Data the app stores
Depending on the features a merchant uses, the app may store:
- Products, categories, stock, modifiers, product images, shop details, and settings.
- Sale, refund, and void records, including amounts, payment methods, line items, and relevant times.
- Customer name and phone number when staff choose to enter them.
- Table, kitchen, shift, counter, and operational status records.
- A payment photo when a user chooses to attach one.
A customer name or phone number is not required for every sale. The merchant decides whether those fields are appropriate to collect.
On-device storage and the owner PIN
Core operational data is stored in a SQLite database on the iPad through GRDB. The owner PIN is not stored as plain text: the app stores a salted hash in Keychain and PIN retry-lockout state in UserDefaults.
A review of this version’s code found no analytics, advertising, or tracking system and no app networking feature that automatically sends shop data. This does not mean that “data never leaves the device,” because users can export and share it.
Financial history and deletion
The sales ledger is append-only. A void or refund adds a correction event and preserves the earlier history; it does not remotely erase an earlier sale.
Deleting the app may remove its app database from the device, but it does not delete files or documents previously exported. It may not remove Keychain items or copies held in operating-system or iCloud backups. The merchant must manage external files, iPad/iCloud backups, and its own retention policy.
This support website
This site is hosted on Cloudflare. Cloudflare may process IP addresses, request information, and technical data needed to deliver and secure the site and prevent abuse. See the Cloudflare Privacy Policy.
The PhoneBooth POS site itself sets no analytics, cookies, advertising, trackers, forms, or client-side JavaScript. It serves only HTML, CSS, and the local app-icon image.
Merchant responsibility
The merchant chooses what customer data to enter, why to use it, who may access it, how long to keep it, how to back it up, and where to share it. Merchants should inform customers and handle data according to the obligations that apply to their business. This site does not identify a controller on a merchant’s behalf or claim legal compliance.
Customers with questions or requests about a merchant’s records should contact that merchant directly. PhoneBooth POS cannot remotely access or delete a shop’s local ledger, and refund or void events preserve the earlier history.