We believe in complete transparency about how we collect, use, and protect the data you trust us with. This policy explains everything in plain language.
Last updated: May 2026 · Effective: May 2026
Puffer ("we", "us", or "our") provides a point-of-sale, inventory, and business analytics platform for cafes and commercial workspaces. This Privacy Policy describes how we collect, process, store, and protect the information you and your organization provide when using our services.
By using Puffer, you agree to the collection and use of information as described in this policy. If you do not agree, please discontinue use of the service.
We collect the following categories of information:
Account & Organization Data
Name, email address, phone number, business name, business type, subscription plan, and billing information. This is required to operate your account.
Business Operations Data
Orders, products, categories, pricing, sales transactions, expenses, inventory levels, staff members, customer records, and daily analytics snapshots. This is the core data Puffer stores on your behalf to deliver the service.
Usage & Session Data
IP addresses, device type, browser type, session duration, feature usage patterns, and interaction logs. Used for security, debugging, and improving the platform.
Authentication Data
Hashed passwords, OAuth tokens (Google Sign-In), and session tokens. Never stored in plain text.
Your data is used for the following purposes:
We do not use your business data for targeted advertising. We do not sell your data to third parties.
We intend to introduce optional benchmark features that help business owners understand how their performance compares to industry trends - for example, average order value across similar businesses, typical peak hours for a café, or common product pricing patterns.
To power these features, Puffer may use anonymized, aggregated versions of your business data (orders, sales, pricing, product categories). Here is exactly what that means:
✓ What we DO
✗ What we DON'T do
Your organization's data is only ever a small, indistinguishable contribution to a much larger statistical pool. No other business can identify your data within any benchmark result.
Participation in the Aggregated Insights Program is optional. You may opt out at any time from your organization's Settings panel, under Settings → Data & Privacy.
When you opt out:
We do not sell, rent, or trade your data. We share data only in the following limited circumstances:
Firebase (Google Cloud)
Our database and authentication infrastructure. Data is stored and processed under Google's data processing agreements.
Vercel
Our hosting and deployment platform. Request logs and edge network metadata are processed by Vercel.
Legal obligations
We may disclose data if required by law, court order, or to protect the rights and safety of Puffer, its users, or the public.
Business transfer
In the event of a merger, acquisition, or sale of assets, user data may be transferred. You will be notified in advance.
We implement industry-standard security measures to protect your data:
No method of electronic storage or internet transmission is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. In the event of a data breach that affects your rights, we will notify you within 72 hours of becoming aware.
Depending on your jurisdiction, you may have the following rights regarding your personal data:
Access
Request a copy of the personal data we hold about you.
Rectification
Correct inaccurate or incomplete personal data.
Erasure
Request deletion of your data, subject to legal retention requirements.
Portability
Receive your data in a machine-readable format.
Restriction
Limit how we process your data in certain circumstances.
Objection
Object to processing based on legitimate interests.
To exercise any of these rights, contact us at privacy@puffer.app. We will respond within 30 days.
We retain your data for as long as your account is active. When you cancel your subscription or delete your organization, we will delete your business data within 90 days, except where retention is required by law (e.g., financial records may be retained for up to 7 years).
Aggregated, anonymized data derived from your account (if you have not opted out) may be retained indefinitely as it contains no personally identifiable information.
If you have questions about this Privacy Policy or how we handle your data:
Privacy Team
privacy@puffer.appStart a 14-day free trial today. Set up in 5 minutes, get real-time insights from the first order, and pay only when you're convinced.
14-day free trial · No credit card required · Cancel anytime