Privacy
Privacy Policy
Effective 1 October 2026. This Privacy Policy describes how safetill.io ("safetill", "we") collects, uses, shares and protects information when you visit https://safetill.io, use the application at app.safetill.io, or otherwise interact with us. It forms part of our Terms of Service.
1. Who we are and our role
safetill is a business-to-business connector between point-of-sale (POS) systems and Verkada Helix. For information about our own customers' accounts (names, emails, billing) we act as the controller. For transaction data we retrieve from your POS and forward to Verkada on your instructions, you are the controller and we are your processor / service provider; we process that data only to provide the Service to you.
2. Information we collect
2.1 Account and workspace information
- Name, email address and authentication details, handled by our identity provider Clerk.
- Workspace name, the admins you invite and their roles.
- Your Verkada organisation identifier and region, and the Helix event types you create.
2.2 Credentials you give us
Verkada API keys and POS OAuth tokens, which we encrypt before storing and use only to call those services on your behalf.
2.3 Transaction data (Customer Data)
Receipt-level payment and refund events from your POS: amount, currency, line items, tender type, till (device) and location identifiers, timestamps and POS transaction IDs; plus the list of cameras in your Verkada organisation and the delivery status of each event. We do not collect card numbers, expiry dates, CVVs or other cardholder data, and we do not collect or store video.
2.4 Billing information
Subscription plan, number of locations, invoices and payment status. Payments are processed by Stripe, which collects your payment card details directly; we receive only a token, the card brand, the last four digits and billing contact details.
2.5 Technical and usage information
IP address, browser and device type, pages visited, actions taken in the app, timestamps, and server logs including error reports. The site and the application use strictly necessary cookies for sign-in, security and remembering your cookie choice, and Google Analytics cookies only if you accept them. See our Cookie Policy for the full list and how to change your choice.
2.6 Communications
Emails and support requests you send us, and our replies.
3. How we use information
- To provide, operate, secure and maintain the Service, including matching POS transactions to cameras and submitting events to Verkada Helix.
- To create and manage accounts, workspaces and permissions.
- To process subscriptions, payments, invoices and refunds through Stripe, and to enforce plan limits.
- To send service, security and billing communications (for example failed-payment or expired-key notices).
- To provide support and respond to your requests.
- To monitor, troubleshoot and improve performance and reliability, and to detect and prevent abuse, fraud and security incidents.
- To comply with legal obligations and enforce our Terms.
Our legal bases (where required, e.g. under the GDPR or UK GDPR) are performance of our contract with you, our legitimate interests in operating and securing the Service, compliance with law, and consent where we ask for it. We do not sell personal information and do not use Customer Data for advertising.
4. How we share information
- Verkada — we submit transaction events to your Verkada Command organisation, as instructed by your mappings.
- Your POS provider (e.g. Square) — we read payments, refunds, devices and locations under the scopes you authorised.
- Stripe — payment processing, subscriptions, invoicing and tax calculation.
- Clerk — authentication, sessions and organisation membership.
- Google Cloud — hosting, database and secret storage.
- Google Analytics — website and app usage statistics, only if you accept analytics cookies.
- Service providers for email delivery, error monitoring and analytics, bound by confidentiality and data-processing terms.
- Legal and safety — where required by law, subpoena or court order, or to protect the rights, safety or property of safetill, our customers or others.
- Business transfers — in connection with a merger, acquisition, financing or sale of assets, subject to this Policy.
5. International transfers and hosting
safetill runs on Google Cloud and is currently hosted in the United States. If you access the Service from outside the United States, your information will be transferred to and processed there. Where required, we rely on appropriate safeguards such as standard contractual clauses and our providers' data-processing agreements. By using the Service you acknowledge this transfer.
6. Retention
- Credentials are deleted immediately when you disconnect Verkada or your POS.
- Deleting a workspace removes its connections, credentials, mappings and event history from the live database; backups and logs expire on a rolling basis within a reasonable period afterwards.
- Account information is kept while your account is active and for a limited period afterwards to resolve disputes and meet legal obligations.
- Billing and tax records are retained for as long as the law requires (typically seven years).
- Server logs are retained for a limited period for security and troubleshooting.
7. Security
We use HTTPS everywhere, encrypt credentials at rest with AES-256-GCM, isolate every workspace in a safe and secure database, verify webhook signatures, rate-limit public endpoints and restrict access to production systems. No method of transmission or storage is completely secure, so we cannot guarantee absolute security; you are responsible for keeping your own login and API keys confidential. See our Security overview for more.
8. Your responsibilities as a business
You decide which tills, cameras and transactions to connect and how to use the resulting Helix events. You are responsible for complying with surveillance, employment, consumer and privacy laws that apply to your locations, including giving any notices to staff and customers and obtaining any consents required, and for responding to requests from your own staff and customers about their data. We will assist you with such requests to the extent we reasonably can.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of your personal information, to data portability, to withdraw consent, and to lodge a complaint with a supervisory authority. You can update account details and export transaction history as CSV from the app, and delete a workspace from Settings. For anything else, contact us at the address below; we may need to verify your identity first. We do not discriminate against you for exercising your rights.
10. Children
The Service is for businesses and is not directed at anyone under 18. We do not knowingly collect personal information from children.
11. Third-party sites and services
The Service links to and integrates with third-party services (Verkada, Square, Stripe, Clerk and others) that have their own privacy policies. We are not responsible for their practices, and this Policy does not cover information they collect directly from you.
12. Changes to this Policy
We may update this Policy from time to time. We will post the new version here and update the effective date; for material changes we will notify you in the app or by email. Continued use of the Service after the effective date means you accept the updated Policy.
13. Contact
safetill.io · legal@safetill.io