Privacy Policy

Last updated: July 7, 2026

Introduction

Torismic LLC (“Torismic,” “we,” “us,” or “our”) operates the Torismic POS platform, including our website (torismic.com), dashboard (dashboard.torismic.com), mobile applications, and POS terminal software. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.

Torismic is a B2B SaaS platform providing point-of-sale hardware and software subscriptions to local businesses. We serve two types of users: Business Customers (the businesses that subscribe to our platform) and End Consumers (the customers of those businesses).

By using our services, you consent to the data practices described in this policy. If you do not agree with this policy, please do not access or use our services.

Information We Collect

From Business Customers (Subscribers)

When a business signs up for Torismic, we collect:

  • Business owner name, email address, and phone number
  • Business name, physical address, and tax identification number
  • Employee information (names, email addresses, hire dates, POS PINs, hourly rates, commission structures)
  • Transaction data (orders, payment amounts, items sold, tips, refunds)
  • Subscription and billing information (processed via Stripe)
  • Device and browser information when accessing the dashboard
  • IP address and approximate location (for security and fraud prevention)

From End Consumers

When consumers interact with a Torismic-powered business, we may collect:

  • Name, phone number, and email address (for loyalty programs and digital receipts)
  • Purchase history at each business (orders, amounts, items)
  • Loyalty points balance per business
  • Pet information (for pet grooming businesses — pet names, breeds, weight, vaccination records)
  • Vehicle information (for automotive businesses — year, make, model, VIN, license plate, service history)
  • Appointment and booking history
  • Torismic account information (if consumers create a free account to track points, appointments, and history across businesses)

Automatically Collected Information

When you visit our website or use our services, we automatically collect:

  • Device type, operating system, and browser type
  • IP address and approximate geographic location
  • Pages viewed, time spent, and navigation patterns on our website
  • Referring URL (how you found us)
  • App usage data and crash reports (for mobile applications)

Payment Card Data

Card payment data for POS transactions is processed through NMI, our PCI DSS Level 1 compliant payment gateway. We do not store, process, or have access to raw card numbers, CVVs, or magnetic stripe data. We retain only transaction IDs and last-four digits for record-keeping purposes.

Subscription billing for business customers is processed through Stripe. Stripe handles all payment card storage and PCI compliance for recurring charges. We never see or store your full card number.

Information We Do NOT Collect

Torismic does not collect:

  • Biometric data (fingerprints, facial recognition, voiceprints)
  • Social Security numbers
  • Genetic or health data (vaccination records for pets are not considered human health data)
  • Data from children under 13

Cookies & Tracking Technologies

Our website and dashboard use the following tracking technologies:

Essential Cookies

Required for the platform to function. These include session tokens, authentication cookies, and CSRF protection. You cannot opt out of essential cookies.

Analytics

We use Vercel Analytics (privacy-focused, no personal data collected) to understand website traffic and page performance. No personally identifiable information is tracked by our analytics.

Third-Party Cookies

We do not sell advertising space on our platform. We do not use third-party advertising cookies or tracking pixels. We do not participate in cross-site tracking or behavioral advertising networks.

You can control cookies through your browser settings. Disabling essential cookies may prevent you from using certain features of our platform.

How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our POS platform and services
  • Process transactions and manage subscriptions
  • Send transactional communications (account invitations, receipts, password resets, appointment reminders)
  • Administer loyalty programs and rewards on behalf of businesses
  • Generate analytics and reporting for business customers
  • Provide customer support and respond to inquiries
  • Comply with legal obligations (tax reporting, FLSA record retention)
  • Detect, prevent, and respond to fraud, abuse, or security incidents
  • Improve our products through aggregated, anonymized usage analysis
  • Send service announcements (downtime, updates, security notices)

Communications

We send transactional emails only (invitations, receipts, reminders, security alerts). We do not send marketing or promotional emails unless you have explicitly opted in. You may opt out of marketing communications at any time by clicking the unsubscribe link or contacting us.

Data Isolation & Multi-Tenancy

Business data is strictly isolated using row-level security at the database level. Business A cannot access Business B's customer data, transactions, employee records, or any other information. Each business operates within its own secure tenant.

Consumers with a Torismic account can view their own cross-business history (loyalty points, appointments, purchase history) within the consumer app. This data is only visible to the consumer themselves and cannot be accessed by any business other than the one that originally recorded it.

Torismic employees access business data only when necessary for customer support, and only with appropriate authorization and audit logging.

Data Sharing & Disclosure

We do not sell, rent, or trade your personal information. We share data only in these circumstances:

Service Providers

We share the minimum data necessary with third-party providers who help us operate our platform:

  • Supabase — Database hosting and authentication
  • Stripe — Subscription billing
  • NMI — Payment card processing (PCI DSS Level 1)
  • Firebase — Application hosting and cloud functions
  • Resend — Transactional email delivery
  • Third-party hardware provider — Device fleet management and remote updates

All service providers are contractually bound to protect your data and use it only for the purposes we specify.

Legal Requirements

We may disclose your information if required by law, subpoena, court order, or governmental regulation. We may also disclose information when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.

Business Transfers

If Torismic is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website of any change in ownership or uses of your personal information.

Aggregated Data

We may share aggregated, anonymized data that cannot identify any individual (e.g., “average transaction value across all restaurant customers”) for research or industry reports. This data cannot be traced back to any specific business or person.

Data Retention

  • Business accounts: Data retained for the duration of the subscription plus 90 days after cancellation for recovery purposes. After 90 days, data may be permanently deleted.
  • Employee records: Retained for a minimum of 3 years after deactivation (per FLSA requirements). Active employees can view their own records; deactivated employees retain read-only access for 2 years.
  • Consumer data: Retained while the consumer has an active account or an active relationship with a Torismic business. Consumers may request deletion at any time (subject to business record-keeping requirements).
  • Transaction records: Retained for 7 years for tax, audit, and chargeback dispute purposes.
  • Website analytics: Aggregated data retained indefinitely. Raw logs deleted after 90 days.
  • Support communications: Retained for 3 years after resolution.

Data Security

We implement industry-standard security measures to protect your data, including:

  • Encryption in transit (TLS 1.2+/SSL for all connections)
  • Encryption at rest (AES-256 for stored data)
  • Row-level security for multi-tenant data isolation
  • Role-based access controls for internal systems
  • Multi-factor authentication for administrative access
  • Regular security audits and penetration testing
  • Automated threat detection and monitoring
  • PCI-compliant payment handling via third parties

No system is 100% secure. While we take extensive measures to protect your data, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials.

Data Breach Notification

In the event of a data breach that compromises your personal information, we will:

  • Notify affected users via email within 72 hours of discovering the breach
  • Notify relevant regulatory authorities as required by applicable law
  • Provide a description of the breach, what data was affected, and steps we are taking
  • Offer guidance on steps you can take to protect yourself
  • Post a notice on our website if the breach affects a large number of users

Your Rights

Depending on your location, you may have the right to:

  • Access — Request a copy of the personal data we hold about you
  • Correction — Request correction of inaccurate or incomplete data
  • Deletion — Request deletion of your data (subject to legal retention requirements)
  • Portability — Request your data in a machine-readable format (JSON or CSV)
  • Opt-out — Opt out of marketing communications at any time
  • Restrict processing — Request that we limit how we use your data
  • Withdraw consent — Where processing is based on consent, withdraw it at any time

To exercise any of these rights, contact us at support@torismic.com. We will respond within 30 days. We may ask you to verify your identity before processing your request.

California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

  • Right to Know — You may request disclosure of the categories and specific pieces of personal information we have collected about you in the past 12 months.
  • Right to Delete — You may request deletion of personal information we have collected from you, subject to certain exceptions.
  • Right to Opt-Out of Sale — We do not sell your personal information. We do not share personal information for cross-context behavioral advertising.
  • Right to Non-Discrimination — We will not discriminate against you for exercising your CCPA rights.
  • Right to Correct — You may request that we correct inaccurate personal information.
  • Right to Limit Use of Sensitive Personal Information — We only use sensitive information for purposes authorized by the CCPA.

We do not sell or share personal information as defined by the CCPA/CPRA. We do not use personal information for cross-context behavioral advertising.

To submit a CCPA request, email us at support@torismic.com with the subject line “CCPA Request.” We will verify your identity and respond within 45 days.

Nevada Residents

Nevada residents may submit a request directing us not to sell their personal information. We do not currently sell personal information as defined by Nevada law. To submit such a request, contact us at support@torismic.com.

Data Controller & Processor Roles

For the purposes of data protection law:

  • Torismic as Data Processor: When processing employee data, customer data, or transaction data on behalf of a business subscriber, Torismic acts as a data processor. The business subscriber is the data controller and is responsible for obtaining appropriate consent from their employees and customers.
  • Torismic as Data Controller: When collecting information directly from business subscribers (account registration, billing) or from consumers who create a Torismic account, we act as the data controller.

International Users

Torismic is based in the United States and our services are primarily designed for businesses operating within the United States. If you access our services from outside the United States, please be aware that your information will be transferred to, stored, and processed in the United States where our servers are located and our central database is operated.

By using our services, you consent to this transfer. We do not currently offer services specifically targeted at users in the European Economic Area (EEA), United Kingdom, or other jurisdictions with comprehensive data protection laws (such as GDPR), though we aim to follow industry best practices regardless of user location.

Torismic Pay (Future Feature)

Torismic Pay is a closed-loop digital wallet feature currently in development. When launched, it will allow consumers to convert loyalty points into wallet balance and spend that balance at participating businesses. Torismic Pay is not a bank, money transmitter, or stored-value card — it operates as a closed-loop prepaid program within the Torismic network.

Additional privacy disclosures specific to Torismic Pay will be published prior to its launch. By opting into Torismic Pay, consumers will agree to supplemental terms and data practices specific to that feature.

Children's Privacy

Torismic is not directed at individuals under the age of 13, and we do not knowingly collect personal information from children under 13. If we become aware that we have collected data from a child under 13, we will delete it within 30 days. If you believe a child under 13 has provided us with personal information, please contact us at support@torismic.com.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify affected users of material changes via email at least 30 days before they take effect. Non-material changes (formatting, clarifications) may be made without notice.

The “Last updated” date at the top indicates when this policy was last revised. Continued use of our services after changes take effect constitutes acceptance of the updated policy.

Contact Us

If you have questions about this Privacy Policy, our data practices, or wish to exercise your rights, contact us at:

Torismic LLC
Email: support@torismic.com
State of incorporation: Nevada, United States

For data protection inquiries, please include “Privacy” in your email subject line and we will respond within 30 days.