Legal

Privacy Notice

Operational notice for CashOutly apps and cashoutly.com licensing. This is not legal advice and is not a counsel-reviewed privacy policy. Store listings should link here until counsel publishes a policy URL.

Who we are

CashOutly operates a merchant point-of-sale and a customer ordering app. The API stores identity and business data in Azure Cosmos DB (Mongo API). Website licensing is on cashoutly.com.

What we collect

  • Microsoft Entra sign-in identity (name, email, object id) used as the API bearer id_token
  • Store profile, catalog, orders, and payment metadata needed to run the POS
  • License and checkout metadata for Standard/Growth purchases via Dejavoo / iPOSpays Hosted Payment Page
  • Last-four SSN digits for W-2 worksheets; a full SSN is encrypted at rest if saved and is never returned in full by the API
  • Bank account details for Free Tap to Pay fee settlement (routing number, account number, account holder name). Routing and account numbers are encrypted at rest on the API

Children (COPPA)

CashOutly Customer requires users to confirm they are 13 or older before Microsoft sign-in. The service is not directed at children under 13, and we do not knowingly collect personal information from children under 13. This marketing site's contact form is for business inquiries.

What we do not do

  • We do not e-file with the IRS
  • We do not claim PCI DSS certification; card capture for Free / Standard Tap to Pay and website licensing runs on Dejavoo / iPOSpays
  • We do not capture Apple Pay or Google Pay in the customer app until a payment processor verifies capture (fail closed)
  • Free stores are not listed in CashOutly Customer; only paid stores that opt in appear
  • We do not sell personal information

Payments

Card data for website licensing is entered on Dejavoo's hosted payment page — not on cashoutly.com. CashOutly does not store full card numbers. Venmo / PayPal / Cash App QR flows use merchant-owned profile links; CashOutly does not process those payments.

Transport security

CashOutly API JSON uses TLS plus application-layer encryption (transport-x25519-aes256gcm-v1). Field-level end-to-end order notes use a separate merchant key scheme; the API cannot read those notes.

Your choices (CCPA-style)

  • In-app account deletion (DELETE /api/account) removes login profile, owned merchant records, licenses, employees, sales, payments, tax worksheets, discovery listings, and the merchant's dedicated database
  • California residents may contact us for access / deletion requests. We do not sell personal information

Contact

support@cashoutly.com or in-app support. See also our Terms of Use.

Last updated: September 2026. Made by NT Solutions Lab LLC.

CashOutly POS Terminal

Ready to Modernize Your Business?

Start Selling With CashOutly

CashOutly Tap to Pay