possible fields are:

CategoryFieldsRequired?
ContactFirst name, last name, email address, phone number, preferred nameName and email are always required; phone is optional
Visit contextOccasion being celebrated, birthday month, anniversary month, who is being celebratedOptional
PreferencesCustom questions the venue writes, for example seating, drink, or spice preferencesSet by the venue
Consent signalsWhether you agreed to receive marketing from the venue, whether you agreed to be sent event photos, plus the time each was recordedOptional
Check-in recordWhich event, the name you typed, and the time you checked inAutomatic
Added by the venueTags, private notes, a VIP flag, and your visit history at that venueNot visible to you

If you are selected for a prize, we also store a claim token, the prize status, and whether the notification email reached you.

From businesses that use AcePOS

Account holder name, email address, username, role, business name, and event configuration. For a paid plan we also store Stripe customer and subscription identifiers, when the subscription began, its status, whether it is set to cancel at the end of the current period, the current period's end date, and the billing name, email, country, and address you provide for invoices. For a one-time event or credit purchase we store the PayPal order ID, amount, and status. We record an audit log of privileged actions taken in the dashboard: who did what, and when.

To save you typing, the billing form may arrive with a country already selected, suggested from the approximate location of your IP address or from your browser's language setting. It is only a suggestion: nothing is stored until you save the billing form, and you can change it before you do.

We do not receive or store payment card numbers or bank details. Stripe and PayPal handle that entirely.

Automatically

Standard web server logs (IP address, browser type, pages requested, timestamps) and Google Analytics 4, which we use to understand overall traffic patterns. Analytics data is not linked to your check-in record.

3. What we never collect

Our terms prohibit venues from using check-in forms to collect government identifiers, payment card or bank details, health, medical, or biometric information, precise geolocation, or information from children under 13. The Service performs no facial recognition and stores no biometric identifiers of any kind.

Venues in real estate are additionally prevented from asking questions that touch classes protected by the Fair Housing Act; those topics are excluded from the question bank outright.

4. How the information is used

Guest information is used to:

  • Record your check-in and show the venue who attended.
  • Recognize you on a return visit, so you are not entered twice.
  • Enter you into a prize drawing at that event, if the venue is running one, and notify you if you win.
  • Let the venue export its own guest list as a spreadsheet.
  • Pass along, to the venue, the consent choices you made, so that the venue knows whether it may contact you.
  • Send you marketing email on the venue's behalf, if you agreed to receive it.

Account information is used to operate your account, process payment, provide support, secure the platform, and send service notices.

5. Email: who actually sends what

This is the part most often misunderstood, so it is worth stating exactly.

AcePOS sends guests two kinds of email at the platform level: a prize-winner notification containing your claim link, sent only if a venue has drawn you as a winner, and marketing email that a venue composes and directs us to deliver on its behalf, described next. We send no newsletters or promotions of our own, and we never email you about our own products.

The venue decides what to send and when; we deliver it. If you ticked the box agreeing to hear about events and offers, that preference is recorded and handed to the venue, which writes the message. We send it on the venue's behalf from our own sending address, and every one carries our own working, one-click unsubscribe link, which takes effect immediately. You can also ask the venue directly to stop contacting you, or clear the marketing flag on your record on request so we stop sending to you.

The same is true of event photos. If you asked to be sent photos, that choice is recorded and given to the venue. AcePOS does not store, process, or send event photographs.

6. Who we share information with

We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under California law or any comparable state law. We have never done so. Guest information is never pooled across venues and is never disclosed to another venue on the platform.

We use the following service providers, which process information only to provide their service to us:

ProviderPurposeWhat it touches
SupabaseDatabase, authentication, file storageAll stored data
VercelApplication hosting and deliveryRequests and server logs
ResendSending the prize-winner notice, sign-up and password-reset email, guest marketing campaigns a venue sends, and the account-deletion noticeRecipient name, email, and message content
StripeProcessing subscription paymentsBusiness payment details only
PayPalProcessing venue paymentsBusiness payment details only
Google AnalyticsAggregate site analyticsSite usage, not check-in data

We may also disclose information when required by law, to enforce our terms, to protect someone's safety, or in connection with a merger or acquisition, in which case we will give notice before personal information becomes subject to a different policy.

7. Cookies and analytics

The check-in form itself sets no advertising cookies. Across the site we use:

  • Essential cookies: session cookies that keep a signed-in staff member signed in, and a preference cookie remembering light or dark mode. These cannot be switched off without breaking the site.
  • Analytics: Google Analytics 4 sets cookies to measure aggregate traffic. You can opt out with Google's browser add-on, or by blocking cookies in your browser. Blocking them does not affect your ability to check in.

We honor Global Privacy Control signals sent by your browser as a valid opt-out request where applicable law requires it.

8. How long it is kept

InformationRetention
Guest profiles and check-in recordsFor as long as the venue keeps its account, since the guest book is the product they are paying for. Deleted within 30 days of a venue deleting the record or closing its account.
Prize and claim recordsKept for the life of the venue account, as proof that prizes were awarded as advertised.
Payment recordsSeven years, for tax and accounting purposes.
Staff and owner accountsDeleted at your request, then kept for 30 days during which the account cannot be signed in to and can usually be restored on request. Restoring is not always possible: we cannot do it once the 30 days have passed, if the business has been suspended, or if the business has since filled every seat its plan allows. Shortly after 30 days the login, the profile and the profile photo are permanently erased. Your email address stays reserved until then, so it cannot be used to sign up again until the period ends or you ask us to release it.
Audit logsTwo years, for security and dispute investigation. Entries recording what an account did are kept as business records after that account is erased, including the record of the erasure itself, and are then identified by the email address rather than by a live account.
Server logsApproximately 30 days.
Encrypted backupsDeleted records may persist in backups for up to 30 days before expiring on the ordinary backup cycle.

The analytics date ranges in the dashboard are a display limit, not a retention limit. A plan determines how far back the charts can be opened, up to 90 days on paid plans. Nothing is deleted when a plan changes, and a venue's own check-in and guest records are kept for as long as the table above says regardless of which ranges its plan can display. Exports include the full history.

9. How it is protected

  • Encrypted in transit (HTTPS/TLS) and at rest.
  • Venue separation enforced in the database itself. Every table holding guest information carries row-level security policies keyed to the owning venue, so isolation does not depend on the application getting a query right.
  • Writes to sensitive fields, including payment status and form definitions, are restricted at the database grant level so they cannot originate from a browser.
  • Staff access within a venue is limited by role, and privileged actions are recorded in an audit log.
  • Check-in submissions are rate limited to protect the public form.

No system is perfectly secure. If a breach affects your information we will notify the affected venue within 72 hours of becoming aware, and will notify individuals and regulators where the law requires it.

10. Your rights

Depending on where you live (California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and a growing list of other states, or the EU/UK), you may have the right to:

  • Know what information is held about you and get a copy.
  • Correct information that is wrong.
  • Delete information about you.
  • Opt out of sale or targeted advertising (we do neither).
  • Not be discriminated against for exercising these rights.

How to exercise them

For check-in information, start with the venue. They control it and can act immediately using the guest tools in their dashboard. If you don't know how to reach them, or they don't respond, email [PRIVACY@YOURDOMAIN.COM] with the venue name and the date of your visit, and we will route the request and follow up. You may also write to us at [STREET ADDRESS, CITY, NY ZIP].

We will confirm receipt within 10 days and respond within 45 days, extendable once by another 45 days where the law permits. We verify requests by matching the email address on file; we may ask for additional detail about your visit if the match is ambiguous. An authorized agent may submit a request with written proof of authority.

California residents may designate an authorized agent and may appeal a refused request; residents of states providing an appeal right may do the same by replying to our decision. If we deny an appeal, you may contact your state attorney general.

11. Children

The Service is not directed to children under 13, and we do not knowingly collect their information. Venues are contractually required to collect an accompanying adult's details instead. If you believe a child has submitted information, email [PRIVACY@YOURDOMAIN.COM] and we will delete it.

12. Where information is stored

AcePOS is operated from the United States and all information is stored there. If you check in from outside the U.S., you are sending your information to the U.S., where privacy laws differ from those in your home country.

13. Changes

We will update this policy as the Service changes, and will revise the date at the top. For material changes affecting guests we will update the notice shown on the check-in form. Business account holders will be given at least 30 days' notice by email.

14. Contact

Questions, requests, or complaints about privacy go to [PRIVACY@YOURDOMAIN.COM], or by mail to [LEGAL ENTITY NAME], [STREET ADDRESS, CITY, NY ZIP]. Everything else: [CONTACT@YOURDOMAIN.COM].

Businesses using AcePOS should also read the Terms of Service, including the Data Processing Addendum in Annex A.