Legal
Privacy Policy
Effective and last updated September 23, 2026. Storey POS is operated by Paynetic Technologies LLC.
This policy explains how Storey and Storey POS (collectively, “Storey,” “we,” “us,” or “our”) handle information when merchants, their employees, and other authorized users use our websites, web application, Android application, and related services.
Information Storey handles
Account and staff information. This can include names, email addresses, phone numbers, authentication information, employee profiles, job information, roles, permissions, schedules, time records, and account preferences.
Business and operational information.Storey handles information entered or generated while running a business, including company and location details, catalogs, inventory, customers and contacts, bookings, invoices, estimates, orders, transactions, refunds, tips, gift cards, loyalty activity, shipping and fulfillment records, communications, uploaded images or documents, and hardware or station configurations.
Payment information. Card numbers and card security codes are collected and handled through Valor or another applicable payment processor using a payment terminal or processor-hosted entry flow. Storey is designed not to store raw card numbers or card security codes. Storey may retain the processor’s transaction identifiers or tokens, payment status and amounts, and limited card descriptors such as card brand and last four digits when supplied by the processor.
Technical and operational information.Storey may handle device, browser, application, network, session, diagnostic, and error information needed to secure, operate, troubleshoot, and improve the service. We found no advertising-tracking or third-party behavioral-analytics implementation in the current product. If those practices change, this policy must be updated before they are used.
How information is used
We use information to provide and secure Storey, authenticate users, enforce company roles and permissions, process and record business activity, connect enabled services and hardware, provide support, prevent misuse, troubleshoot failures, and administer the platform.
Merchants and authorized users determine much of the business and customer information entered into Storey and how it is used in their operations. They are responsible for providing appropriate notices and obtaining any consent required for information they collect from customers or employees.
Who can access information
A user can access their own account information and company or business information made available to them because they are listed as an employee or staff member of that company, subject to their assigned roles and permissions. Access controls are enforced by the service, not only by what the screen displays.
Authorized Paynetic Technologies LLC staff may access account or business information for legitimate purposes such as customer support, security, and platform administration. This access uses a server-enforced internal mechanism. Support visits are time-limited and recorded, and the service continues to identify the actual Storey staff account rather than logging that person in as the customer.
Authorized partner administrators may also receive server-limited access to the businesses in their own managed portfolio. They do not receive platform-wide access through that role.
Service providers and integrations
Storey uses Lovable Cloud for hosted database, authentication, file storage, and related application infrastructure. Valor and other applicable payment processors handle card payment processing. We disclose information to these providers only as needed to deliver the service, process a requested transaction, maintain security, or meet legal obligations.
A merchant may choose to connect optional services for email delivery, calendars, marketing, accounting, shipping, and AI-assisted product content. Current integrations include services such as Resend, Google Calendar, Mailchimp, Kit, QuickBooks, Shippo, and Anthropic. Information is sent to an optional service only when the corresponding feature is enabled or used. The connected provider’s own privacy terms also apply.
We may disclose information when required by law, to protect people or the service, in connection with a corporate transaction, or with the merchant’s or user’s direction or consent. We do not state that Storey sells personal information, and no advertising-data sale mechanism was found in the current product.
Android application and connected hardware
The Android application uses internet access and may use notifications. When a merchant configures compatible equipment, it can communicate with USB devices, paired Bluetooth devices, and devices on the local network, including printers, scales, card readers, and external barcode scanners. Current barcode scanning is keyboard-style or external-scanner based; the Android application does not currently request camera permission for scanning.
To keep business workflows available during temporary connectivity problems, the app can store functional data on the device, including authentication session information, preferences, catalog or stock cache data, and queued offline sales. Anyone controlling the device may be able to affect access to locally stored information, so merchants should use device locks and restrict physical access to point-of-sale devices.
Security and retention
We use technical and organizational safeguards intended to protect information, including authenticated access, company membership and permission checks, server-enforced support access, and processor-hosted card-entry paths. No system can guarantee absolute security.
Storey retains information for as long as needed to provide the service, preserve legitimate business and transaction records, resolve disputes, maintain security, and meet legal obligations. A single fixed retention period has not yet been established for every category of information; this policy should be updated when formal category-specific periods are adopted.
Choices and requests
Users can update some account and business information in Storey, control optional integrations, and manage device permissions through Android settings. Merchants may have legal obligations to respond to requests involving customer or employee information they control.
Storey currently provides limited CSV exports in specific parts of the product, including employee and workforce records and accounting transactions. It does not provide one complete, account-wide data export.
Account deletion is a manual request-based process today, not an automated self-service control. A user or merchant can ask their reseller or partner, if they have one, or Storey directly to remove their information. Privacy and account requests can be sent to support@storeypos.com. Storey will process the request after verifying the requester's identity and authority, subject to any information Storey or the merchant must retain for legal, security, dispute-resolution, or transaction-record purposes.
Rights vary by location. We will evaluate requests under the laws that apply to the requester and the information, and may need to verify identity and authority before acting.
Children and changes to this policy
Storey is a business service and is not directed to children. We may revise this policy when the product, providers, or legal requirements change. The effective date above will identify the latest version, and material changes may also be communicated through the service or another appropriate channel.
Contact
Storey POS is operated by Paynetic Technologies LLC. Privacy and account requests can be sent to Storey's support email at support@storeypos.com.
