1Who this covers #
Overlay ("we", "us") operates this platform from Chicago, Illinois. This policy describes how we handle personal information for three groups of people:
- Merchants — the businesses that sign up for Overlay and their staff who log in.
- Merchant customers — the shoppers who buy from a merchant's Overlay-powered storefront or receive their marketing emails. We handle this data as a processor on the merchant's behalf; the merchant is the controller.
- Visitors — people who browse
overlaypos.com, read this policy, or start a signup.
If you are a customer of a merchant that uses Overlay and want to exercise a data right, contact that merchant first — they control your data. If they don't respond, or you can't reach them, email us and we will route the request.
2What we collect #
From merchants at signup
- Business name and merchant contact name.
- Email address and password (stored hashed with bcrypt).
- Business address, phone number, and the domain the storefront will run on.
- POS provider and API credentials the merchant chooses to connect (Square access token, Shopify admin token, WooCommerce keys).
- Payment method for Overlay's subscription billing (handled by Stripe; we receive metadata only — no card numbers).
From merchants during normal use
- Content the merchant creates in Overlay: marketing campaigns, product descriptions, design settings, wine-club rosters, waitlist rules.
- Server logs of API activity (request path, method, tenant, timestamp, response code).
- Support conversations at team@overlaypos.com.
From the merchant's POS (about the merchant's customers)
When a merchant connects a POS, Overlay reads the following on their behalf:
- Customer name, email, phone (where the merchant has collected them).
- Order history: items, quantities, totals, dates.
- Product catalog and inventory.
We do not read or store card numbers, CVVs, or bank details from any POS. Payment authorization stays on the POS provider's side.
From visitors to overlaypos.com
- Basic server access logs (IP address, user agent, referring URL, timestamp).
- Anything a visitor submits through a form (name, email, business name, comments).
3How we use it #
We use the information above to:
- Provide the service — run the merchant's storefront, deliver marketing emails, sync inventory, process club billing.
- Authenticate merchants and secure their accounts (session tokens, admin keys, rate limits).
- Bill merchants for the Overlay subscription and reconcile disputes.
- Send transactional email to merchants: signup confirmation, billing receipts, security notices, service announcements.
- Send Overlay product marketing to merchants (only to the merchant contact — never to the merchant's customers). Merchants can opt out of Overlay product marketing at any time.
- Debug production issues (error monitoring with redacted headers, described in Security).
- Detect abuse and enforce our Terms of Service.
4Legal basis #
Where GDPR applies, we rely on the following bases:
- Contract — to provide the Overlay service to merchants who have signed up.
- Legitimate interests — securing accounts, preventing abuse, improving the product, sending merchant product updates.
- Consent — for optional communications and any tracking beyond what is strictly necessary. Consent is revocable at any time.
- Legal obligation — tax records, responding to lawful requests.
For merchant-customer data, the merchant chooses the legal basis; we process it under their direction, bound by the Data Processing Agreement.
7Merchant-customer data #
Data about the merchant's own customers is handled differently from data about the merchant. Overlay is a processor for this data; the merchant is the controller. The rules are set out in our Data Processing Agreement, which is binding on every merchant account.
In practice:
- Customer PII lives in the merchant's POS. Overlay reads it on-demand and caches minimally-necessary fields (name, email) to power features like marketing sends and wine-club rosters.
- When a merchant deletes a customer from their POS, the cached copy is purged on the next sync (typically within 24 hours).
- Merchant-customer data is never sold, rented, or used for cross-tenant analytics. Overlay's cross-tenant analytics measure Overlay usage (AI credits consumed, campaigns sent), not customer identities.
- If a data-subject request reaches us but names a merchant we host, we forward it to the merchant and CC the requester.
8Retention #
- Active merchant accounts — data is retained for the life of the subscription.
- Closed merchant accounts — all merchant and merchant-customer data is deleted within 30 days of closure. Merchants can request an immediate export or purge.
- Server logs — 30 days.
- Billing records — retained for 7 years to satisfy tax obligations.
- Backups — daily snapshots retained for 7 days. Deletion requests are honored within the active dataset immediately; the corresponding backup rolls off within 7 days.
9Your rights #
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Delete your information (subject to legal-retention requirements).
- Export your data in a portable format.
- Object to processing or withdraw consent where consent was the basis.
- Not receive marketing — unsubscribe links are on every Overlay marketing email, and you can email us to opt out of all future contact.
- Lodge a complaint with a supervisory authority (for EU/UK residents) or your state Attorney General (for US residents in states with privacy laws).
To exercise a right, email team@overlaypos.com from the address on file with the wording Data request in the subject. We respond within 30 days. We do not charge a fee for the first request in a 12-month period. We may need to verify your identity before acting.
Merchant customers who want to exercise a right about data held by a merchant should contact that merchant directly. Overlay will support the merchant in responding.
10Security #
Every piece of personal information handled by Overlay is protected by tenant-level isolation, TLS in transit, encryption at rest at the disk layer, bcrypt-hashed passwords, and layered access controls. The full description — including our known limitations and security roadmap — lives on the Security page.
If you find a vulnerability, please email team@overlaypos.com instead of posting publicly.
11International transfers #
Overlay processes and stores data in the United States. If you are outside the US, using Overlay means data is transferred to and processed in the US. For merchants and customers in the European Economic Area, the United Kingdom, or Switzerland, transfers are made under the European Commission's Standard Contractual Clauses (SCCs), incorporated by reference in the Data Processing Agreement.
12Children #
Overlay is a B2B platform for retail operators. The service is not directed at children under 16 and we do not knowingly collect personal information from them. If you believe a child has provided information to us, email us and we will delete it.
Where merchants sell age-restricted products (alcohol, cannabis), it is the merchant's responsibility to enforce age gates and verify identity at delivery.
13Changes to this policy #
If we make a material change to how we handle personal information, we will email active merchants at the address on file at least 30 days before the change takes effect and update the "Effective" date at the top of this page. Non-material changes (typos, clarifications) may take effect immediately with an updated "Last updated" date.
14Contact #
Privacy questions, data requests, or complaints: