Skip to content
Security

What we hold, where it sits, and who inside your café can reach it.

A café's counter data is not especially glamorous, and it is genuinely sensitive. It contains what your business takes hour by hour, which of your staff processed a refund, and the visit patterns of people who trusted you with a name and a phone number.

This page states what is stored, how long for, how it is protected and what our compliance position actually is right now. Where we do not yet hold a certification, it says so instead of implying otherwise.

In transit
TLS 1.2 and above
At rest
AES-256
Card data stored
None
Data residency
India

Encrypted both ways

Every connection between your counter and CAPPATERY runs over TLS 1.2 or higher. Stored data is encrypted at rest with AES-256, including database backups.

Scoped by role

Counter staff, site manager, area manager and owner each see the scope they are responsible for. Access is granted explicitly rather than inherited by seniority.

Card data never touches us

Payment acceptance stays with your provider. We record the mode and, where returned, a masked reference. There is no card number in our systems to lose.

What is stored

Every class of data we hold, and how long we hold it.

Listed in full rather than summarised as customer data. If something you expected to see is missing from this table, it is because we do not collect it.

Order and sales records

Retained while your account is active

Stored: Items, quantities, modifiers, timestamps, payment mode, counter and staff member

This is the operating record of your business and the basis of every forecast. It is not shared outside your account.

Payment details

Same as the order record

Stored: Payment mode and the last four digits where your provider returns them

Full card numbers, CVV and PINs are never transmitted to or stored by CAPPATERY. Card data stays with your payment provider.

Customer records

Until deleted on request, or 24 months after last visit

Stored: Loyalty identifier, name if given, order history, reward balance

Deletion on request removes the profile and the order history behind it. Aggregate sales figures remain, with no link to the person.

Bake and waste records

Retained while your account is active

Stored: Quantities baked, sold, transferred, wasted, with timestamps per line

Contains no personal data. This is what per-line forecasting reads from.

Staff records

Retained while employed, then 12 months

Stored: Name, role, access scope, clock in and out times, shift attribution

Visible to owner and manager scopes. Staff can see their own hours and rota, not those of colleagues.

Access and audit logs

12 months

Stored: Sign-in events, permission changes, refunds, voids, price and threshold edits

Kept so a disputed change can be traced. Deliberately not deletable from inside the product.

Role-based access

A person on the counter does not need to see last month's takings.

Counter staff

Can: Take orders, apply refunds within a limit, log bake quantities, record non-sale depletion, clock in and out, see their own hours and rota.

Cannot: Revenue reporting, margin, other staff attendance, threshold and price edits, customer records beyond the order in front of them.

Site manager

Can: Everything counter staff can, plus rosters, thresholds, quick-key layout, waste and sell-through for their own site, and staff attendance at that site.

Cannot: Other sites, group-level reporting, billing, or granting area and owner access.

Area manager

Can: Read across the sites assigned to them, compare waste and sell-through, publish rosters and approve threshold changes within scope.

Cannot: Sites outside their assignment, billing, or changing the group bake-line catalogue.

Owner

Can: Full scope across the group, including the catalogue, billing, access grants and data export.

Cannot: Alter or delete the audit log, which is retained independently of any role.

Compliance posture

Current status, without the badges we have not earned.

CAPPATERY does not currently hold ISO 27001 or a SOC 2 report. Claiming a certification we are not audited against would be straightforwardly untrue, and the badges are easy enough to fake that stating the position plainly is worth more.

Where we stand today

  • Card data: out of scope by design. Card acceptance remains with your PCI-compliant payment provider and no card number, CVV or PIN reaches our systems.
  • Indian data protection: we operate to the obligations of the Digital Personal Data Protection Act, 2023 - purpose limitation, deletion on request, breach notification and processing customer data only as your processor.
  • Data residency: customer and sales data is stored on infrastructure located in India.
  • Encryption: TLS 1.2 or above in transit, AES-256 at rest, including backups.
  • Access control: role-scoped inside the product, and least-privilege internally with access to production data limited to named engineers and logged.
  • Backups: encrypted, taken daily, with restores tested rather than assumed.

What we are working towards

A formal external audit is the intended path, and this page will be updated when there is a report to point at rather than an intention to describe. In the meantime we will answer specific security questions directly, including for a procurement review.

If something goes wrong

If a breach affects your data we will tell you what happened, what was exposed and what we have done about it, within the timelines the DPDP Act requires. We would rather send an uncomfortable email promptly than a polished one late.

Questions

Security, answered directly.

Do you store our customers’ card details?
No. Card acceptance stays entirely with your payment provider. We record which payment mode was used and, where your provider returns it, a masked reference such as the last four digits. There is no card number, expiry, CVV or PIN in our systems.
Can a member of counter staff see our revenue?
Not by default. Counter scope covers taking orders, logging bakes, refunds within a limit and their own hours. Revenue, margin and cross-day reporting sit with manager and owner scopes.
Where is our data physically stored?
On infrastructure located in India. If you have a specific residency requirement for a procurement process we will confirm the region in writing.
What happens if a customer asks to be deleted?
Their profile and the order history attached to it are removed. The underlying sales remain in your aggregate figures, because those are your accounting records, but they are no longer linked to a person.
Do you use our data to train models for other cafés?
No. Forecasting for your counter runs on your counter’s history. There is no pooled cross-customer model, and we do not sell or share your sales or customer data with third parties.
Who on your side can access our production data?
A limited set of named engineers, under least privilege, with access logged. It is used for support and incident response, not browsed.
Can we get a security questionnaire completed?
Yes. Send it through the contact page and we will complete it, including the questions where the honest answer is not yet.

Security

Send the questionnaire. We will answer the awkward questions too.

If you are running a procurement review, ask directly. Where the answer is that we do not hold a certification yet, that is what you will get.

  • TLS 1.2 or above in transit, AES-256 at rest including backups
  • No card numbers, CVV or PINs stored at any point
  • Role-scoped access inside the product, audit log retained separately