// legal

Privacy Policy

Last updated: July 22, 2026

Introduction

At Bitta Apps, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit our website, use our services, or activate and use our Microsoft Dynamics 365 Business Central applications.

Information we collect

Personal information

We may collect personal information that you provide to us such as:

  • Name and contact information
  • Billing information and payment details
  • Company information
  • User credentials
  • Communication preferences

Usage information

We may also collect information about how you use our services:

  • Log and usage data
  • Device information
  • Location information
  • Cookie data

How we use your information

We use the information we collect to:

  • Provide and maintain our services
  • Process your transactions
  • Send you marketing communications (with your consent)
  • Improve our services
  • Comply with legal obligations

Information sharing

We may share your information with:

  • Service providers and business partners
  • Legal authorities when required by law
  • Other parties with your consent

Business Central applications

Bitta Apps publishes applications for Microsoft Dynamics 365 Business Central, including Universal Search and Bitta Retail POS. This section describes the application data flows we operate. Features that connect to an optional provider are used only when a customer chooses and configures that provider.

When an administrator uses the license and entitlement service, after following the consent flow presented by the application, the application may send the following information to Bitta Apps:

  • Microsoft Entra tenant ID and, when supplied, tenant domain
  • Environment identifier or name
  • Business Central company system ID and company name
  • Contact email
  • Country code
  • Business Central platform version
  • Application version
  • Application identifier, plan, term, and licensed capacity
  • License, activation, and broker-protocol identifiers needed to issue, refresh, verify, or deactivate an entitlement

We use this information only to:

  • Issue, verify, refresh, or deactivate the application license
  • Protect the service against unauthorized activation, replay, and tampering
  • Provide updates and support requested by the customer

License and entitlement records are stored in Supabase in the United States. We retain them while the entitlement is active and afterward as reasonably necessary for security, dispute handling, accounting, legal compliance, and service recovery.

Payment integrations

Bitta Retail POS can use an external card terminal without a Bitta Apps connection, communicate directly with a processor, or use a Bitta Apps broker for an integration such as Square. Depending on the configured path, the processor or broker may receive the tenant, environment, and company binding; merchant connection, location, and device identifiers; amount and currency; POS transaction reference; idempotency and operation identifiers; payment or refund status; and provider checkout, payment, or refund identifiers.

For a brokered OAuth integration, provider access and refresh tokens are encrypted at rest and used only to perform the merchant operations the customer authorizes. The Bitta Apps broker does not request or store the full card number or card security code; cardholder entry and card credentials are handled by the selected terminal and payment provider under that provider's terms. Payment providers retain and use information according to the customer's merchant agreement and their own privacy notices.

Printing integrations

Browser, WebUSB, and local-network printing can remain between the customer's browser, Business Central environment, and local hardware. If the customer configures a cloud printing service such as PrintNode, the service receives the receipt, label, kitchen ticket, or drawer-command payload and routing information needed to complete the print job. Bitta Apps does not enable a cloud print path on the customer's behalf.

Operational telemetry

Our Business Central applications may send operational events to Microsoft Application Insights. These events can include the application and Business Central version, environment context, feature or operation name, status, timing, diagnostic error data, and pseudonymous operational identifiers. We use telemetry for security, reliability, troubleshooting, and product improvement. We do not intentionally send complete business documents, receipt bodies, or payment-card credentials as telemetry.

Service providers and transfers

We use service providers such as Microsoft Azure, Supabase, and Vercel to operate the website, licensing, broker, security, and telemetry services. Optional payment and printing providers are selected by the customer. These providers may process information in the United States or other locations where they operate, subject to their contracts, privacy terms, and applicable law.

Data security

We implement appropriate technical and organizational measures to protect your personal information. However, no method of transmission over the Internet is 100% secure.

Your rights

You have the right to:

  • Access your personal information
  • Correct inaccurate information
  • Request deletion of your information
  • Object to processing of your information
  • Withdraw consent

Contact us

If you have questions about this Privacy Policy, please contact us at [email protected].