Privacy Policy
Last updated September 8, 2026
Suma Systems (“Suma”, “we”) makes point-of-sale software for stores: the Suma Store Manager and Self-checkout apps for Windows, the seller portal at sellerportal.sumasystems.com and the vendor portal at vendorportal.sumasystems.com. This policy explains what data those products handle, where it lives, and the choices you have. The short version: your store's data lives on your own PC, we keep only what is needed to run your account and sync, and we never sell data.
1. Data that stays on your computer
The Suma Store Manager is offline-first. Products, prices, stock levels, sales, receipts, customer accounts, cashier PINs, vendor lists, buying lists and purchase orders are stored in a database on the PC where the software is installed. Card details never pass through the software; your payment reader talks to your processor directly and Suma stores only a safe reference.
Email account credentials you enter in the app (an SMTP password, a Gmail App Password, or a Google sign-in token) are encrypted on that PC with the Windows credential store and are never sent to Suma’s servers.
2. Data we hold for your account
When you create a Suma account we store:
- Your email address and a hashed password (via Supabase Auth).
- Your store name and subscription status. Payments are handled by Stripe; we receive a customer reference, not your card number.
- An encrypted sync copy of your store data, if you enable cloud backup, so you can restore it or share it between registers.
- Purchase orders you choose to send to a vendor, so the vendor can view them in the vendor portal.
- Products you add to the shared vendor catalog (vendor name, product names, barcodes, case sizes and list prices). Store-private information such as negotiated prices and account numbers is never shared with other stores.
3. Gmail sign-in and Google user data
The Store Manager can send purchase-order emails to your vendors from your own Gmail account. If you choose “Sign in with Google” in Settings → Order emails, the app asks Google for:
https://www.googleapis.com/auth/gmail.send— the narrowest Gmail permission that allows sending. It is used solely to call the Gmail APIusers.messages.sendfor the purchase-order emails you compose and send in the app. Suma does not read, store, search, modify or delete any messages in your mailbox and requests no other Gmail permission.openidandemail— used to learn the address of the account you signed in with, so it can be shown in Settings and used as the sender address.
The OAuth refresh token and access token are stored only on your PC, encrypted with the Windows credential store. They are transmitted only to Google to send mail, and are never sent to, logged by or accessible to Suma Systems. Signing in is optional; you can use an App Password or any other SMTP provider instead.
Suma’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the email-sending feature described here, is never used for advertising, is never sold, and is never transferred to humans or third parties except as required by law or with your explicit consent.
You can disconnect Gmail at any time by switching back to manual SMTP in Settings, and revoke Suma’s access at myaccount.google.com/permissions. Revoking removes the stored token’s validity immediately.
4. How we use data
- To provide, sync and back up the software you use.
- To bill your subscription and send account emails (confirmation, receipts, password reset).
- To let vendors you order from see the orders you sent them.
- To answer support requests you send us.
6. Security
Data in transit is encrypted with TLS. Cloud data is protected by row-level security so each store and vendor can reach only its own rows. Credentials stored on your PC are encrypted with the operating system’s credential store. Cashier PINs are stored as salted scrypt hashes.
7. Retention and deletion
Local data stays on your PC until you uninstall or delete it. Cloud account data is kept while your account exists. Email [email protected] from the account address to delete your account and cloud data; we complete deletion within 30 days, except for billing records we must retain by law.
8. Children
Suma is business software and is not directed at children under 13. We do not knowingly collect data from children.
9. Changes
We will post any changes to this policy on this page and update the date above. Material changes will also be announced by email to account holders.
10. Contact
Suma Systems · [email protected]
Questions about this document: [email protected]