Privacy: where data stays, and when you choose to send it elsewhere

This notice describes PhoneBooth POS 26.10.4 and its support website as of 4 October 2026. It is not a promise that a merchant complies with any particular law.

Data the app stores

Depending on the features a merchant uses, the app may store:

  • Products, categories, stock, modifiers, product images, shop details, and settings.
  • Sale, refund, and void records, including amounts, payment methods, line items, and relevant times.
  • Customer name and phone number when staff choose to enter them.
  • Table, kitchen, shift, counter, and operational status records.
  • A payment photo when a user chooses to attach one.

A customer name or phone number is not required for every sale. The merchant decides whether those fields are appropriate to collect.

On-device storage and the owner PIN

Core operational data is stored in a SQLite database on the iPad through GRDB. The owner PIN is not stored as plain text: the app stores a salted hash in Keychain and PIN retry-lockout state in UserDefaults.

A review of this version’s code found no analytics, advertising, or tracking system and no app networking feature that automatically sends shop data. This does not mean that “data never leaves the device,” because users can export and share it.

When you export or share

The user initiates exports such as JSON backups, CSV files, reports, receipts, or other documents, and chooses images or files to import. Apple’s system interface presents destinations such as Files, AirDrop, messages, or installed services.

Once you choose an external destination, its recipient or service applies its own privacy, security, and retention practices. Review the content and share only what is needed.

Financial history and deletion

The sales ledger is append-only. A void or refund adds a correction event and preserves the earlier history; it does not remotely erase an earlier sale.

Deleting the app may remove its app database from the device, but it does not delete files or documents previously exported. It may not remove Keychain items or copies held in operating-system or iCloud backups. The merchant must manage external files, iPad/iCloud backups, and its own retention policy.

This support website

This site is hosted on Cloudflare. Cloudflare may process IP addresses, request information, and technical data needed to deliver and secure the site and prevent abuse. See the Cloudflare Privacy Policy.

The PhoneBooth POS site itself sets no analytics, cookies, advertising, trackers, forms, or client-side JavaScript. It serves only HTML, CSS, and the local app-icon image.

Merchant responsibility

The merchant chooses what customer data to enter, why to use it, who may access it, how long to keep it, how to back it up, and where to share it. Merchants should inform customers and handle data according to the obligations that apply to their business. This site does not identify a controller on a merchant’s behalf or claim legal compliance.

Customers with questions or requests about a merchant’s records should contact that merchant directly. PhoneBooth POS cannot remotely access or delete a shop’s local ledger, and refund or void events preserve the earlier history.

Send a privacy question

Policy version 1.0Scope: PhoneBooth POS 26.10.44 October 2026