Privacy Policy

Last updated: 2026-05-05 · Version 1.0 (beta)

Beta release. We comply with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Final policy will be reviewed by a privacy lawyer before public launch.

1. Who we are

Melbourne AI POS, based in Melbourne, Victoria, Australia. Contact: melbourneaipos@gmail.com. We are the data controller for café operator account data and the data processor for customer ordering data on behalf of each operator.

2. What we collect

From whomWhatWhy
Café operator (you)Email, name, password (hashed), phone, business name, address, ABN, bank details (via Stripe)Account, billing, support
Café staff (added by operator)Name, email, roleStaff access to dashboard
End customer (who orders at the café)Order items, table number, optional name, optional phoneProcess the order; the operator owns this data
AutomaticIP, device, log events, error reportsSecurity, debugging, abuse prevention

3. How we use it

We do not sell your data. We do not use it for advertising. We do not train AI models on your customers' personal data.

4. Where it lives

Data may be processed outside Australia (Stripe, SendGrid). These providers are contractually bound to industry-standard security.

5. Sharing

We share your data only with:

6. Your rights (Australian Privacy Principles)

Email melbourneaipos@gmail.com to exercise any of these. We respond within 30 days.

7. Customer data (the people who order at your café)

You — the café operator — are the data controller for your customers' order data. You decide retention, you respond to their requests. Melbourne AI POS is your data processor.

If you collect customer phone numbers via the order page, you must comply with the Australian Privacy Act (e.g., have a clear privacy notice at the table for orders > $250 / handling of personal info).

8. Security

9. Cookies

The service uses Firebase Authentication cookies (login session) and Stripe cookies (payment). No advertising cookies.

10. Retention

11. Children

The service is for businesses, not children. We do not knowingly collect data from anyone under 16.

12. Changes

We notify operators by email 30 days before any material privacy policy change.