Privacy Policy

Last updated: August 5, 2026

Who we are

Let's Quantify is a sales visibility tool for coffee shops and other register based hospitality businesses. When we say "we" or "us" in this policy, we mean the team that operates Let's Quantify.

For the account details of the people who sign up with us, and for our marketing and waitlist emails, we are the data controller. For the sales, shift, catalog, and team information that a workspace imports from its point of sale, the business that owns the workspace is the controller and we act as its processor, handling that data on its instructions.

What we collect

We collect only what we need to run the service:

  • Account information such as your name, email address, and role.
  • Business information such as store names, timezones, districts and regions, monthly goals, commission and bonus settings, and the logo and branding you upload.
  • Sales, shift, and catalog information from your point of sale, currently Square and Clover, including from more than one point of sale account when your group uses several. Shift records include the name of the team member who is clocked in and the time they clocked in and out.
  • Access codes for team members who open a store view with a PIN. Codes are stored hashed, never in plain text, and those sessions expire on their own after 24 hours.
  • Waitlist email addresses so we can let you know when access opens up.
  • Basic technical information such as browser type, device, approximate location derived from your IP address, and log data.

We do not collect payment card numbers, and we do not import your customers' identity data from your point of sale. We do not use your data to train machine learning models, and we do not make automated decisions that produce legal or similarly significant effects about anyone.

How we use it and our legal bases

Under the GDPR we need a lawful basis for each use of personal data. Ours are as follows:

  • Performance of a contract. Creating and securing your account, importing your sales and shift data, and showing live sales, shift, commission, and bonus information to your team.
  • Legitimate interests. Keeping the service secure, preventing abuse, troubleshooting, and improving the product based on how it is used. We balance these interests against your rights and use aggregated or minimal data wherever we can.
  • Consent. Joining the waitlist and receiving marketing emails. You can withdraw consent at any time by using the unsubscribe link or emailing us.
  • Legal obligation. Keeping records we are required to keep and responding to lawful requests.

Who we share it with

We do not sell personal data and we do not share it for advertising. We use a small set of service providers, acting as our subprocessors under written agreements:

  • Our application hosting and managed database provider, which stores and serves your workspace data.
  • Your point of sale provider, currently Square and Clover, which is the source of the sales, catalog, and clock in data you choose to connect.
  • Our transactional email provider, which delivers sign in, invite, and system emails.

We may also disclose information where the law requires it, or as part of a merger or acquisition, in which case we will tell you before your data becomes subject to a different policy. We can provide the current subprocessor list and a data processing agreement on request.

Where your data lives and international transfers

Your data is stored on our hosting provider's infrastructure in the United States. If you are in the European Economic Area, the United Kingdom, or Switzerland, that means your data is transferred outside your region. Those transfers rely on the European Commission's Standard Contractual Clauses, together with the UK Addendum where it applies, and on the security measures described below.

How long we keep it

  • Account and workspace records: for as long as the workspace is active, then deleted within 30 days of a deletion request or account closure.
  • Imported sales, shift, and catalog data: for as long as the workspace is active. New connections import a limited recent window rather than your full history, and manual imports are capped at 90 days.
  • PIN sessions: expire automatically after 24 hours.
  • Waitlist emails: until you ask us to remove them or we close the waitlist.
  • Security, audit, and export logs: up to 12 months, so we can investigate incidents.

Backups roll off on their own schedule, so deleted data can persist in backups for a short period after removal from the live service.

How we protect it

  • Data is encrypted in transit and at rest by our hosting provider.
  • Every workspace is isolated by row level security, so one business cannot read another business's data.
  • PIN codes are stored as salted hashes and are never recoverable in plain text.
  • Access to production data is limited to the people who need it, and sensitive actions are logged.

If a breach affects your personal data, we will notify the relevant supervisory authority within 72 hours where required, and tell affected users without undue delay.

Your rights

If you are in the EEA, the UK, or Switzerland, you have the following rights over your personal data:

  • Access a copy of the personal data we hold about you.
  • Correct data that is inaccurate or incomplete.
  • Erasure of your data where we no longer need it.
  • Restrict or object to processing based on our legitimate interests.
  • Portability, meaning a machine readable copy of the data you gave us. Workspace owners and admins can do this themselves at any time in Settings, under Data and privacy, which produces a ZIP of CSV files.
  • Withdraw consent for marketing or waitlist emails at any time.
  • Complain to your local supervisory authority if you believe we have handled your data improperly.

Email connect@letsquantify.app to exercise any of these rights. We respond within 30 days. If your data sits inside a workspace run by your employer, we will pass the request to that business, since they control it.

Cookies and analytics

We use cookies and similar storage that are strictly necessary to keep you signed in and to keep PIN sessions working. We do not use advertising cookies or cross site tracking. If we add optional analytics, we will ask for consent first where the law requires it.

Children

Let's Quantify is not intended for people under 16, and we do not knowingly collect their data. If you believe a child has provided us with personal data, contact us and we will delete it.

Changes

We may update this policy from time to time. If we make significant changes, we will let you know by email or in the app before they take effect.

Contact us

Questions about this policy, or a request about your data? Email us at connect@letsquantify.app and we will get back to you.