SugarSnapp is a register and ledger for market vendors, made by Francesco Bertocci LLC. This policy says plainly what the app stores, where it lives, and what never gets collected. No legalese padding, no surprises.
On your device only: whether you've finished onboarding, and your stand name before you sign in. Your sign-in session tokens live in the iOS Keychain.
On our backend (a Supabase database operated for SugarSnapp, project psiattienhrooetmjvue.supabase.co), tied to your account:
This data exists so your ledger syncs and your QR checkout works. We can technically access it as the database operator; we look only for support or debugging, and never sell or share it.
If you turn on the self-checkout page for your stall, your stand name, logo, address, website, and item catalog become publicly readable — that is what makes the page work. Your contact email and phone number are not exposed on the public page. Turning the page off takes it offline; the data returns to being private to your account.
Buyers never need an account, and the app never asks them for personal information. When a customer scans a sale QR code, our redirect service logs the scan time and — like every web server — briefly records standard request metadata (IP address, browser user agent) in infrastructure logs. We do not build buyer profiles.
Self-checkout shoppers: the cart lives in the shopper's own browser (localStorage) and is never sent to us until they pay. When they pay, the sale record (items, amounts, timestamps) is stored so your ledger and their receipt work. Card details go directly to Stripe and never touch SugarSnapp's servers. The receipt link contains no personal information about the shopper.
If you send a customer a payment link or receipt, it goes from your own Messages or Mail app — SugarSnapp stores no customer contact details.
If you check in to a market with its join code, that market's organizer can see your stand name and your check-in time on their roster for that day. That's the whole point of checking in — it's how end-of-day reconciliation knows who was there. Organizers never see your sales, ledger, or payment connections.
Not in the current App Store release. This section describes how the feature will behave when it ships, so there are no surprises later; today the app neither offers it nor requests the permissions below.
When you enable Tap to Pay on iPhone, iOS will ask for location access while accepting a tap — Stripe checks device location during a contactless payment for fraud prevention. SugarSnapp never stores, tracks, or sees your location. iOS may also mention Bluetooth as part of the contactless reader setup; no data about you or your customers is collected through it. Your customer's card data is read by Apple's secure hardware and goes directly to Stripe — SugarSnapp never sees it. If you don't enable Tap to Pay, the app requests neither permission.
To know whether the app actually works for people, SugarSnapp records a small, fixed set of milestones: the app was opened for the first time, an account was created, a first product was added, a first sale was recorded, Stripe was connected, and a sale happened on a given payment rail (cash, Venmo, PayPal, card, EBT tokens). That is the entire list. The single number we care most about is how many people who create an account go on to record a first sale.
Three things are worth stating plainly:
Our marketing pages — the home page, the vendor, shopper and organizer pages, pricing and support — measure which pages get read, so we can tell what is worth writing. It is our own analytics tool, Foliàire, built by the same company that builds SugarSnapp. It is not an advertising network, and nothing it records is sold or shared.
What it records: the page address and title, the page you arrived from, how far down you scrolled, how long you stayed, and which buttons or links you clicked. It sets no cookies. It does store a random identifier in your browser’s local storage so a repeat visit is not counted as a new person; that identifier is a random string and is not connected to your name, your email, or any SugarSnapp account.
Where it is not. None of this runs on the pages that matter most for privacy: not in the app, not on the checkout page a shopper reaches by scanning a stand’s code, not on receipts, not on the vendor dashboard, not on sign-in or password-reset pages — and not on this page or the Terms. Reading a privacy policy should not be measured.
Turning it off. Use this link to opt out — it records your choice in your own browser and deletes the identifier already stored. The link points at the home page rather than this one on purpose: this page runs no analytics, so the switch has nothing to act on here. This link turns it back on if you change your mind.
We also honour your browser’s “Do Not Track” setting without you having to do anything, and if your browser blocks site storage altogether we take that as a no rather than assuming a yes. Any content blocker will stop it too, and clearing your site data removes the identifier.
EBT sales are logged for your bookkeeping only. The app does not process EBT/SNAP payments and no EBT data beyond the amount and time of your own log entry is stored.
Settings → Delete account removes your account and every sale, item, check-in, and payment connection from our backend, permanently. Records already in your Stripe, PayPal, or Venmo accounts are yours and are unaffected.
SugarSnapp is a business tool, not directed at children under 13, and we do not knowingly collect their data.
If this policy changes materially, the date above changes and significant updates will be noted in the app's release notes.
Questions? [email protected]