Privacy Policy
Effective date: July 2, 2026 | Last updated: July 2, 2026
Software Development Services, LLC ("we," "us," or "our") operates the TallyTill autonomous checkout platform. This Privacy Policy explains how we collect, use, and protect information when merchants and their customers use TallyTill-powered kiosks and the TallyTill mobile/web application (collectively, the "Service").
1. Who This Policy Covers
This policy applies to:
- Merchants — businesses that register a TallyTill account and deploy the Service at their location.
- Shoppers — customers who interact with a TallyTill kiosk to browse and purchase items.
The Service is intended for users in the United States. We do not knowingly collect data from individuals outside the U.S.
2. Information We Collect
From Merchants (account holders):
- Name and email address (used for account creation, receipts, and support).
- Business name and optional branding assets (logo, colors).
- Payment configuration — the merchant's connected payment-provider account (e.g., a Stripe account identifier) used to process card and Cash App Pay transactions, plus any optional payment handles the merchant chooses to enable. We do not store raw card numbers or bank credentials.
- Device identifiers for kiosk registration.
From Shoppers (at the point of sale):
- Cart and transaction data — items selected, quantities, prices, and totals.
- Receipt email address, if a shopper voluntarily requests an email receipt.
- Cart photos — images captured by the kiosk camera during checkout events (item scan, item selection). Photos are associated with transaction sessions, not individual shoppers.
- Voice input — if the merchant enables the optional voice assistant, shopper speech captured by the device microphone during a voice interaction (see Section 5).
Automatically collected:
- Device identifiers and basic usage telemetry to support diagnostics and improve the Service.
- Camera frames used for product identification. Barcodes and QR codes are read on the device; when a merchant uses AI-assisted identification, a captured frame is transmitted to our servers and our AI vision provider for analysis (see Section 5).
- Device location (GPS): the approximate or precise geographic coordinates of the kiosk at the time a sale is recorded. Location is attached to the transaction record and used solely for transaction audit, fraud prevention, and to validate or resolve payment disputes. It is not used for advertising or shopper tracking.
3. How We Use Your Information
- To authenticate merchant accounts and deliver the Service.
- To identify products in the camera field of view and add them to the shopper's cart.
- To present payment options and generate QR codes for card, Cash App Pay, and any other payment methods the merchant has enabled.
- To operate the optional voice assistant that answers shopper questions.
- To send email receipts requested by shoppers, via Azure Communication Services.
- To provide merchants with sales reports, transaction history, and reconciliation tools.
- To detect and prevent fraud and to investigate or resolve payment disputes (including using the recorded transaction location).
- To communicate with merchants about their account, billing, and Service updates.
4. Payments
Card and Cash App Pay transactions are processed by our third-party payment provider (Stripe) through the merchant's connected account. Full payment card numbers, bank account numbers, and wallet credentials are handled directly by the payment provider under its PCI-compliant systems — TallyTill does not receive or store them. A platform fee is applied to processed transactions. Cash and check payments are handled directly between the shopper and the merchant.
5. Artificial Intelligence, Camera, and Voice Data
TallyTill uses AI for product identification and, optionally, a voice assistant:
- Barcode & QR scanning (on-device): Barcodes and QR codes are detected locally on the device and are not transmitted.
- AI product identification (cloud): When a merchant uses the "Identify with AI" action, a captured camera frame is transmitted to our servers and to our AI vision provider (Microsoft Azure OpenAI) to identify the product. Frames are processed to return a result and are not used to train third-party models under our providers' default terms.
- Voice assistant (optional, microphone): When a merchant enables the voice assistant, shopper speech is transcribed and the text is sent to our servers and to Anthropic (to generate a reply) and Microsoft Azure (to synthesize the spoken response). Voice audio and transcripts are processed transiently to answer the question and are not retained for advertising.
Cart photos captured during a shopping session are stored on the merchant's device and, if the merchant has enabled cloud sync, uploaded to our servers and associated with the transaction record for that session.
6. Data Sharing
We do not sell, rent, or trade personal information. We may share information only with:
- Service providers: Stripe (payment processing), Microsoft Azure (hosting, AI product identification, speech synthesis, email delivery), and Anthropic (voice-assistant replies). These providers receive only the data necessary to perform their services and are bound by appropriate data-processing agreements.
- Legal compliance: If required by law, court order, or government request, or to protect the rights, property, or safety of TallyTill, its merchants, or others.
7. Data Retention
Transaction records, cart photos, and account information are retained indefinitely until the merchant deletes their account or requests deletion of specific records by contacting us at privacy@tallytill.com. Merchant accounts and all associated data are purged upon confirmed account deletion.
Shopper receipt email addresses are retained only for the duration needed to deliver the email and are not stored beyond that transaction. Voice audio and transcripts are not retained beyond the interaction.
8. California Privacy Rights (CCPA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):
- Right to Know: You may request a summary of the categories and specific pieces of personal information we have collected about you.
- Right to Delete: You may request deletion of personal information we hold about you, subject to certain exceptions.
- Right to Opt-Out of Sale: We do not sell personal information. No opt-out mechanism is required, but you may still contact us to confirm.
- Right to Non-Discrimination: We will not discriminate against you for exercising any CCPA right.
To submit a request, email privacy@tallytill.com with the subject line "California Privacy Request." We will respond within 45 days.
9. Children's Privacy
The Service is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it promptly.
10. Security
We use industry-standard technical and organizational measures (TLS in transit, AES-256 encryption at rest for credentials) to protect information. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top. For material changes, we will notify merchants via email. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
12. Contact Us
For privacy questions, data requests, or to exercise your rights:
- Email: privacy@tallytill.com
- Mail: Software Development Services, LLC, 360 Central Avenue, Suite 800, St. Petersburg, FL 33701