SaleStar

Privacy Policy

Version 1.0.0 · Effective 2026-08-13

This Privacy Policy describes how SaleStar (“SaleStar,” “we,” “us,” or “our”) handles information when you use the SaleStar inventory and point-of-sale application, related tenant sites, and our public marketing pages (together, the “Service”).

SaleStar is multi-tenant software: each business customer (“tenant”) has an isolated data space. If you use a tenant site operated for a specific seller or organization, that tenant’s administrators also control and may access data stored for that tenant.

1. Who this applies to

  • Visitors / guests who browse a tenant storefront or app without signing in.
  • Registered users with a SaleStar account on a tenant (including administrators, staff, and customer-role accounts).
  • People who visit our public marketing / landing pages.

2. Information we process

Account and authentication

  • Username and a securely hashed password for registered users.
  • Session tokens (JWT) stored in your browser’s local storage, namespaced to the tenant you signed into.
  • Permissions / role assigned by the tenant administrator.

Business and inventory data

  • Inventory items, stock, prices, locations, custom properties, and related records.
  • Orders, discounts, taxes, and checkout history.
  • Product photos and thumbnails, branding assets (logo, app icons), and label / print templates.
  • Site settings and preferences configured by tenant administrators.

Optional features

  • User preferences (for example, notification choices).
  • Web push subscription details if you enable push notifications on a supported device.
  • Camera access, when you grant it in the browser, for QR scanning or taking product photos. We do not continuously record video; captures are used for the feature you invoked.

Technical and security logs

  • IP addresses and related metadata used to rate-limit login attempts and protect accounts.
  • Merchant / device binding information (such as device tokens, user agent, and IP) where the merchant scan portal is used.
  • Optional tracked-link hit logs (for example destination visits, referrer, user agent, and IP) when a tenant enables link tracking.

What we do not do

  • We do not sell your personal information.
  • We do not use third-party advertising trackers on the Service as part of SaleStar’s core product.
  • Tenant databases and media are stored separately per client folder and are not shared across tenants in normal operation.

3. How we use information

  • To provide inventory, checkout, reporting, printing, branding, and related features.
  • To authenticate users, enforce permissions, and secure the Service.
  • To send optional push notifications you have enabled.
  • To diagnose problems, prevent abuse, and improve reliability.
  • To communicate about the Service when you contact us.

4. Where information is stored

Tenant application data (including accounts, inventory, orders, media, and many logs) is stored on the server hosting that SaleStar installation, typically in per-tenant databases and file storage under that tenant’s client directory. Platform registry and some platform-wide settings may live in a separate master database on the same installation.

Session tokens and some UI preferences may also be stored in your browser.

5. Sharing

We do not sell personal information. Information may be accessed by:

  • Tenant administrators and other users they authorize on that tenant.
  • The operator of the SaleStar installation (SaleStar) for hosting, maintenance, and support.
  • Service providers strictly as needed to host or operate the installation (for example the server host), under their own terms.
  • Authorities when required by law.

6. Retention

Account and business data generally remain until a tenant administrator deletes them or the tenant is removed from the installation. Security and traffic logs may be retained for a limited period for abuse prevention and troubleshooting. You may clear your browser storage to remove local session tokens.

7. Security

We use industry-common practices such as hashed passwords, tenant-scoped authentication tokens, and separation of tenant data. No method of transmission or storage is 100% secure. During early access, you should keep your own backups of critical business information.

8. Children

SaleStar is intended for business use and is not directed at children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children.

9. Your choices

  • You may decline camera or notification permissions in your browser or device settings.
  • Registered users may ask a tenant administrator to update or delete their account, subject to that tenant’s policies and operational needs.
  • Guests may use public or guest-visible features without creating an account; agreement acceptance is required only for registered (signed-in) users.

10. Changes

We may update this Privacy Policy from time to time. The version number and effective date at the top of this page will change when we do. Registered users will be asked to accept the latest version before continuing to use the Service after a material update to this policy or the Early Access Agreement.

11. Contact

Questions about this Privacy Policy: privacy@salestar.example (SaleStar).

This document is provided for transparency about how SaleStar works today. It is not legal advice.