Retail Relay Privacy Notice Version: 2026-08-02-private-test Updated: August 2, 2026 Status: Attended private-test notice This notice documents current product behavior for the attended, operator-controlled private test. It is not represented as a final public-launch privacy notice. Public contact channels, a documented retention schedule, launch jurisdictions, and any jurisdiction-specific supplements must be completed and reviewed before broader enrollment. Putnam Development Studios LLC provides a business-to-business operations service for Lightspeed Retail R-Series under the Retail Relay brand (collectively, “Retail Relay,” “we,” “us,” or “our”). This notice explains the information the current Service processes, why it is used, and the controls visible in the current implementation. Retail Relay is intended for business use. A customer organization controls the retail records, documents, prompts, and source-system information it supplies. Retail Relay separately determines how it handles account administration, security, billing, and legal-compliance records. This notice does not replace a customer’s own notices to its employees, contractors, customers, or other people whose information it submits. 1. Scope and current program This notice covers the retailrelayai.com website and the Retail Relay application. The current program is an attended private test on R-Series accounts owned and controlled by the operator. It does not describe a consumer point-of-sale service, advertising network, public mobile app, or general-purpose data broker. Lightspeed, Stripe, OpenAI, Supabase, Vercel, and any other linked service operate under their own terms and privacy notices. A customer-directed Lightspeed connection is a source and destination selected by the customer; it is not a general authorization for Retail Relay to obtain information from unrelated accounts. 2. Information the Service processes - Account and organization information, such as user ID, email address, display name, organization name, membership, role, and current Terms-acceptance evidence. - Connected R-Series information, including account and Shop identifiers, Items, ItemShops, inventory quantities, Vendors, purchase orders, sales and related records, synchronization checkpoints, source timestamps, and preserved source evidence needed to make results reproducible. - Prompts, questions, report parameters, uploaded procurement documents, document-derived evidence, corrections, product and Vendor bindings, recommendations, immutable plans, reviews, approvals, execution results, verification results, alerts, and audit records. - Billing metadata, including Stripe Customer, Subscription, Price and event identifiers; subscription status and lifecycle timestamps; billed connection count; calculated monthly amount; and reconciliation state. Retail Relay does not store raw payment-card or PaymentMethod payloads. - Technical and security information, such as authentication-session data, first-party cookies, request timing, browser user-agent information where recorded for legal assent, authorization failures, operational logs, rate-limit state, and security or reliability events. The current document workflow accepts one PDF, image, text file, or .eml email up to 4 MB. The file is used for bounded extraction. The application stores the resulting structured evidence and file digest for review; it is not designed as a general document-storage system. Customers must not submit payment-card data, government identifiers, health information, biometric data, children’s data, or other specially regulated information unless a later written agreement and product feature expressly support it. 3. Sources of information - The user or organization, including through signup, workspace administration, prompts, review forms, uploads, and approved operations. - Customer-authorized Lightspeed Retail R-Series accounts, using separately stored OAuth credentials for each exact connection. - Stripe, for signed billing and subscription events and hosted Checkout or Customer Portal activity. - The Service itself, when it derives calculations, logs audit evidence, verifies source results, or detects reliability and security conditions. 4. How information is used - Authenticate users, enforce organization and connection scope, administer workspaces, and record assent. - Synchronize exact R-Series records; answer questions; generate reports, calculations, alerts, and recommendations; and process customer-provided procurement documents. - Prepare, policy-check, queue, reconcile, verify, and audit only the narrow source operations separately enabled, reviewed, and approved through the Service. - Create and administer Stripe-hosted subscription billing, derive account quantity on the server, and reconcile signed billing events. - Secure, debug, maintain, and improve the customer-specific Service; investigate misuse; enforce agreements; and comply with legal obligations. Accepting a legal document never approves an inventory, purchase-order, reorder, transfer, or other source-system action. Operational authorization is handled through a separate exact-plan review and approval workflow. 5. AI processing Retail Relay sends selected prompts and bounded supporting context to OpenAI for retail planning and document evidence extraction. The current application sets the OpenAI API request option store to false for both workflows. That setting is not a promise of zero provider-side retention: provider security, abuse-monitoring, and legal processes may still apply under OpenAI’s business data terms and documented API data controls. Retail Relay does not use Customer Data to train a generalized model for other customers unless the customer separately and expressly opts in through a written or comparably clear agreement. Customer-submitted document text is treated as untrusted evidence and cannot select a tenant, enable a capability, or approve an operation. - OpenAI API data controls: OpenAI’s current endpoint-specific storage and training documentation. (https://platform.openai.com/docs/models/default-usage-policies-by-endpoint) - OpenAI privacy policy: OpenAI’s notice for its own processing activities. (https://openai.com/policies/privacy-policy/) 6. Disclosures and service providers Retail Relay discloses information only as needed to operate the Service, follow a customer’s connection instructions, protect users and the Service, complete a business transaction subject to appropriate safeguards, or comply with law. The current core service providers are Vercel for application hosting, Supabase for managed database and authentication services, OpenAI for AI model inference, and Stripe for hosted billing. The current list and service functions appear on the Subprocessor List. Retail Relay does not currently include an advertising SDK or behavioral-advertising analytics integration in the application. The Service does not sell payment-card data and does not receive raw card details from Stripe-hosted Checkout or the Customer Portal. 7. Cookies and similar storage The application uses Supabase-managed first-party authentication cookies to maintain and refresh the signed-in session. It also uses one first-party cookie named relay-active-organization to remember the exact organization selected by an authenticated user. That selector cookie is HTTP-only, SameSite=Lax, limited to the site path, Secure in production, and configured for up to one year. These cookies are used for authentication, tenant selection, and security rather than advertising. Blocking required session cookies can prevent sign-in or safe workspace selection. 8. Retention and deletion A final record-by-record retention schedule has not yet been approved or implemented, so this private-test notice does not promise a fixed deletion period. The Service currently retains information for as long as reasonably needed to provide and secure the private test, reconcile ambiguous source operations, preserve reproducible source evidence, meet billing or legal duties, and resolve disputes. Legal-acceptance evidence and operational audit records are designed to be append-only. Customers should keep their own source-system records and exports. Lightspeed remains the source of truth, and Retail Relay is not the customer’s sole record-retention or backup system. A reviewed retention schedule and deletion-request procedure are required before broader enrollment. 9. Security and operational controls The current design uses authenticated organization scoping, independent encrypted OAuth token sets for each R-Series connection, role checks, bounded typed operations, human review, immutable plan and approval evidence, kill switches, durable queues, exact read-back verification, and audit logging. Secrets and source credentials are excluded from model-visible output and ordinary logs. No internet-connected system can eliminate every risk. 10. Access, correction, and privacy requests An organization owner controls workspace membership and connected source accounts. During the attended private test, participants may make access, correction, export, restriction, objection, or deletion requests through the same direct operator channel used for enrollment. Requests may require identity and authority verification, and some billing, security, legal-acceptance, source-operation, and audit records may need to be preserved. A dedicated public privacy email is not yet configured. Broader enrollment must not begin until a durable public request channel and any required jurisdiction-specific rights process are published and tested. 11. Business users and children Retail Relay is offered for commercial and professional use, not personal, family, or household use. It is not directed to children, and customers must not submit children’s data to the current Service. 12. Changes and contact Retail Relay will identify a new version and updated date when this notice changes. Material changes that affect a customer’s contract or data-processing instructions may also require notice, an updated DPA, or renewed organization assent under the applicable agreement. The configured privacy, legal, and support emails appear at the end of this page when available. Until then, this page remains an attended-private-test disclosure and the operator’s established direct enrollment channel is the contact method for participants. Configured public contacts Legal: not configured Privacy: not configured Support: not configured