1. Introduction

This Privacy Policy explains how CPMC, LLC (“we,” “us,” or “our”), operating the TransactionCam platform at transactioncam.com, collects, uses, stores, shares, and protects information when you access or use our services.

TransactionCam is a hosted service that bridges Clover® point-of-sale transaction data to UniFi® Protect surveillance cameras. We are committed to protecting your privacy and handling your data with transparency and care.

By creating an account or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of it, please do not use the Service.

Important: TransactionCam is not affiliated with, endorsed by, or officially connected to Clover®, Fiserv®, Ubiquiti®, or UniFi®. All trademarks belong to their respective owners.

2. Who We Are

Legal entityCPMC, LLC
Contact emailsupport@transactioncam.com
Mailing address411 Lakewood Circle, Unit C-108, Colorado Springs, CO 80910, USA
Governing lawState of Colorado, United States

For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, CPMC, LLC is the data controller of the personal data described in this policy.

3. What Data We Collect

We collect only the data necessary to operate the Service. We organize it into the following categories:

3.1 Account Information (provided by you)

3.2 Third-Party Connection Credentials (provided by you)

3.3 Transaction Data (received from Clover)

When a sale or refund occurs on your Clover device, Clover sends TransactionCam a webhook notification. We then read the order and payment details (line items, amounts, tender type, timestamps) from Clover’s API using your authorized token. This data is used solely to format a transaction record and deliver it to your designated UniFi Protect camera(s). We do not use transaction data for analytics, advertising, profiling, or any purpose other than operating the delivery pipeline.

Transaction records are kept temporarily for retry tracking and audit purposes (see Section 6 for retention periods).

3.4 Technical & Usage Data (collected automatically)

3.5 Data We Do Not Collect

We do not collect, store, or process:

4. How We Use Your Data

We use the data we collect for the following purposes and no others:

PurposeLegal basis (GDPR)
Provide and operate the Service (deliver transactions to cameras, manage your account, process webhooks)Performance of contract (Art. 6(1)(b))
Authenticate your identity and manage sessionsPerformance of contract
Process payments through StripePerformance of contract
Send transactional emails (team invitations, password resets, connection health alerts, delivery failure alerts)Performance of contract / Legitimate interest
Maintain security, prevent fraud, and detect abuseLegitimate interest (Art. 6(1)(f))
Debug errors and maintain system reliabilityLegitimate interest
Comply with legal obligations (e.g., tax records, lawful data requests)Legal obligation (Art. 6(1)(c))

We do not sell, rent, lease, or trade your personal data. We do not use your data for advertising, profiling, or automated decision-making.

5. How We Protect Your Data

We take the security of your data seriously and implement multiple layers of protection:

6. Data Retention

We retain your data only for as long as it is needed for the purposes described in this policy:

Data typeRetention period
Account information (name, email, organization)While your account is active, plus 30 days after you request deletion (to resolve any pending disputes or billing matters)
Clover tokens & Protect API keysDeleted immediately when the connection is disconnected or the account is closed
Transaction and delivery records90 days from the date of creation (used for retry tracking and audit). The permanent record of each transaction is the overlay on your UniFi Protect footage, which resides on your own hardware.
Bridge enrollment key hashesDeleted when the bridge agent is revoked or hard-deleted, or when the account is closed
Server and application logs30 days, then automatically purged
Database backups30 days (rolling nightly backups)

When data reaches the end of its retention period, it is permanently deleted or anonymized. Encrypted credentials are securely wiped by deleting the ciphertext — without the encryption key, the deleted data is unrecoverable.

7. Third-Party Service Providers (Sub-Processors)

We share data with a limited number of trusted third-party service providers, solely to operate the Service:

ProviderPurposeData sharedLocation
Stripe, Inc.Payment processing for subscriptionsYour email, name, and payment details (handled directly by Stripe — we do not see or store full card numbers)United States
Vultr / The Constant Company, LLCInfrastructure hosting (virtual private server)All data stored by the Service resides on this infrastructureUnited States
Clover / Fiserv, Inc.POS data source (you authorize this connection)OAuth tokens (encrypted), order/payment data retrieved on your behalfUnited States

Each sub-processor is bound by their own privacy policies and, where applicable, data processing agreements. We do not share data with any other third parties, and we do not sell data to anyone.

8. Your Rights

8.1 Rights for All Users

Regardless of your location, you have the right to:

8.2 Additional Rights Under the GDPR (EEA & UK Residents)

If you are located in the European Economic Area (EEA) or the United Kingdom, the General Data Protection Regulation (GDPR / UK GDPR) grants you additional rights:

International data transfers: your data is stored and processed in the United States. By using the Service, you acknowledge that your data will be transferred to the United States. We rely on the performance-of-contract derogation under Art. 49(1)(b) GDPR for necessary transfers, and we implement the security safeguards described in Section 5.

8.3 Additional Rights Under the CCPA/CPRA (California Residents)

If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) grant you additional rights:

Categories of personal information collected (using CCPA categories): identifiers (name, email, IP address); commercial information (subscription plan); internet activity (server logs); and professional information (organization name). We do not collect sensitive personal information as defined by the CPRA.

To exercise any of these rights, contact us at support@transactioncam.com. We will respond within the timeframes required by applicable law (generally 30 days for GDPR, 45 days for CCPA/CPRA).

9. Cookies and Tracking

TransactionCam uses only essential, first-party cookies required for the Service to function:

We do not use:

Because we use only strictly necessary cookies, no cookie consent banner is required under the ePrivacy Directive. You can still block cookies in your browser settings, but doing so will prevent you from logging in.

10. Children’s Privacy

The Service is intended for business use and is not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If we learn that we have inadvertently collected data from a person under 18, we will delete it promptly. If you believe a minor has provided us with personal data, please contact us at support@transactioncam.com.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

Your continued use of the Service after the updated policy takes effect constitutes acceptance of the revised policy.

12. How to Contact Us

If you have any questions about this Privacy Policy, wish to exercise your data rights, or have a privacy concern, please contact us:

Emailsupport@transactioncam.com
Mailing addressCPMC, LLC
411 Lakewood Circle, Unit C-108
Colorado Springs, CO 80910
United States

We aim to respond to all privacy-related inquiries within 7 business days.