Last updated: October 30, 2025
Band Merch POS ("we", "our", or "us") is a point of sale application designed for musicians and bands to track merchandise sales during tours. This Privacy Policy explains how we collect, use, and protect your information when you use our application.
When you sign in with Google OAuth, we collect:
We store the following data related to your merchandise sales:
We use your information to:
We use IndexedDB (a browser database) to store sales data locally on your device. This enables offline functionality. You can clear this data at any time by clearing your browser data or reinstalling the app.
Your sales data is synced to your own Google Sheets spreadsheet in your Google Drive. We do not store your sales data on our servers. The data remains in your Google account, under your control.
Authentication tokens are stored securely in your browser session and are encrypted using Supabase Auth security standards.
Our application uses Google APIs with the following scopes:
Why we need it: To read and write sales transaction data to your Google Sheets spreadsheet.
What we do with it:
What we DON'T do: We do not access any spreadsheets other than the one created by our app for sales tracking. We do not read, modify, or delete your other spreadsheets.
Why we need it: To create and access the sales tracking spreadsheet in your Google Drive.
What we do with it:
What we DON'T do: The drive.file scope is limited to files created by our app. We cannot see, access, or modify any other files in your Google Drive.
Important: Band Merch POS's use and transfer of information received from Google APIs adheres to Google API Services User Data Policy, including the Limited Use requirements.
We do not sell, rent, or share your personal information with third parties.
Your data is shared only in the following limited circumstances:
You have the following rights regarding your data:
We implement security measures including:
Local Data: Sales data stored locally on your device remains until you clear your browser data or uninstall the app.
Google Sheets Data: Your sales data in Google Sheets remains in your Google account indefinitely unless you delete it.
Authentication Tokens: OAuth tokens are stored for the duration of your session and refreshed as needed. They expire automatically based on Google's token expiration policies.
Band Merch POS is not intended for use by children under 13 years of age. We do not knowingly collect personal information from children under 13.
This application is hosted in the United States. If you are accessing the application from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States where our servers are located.
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page indicates when this policy was last revised. We encourage you to review this policy periodically.
If you have questions about this Privacy Policy or how we handle your data, please contact us:
Email: privacy@yourband.com
(Update this with your actual contact email)
Band Merch POS's use of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.