Privacy Policy
This policy explains what information Aced(“we,” “us”) collects, how we use it, and the choices you have. It covers two audiences: businesses that use Aced to run their operations, and the customers of those businesses whose information passes through the platform when they buy, book, or order.
1. Information we collect from businesses
- Account details: name, email, password (stored as a hash), business name and settings.
- Billing details: your subscription status and payment method, held by Stripe — we never store full card numbers.
- Content you create: products, prices, staff records, schedules, website content, photos.
- Usage and device data: logs, IP addresses, and browser information used for security and reliability.
2. Information we process for businesses (their customers’ data)
When a business rings a sale, takes a booking, sends an invoice, or receives an online order, the customer information involved — such as a name, email, phone number, order details, or loyalty balance — is stored in that business’s account. The business owns this data; we process it only on the business’s behalf to provide the service, and we do not sell it or use it to advertise to those customers. If you are a customer of a business that uses Aced and want your information corrected or deleted, contact that business — we support them in honoring your request.
3. Payments
Card payments are processed by Stripe. Card numbers are entered on or read into Stripe’s systems and never touch our servers; we store only what is needed to run the business’s books — amounts, timestamps, card brand, and last four digits. Saved cards (“card on file”) are stored as Stripe tokens with the cardholder’s consent.
4. How we use information
- To provide, secure, and improve the platform.
- To send transactional messages: receipts, order confirmations and pickup notices, booking reminders, invoices, and account emails.
- Marketing messages are sent by a business to its own customers. Every one carries a one-click unsubscribe link, customers can also turn marketing off in their account at any time, and opt-outs are enforced by the platform at send time. Marketing text messages are sent only to customers who asked for them.
- To meet legal obligations and prevent fraud or abuse.
We do not sell personal information.
5. Service providers
We use a small set of processors to run the platform: Supabase (database and authentication), Vercel (hosting), Stripe (payments), Resend (email delivery), Twilio (text messages), and Expo (mobile push notifications). Each receives only the data needed for its role.
6. Cookies and sessions
We use cookies to keep you signed in and to remember preferences like your active location. We do not use third-party advertising cookies or cross-site trackers.
7. Retention and deletion
This is our complete retention commitment. It is stated identically in the Terms of Service, so there is one promise rather than two versions of one.
- While the account is active — data is retained, and the business can export its customers, sales, timesheets, and reports at any time.
- If a payment fails — the account becomes read-only. Data is retained, not deleted, so nothing is lost while billing is resolved.
- After termination — the business may request a full export of its account data for thirty (30) days. After that period we may delete the account data, except records we are required to retain by law (including financial records) and backups, which age out on their normal cycle.
- Logs — delivery and security logs are kept on shorter cycles and purged automatically.
An individual customer of a business that uses Aced should contact that business directly about their own information; we support the business in honoring the request.
8. Security
Data is encrypted in transit, access is controlled per business with row-level security, staff actions are permission-gated, and money movements are recorded in an append-only double-entry ledger. No system is perfectly secure — if a breach affects your data, we will notify you as the law requires. We want to be equally clear about what we do not have: there is no SOC 2 report, no third-party penetration test report and no audited accessibility conformance report. If your procurement process requires any of these, ask us and you will get our current position in writing rather than a marketing answer.
9. Children
The platform is a business tool and is not directed to children under 13.
10. Changes and contact
We may update this policy; material changes get a new version date and in-product notice. Questions or requests: reach us through Help & docs in your dashboard. See also the Terms of Service.