Privacy Policy
Last updated 19 August 2026
This Privacy Policy explains what information Staffless collects when you use staffless.app, why we collect it, and the choices you have. The short version: we collect what we need to run your account and your storefront, we don't run third-party advertising or analytics trackers, and we never sell your data.
Who we are
staffless.app is operated by Falcore Digital FZ-LLC trading as Staffless, a company registered in the Ras Al Khaimah Economic Zone (RAKEZ), United Arab Emirates (licence 45036411). Clients contract with Falcore Digital FZ-LLC. In this policy, "we", "us", and "our" mean Falcore Digital FZ-LLC. Falcore Group Pty Ltd (ABN 88 637 467 380) is our affiliated Australian entity. We handle personal information in line with applicable privacy laws, including the Australian Privacy Principles where they apply and, where it applies to you, the GDPR.
What Staffless does
Staffless connects to a merchant's point-of-sale system with read-only access, syncs their live inventory, and turns it into a shareable online storefront. Two kinds of people interact with us: merchants who hold a Staffless account, and visitors who browse a merchant's storefront. This policy covers both.
Information we collect
Account information. When you create an account we collect your name and email address through our sign-in provider, Clerk. If you sign in with Google, we receive the basic profile details Google shares.
POS connection data. When you connect a POS system (such as Lightspeed or Shopify), we store the access tokens needed to read your product and inventory data. Tokens are encrypted at rest, the connection is strictly read-only, and we never write back to your POS. Your public storefront only ever shows safe product fields — never cost, margin, or supplier data.
Billing information. Payments are processed by Stripe. We receive your plan, billing status, and a payment reference — full card numbers never touch our servers. If you connect a Stripe account to your workspace, Stripe processes that connection under its own terms.
Storefront visitor data. When a visitor sends an order request or subscribes to email updates on a merchant's storefront, we collect the details they submit (such as name, contact details, and the request itself) and store them for that merchant. Email subscriptions use double opt-in, and every email includes an unsubscribe link.
Storefront analytics. We measure storefront activity with our own first-party system. It records aggregate events such as page views and link taps using hashed identifiers, a coarse referrer source, and a broad device class. It does not track anyone across other websites and does not build advertising profiles.
Technical information. Like almost every website, our hosting provider automatically records standard server logs such as IP address, browser type, and pages requested. This is used to serve the site securely and diagnose problems — not to profile you.
How we use your information
We use the information above only to:
- Provide and operate your account, workspace, and storefront.
- Sync your inventory and deliver order requests to you.
- Process subscriptions and billing.
- Send transactional email such as confirmations and order notifications.
- Keep the service secure, prevent abuse, and fix problems.
- Meet legal, tax, and accounting obligations.
We do not sell personal information or share it for advertising.
Merchants and their customers
Information that storefront visitors submit belongs to the merchant whose store they used — we process it on the merchant's behalf. If you are a visitor and want your details corrected or deleted, the fastest path is to contact the store owner; you can also contact us and we will help. Merchants are responsible for their own legal obligations to their customers, including any consumer-law and privacy obligations that apply to their business.
Cookies
We use only essential cookies: the session cookies our sign-in provider (Clerk) needs to keep you logged in, and the minimal operational cookies our hosting provider may set to serve the site securely. We do not use advertising cookies, third-party analytics cookies, or cross-site tracking. We do measure aggregate site usage with Vercel Web Analytics, which is cookieless: it records page views with coarse, anonymised device, referrer and country information, and cannot identify you or follow you across other sites. See Vercel's analytics privacy notice for details.
Who we share it with
We use a small number of service providers to run Staffless. Each processes data only on our behalf:
- Clerk — sign-in and account authentication.
- Supabase — the secure database that stores workspace data.
- Stripe — subscription billing and payment processing.
- Vercel — hosting, delivery, and standard server logs.
- Resend — transactional email delivery.
- The POS providers you choose to connect (such as Lightspeed or Shopify), which process the connection under their own terms.
International transfers
Our providers may store or process data on servers in other countries. Where personal data crosses borders we rely on those providers' safeguards, such as standard contractual clauses, to keep it protected to the standard required by applicable law.
How long we keep it
We keep information for as long as your account is active or as needed to provide the service, then for any period required for legal, tax, or accounting purposes. When it is no longer needed we delete it or anonymise it. You can ask us to delete your account and its data at any time.
How we protect it
The service is served over encrypted HTTPS, POS tokens are encrypted at rest, and data lives in access-controlled databases. No method of transmission or storage is completely secure, but we take reasonable technical and organisational measures to protect your information.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain uses, and to withdraw consent where we rely on it. You may also complain to your local data protection authority — in Australia, the Office of the Australian Information Commissioner (OAIC).
Making a request
To exercise any of these rights, contact us through your Staffless dashboard or via the contact options published on staffless.app. We will respond within the timeframe required by applicable law and may need to verify your identity first.
Data deletion (Instagram and Meta connections)
If you connected an Instagram or Meta account to Staffless, you can remove that connection and its data at any time: open your Staffless dashboard, go to Connections, and choose Disconnect on the account. Disconnecting revokes our stored access token and removes the connection record; associated social data we hold (such as cached media lists, insights snapshots, and comment automation records) is deleted or anonymised in line with the retention section above.
You can also remove Staffless from your Instagram or Facebook account settings under Apps and Websites — we honour those removals. To request deletion of everything we hold, including your Staffless account itself, contact us via the options published on staffless.app and we will action it within the timeframe required by applicable law.
Children
Staffless is built for businesses and adults. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
Changes to this policy
We may update this policy as our practices or the law change. When we do, we will revise the "last updated" date at the top of this page and make significant changes clear on the site. See also our Terms of Service.
