What we hold, where it sits, and who inside your café can reach it.
A café's counter data is not especially glamorous, and it is genuinely sensitive. It contains what your business takes hour by hour, which of your staff processed a refund, and the visit patterns of people who trusted you with a name and a phone number.
This page states what is stored, how long for, how it is protected and what our compliance position actually is right now. Where we do not yet hold a certification, it says so instead of implying otherwise.
- In transit
- TLS 1.2 and above
- At rest
- AES-256
- Card data stored
- None
- Data residency
- India
Encrypted both ways
Every connection between your counter and CAPPATERY runs over TLS 1.2 or higher. Stored data is encrypted at rest with AES-256, including database backups.
Scoped by role
Counter staff, site manager, area manager and owner each see the scope they are responsible for. Access is granted explicitly rather than inherited by seniority.
Card data never touches us
Payment acceptance stays with your provider. We record the mode and, where returned, a masked reference. There is no card number in our systems to lose.
Every class of data we hold, and how long we hold it.
Listed in full rather than summarised as customer data. If something you expected to see is missing from this table, it is because we do not collect it.
Order and sales records
Retained while your account is activeStored: Items, quantities, modifiers, timestamps, payment mode, counter and staff member
This is the operating record of your business and the basis of every forecast. It is not shared outside your account.
Payment details
Same as the order recordStored: Payment mode and the last four digits where your provider returns them
Full card numbers, CVV and PINs are never transmitted to or stored by CAPPATERY. Card data stays with your payment provider.
Customer records
Until deleted on request, or 24 months after last visitStored: Loyalty identifier, name if given, order history, reward balance
Deletion on request removes the profile and the order history behind it. Aggregate sales figures remain, with no link to the person.
Bake and waste records
Retained while your account is activeStored: Quantities baked, sold, transferred, wasted, with timestamps per line
Contains no personal data. This is what per-line forecasting reads from.
Staff records
Retained while employed, then 12 monthsStored: Name, role, access scope, clock in and out times, shift attribution
Visible to owner and manager scopes. Staff can see their own hours and rota, not those of colleagues.
Access and audit logs
12 monthsStored: Sign-in events, permission changes, refunds, voids, price and threshold edits
Kept so a disputed change can be traced. Deliberately not deletable from inside the product.
A person on the counter does not need to see last month's takings.
Counter staff
Can: Take orders, apply refunds within a limit, log bake quantities, record non-sale depletion, clock in and out, see their own hours and rota.
Cannot: Revenue reporting, margin, other staff attendance, threshold and price edits, customer records beyond the order in front of them.
Site manager
Can: Everything counter staff can, plus rosters, thresholds, quick-key layout, waste and sell-through for their own site, and staff attendance at that site.
Cannot: Other sites, group-level reporting, billing, or granting area and owner access.
Area manager
Can: Read across the sites assigned to them, compare waste and sell-through, publish rosters and approve threshold changes within scope.
Cannot: Sites outside their assignment, billing, or changing the group bake-line catalogue.
Owner
Can: Full scope across the group, including the catalogue, billing, access grants and data export.
Cannot: Alter or delete the audit log, which is retained independently of any role.
Current status, without the badges we have not earned.
CAPPATERY does not currently hold ISO 27001 or a SOC 2 report. Claiming a certification we are not audited against would be straightforwardly untrue, and the badges are easy enough to fake that stating the position plainly is worth more.
Where we stand today
- Card data: out of scope by design. Card acceptance remains with your PCI-compliant payment provider and no card number, CVV or PIN reaches our systems.
- Indian data protection: we operate to the obligations of the Digital Personal Data Protection Act, 2023 - purpose limitation, deletion on request, breach notification and processing customer data only as your processor.
- Data residency: customer and sales data is stored on infrastructure located in India.
- Encryption: TLS 1.2 or above in transit, AES-256 at rest, including backups.
- Access control: role-scoped inside the product, and least-privilege internally with access to production data limited to named engineers and logged.
- Backups: encrypted, taken daily, with restores tested rather than assumed.
What we are working towards
A formal external audit is the intended path, and this page will be updated when there is a report to point at rather than an intention to describe. In the meantime we will answer specific security questions directly, including for a procurement review.
If something goes wrong
If a breach affects your data we will tell you what happened, what was exposed and what we have done about it, within the timelines the DPDP Act requires. We would rather send an uncomfortable email promptly than a polished one late.
Security, answered directly.
Do you store our customers’ card details?
Can a member of counter staff see our revenue?
Where is our data physically stored?
What happens if a customer asks to be deleted?
Do you use our data to train models for other cafés?
Who on your side can access our production data?
Can we get a security questionnaire completed?
Security
Send the questionnaire. We will answer the awkward questions too.
If you are running a procurement review, ask directly. Where the answer is that we do not hold a certification yet, that is what you will get.
- TLS 1.2 or above in transit, AES-256 at rest including backups
- No card numbers, CVV or PINs stored at any point
- Role-scoped access inside the product, audit log retained separately