Deliiq Security & Data Practices

Version 2026-09-05

Deliiq is a service of Deliiq IQ Holdings LLC d/b/a Deliiq, a New York limited liability company.

This page describes how Deliiq handles store data today, in plain language. It only states practices that are actually in place. Where we do not have something, this page says so instead of implying it.

Your store's records are yours

The tenant owns its raw store records. Deliiq does not sell individual store records, and shared catalog suggestions and cross-tenant product intelligence are not active features. If we ever introduce them, they will require a separate notice and your opt-in first. This is the same commitment made in the Privacy Policy and the Terms of Service.

One store cannot read another store

Store data is isolated with database row-level security, so one store can never read another store's records. Privileged operations — the ones that change accounts, activation, or billing state — do not run from the browser; they go through audited server-side functions.

Encryption

Data is encrypted in transit over HTTPS. The site is served over HTTPS only, with HTTP Strict Transport Security enabled.

Sign-in

The free tracker signs you in with a one-time code sent to your email, so there is no password to reuse or leak. Sessions are held in your browser, and you can sign out to end them.

Card payments never touch Deliiq

Subscription payments are processed by Stripe, and Deliiq never stores card numbers. At the counter, card transactions run on your payment processor's certified terminal and its own connection. Deliiq does not take a cut of your card volume. Before any register goes live, staff confirm the exact processor, reader model, Datacap configuration, merchant approval, and certification.

Bank connections are read-only

If a paid owner connects a bank account, that connection runs through Plaid and imported bank transactions are stored as read-only review data. On disconnect, you choose whether to delete the imported bank data or keep it as read-only history. If Plaid reports that access was revoked or the connection was removed, Deliiq deletes stored Plaid tokens and, by default, deletes the imported Plaid data.

Who processes your data

Deliiq runs on a small set of providers, each receiving only what it needs: Supabase (database, sign-in, sync), Stripe (payments), Plaid (bank connection, only when an owner enables it), Resend (transactional email), Vercel (hosting), and our analytics provider. Deliiq is operated from the United States and data is processed on US-based infrastructure.

Backups and retention

Store data is backed up as part of running the service. We keep tenant data while the workspace is active and for up to 30 days after termination so you can export it, after which it is deleted on a rolling schedule. Deleted data may persist in encrypted backups for a limited period before those backups expire. Some records, such as billing records, are kept longer where the law requires it.

Getting your data out

You can export your data from the app at any time. To request a full export or permanent deletion, email us and we will complete it within 30 days.

Analytics

The Deliiq website loads a lightweight analytics script to understand aggregate page usage. We do not run ad trackers and we do not sell browsing data. The apps use cookies and on-device storage for sign-in sessions and offline data, not for advertising.

What we do not claim

Deliiq does not hold a SOC 2, ISO 27001, PCI DSS, or any other third-party security certification, and this page does not imply one. We would rather tell you that than let a badge suggest an audit that has not happened. If your insurer or landlord needs a written answer about a specific control, email us and we will answer it directly.

Reporting a security problem

If you find a vulnerability or think an account has been accessed without permission, email hello@deliiq.pro with the subject "Security". Please include what you found and how to reproduce it. Do not post it publicly before we have had a chance to fix it.

Contact

Security and data questions: hello@deliiq.pro · Contact form

All policies: Legal hub · Privacy · Terms · Data Use · Refunds · Warranty · AI Disclaimer · Accessibility · Contact