Privacy Policy
Last updated: August 10, 2026
1. Information We Collect
When you create an account, we collect your name, email address, and the name of your organization. When you use TentTally, we store the business data you enter — including products, sales records, market events, and custom orders — to provide the service to you.
We also collect standard usage data such as browser type, IP address, and pages visited to operate and improve the service.
2. How We Use Your Information
- To provide, maintain, and improve the TentTally service
- To process payments and manage your subscription via Stripe
- To send transactional emails (account confirmation, billing receipts)
- To send occasional product announcements to organization owners, which you can unsubscribe from at any time
- To respond to support requests
- To detect and prevent fraud or abuse
We do not sell your personal information or your business data to third parties.
3. Data Storage and Security
Your data is stored on servers in the United States. We use industry-standard encryption in transit (HTTPS/TLS) and at rest. Access to production data is restricted to authorized personnel only.
Your business data (products, sales, orders) is private to your organization. No other TentTally customer can access it.
4. Third-Party Services
We use the following third-party services to operate TentTally:
- Stripe — payment processing. Your payment details are handled directly by Stripe and are never stored on our servers.
- Square — optional integration, only if you choose to connect your Square account. See section 5 below.
- Resend — delivery of transactional and announcement emails. If you are an organization owner, we store your name and email address with Resend so we can send product announcements. Every announcement includes an unsubscribe link, and unsubscribing does not affect transactional email.
- Railway — cloud infrastructure and hosting for our application and database.
- Cloudflare — DNS, TLS, and content delivery for tenttally.com. Cloudflare processes the IP addresses of visitors to our site.
5. Connecting Your Square Account
Connecting Square is entirely optional — TentTally works fully without it. If you do connect, you authorize us through Square's official OAuth process. We never see or store your Square password.
When connected, we request read-only access to:
- Your item library — item names, categories, variations (including SKUs), and prices. We use this so you can import your items as TentTally products instead of re-entering them by hand; SKUs are currently read as part of your item library but are not stored. We cache this data for up to 30 minutes to avoid re-fetching it while you work through an import.
- Your business and location information — Square grants this as a single permission that covers your business profile and your complete location records. In practice we read only your list of locations, using each location's name and street address so you can identify which one to sync. We do not retrieve your business profile.
If you turn on inventory sync, we will ask you separately for permission to read and update inventory counts. That permission is never requested when you first connect, and inventory counts are the only thing it changes.
We do not request or receive access to your Square payments, payouts, customers, bank or card details, or staff records, and we never modify your Square account settings.
Your Square access tokens are encrypted before being stored. Disconnecting from Settings → Integrations immediately deletes our copy of those tokens and our cached copy of your catalog, and asks Square to revoke the authorization on their end. Even if that request to Square does not go through, our own access ends immediately, because we no longer hold the tokens. Products you already imported remain in TentTally as your own data.
6. Cookies
TentTally uses essential cookies and browser local storage to keep you logged in. If you connect Square, we also set one short-lived cookie for the duration of that authorization — it holds a random value that lets us confirm the authorization finishes in the same browser that started it, and it is discarded as soon as the connection completes. We do not use tracking or advertising cookies.
7. Data Retention and Deletion
We retain your data for as long as your account is active. If you cancel your subscription, your data is retained for 30 days to allow for reactivation, then deleted. You may request deletion of your account and associated data at any time by contacting us.
8. Your Rights
You may request a copy of your data, correction of inaccurate data, or deletion of your account at any time. To exercise these rights, contact us at the address below.
9. Changes to This Policy
We may update this policy from time to time. If we make material changes, we will notify you by email or by displaying a notice in the application before the changes take effect.
10. Contact
If you have questions about this privacy policy, please contact us at [email protected].