1. Introduction
This Privacy Policy explains how CPMC, LLC (“we,” “us,” or “our”), operating the TransactionCam platform at transactioncam.com, collects, uses, stores, shares, and protects information when you access or use our services.
TransactionCam is a hosted service that bridges Clover® point-of-sale transaction data to UniFi® Protect surveillance cameras. We are committed to protecting your privacy and handling your data with transparency and care.
By creating an account or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of it, please do not use the Service.
Important: TransactionCam is not affiliated with, endorsed by, or officially connected to Clover®, Fiserv®, Ubiquiti®, or UniFi®. All trademarks belong to their respective owners.
2. Who We Are
| Legal entity | CPMC, LLC |
|---|---|
| Contact email | support@transactioncam.com |
| Mailing address | 411 Lakewood Circle, Unit C-108, Colorado Springs, CO 80910, USA |
| Governing law | State of Colorado, United States |
For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, CPMC, LLC is the data controller of the personal data described in this policy.
3. What Data We Collect
We collect only the data necessary to operate the Service. We organize it into the following categories:
3.1 Account Information (provided by you)
- Registration data: your name, email address, and a password (stored as a one-way bcrypt hash — we never store your plaintext password).
- Organization details: organization name, team member names and email addresses added through invitations.
- Billing data: if you subscribe to a paid plan, payment is processed by Stripe (see Section 7). We do not store your credit card number, bank account details, or full payment card information on our servers. Stripe provides us with a truncated card reference and subscription status only.
3.2 Third-Party Connection Credentials (provided by you)
- Clover OAuth tokens: when you authorize TransactionCam to connect to your Clover merchant account, Clover issues an access token. We store this token encrypted with AES-256-GCM, decrypt it only in memory at the moment of use, and never log or display it.
- UniFi Protect API keys: the API key you provide for your Protect console is stored with the same AES-256-GCM encryption and handled identically.
- Bridge enrollment keys: if you use the Local Bridge Connector, an enrollment key is generated. Only a SHA-256 hash of the key is stored; the plaintext key is shown once at creation and never stored.
3.3 Transaction Data (received from Clover)
When a sale or refund occurs on your Clover device, Clover sends TransactionCam a webhook notification. We then read the order and payment details (line items, amounts, tender type, timestamps) from Clover’s API using your authorized token. This data is used solely to format a transaction record and deliver it to your designated UniFi Protect camera(s). We do not use transaction data for analytics, advertising, profiling, or any purpose other than operating the delivery pipeline.
Transaction records are kept temporarily for retry tracking and audit purposes (see Section 6 for retention periods).
3.4 Technical & Usage Data (collected automatically)
- Server logs: IP address, browser user-agent string, request timestamps, HTTP status codes, and referring URLs. These are used solely for security monitoring, debugging, and maintaining system health.
- Session tokens: we use server-side JSON Web Tokens (JWTs) to maintain authenticated sessions. No third-party tracking cookies are used.
3.5 Data We Do Not Collect
We do not collect, store, or process:
- Video footage or images from your cameras
- Customer (end-consumer) personal data from your Clover transactions — we do not read or store cardholder names, card numbers, or personal identifiers of your customers
- Biometric data
- Location data (beyond what is part of your Clover merchant profile, such as store address)
- Data from minors (users must be 18 or older)
4. How We Use Your Data
We use the data we collect for the following purposes and no others:
| Purpose | Legal basis (GDPR) |
|---|---|
| Provide and operate the Service (deliver transactions to cameras, manage your account, process webhooks) | Performance of contract (Art. 6(1)(b)) |
| Authenticate your identity and manage sessions | Performance of contract |
| Process payments through Stripe | Performance of contract |
| Send transactional emails (team invitations, password resets, connection health alerts, delivery failure alerts) | Performance of contract / Legitimate interest |
| Maintain security, prevent fraud, and detect abuse | Legitimate interest (Art. 6(1)(f)) |
| Debug errors and maintain system reliability | Legitimate interest |
| Comply with legal obligations (e.g., tax records, lawful data requests) | Legal obligation (Art. 6(1)(c)) |
We do not sell, rent, lease, or trade your personal data. We do not use your data for advertising, profiling, or automated decision-making.
5. How We Protect Your Data
We take the security of your data seriously and implement multiple layers of protection:
- Encryption at rest: all third-party credentials (Clover tokens, Protect API keys) are encrypted with AES-256-GCM before being written to the database. The encryption key is stored separately from the database and is never committed to version control or logged.
- Encryption in transit: all connections to and from TransactionCam are encrypted with TLS 1.2 or higher (HTTPS). This includes connections to Clover’s API, to your Protect console, and to your browser.
- Password hashing: user passwords are hashed with bcrypt using a cost factor that makes brute-force attacks computationally infeasible. We never store or transmit plaintext passwords.
- Credential handling: decrypted credentials exist only in memory for the duration of an API call and are never written to logs, error reports, browser responses, or debugging output.
- Role-based access control (RBAC): every API request is scoped to the authenticated user’s organization and role (Owner, Admin, Operator, or Viewer). Users cannot access data belonging to other organizations.
- Tenant isolation: every database query is scoped by organization ID, enforced at the application layer. There is no cross-tenant data access.
- Certificate pinning: when communicating with UniFi Protect consoles (which typically use self-signed certificates), TransactionCam captures and pins the console’s TLS certificate fingerprint and alerts on unexpected changes.
- Infrastructure: the Service is hosted on a dedicated virtual private server with restricted access, automatic security updates, and nightly encrypted database backups.
6. Data Retention
We retain your data only for as long as it is needed for the purposes described in this policy:
| Data type | Retention period |
|---|---|
| Account information (name, email, organization) | While your account is active, plus 30 days after you request deletion (to resolve any pending disputes or billing matters) |
| Clover tokens & Protect API keys | Deleted immediately when the connection is disconnected or the account is closed |
| Transaction and delivery records | 90 days from the date of creation (used for retry tracking and audit). The permanent record of each transaction is the overlay on your UniFi Protect footage, which resides on your own hardware. |
| Bridge enrollment key hashes | Deleted when the bridge agent is revoked or hard-deleted, or when the account is closed |
| Server and application logs | 30 days, then automatically purged |
| Database backups | 30 days (rolling nightly backups) |
When data reaches the end of its retention period, it is permanently deleted or anonymized. Encrypted credentials are securely wiped by deleting the ciphertext — without the encryption key, the deleted data is unrecoverable.
7. Third-Party Service Providers (Sub-Processors)
We share data with a limited number of trusted third-party service providers, solely to operate the Service:
| Provider | Purpose | Data shared | Location |
|---|---|---|---|
| Stripe, Inc. | Payment processing for subscriptions | Your email, name, and payment details (handled directly by Stripe — we do not see or store full card numbers) | United States |
| Vultr / The Constant Company, LLC | Infrastructure hosting (virtual private server) | All data stored by the Service resides on this infrastructure | United States |
| Clover / Fiserv, Inc. | POS data source (you authorize this connection) | OAuth tokens (encrypted), order/payment data retrieved on your behalf | United States |
Each sub-processor is bound by their own privacy policies and, where applicable, data processing agreements. We do not share data with any other third parties, and we do not sell data to anyone.
8. Your Rights
8.1 Rights for All Users
Regardless of your location, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data (you can update your name and email in your account settings at any time).
- Delete your account and all associated data (contact us at support@transactioncam.com).
- Export your data in a portable format upon request.
8.2 Additional Rights Under the GDPR (EEA & UK Residents)
If you are located in the European Economic Area (EEA) or the United Kingdom, the General Data Protection Regulation (GDPR / UK GDPR) grants you additional rights:
- Right to restriction of processing: you may request that we limit how we process your data in certain circumstances.
- Right to object: you may object to processing based on our legitimate interests. We will honor your objection unless we have compelling legitimate grounds.
- Right to data portability: you may request a machine-readable copy of the data you provided to us.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
- Right to lodge a complaint: you have the right to lodge a complaint with your local data protection authority (supervisory authority).
International data transfers: your data is stored and processed in the United States. By using the Service, you acknowledge that your data will be transferred to the United States. We rely on the performance-of-contract derogation under Art. 49(1)(b) GDPR for necessary transfers, and we implement the security safeguards described in Section 5.
8.3 Additional Rights Under the CCPA/CPRA (California Residents)
If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) grant you additional rights:
- Right to know: you may request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, the business purposes, and the categories of third parties with whom we share it.
- Right to delete: you may request deletion of personal information we have collected.
- Right to correct: you may request that we correct inaccurate personal information.
- Right to opt out of sale or sharing: we do not sell or share (as defined by the CCPA/CPRA) your personal information, so there is nothing to opt out of. We do not engage in cross-context behavioral advertising.
- Right to non-discrimination: we will not discriminate against you for exercising any of your CCPA/CPRA rights.
Categories of personal information collected (using CCPA categories): identifiers (name, email, IP address); commercial information (subscription plan); internet activity (server logs); and professional information (organization name). We do not collect sensitive personal information as defined by the CPRA.
To exercise any of these rights, contact us at support@transactioncam.com. We will respond within the timeframes required by applicable law (generally 30 days for GDPR, 45 days for CCPA/CPRA).
9. Cookies and Tracking
TransactionCam uses only essential, first-party cookies required for the Service to function:
- Session cookie: a server-side session token (JWT) that keeps you logged in. It is set when you sign in and expires when you log out or after a defined inactivity period. It contains no personal data beyond your user ID and role.
We do not use:
- Third-party tracking cookies
- Analytics or advertising cookies
- Social media tracking pixels
- Fingerprinting or cross-site tracking technologies
Because we use only strictly necessary cookies, no cookie consent banner is required under the ePrivacy Directive. You can still block cookies in your browser settings, but doing so will prevent you from logging in.
10. Children’s Privacy
The Service is intended for business use and is not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If we learn that we have inadvertently collected data from a person under 18, we will delete it promptly. If you believe a minor has provided us with personal data, please contact us at support@transactioncam.com.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the “Last updated” date at the top of this page.
- Notify registered users by email at least 14 days before the changes take effect, unless the change is required by law to take effect sooner.
Your continued use of the Service after the updated policy takes effect constitutes acceptance of the revised policy.
12. How to Contact Us
If you have any questions about this Privacy Policy, wish to exercise your data rights, or have a privacy concern, please contact us:
| support@transactioncam.com | |
| Mailing address | CPMC, LLC 411 Lakewood Circle, Unit C-108 Colorado Springs, CO 80910 United States |
We aim to respond to all privacy-related inquiries within 7 business days.