Privacy Policy
This Privacy Policy describes how Copper ("we", "us") handles information in the Copper POS and Copper Owner mobile applications and on this website. Copper is a point-of-sale and restaurant-management service for cafes and restaurants, developed in Uzbekistan.
1. Information we collect
- Account data: the venue owner's email address and password, used to create and sign in to the account. Passwords are handled by our authentication provider and are never visible to us in plain text.
- Business data: information the venue enters to run its business — venue name, menu items and photos, prices, tables, orders, payments recorded, shifts, stock levels, and reports derived from them.
- Staff data: staff names and roles entered by the venue owner. Staff PIN codes are stored only as secure cryptographic hashes (bcrypt) and cannot be read back.
- Customer data entered by venues: when a venue uses the pay-later (nasiya) or reservation features, it may enter a customer's name and phone number. This data belongs to the venue and is visible only to that venue.
We do not collect precise location, contacts, photos (except menu photos the venue chooses to upload), advertising identifiers, or any data for advertising purposes.
2. How we use information
- To provide the service: taking orders, syncing devices in real time, printing, generating reports and analytics for the venue.
- To provide support and maintain the security and reliability of the service.
We do not sell personal data. We do not use personal data for advertising. We do not share data with third parties, except the infrastructure providers listed below.
3. Storage and security
- Data is stored in a cloud database hosted by Supabase (our backend infrastructure provider). All connections use TLS encryption in transit, and data is encrypted at rest.
- Every venue's data is isolated with database-level row security: one venue can never see another venue's data.
- Staff PINs are stored as bcrypt hashes; owner passwords are managed by the authentication provider.
4. Data retention and deletion
We keep a venue's data for as long as its account is active. A venue owner may request a full export or complete deletion of their venue's data at any time by contacting us at the email below; we complete deletion requests within 30 days.
5. Customers of venues
For customer names and phone numbers entered by a venue (for pay-later or reservations), the venue acts as the data controller and Copper as its processor. Individuals may direct requests either to the venue that entered their data or to us directly.
6. Children
Copper POS and Copper Owner are business tools intended for use by adults (18+). They are not directed at children, and we do not knowingly collect data from children.
7. Changes to this policy
If we make material changes to this policy, we will update this page and the effective date above.
8. Contact
Questions, export or deletion requests: sardorkholmonov@gmail.com