Version 2026.08.12

Privacy Policy

How Tamper collects, uses, shares, retains, and protects personal information, including GDPR and CCPA rights.

Effective
2026-08-12
Audience
Merchants, staff users, café customers, website visitors, and job applicants whose information is processed through Tamper.
Notice
Email + in-product for material changes

1. Scope and roles

This Privacy Policy explains how Tamper collects, uses, discloses, retains, and protects personal information. For merchant account data, Tamper is generally a controller or business. For personal information that merchants upload about their café customers or staff, Tamper generally acts as a processor or service provider on behalf of the merchant, unless otherwise required by law.

2. Personal information we collect

  • Account and business data: names, email addresses, phone numbers, roles, authentication data, business names, addresses, tax settings, merchant identifiers, support contacts, and onboarding details.
  • Transaction data: order details, items purchased, discounts, taxes, timestamps, payment status, refunds, disputes, receipts, loyalty activity, and limited payment metadata. Tamper does not intentionally store full card numbers.
  • Customer PII processed for merchants: customer names, contact details, order history, loyalty identifiers, delivery or pickup notes, communication preferences, and support requests.
  • Device and usage data: IP address, device identifiers, browser type, operating system, pages viewed, clicks, approximate location, referral source, logs, diagnostics, performance metrics, crash reports, and Core Web Vitals.
  • Communications: emails, SMS content, chat messages, support tickets, call notes, survey responses, and feedback.
  • AI input and output: prompts, merchant instructions, generated copy, menu descriptions, business context, edits, and related metadata needed to provide AI features.

3. Sources of information

We collect information directly from users, from merchants using Tamper, from café customers who interact with merchant experiences, from devices and cookies, from payment and messaging providers, from integrated services authorized by merchants, and from publicly available or commercially available business information where permitted.

4. How we use information

  • Provide, operate, secure, troubleshoot, personalize, and improve Tamper services.
  • Create accounts, authenticate users, manage subscriptions, process payments, fulfill orders, issue invoices, support refunds, and resolve disputes.
  • Send transactional messages, service updates, security alerts, onboarding communications, receipts, customer messages requested by merchants, and marketing where allowed.
  • Generate AI-assisted content and operational insights at the merchant’s direction.
  • Analyze usage, reliability, conversion, errors, fraud risk, product performance, and customer support quality.
  • Comply with legal, tax, accounting, sanctions, payment-network, law-enforcement, and regulatory obligations.

5. Legal bases for EEA and UK processing

Where GDPR or UK GDPR applies, Tamper relies on one or more legal bases: performance of a contract, legitimate interests in operating and improving secure business software, consent for optional analytics or marketing where required, compliance with legal obligations, and protection of vital interests in exceptional safety or security circumstances.

6. Third-party sharing and processors

Tamper does not sell personal information for money. We share personal information with service providers and processors that help us provide the services, subject to contracts and appropriate safeguards.

  • Stripe and payment partners for payment processing, invoices, fraud prevention, disputes, refunds, and financial compliance.
  • Twilio or messaging providers for SMS, phone, and customer communication workflows requested by merchants.
  • OpenAI and AI infrastructure providers for AI-assisted generation, summarization, classification, and support features.
  • PostHog or analytics infrastructure for product analytics, page views, autocaptured interactions, errors, and performance metrics when analytics consent is enabled or where otherwise permitted.
  • Hosting, database, storage, email, security, support, monitoring, and professional service providers.
  • Authorities, regulators, payment networks, advisors, successors, or counterparties where required by law, merger, financing, acquisition, dispute, or enforcement of our rights.

7. Cookies, analytics, and opt-outs

Tamper uses necessary storage for authentication, security, preferences, offline operation, and service reliability. Optional analytics cookies and similar technologies help us understand product usage, errors, performance, and conversion. You can manage optional analytics through the cookie banner or browser settings. If a Global Privacy Control or similar legally recognized opt-out signal is received and technically supported, Tamper will treat it as an opt-out of sale or sharing where required.

8. Data retention

  • Account, merchant, and subscription records: retained while the account is active and up to 7 years after closure for tax, accounting, dispute, and compliance purposes.
  • Transaction, invoice, refund, chargeback, tax, and payout records: generally retained for 7 years or longer if required for legal, financial, or payment-network obligations.
  • Customer order and loyalty data processed for merchants: retained while the merchant account is active, unless deleted or exported according to merchant instructions and legal requirements.
  • Security logs, device logs, diagnostics, and fraud signals: generally retained for up to 24 months unless needed for investigation, legal claims, or security.
  • Product analytics: generally retained for up to 25 months in identifiable or pseudonymous form, then deleted, aggregated, or de-identified.
  • Support communications: generally retained for up to 3 years after resolution unless needed longer for account history, quality, compliance, or disputes.
  • Marketing preferences: retained until you opt out, plus suppression records needed to honor opt-outs.

9. Your rights

Depending on your location, you may have rights to access, know, confirm, correct, delete, port, restrict, object to, or withdraw consent for certain processing. California residents may also have rights to opt out of sale or sharing, limit use of sensitive personal information, and not be discriminated against for exercising privacy rights. EEA and UK individuals may lodge a complaint with a supervisory authority.

10. How to exercise rights

Submit privacy requests to privacy@tamper.app. We may need to verify your identity and authority before completing a request. If Tamper processes your information on behalf of a merchant, we may direct your request to that merchant or assist the merchant in responding. You may opt out of marketing emails using unsubscribe links and opt out of optional analytics through the cookie banner.

11. International transfers

Tamper may process information in the United States and other countries where service providers operate. Where required, Tamper uses appropriate safeguards such as standard contractual clauses, data processing agreements, or other lawful transfer mechanisms.

12. Children

Tamper is designed for businesses and is not directed to children under 16. Do not create an account or submit personal information if you are under 16.

13. Security

Tamper uses administrative, technical, and organizational safeguards designed to protect personal information. No system can be guaranteed completely secure, and merchants remain responsible for configuring staff permissions and protecting credentials.

14. Changes and notices

Tamper versions this Privacy Policy by effective date. For material privacy changes, Tamper will provide email and/or in-product notice to account owners where required before the changes take effect.

15. Contact

Privacy questions and requests may be sent to privacy@tamper.app.

Versioning system

Material-change notice

Material changes are sent by email to account owners and shown in-product before or when they take effect, unless immediate changes are needed for legal, security, or product integrity reasons.

Email template: “Tamper legal terms updated — effective 2026-08-12