Skip to main content

Privacy Policy

Last updated: 2026-05-15

Fortune Technology Inc., operating as Storeveu ("Storeveu", "we", "us", or "our"), provides a multi-tenant point-of-sale and back-office platform to retailers, including convenience stores, grocery stores, and liquor stores. This Privacy Policy explains how we collect, use, share, and protect personal information when you create an account, use the Storeveu portal, cashier app, customer-facing storefront, or interact with our customer support team.

This Policy applies to information we collect about account holders, store staff, and platform administrators. Information processed about a retailer's customers is processed on behalf of the retailer (the "Merchant") under the Storeveu Master Services Agreement; the Merchant is the data controller for that information.

1. Information We Collect

1.1 Account Information

  • Name, email address, phone number, and password (stored hashed via bcrypt)
  • Business legal name, EIN, address, owner contact, and merchant agreement details
  • Subscription plan, add-on selections, and billing records
  • Payment instrument details necessary for ACH or card-based subscription billing (collected and stored by Stripe; we never store full bank account or card numbers)

1.2 Operational Information

  • Login records, session tokens, IP address, browser/device user agent
  • Employee PINs (stored as bcrypt hashes), shift open/close events, clock-in/out timestamps
  • Implementation Engineer PINs (encrypted at rest with AES-256-GCM)
  • Audit logs of platform actions (who changed what, when)

1.3 Transaction and Compliance Data

  • Sales transactions, refunds, voids, tender method, and totals
  • Lottery scan events (ticket book numbers, sales/payout activity) which may be transmitted to state lottery authorities
  • Tobacco/alcohol age-verification dates of birth captured at the point of sale (retained for compliance with state inspection requirements)
  • Tobacco scan data transmitted daily to manufacturers (Altria PMUSA, RJR Reynolds, ITG Brands) under their Retail Leaders / Retail Engagement programs
  • EBT/SNAP eligibility and transaction records (subject to USDA Food and Nutrition Service rules)
  • Fuel deliveries, tank readings, and dispenser activity

1.4 Bank Account Verification and ACH Information

When you connect a bank account for ACH subscription billing, payouts, or marketplace settlement, we use trusted third-party financial-data networks (including Plaid Inc. and Stripe, Inc.) to securely verify your account. The bank credentials you enter into a Plaid Link or Stripe Financial Connections session are submitted directly to the provider and are never seen, transmitted, or stored by Storeveu. We receive only the resulting bank-account metadata (institution name, account type, last four digits, and a tokenized account identifier) and the access token required to initiate the authorized debits or credits. Use of Plaid is governed by Plaid's End User Privacy Policy at plaid.com/legal.

1.5 Communications

  • Records of support tickets, in-platform chat messages, and email correspondence
  • Recordings or transcripts of phone, video, or screen-share customer support sessions where permitted by applicable law (see Section 5)
  • AI Assistant conversation history, including the prompts you submit and the responses generated. Conversation content may be sent to our AI processors (Anthropic and OpenAI) under their respective business terms

1.6 Cookies and Similar Technologies

See our Cookie Notice for details on the cookies, local storage entries, and IndexedDB caches we use to operate the portal, cashier app, and storefront.

2. How We Use Information

We use the information we collect to:

  • Provide, maintain, secure, and improve the Storeveu platform
  • Authenticate users, gate access via role-based permissions, and prevent fraud
  • Process subscription billing, deliver hardware, and reconcile ACH or card payments
  • Generate operational reports, analytics, and AI-assisted recommendations
  • Transmit lottery scan data to state lotteries and tobacco scan data to participating manufacturers as required for our customers' participation in those programs
  • Provide customer support, respond to inquiries, and improve our services
  • Send service-related notifications (subscription renewal, security alerts, scheduled maintenance, contract reminders)
  • Comply with legal, tax, and regulatory obligations (including subpoenas, lottery-commission reporting, and 1099-K issuance where applicable)

3. Legal Bases (for users in jurisdictions requiring them)

  • Contract performance — to deliver the services you purchased
  • Legitimate interests — to secure the platform, prevent abuse, and improve features
  • Legal obligation — to comply with tax, financial, lottery-commission, tobacco-program, or law-enforcement requirements
  • Consent — for optional communications, AI Assistant usage, and call recording where required by law

4. How We Share Information

We do not sell personal information. We share information only with the following categories of recipients, and only as necessary:

4.1 Service Providers (Sub-processors)

Storeveu uses the following categories of sub-processors. The current list reflects active integrations; specific sub-processors may be added or replaced from time to time as the Service evolves, with this Policy updated accordingly.

  • Stripe, Inc. — subscription billing, ACH processing, payment-instrument vaulting, Stripe Financial Connections for bank-account verification (US)
  • Plaid Inc. — bank-account verification and ACH authorization for Merchants who connect a bank account through the Plaid Link interface (US). Bank credentials entered into Plaid Link are submitted directly to Plaid and are never seen, transmitted, or stored by Storeveu. Use of Plaid is governed by Plaid's End User Privacy Policy at plaid.com/legal.
  • Dejavoo — point-of-sale card processing (processed under PCI-DSS scope)
  • Anthropic, PBC — AI Assistant (Claude) inference and tool use; conversation content sent only when the AI Assistant is invoked by a user
  • OpenAI, L.L.C. — embeddings for the knowledge base; OCR enrichment for invoice processing
  • Open-Meteo — weather forecast data for sales analytics (aggregate location coordinates only; no personal information transmitted)
  • Twilio Inc. — SMS and voice notifications (when configured by the Merchant)
  • ElevenLabs, Inc. — speech synthesis and conversational voice for the in-app voice assistant and the inbound phone assistant (audio and transcripts processed only while a voice session or call is active)
  • Microsoft Corporation (Azure AI Document Intelligence) — invoice and document text extraction for the invoice import feature (vendor invoices uploaded by the Merchant)
  • United States Postal Service (USPS Addresses API) — address standardization and ZIP code lookup for addresses the Merchant enters (address fields only; no name or contact details transmitted)
  • Cloudinary / object-storage providers — product-image hosting, label storage
  • Cloud hosting and infrastructure providers — application hosting, managed PostgreSQL, email delivery (transactional SMTP)

An updated sub-processor list is available on request to privacy@thefortunetech.com.

4.2 Compliance Partners

  • State lottery commissions (where the Merchant operates lottery)
  • Tobacco manufacturers participating in scan-data programs (Altria, RJR, ITG)
  • Federal SNAP/EBT processors (where the Merchant accepts EBT)
  • Marketplace integrations (DoorDash, Uber Eats, Instacart, etc.) if the Merchant has connected them

4.3 Legal and Safety

We may disclose information when we have a good-faith belief that disclosure is required by law, subpoena, or court order, or to protect our rights, property, or safety, or that of our users or the public.

4.4 Business Transfers

If Storeveu is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to standard confidentiality obligations.

5. Customer Support Communications and Call Recording

By creating an account, you consent to receive customer support communications by email, phone, SMS, and in-platform chat at the addresses and numbers you provide. You may opt out of non-essential marketing communications at any time, but service-related and billing-related notices are required for the operation of your account.

Call recording. We may record customer support phone, video, and screen-share sessions for quality assurance, training, dispute resolution, and security purposes where permitted by applicable law. Federal law and most U.S. states permit recording with one-party consent (Storeveu's consent as the recording party). The following states require all-party consent and you will be notified at the start of any such call: California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, Nevada, New Hampshire, Pennsylvania, Vermont, and Washington. By continuing a recorded call after the disclosure, you consent to the recording.

6. Data Retention Schedule

We retain personal information only for as long as it is needed to provide the Service, comply with our legal and regulatory obligations, resolve disputes, and enforce our agreements. When information is no longer needed, we securely delete or anonymize it. The following retention periods apply by data category:

Data Category Retention Period Basis

 Account profile (name, email, phone, business identity)

Active account + 12 months after closure

Contract performance; dispute resolution

Authentication credentials (bcrypt hashes, PIN hashes)

Until rotated, deleted, or account closure

Security; account access

Sales transactions, refunds, voids, tender details

7 years from transaction date

Tax (IRS); state revenue requirements

Subscription billing records, invoices, ACH/card receipts

7 years from billing date

Tax; financial-records retention

Bank account metadata and ACH tokens (Plaid / Stripe)

Until revoked by Merchant or account closure, then 12 months

Active billing; chargeback / NACHA dispute window

Lottery scan events and shift snapshots

Indefinitely while the Merchant remains licensed; archived after license termination

State lottery commission audit

Tobacco scan-data submissions and acknowledgments

5 years from submission

PACT Act; manufacturer-program audit

Age-verification records (DOB at point of sale)

2 years (or longer if state law requires)

State tobacco/alcohol inspection

Employee timekeeping (clock-in / clock-out)

4 years from event date

Federal Fair Labor Standards Act

Customer profiles (loyalty, house accounts)

Active + 24 months, or until Merchant deletes

Merchant operates as data controller

Audit logs (administrative actions, mutations)

3 years from event date

Forensic investigation; regulatory audit

AI Assistant conversation history

90 days, then anonymized for service improvement

Quality assurance; user support

Customer support recordings and transcripts

12 months from recording date

Quality assurance; dispute resolution

System and access logs

12 months from log entry

Security monitoring

Database backups

35 days rolling

Disaster recovery

Retention periods may be extended where required by a legal hold, ongoing investigation, regulatory request, or active dispute. When you close your account, transaction records and billing data are retained for the periods above; account-profile information is deleted or de-identified at the end of its retention period.

7. Information Security Program

Storeveu maintains an information security program designed to protect the confidentiality, integrity, and availability of personal information. The program is operationally implemented and the underlying written policies and procedures are being formalized. Specific safeguards include:

7.1 Encryption

  • In transit — TLS 1.2 or higher for all network traffic; HTTPS-only for the portal, cashier app, admin panel, storefront, and APIs
  • At rest — AES-256-GCM encryption for sensitive credentials (payment-processor secrets, SFTP keys for tobacco scan-data feeds, Stripe customer references, Implementation Engineer PINs) using a vault key managed outside the application database
  • Database backups — encrypted at rest using the cloud provider's managed encryption

7.2 Authentication and Access Control

  • bcrypt password and employee PIN hashing
  • JWT-based session authentication with configurable short-lived access tokens (default 8 hours, with inactivity-based auto-lock)
  • Server-side rate limiting on all authentication endpoints (login, password reset, signup, register PIN, Implementation PIN)
  • Role-based access control (RBAC) with 130+ granular permissions across 30 modules; every backend route is permission-gated
  • Multi-factor authentication (TOTP) is on our active security roadmap. Third-party administrative consoles (Stripe, source-control, cloud hosting, administrative email) currently enforce provider-level MFA
  • Implementation Engineer PIN gate (auto-rotated weekly) for hardware-configuration access
  • Manager-PIN elevation for refunds, voids, and other sensitive cashier actions

7.3 Application Security

  • Server-side input validation and typed numeric/string parsers (price, fuel-quantity, integer count, alphanumeric)
  • XSS protection via DOMPurify sanitization on rendered HTML; CSRF protection via JWT in headers
  • Multi-tenant data isolation enforced at the database query layer (every query is scoped by org and store)
  • Audit logging of all data mutations with field-level before/after diffs and actor attribution
  • SQL-injection protection via parameterized queries (Prisma ORM)
  • Internal security audits performed periodically; remediation tracked through release cycles

7.4 Operational Security

  • Production database is not exposed to the public internet; reachable only via the backend application server
  • Server access restricted to SSH-key-based authentication (password authentication disabled)
  • Secrets managed via environment variables; never committed to source control
  • Code review prior to merge for material changes
  • Automated and manual testing prior to release

No system is perfectly secure. We notify affected users and applicable regulators of confirmed material data breaches in accordance with the timelines in Section 10.

8. Bank Account and Payment Data

When a Merchant connects a bank account for ACH subscription billing or marketplace settlement using Plaid Link or Stripe Financial Connections, the following protections apply:

  • Online banking credentials (username, password, security questions) are entered directly into the Plaid or Stripe interface and are never seen, transmitted, or stored by Storeveu.
  • Storeveu receives only bank-account metadata (institution name, account type, last four digits of the account number) and a tokenized access identifier required to initiate authorized debits or credits.
  • Card payment data accepted through point-of-sale terminals (Dejavoo) is processed within the PCI-DSS-validated boundary of the payment processor; Storeveu does not store full card numbers.
  • Stripe customer and payment-method tokens are stored in encrypted form to enable recurring billing.
  • Merchants may revoke a connected bank account at any time through their account settings or by contacting support@thefortunetech.com; revocation immediately suspends future ACH billing on that account.

Use of Plaid is governed by Plaid's End User Privacy Policy at plaid.com/legal. Use of Stripe is governed by Stripe's Privacy Policy at stripe.com/privacy.

9. Your Rights and Data Subject Request Process

9.1 California Residents (CCPA / CPRA)

California residents have the right to:

  • Know what personal information we collect, use, disclose, and sell (we do not sell personal information)
  • Request access to and a copy of personal information we hold about you
  • Request correction of inaccurate personal information
  • Request deletion of personal information, subject to legal retention requirements
  • Opt out of "sharing" of personal information for cross-context behavioral advertising (Storeveu does not engage in this)
  • Limit use of sensitive personal information
  • Be free from discrimination for exercising these rights

9.2 Other US State Residents

Residents of states with comprehensive privacy laws (including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Tennessee, Indiana, Iowa, Delaware, New Hampshire, New Jersey, Kentucky, Minnesota, Maryland, and others as enacted) have substantially similar rights to access, correct, delete, and port their personal information.

9.3 How to Submit a Request

  1. Send an email to privacy@thefortunetech.com with the subject line "Data Subject Request", identifying the type of request (access, correction, deletion, portability, opt-out, or limit use).
  2. We will acknowledge receipt within 10 business days and may request information necessary to verify your identity (typically the email address on file plus a recent transaction or account-detail confirmation).
  3. We will substantively respond within 45 calendar days of verified receipt. If we need additional time, we will notify you in writing and may extend the response window by an additional 45 days as permitted by applicable law.
  4. Requests are free of charge; we may decline manifestly unfounded or excessive requests as permitted by applicable law and will explain the basis for any decline.
  5. You may designate an authorized agent to submit a request on your behalf, subject to verification.

Customer-facing requests directed to a Merchant. If you are a customer of a Storeveu Merchant (e.g., a loyalty member of a convenience store using Storeveu) and wish to exercise rights regarding your information, your request should be directed to the Merchant, who is the data controller. Storeveu will assist the Merchant in responding to your request as required by our agreement with the Merchant.

10. Incident Response and Breach Notification

Storeveu maintains an incident response capability covering detection, containment, eradication, recovery, and post-incident review. In the event of a confirmed data breach affecting personal information of account holders or authenticated users:

  • We will notify affected users without undue delay and no later than 72 hours after confirmation, where the breach is reasonably likely to result in a risk of harm.
  • We will notify regulators in accordance with applicable state and federal law (including state attorneys general and, where applicable, sectoral regulators).
  • Notifications will describe the nature of the breach, the categories of information affected, the likely consequences, the measures taken or proposed, and contact details for further information.
  • We will cooperate with affected Merchants to support their downstream notification obligations to their own customers.

11. Children's Privacy

Storeveu is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If you believe we have collected such information, please contact us at privacy@thefortunetech.com so we can delete it.

12. International Users

Storeveu is operated from the United States, and information is processed in the United States. If you access the Service from outside the United States, you consent to the transfer of information to the United States.

13. Changes to this Policy and Periodic Review

This Privacy Policy is reviewed at least annually and whenever there is a material change to the Service, our sub-processors, or applicable law. We may update this Policy from time to time; material changes will be notified via email or in-platform notification at least 30 days before they take effect. The "Last updated" date at the top reflects the most recent revision. Prior versions of this Policy are available on request.

14. Contact

Questions, requests, or complaints about this Policy should be directed to:

Storeveu Privacy Team

 Email: privacy@thefortunetech.com

 Security inquiries: security@storeveu.com

 Mail: Fortune Technology Inc., Privacy Office, 27 Depot Sq, Mechanic Falls, ME 04256, United States

Text Message (SMS) Program

Where a retailer using Storeveu operates a text-message loyalty program, Storeveu sends those messages on the retailer's behalf. Shoppers opt in in person at the store by entering their phone number and ticking a consent box that is never pre-ticked and never a condition of purchase. We record the consent timestamp, the surface it was collected on, and the exact wording displayed.

Message frequency varies by store and is typically a few messages per month. Message and data rates may apply. Reply STOP to any message to opt out of all promotional messages platform-wide, START to resume, or HELP for help.

We do not sell, rent, or share mobile phone numbers or SMS consent with third parties for their own marketing purposes. Numbers collected for a store's text-message program are used only to send that program's messages and the transactional messages a shopper requests.

Full program terms, including the verbatim consent wording, are published at Text Message Terms.

4.5 Marketplace and Delivery Platform Integrations

A Merchant may connect its Storeveu store to third-party ordering marketplaces such as Uber Eats, DoorDash and Instacart (each a "Platform"). When a Merchant does so, Storeveu exchanges information with the Platform on the Merchant's behalf and solely to list the store and fulfil orders:

  • Sent to the Platform: the Merchant's catalogue (item names, descriptions, images, barcodes, categories, prices, container deposits, tax and age-restriction classification), item availability, store hours and status, and order updates (accepted, denied with reason, item changes, ready, cancelled).
  • Received from the Platform: order details (items, quantities, prices, fees, order and delivery timing, the customer's stated preferences for unavailable items) and limited customer contact details as the Platform chooses to share them, typically a first name and a masked phone number. Storeveu does not receive the customer's payment details from any Platform.

Platform customer information is processed on behalf of the Merchant, used only to prepare and hand off the order and to support the Merchant on that order, and is never used by Storeveu for marketing or combined with other data to build profiles. It is retained with the Merchant's sales records under the retention schedule in Section 6, and is deleted or anonymized earlier when the Platform or the Merchant requires it, including when a Merchant disconnects a Platform or a Platform removes a store. Each Platform handles the customer's own account and payment information under its own privacy policy, and each Platform's terms also govern how Storeveu may use the data it provides.

Automated phone assistant. Some support and store phone lines are answered by an automated voice assistant. Calls to those lines are transcribed and may be summarized to route or resolve the request, and the caller is told at the start of the call that the line is automated and recorded. The all-party-consent notice above applies to these calls in the same way. Voice transcripts are retained for 90 days for quality review, then deleted.

Ready to modernize your store?

See how Storeveu replaces five systems with one platform.