AI Powered Mobility

Privacy Policy — Cashless Stand

Last updated: August 5, 2026 Effective: August 5, 2026

1. Who we are

Cashless Stand is a mobile application published by AI Powered Mobility, the trade name of Justin DeLeon, a sole proprietor based in Maryland, United States ("we," "us," "our"). We are the data controller for the personal data described in this policy.

Contact: Email: support@aipoweredmobility.com (support and privacy requests)

Cashless Stand lets small in-person vendors — food stands, market stalls, pop-ups — sell physical goods that are handed over in person. There are no digital goods and no shipping. The app has three signed-in roles (store owner, cashier, customer) and also supports guest use without an account.

This policy covers the iOS app (bundle ID com.aipoweredmobility.cashless-stand) and the backend services that support it.

2. What we collect, why, and on what legal basis

The table below maps 1:1 to the fields our database actually stores. It is also the source for our App Store Connect App Privacy answers.

Legal bases are given for users in the EEA/UK: Contract (Art. 6(1)(b)), Legitimate interests (Art. 6(1)(f)), Legal obligation (Art. 6(1)(c)), Consent (Art. 6(1)(a)).

2.1 Account and profile

Data Where it comes from Purpose Legal basis Required?
Email address You, or Apple/Google sign-in Account identity, sign-in, receipts, service notices Contract Yes
Password (hashed) You (email sign-up only) Authentication. Stored and hashed by Supabase Auth; we never see it in plain text Contract Only for email sign-up
Display name You, or Apple/Google sign-in Shown to vendors on your orders and to teammates Contract No
Phone number You Optional contact detail on your profile Contract No
Profile photo You (camera or photo library) Profile personalisation Consent No
Role (customer / cashier / store_owner) Derived Deciding which screens and permissions you get Contract Yes
Push notification token Your device (if you allow notifications) Delivering order and team notifications Consent No
Push on/off preference You Honouring your notification choice Consent No
Tap to Pay terms-accepted / education-completed flags Your action in the app Recording that Apple's required Tap to Pay disclosures were shown and accepted Legal obligation / Contract Vendors using Tap to Pay
Stripe account reference (acct_…) Stripe Linking your account to your Stripe payouts Contract Vendors only

If you sign in with Apple, we receive your Apple ID email (which may be an Apple private-relay address) and, on first sign-in only, your name. If you sign in with Google, we receive your Google account email, name and profile photo URL. We do not receive your Apple or Google password.

2.2 Guest (no-account) use

You can browse stores and complete a purchase without creating an account. In that case we create an anonymous session and collect:

Data Purpose Legal basis Required?
Email address at checkout Sending your receipt and letting you look up the order Contract Yes, to check out
Phone number at checkout Optional contact for the vendor Contract No
A random order access token (UUID) Letting you open your order receipt without an account Contract Yes

A guest order is flagged as such. If you later create an account, the guest order is not automatically merged into it.

2.3 Orders and transactions

Data Purpose Legal basis
Order number, store, date, status and status timestamps Fulfilling and tracking your order Contract
Items, quantities, unit prices, line totals, product names and images Fulfilling the order; the vendor's sales records Contract
Subtotal, convenience/processing fee, platform fee, tax, total Charging you correctly; the vendor's books Contract / Legal obligation
Tax rate applied and tax jurisdiction Tax records Legal obligation
Payment method type (online card, Apple Pay, in-person tap, in-person cash) Reconciliation and reporting Contract
Your name and email captured at checkout Identifying you at pickup; sending the receipt Contract
Order notes you write Passing your instructions to the vendor Contract
Cash tendered and change given (cash orders) Till reconciliation for the vendor Contract
Which cashier took the order, and who marked it prepared Vendor's staff accountability Legitimate interests (vendor's)
Stripe PaymentIntent ID and connected-account ID Reconciling the payment, refunds, disputes Contract
A record that you accepted the checkout disclosure, and its version Evidence in a payment dispute Legitimate interests / Legal obligation
A temporary inventory reservation holding your cart contents during payment Stopping items being oversold while you pay Contract
Receipt delivery record: recipient email, send status, provider message ID, retry state Making sure your receipt actually arrives Contract
Notification records: the title, body, type and payload of each order or team notification sent to you, whether you have read it and when Showing your in-app notification list Contract
Notification delivery log: the title, body, event, delivery status, send timestamp, linked order and the push token used Diagnosing notifications that fail to arrive Legitimate interests

2.4 Location

We use location in four distinct ways. We never collect background location and we never track you when the app is closed.

Use What happens Stored? Legal basis
Finding nearby stores (customers) If you grant permission, your coordinates are sent to our server to rank stores by distance, for that request only No — not written to any table Consent
Setting up a store address (vendors) "Use my location" reads your GPS position once and sends those coordinates to Apple's geocoding service to convert them into a street address, which pre-fills the store address form Yes — the coordinates saved for your store are the device reading itself, at full precision and not rounded, and they are shown publicly to customers along with the address. Use "Use my location" only while you are at the location you want published Consent / Contract
Proof of in-person handover (vendors/cashiers) When a vendor marks an order Ready or Completed, and location permission has already been granted, the device's coordinates are recorded against that order. No new permission prompt is shown. Coordinates are rounded to 4 decimal places (roughly 11 m) Yes, on the order record, together with GPS accuracy and a coarse device descriptor (e.g. "ios-18.5"). It may be submitted to Stripe as evidence if the customer disputes the charge Legitimate interests (defending against fraudulent chargebacks in an in-person marketplace)
Accepting in-person payments (vendors/cashiers) Stripe, our card-payment provider, requires location access in order to accept in-person payments. It uses the device's location to detect payment fraud and to establish where a transaction took place. If the device's location cannot be determined, Stripe disables in-person payments until location access is restored Held by Stripe as part of its transaction and fraud records. We do not store a separate device fix for this purpose Legal obligation / Legitimate interests (payment fraud prevention)

About the permission prompt you see. Cashless Stand uses a single iOS "while using the app" location permission for all four uses above. Because our card-payment provider requires location to accept in-person payments, the system prompt describes location as being required in order to accept payments. If you only ever buy — never sell — you can decline it and still browse and buy; declining only turns off nearby-store ranking.

Store addresses and coordinates are business information published to customers, not personal location data about the customer.

You can withdraw location permission at any time in iOS Settings → Privacy & Security → Location Services → Cashless Stand. Nearby-store ranking will stop; you can still browse and buy.

2.5 Camera and photo library

Used only when you actively start an image upload or a barcode scan:

  • Profile photo, store logo, store cover photo, product photos.
  • Scanning a product barcode to look up or create an inventory item.

We do not access the camera or photo library in the background. Uploaded images are stored in our file storage and, for store and product images, are publicly visible in the app.

2.6 Device and diagnostic data

Data Purpose Legal basis
Crash reports and unhandled errors (via Sentry) Diagnosing crashes and stability bugs Legitimate interests
Device push token Delivering notifications you opted into Consent
A coarse OS/version string on fulfilment evidence records (e.g. "ios-18.5") Dispute evidence Legitimate interests
In-app funnel events for the cashier join/switch flow: event name, your user ID, timestamp, and small contextual values Understanding where staff get stuck when joining a store Legitimate interests

Our crash reporting is configured with personally identifiable information disabled (sendDefaultPii: false), and it is only active when a reporting endpoint is configured for the build. The app contains no third-party analytics SDK, no advertising SDK and no tracking identifiers. We do not track you across other companies' apps or websites.

2.7 Vendor identity and payout data

If you set up a store to take payments, Stripe verifies your identity ("KYC"). Your identity documents, date of birth, government ID numbers and bank account details go directly to Stripe. We never receive or store them. What we store is the status of that process:

Data Purpose
Business type (individual or company) and verification status Showing you what's left to do; deciding whether your store can accept payments
Which requirements Stripe still needs — the names of the fields, never their values (e.g. "individual.id_number") Telling you what Stripe is waiting on
Whether charges and payouts are enabled, whether details were submitted Gating payment features
Whether a tax ID is on file and whether a 1099-K is expected Tax reporting
Your Stripe connected-account ID Routing payments and payouts
Payout records: amount, currency, status, arrival date, failure reason Your payout history
Dispute records: amount, reason, status, deadline, outcome Managing chargebacks
Monthly statement exports (CSV of your orders, payouts and tax) Your bookkeeping

2.8 Store, product and team data (vendors)

Store name, description, category, address, coordinates, logo, cover photo, brand colour, operating hours, holiday hours, timezone, social links, tax rate, and store status. Product name, description, price, quantity, images, category, SKU, barcode, variants and low-stock threshold. Team records: which user holds which role in which store, who invited them, invitation code and status, and when they were verified.

Most of this is business information you publish deliberately. Note that a store's address and coordinates are visible to customers — if you run a stall from your home, do not enter your home address.

2.9 What we do NOT collect

  • We never receive your card number, expiry, CVC or bank details. Card data goes from your device (or the contactless card at the reader) straight to Stripe. Our servers only ever see Stripe references and amounts.
  • No Bluetooth data and no local-network data. Our card-reader library adds iOS Bluetooth and Local Network permission strings to the app because it also supports external Bluetooth readers. Cashless Stand does not use them. It uses only Tap to Pay on iPhone, which is built into the device's own NFC hardware. We do not scan for Bluetooth devices and we do not scan your local network.
  • No background or "always" location. For the same reason as the Bluetooth strings above, our location library also adds unused "Always" location permission descriptions to the app. We never request them. The app only ever asks for "while using the app" location, has no background location mode, and does not track you when the app is closed.
  • No contacts, no calendar, no microphone, no health data, no browsing history, no advertising identifier, no cross-app tracking.
  • We do not sell personal information, and we do not share it for cross-context behavioural advertising.

3. How we use your information

  • Operate the app: accounts, sign-in, browsing, cart, checkout, order tracking, receipts.
  • Process payments through Stripe and route funds to the selling store.
  • Let vendors run their store: inventory, staff, orders, dashboards, statements.
  • Send transactional notifications (order status, team invitations, low-stock alerts).
  • Prevent fraud and abuse, including defending vendors against fraudulent chargebacks.
  • Keep the financial and tax records the law requires us and vendors to keep.
  • Diagnose crashes and fix bugs.
  • Respond to your support requests.

We do not use your personal data for automated decision-making that produces legal or similarly significant effects about you.

4. Who we share it with

4.1 With other users of the app

If you are… What is shared With whom
A customer Your name and email as captured at checkout, your order contents, notes, and totals The store you ordered from, and its cashiers
A guest customer The email (and phone, if given) you entered at checkout, plus the order The store you ordered from, and its cashiers
A vendor Store name, description, address, coordinates, images, hours, products and prices Every app user, including guests
A cashier or team member Your display name, email and avatar, and your role The other members of that store

4.2 Service providers (processors)

We do not sell your data. We share it only with the providers below, only as needed to run the service.

Provider What they process for us Privacy policy
Supabase — database, authentication, file storage, serverless functions Essentially all app data: account, store, product, order and image data https://supabase.com/privacy
Stripe — payments, Stripe Connect, Apple Pay, Tap to Pay on iPhone, payouts, disputes Card and wallet payment data, amounts, vendor identity/KYC and bank data, dispute evidence https://stripe.com/privacy
Apple — Sign in with Apple, Apple Pay, push delivery (APNs), address lookup (reverse geocoding) and maps Authentication tokens, payment tokens, notification payload delivery, and the device coordinates sent for reverse geocoding when a vendor taps "Use my location" https://www.apple.com/legal/privacy/
Google — Google Sign-In Authentication token, email, name, profile photo URL https://policies.google.com/privacy
Expo — Expo Push Notification Service, build and release tooling Device push tokens and notification titles/bodies, which Expo relays to Apple's APNs https://expo.dev/privacy
Resend — transactional email Receipt emails: recipient address and order contents https://resend.com/legal/privacy-policy
Sentry — crash and error reporting Crash traces and error context, with PII reporting disabled https://sentry.io/privacy/

4.3 Legal and corporate

We may disclose information where legally required (subpoena, court order, regulator, law enforcement), to establish or defend legal claims, to investigate fraud or a violation of our Terms, or to protect the safety of people. In a merger, acquisition or sale of assets, data may transfer as part of that transaction; we will notify you.

5. Storage and security

5.1 Where it lives

  • Database, authentication and images: Supabase, hosted on Amazon Web Services infrastructure in the United States (AWS us-east-2, Ohio).
  • Images: user avatars, store logos/covers and product images are held in our file storage. Store and product images are public; avatars are stored under a per-user path.
  • Payment and identity data: Stripe's PCI DSS Level 1 environment.
  • Receipt emails: Resend.

5.2 How we protect it

  • Row Level Security on the database, so each request can only reach rows that user is entitled to. Server functions forward your own credentials rather than acting with unrestricted privileges.
  • TLS in transit. Session tokens are held in the iOS secure keychain.
  • Server-side price authority: the amount charged is re-derived from our own product prices, so a tampered client cannot alter what you are charged.
  • Role-based access: owner, cashier and customer capabilities are enforced on the server, not only in the interface.
  • No card data on our systems. Stripe handles it end to end.

No system is perfectly secure, and we cannot guarantee absolute security.

6. How long we keep it

Data Retention
Account and profile data Until you delete your account, then removed immediately (see §7)
Order and financial records Kept after account deletion in anonymised form, because they are the vendor's books and tax records (see §7), then deleted seven (7) years after the transaction
Inventory reservations that never completed Released automatically by a scheduled job shortly after they expire
Crash reports Per Sentry's retention
Payment records held by Stripe Per Stripe's own retention policy

We retain order and financial records for seven (7) years after the transaction, to meet tax and financial record-keeping requirements, after which they are deleted.

We want to be straightforward about one thing: our systems do not yet enforce this limit automatically. There is no scheduled purge job for order or financial records, so the seven-year period is currently applied by periodic manual review rather than by code.

7. Deleting your account — exactly what happens

You can delete your account in the app: Profile → Privacy & Security → Delete Account. There is no need to email us. This is what the system actually does, in order:

Step 1 — one precondition. If you are the only owner of a store that is still live, deletion is refused and the app tells you which store is blocking it. This exists so a live storefront isn't orphaned with customers still able to order from it and money still moving through it. You can satisfy it yourself in two ways: take the store offline in Live Mode, or add a second owner. Then delete your account. Stores that are already offline do not block deletion.

Step 2 — your personal details are erased from records that will survive. Before anything is deleted, we clear, on every order you placed: your customer name, customer email, guest email and guest phone; and on the associated receipt records, the recipient email address.

If the order scrub fails, we abort and delete nothing, and tell you to contact support — we will not leave your name attached to a record we can no longer find. We should be precise about the other half: if the receipt scrub fails, that failure is logged and the deletion still completes, which can leave a recipient email address on a receipt record. Email us if you want that checked or cleared, and we will do it by hand.

Step 3 — your uploaded profile photo is deleted from storage.

Step 4 — your account is permanently deleted. Your authentication record and your profile are hard-deleted, not deactivated. Deleting the profile also removes your notifications, your store memberships, your notification delivery log, your in-app usage events, and — for vendors — your identity-verification record.

What survives, and why. Your orders survive without you attached to them. The link from an order to you is set to null, and every personal field on that order was cleared in Step 2. The same applies to other attribution links: products you created, stores you created, invitations you sent, and the fulfilment records you captured. The result is an anonymous financial record.

We keep them because they are not only your data — they are the selling vendor's sales, tax and payout records. Erasing them would retroactively change another business's revenue history and break its reconciliation with Stripe. Under the GDPR this is the Art. 17(3)(b) and 17(3)(e) exception (legal obligation, and establishment/exercise/defence of legal claims); under the CCPA it is the equivalent transaction-completion and legal-compliance exception. After Step 2 the surviving rows no longer identify you.

Stripe. If you were a vendor, records held by Stripe (identity verification, payments, payouts) are governed by Stripe's own retention obligations as a regulated financial services provider. Delete or close your Stripe account through Stripe.

8. Your rights

Wherever you live, you can:

  • Access the personal data we hold about you.
  • Correct it — display name, phone and avatar are editable in the app at any time.
  • Delete it — in the app, as described in §7.
  • Get a copy in a portable format.
  • Object to or restrict certain processing.
  • Withdraw consent for location, camera/photos and push notifications at any time in iOS Settings, without affecting processing already carried out.
  • Complain to your data protection authority (EEA/UK) or your state Attorney General (US).

To exercise a right, email support@aipoweredmobility.com with your account email, a description of your request, and enough detail for us to verify who you are. We respond within 30 days, or sooner where the law requires it. We will not discriminate against you for exercising your rights.

8.1 California (CCPA/CPRA)

CCPA category Do we collect it? Examples
Identifiers Yes Email, name, phone, user ID, device push token
Customer records (Cal. Civ. Code §1798.80) Yes Name and email tied to a purchase
Commercial information Yes Orders, items, amounts, products listed
Financial information Partly Stripe payment references and amounts — never raw card or bank details
Internet or network activity Limited Crash reports, in-app cashier-flow events
Geolocation data Yes, limited Store addresses and coordinates; vendor fulfilment coordinates; customer coordinates used in-session only and not stored
Audio/visual information Yes Profile, store and product photos you upload
Professional/employment information Yes, for vendors Business type, store business details
Sensitive personal information No We do not collect government IDs, precise financial account details, race, religion, health, biometrics, or message contents. Vendor identity documents go to Stripe, not to us
Inferences / profiling No We build no profiles

We do not sell or share personal information, as those terms are defined by the CCPA/CPRA, and we have not done so in the preceding 12 months. There is nothing to opt out of. We do not knowingly sell or share the personal information of consumers under 16.

8.2 Other US states

Residents of Virginia, Colorado, Connecticut, Utah, Texas and other states with comprehensive privacy laws have comparable rights of access, correction, deletion, portability and opt-out. Use the same contact address above. We do not sell personal data or use it for targeted advertising or profiling, so those opt-outs do not apply. Nevada residents: we do not sell personal information as defined under Nevada law.

8.3 EEA and UK (GDPR)

Legal bases are given in the tables in §2. Where we rely on legitimate interests, our interests are running and securing the service and protecting vendors from payment fraud; you may object at the address above.

9. International transfers

Our providers (Supabase, Stripe, Apple, Google, Expo, Resend, Sentry) operate in the United States and elsewhere. If you are in the EEA, UK or Switzerland, your data may be transferred to the United States. Transfers are covered by Standard Contractual Clauses or another lawful transfer mechanism in our agreements with each provider.

Service availability: the Service is offered in the United States only.

EU/UK Article 27 representative: not applicable. We target and offer the Service in the United States only and have not appointed an Article 27 representative. We nonetheless state GDPR legal bases in §2 and will honour the rights described in §8.3 for anyone who reaches us from the EEA, the UK or Switzerland.

10. Children

Cashless Stand is not directed to children, and we do not knowingly collect personal information from anyone under 13. You must be at least 13 years old to use Cashless Stand, and at least 18 years old to operate a Store or act as a cashier — see §3 of our Terms of Service. The app has no content, feature or communication channel designed for children. If you believe a child has given us personal information, contact us and we will delete it promptly.

11. Cookies and similar technologies

The app is not a website and uses no browser cookies or advertising identifiers. It stores on your device: your authentication session (in the iOS keychain), your cart, and app preferences such as whether you have been shown the location prompt. If we launch a website with cookies, we will publish a cookie notice then.

12. Changes to this policy

We may update this policy. We will change the "Last updated" date, and for material changes we will notify you in the app or by email. Continuing to use the app after a change means you accept the updated policy.

13. Apple App Store

Cashless Stand is distributed through the Apple App Store. Apple's handling of your App Store account, purchases and device data is governed by Apple's own privacy policy, not this one.

14. Contact

Justin DeLeon, doing business as AI Powered Mobility Maryland, United States

Privacy: support@aipoweredmobility.com Support: support@aipoweredmobility.com