Who we are
This policy is published by VitaPay LLC ("VitaPay", "we", "us"). VitaPay provides software for businesses that take payments: a web portal for merchants, payment offices and their partners, a point-of-sale system for restaurants and other venues, time-keeping and tip tools for their staff, and payment pages that their guests use.
Some portals are presented under the name of a payment office or reseller that works with us. This policy still applies to the information our platform holds for them.
Two roles
We hold information in two different capacities, and your rights depend on which applies.
- For our own customers — merchants, payment offices, agents and partners who hold an account with us — we decide why and how their account information is used. We are the "business" or "controller" for it.
- For a merchant's own people — its employees and its guests — we hold the information on the merchant's behalf, to run the merchant's point of sale, payroll exports and payment pages. The merchant decides how it is used, and we act as its "service provider" or "processor". If you are a guest or an employee, the venue or employer is usually the right first contact, and we help them answer you.
What we collect
Merchants applying for an account
When a business applies through our website or a partner's website, the application can include:
- business details: legal and trading name, address, contact details, business type and volumes;
- owner details for up to four owners: name, contact details, date of birth and Social Security number;
- the business's federal tax ID (EIN) and the bank routing and account number for settlement;
- documents the applicant uploads, such as bank statements, voided checks and identity documents.
Social Security numbers, tax IDs, dates of birth and bank account numbers are encrypted separately from the rest of the application, and the sender's network address is kept only as a one-way keyed hash.
Merchants, offices, agents and partners using the portal
- account details: name, username, email address, phone number, role and the businesses the account may see;
- sign-in information: password (stored only as a one-way hash), multi-factor settings, trusted devices, and the network address and time of sign-ins and actions;
- business records the account creates or that its processors report: merchant profiles, transactions, deposits, fees, disputes, statements, invoices, contracts and signatures, and accounting records;
- messages to our in-portal assistant ("Chat") and files attached to it.
Employees of a merchant
When a merchant uses our labor and tip tools, we hold on the merchant's behalf:
- profile: name, email, phone, address, date of birth, language, and certification expiry dates (such as liquor or health cards);
- hiring records the employer collects through us: application details, résumés, tax and eligibility forms (for example W-4 and I-9), direct-deposit details and electronic signatures — these are encrypted;
- work records: schedules, punches and timecards, breaks, jobs and pay rates, tips, tip-pool shares, corrections and acknowledgments;
- a till PIN, stored only as a one-way digest;
- a photo or credential check at clock-in, only where the employer turns that on.
We do not track employees' location for clock-in.
Guests and diners
When you order from or pay a venue that uses VitaPay, the venue may hold through us:
- your order, check, tip and payment record, including the card brand and last four digits — never the full card number;
- contact details you give for an order, a receipt, a booking or delivery: name, phone, email and delivery address and instructions;
- if the venue keeps a customer list: your name, contact details, visits, loyalty reference, birthday and preferences such as dietary notes, and the marketing consents you have given or withdrawn;
- if you call a venue that shows caller ID or takes orders by an automated phone assistant: your phone number, the caller-ID name, the order, and what you say to the assistant (converted to text by the telephone provider). Remembering a caller's past orders is optional and off unless the venue turns it on;
- text-message consents and opt-outs (STOP and START);
- gift cards, memberships and wallet passes you hold, and the device token your phone's wallet uses to receive updates;
- on a venue's TV screens, a first name and initial if you play trivia, or the phone number or email you choose to give to join a list, with the consent you tick.
When you open a payment link we record that it was opened and when — not your network address or browser.
Card data
Card numbers, expiry dates and security codes are typed into fields served by the payment provider, not by us. They never reach our servers, our logs or our database. We keep only the card brand, the last four digits and the provider's own reference or token. If you ask a venue to keep your card on file (for example for a membership), the provider keeps the card and we store only the provider's token, encrypted.
Devices
Terminals, kiosks, handhelds and TV screens send us technical logs so we can support them. Card numbers and card track data are removed from those logs before they are stored.
How we use information
- to provide the platform: run the portal, the point of sale, payment pages, staff tools and reports;
- to review merchant applications, verify identity and meet the requirements of payment processors, card networks and anti-money-laundering rules;
- to process payments through the payment provider the merchant has chosen;
- to calculate and report figures such as sales, deposits, fees, tips, pay and residuals;
- to send the messages you or the merchant ask for: receipts, sign-in codes, notifications and, with consent, a venue's marketing;
- to secure the platform: authenticate users, prevent fraud and abuse, and keep a permanent record of who did what;
- to answer questions in Chat using only the data the person asking is allowed to see;
- to meet legal obligations and enforce our agreements.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We use no advertising or analytics trackers on the platform.
Who we share it with
We share information only to provide the platform, at the merchant's direction, or where the law requires it. The service providers we use:
| Service | What it does | When |
|---|---|---|
| Adyen, Payrix | Process card and bank payments; serve the card fields on payment pages | When the merchant uses that processor |
| Datacap | Card-present payment gateway | When the merchant's terminals use it |
| Shift4, Stripe | Payment processing and reporting | When the merchant uses them |
| SendGrid (Twilio) | Sends email | Receipts, notifications, sign-in messages |
| Twilio | Text messages and phone calls | Sign-in codes, receipts, a venue's texts and phone ordering |
| Oracle Simphony | Point-of-sale configuration and reporting | When the merchant connects its Simphony system |
| reCAPTCHA on sign-in and job applications; Google sign-in and Google Wallet | When enabled | |
| Microsoft | Microsoft sign-in | When enabled |
| Apple | Wallet pass updates | When a guest saves a pass |
| A language-model provider chosen by the platform administrator | Answers Chat questions and drafts set-up suggestions | When Chat or set-up assistance is used |
| Delivery and ordering partners (such as DoorDash, Uber Eats, Grubhub, Deliverect, Otter) | Send orders to the venue | When the venue connects them |
| Loyalty, gift, booking and accounting partners (such as Thanx, Givex, Factor4, Tripleseat, Plaid, Snowflake) | The service the merchant connects | When the merchant connects them |
Payment providers' fields may run the provider's own fraud checks, which can read information about your device. We also disclose information when the law requires it, to protect people or the platform, or as part of a merger or sale of our business, under the same protections.
Our servers and file storage are run by us in the United States.
How long we keep it
Each kind of record has its own period, set out in our Data Retention and Deletion Policy. In short: financial, labor and audit records are kept for years because the law and the integrity of the books require it; device logs for 90 days; card numbers never.
Your rights
Depending on where you live, you may have the right to:
- know what personal information we hold about you and receive a copy;
- correct it;
- delete it, subject to the records we must keep;
- opt out of the sale or sharing of personal information — we do neither;
- limit the use of sensitive personal information — we use it only to provide the service, verify identity and meet legal obligations;
- not be treated differently for using these rights.
California residents have these rights under the California Consumer Privacy Act as amended by the CPRA, including job applicants and employees. Residents of other states with privacy laws — among them Colorado, Connecticut, Virginia, Utah, Texas and Oregon — have similar rights, including to appeal a decision we make on a request by replying to it.
To make a request, email go@vitapay.com. We will confirm your identity before we act, usually by matching details we already hold. An authorized agent may ask for you with your signed permission. We answer within 45 days and will explain what we cannot delete and why.
If we hold your information for a merchant — you are a guest or an employee — we will pass your request to that merchant and help it respond.
Security
- Social Security numbers, tax IDs, bank details, hiring documents, Chat files and stored provider tokens are encrypted with AES-256-GCM.
- Passwords are stored as one-way hashes. Sign-in supports multi-factor authentication, and sessions expire after inactivity.
- Every account sees only the businesses it is bound to, and every screen and every change checks that again.
- Every change made through the portal is written to an audit trail that cannot be edited or deleted and is sealed so that tampering shows.
- Public pages travel over HTTPS, and card details go only to the payment provider.
No system is perfectly secure. If a breach affects your information, we will tell you and the affected merchant as the law requires.
Cookies
We use only our own cookies, to keep you signed in and secure. We set no advertising or analytics cookies.
| Cookie | Purpose | Lasts |
|---|---|---|
vp_session | Keeps you signed in to the portal | Ends after 2 hours idle, 12 hours at most |
vp_trust | Remembers a device you trusted, so you are not asked for a code each time | 24 hours by default |
vp_sso | Completes a Google or Microsoft sign-in | 10 minutes |
vp_staff | Keeps an employee signed in to the staff app | 12 hours |
vp_staff_phone | Remembers an employee's trusted phone | Set by the employer |
vp_onb | Holds a venue set-up to the one phone that started it | Up to 7 days |
vp_device | Remembers your time zone and date format | 1 year |
Your browser's local storage also remembers display choices such as light or dark mode. Guest payment pages set no cookies. On sign-in and job-application pages that use reCAPTCHA, Google may set its own cookies under Google's privacy policy.
Children
The platform is for businesses and their staff. It is not directed to children under 13, and we do not knowingly collect their information.
Changes
We will post any change here with a new version number and date. If a change materially affects how we use information we already hold, we will tell account holders before it takes effect.
Contact
VitaPay LLC — go@vitapay.com