OwnPoint

Privacy policy

Last updated September 27, 2026

This policy explains what information OwnPoint holds, why, who else handles it, and what you can do about it. OwnPoint is run by TML Consulting Services LLC, 1934 Meridian Blvd., Mammoth Lakes, CA 93546 (“we”, “us”).

1. Two kinds of information

About the businesses that use OwnPoint. The owner’s and managers’ names, email addresses and sign-in details. We are responsible for this information.

That a shop keeps in OwnPoint. Its sales, staff and customer records. The shop decides what to record and why; we store and process it on the shop’s behalf and only to run OwnPoint for it. If you are a customer or employee of a shop that uses OwnPoint, the shop is the one to ask about your information, and we will help it answer.

2. What is stored

  • Accounts: name, email address and password for owners and managers. Passwords are handled by our sign-in provider and are never stored in readable form.
  • Staff: name, optional email, role, hourly rate, a till PIN (stored only as a one-way hash), clock-in and clock-out times, schedules, availability and time-off requests.
  • The shop: its name, address, phone, email, tax rates, products, prices, stock and suppliers.
  • Sales: what was sold, prices, discounts, tax, tips, how it was paid, which staff member rang it and when, and cash drawer counts. Voids, refunds, discounts and drawer opens are logged with who, what and when, because tax law and theft prevention require it; that record cannot be switched off.
  • A shop’s customers, when the shop records them: name, email, phone, address, birthday, notes, loyalty punches, purchase history and whether they agreed to marketing email. This includes an email address typed in for a receipt, and a phone number entered on the card reader to collect loyalty punches.

3. Card details

Card numbers never touch our systems. Cards are read by the shop’s Stripe card reader or Stripe’s online payment form and processed by Stripe under the shop’s own Stripe account. We keep only Stripe’s reference for each payment, so a sale can be matched to its charge or refunded. Stripe’s handling of card data is described in Stripe’s own privacy policy.

4. What is kept on the device

OwnPoint uses cookies only to keep people signed in. There are no advertising or analytics trackers. The till keeps some things in the browser’s own storage: sales waiting to upload after an outage, the current basket, and till settings. Conversations with the assistant are kept in the browser tab and cleared when it closes.

5. Why we use it

To run OwnPoint for the shop: ring and record sales, print and email receipts, run schedules and reports, back everything up, keep it secure and give support. We do not sell personal information, share it for advertising, or use one shop’s data for any other shop. We do not use aggregated or de-identified data either.

6. Who else handles it

We use these service providers, each only for the part of the service named:

  • Supabase — the database and sign-in.
  • Vercel — hosting the application.
  • Stripe — card payments, under the shop’s own Stripe account.
  • Backblaze B2 — storage for the nightly backup copy of the database.
  • GitHub — runs the job that makes the nightly backup.
  • Resend — sending receipt emails.
  • Anthropic — the AI model behind the assistant. When someone asks it a question, the question and the store information needed to answer it are sent to Anthropic.

The database and the application run in the western United States (Northern California). The nightly backup copy is stored with Backblaze B2, also in the western United States. We may also disclose information when the law requires it.

7. Backups and how long information is kept

We keep a shop’s information while its account is open. A copy of the whole database is backed up every night: daily copies are kept for about a month and one copy a month for about a year, then deleted automatically. When a shop leaves, it has 30 days to export its data; we then delete it from the live system, and it leaves the backups as they age out, within 13 months.

8. Security

Each shop’s data is walled off from every other shop’s in the database itself, not only in the app. Connections are encrypted, PINs are hashed, and card data never reaches us. No system is perfectly secure; if a breach affects your information, we will tell the affected shops, and the authorities, where the law requires it.

9. Your choices

  • Shops can see, correct, export and delete their own data at any time. Everything a shop owns can be exported in standard file formats from Reports → Export, without asking us.
  • A shop’s customers and staff can ask that shop to see, correct or delete what it holds about them, and to stop marketing email.
  • California residents may have the right to know what personal information we hold about them and how it is used, to ask us to correct or delete it, and not to be treated differently for asking. We do not sell or share personal information. Where we hold it on a shop’s behalf, we pass the request to that shop and help it answer. To make a request, email mark@ownpointpos.com.

10. Children

OwnPoint is for businesses and is not directed at children under 13. We do not knowingly collect their information.

11. Changes

If we change this policy, we will post the new version here and update the date at the top, and tell account owners by email before a material change takes effect. Our terms of service cover the rest of the agreement.

12. Contact

TML Consulting Services LLC, 1934 Meridian Blvd., Mammoth Lakes, CA 93546. Email: mark@ownpointpos.com. Phone: 760-230-3755.