Last updated September 18, 2026
Privacy Policy
SellWright POS (“the Service”) is point-of-sale and inventory software for eyewear retailers. It is operated by MRX Software LLC; throughout this policy “we”, “us” and “our” mean MRX Software LLC and nobody else. This policy explains what personal data passes through the website at https://sellwrightpos.com and the Service, why, who sees it, and what choices each kind of person has. It uses the same names for people as our Terms of Use.
Who this policy is about
- Visitors — anyone who browses the website or requests a demo.
- Customers — the retail businesses that subscribe to the Service. A Customer's owners, managers and associates who sign in are its Authorized Users.
- Shoppers — the people who buy from a Customer's stores: the people a store calls its clients or customers, whose records the store keeps in the Service.
Where a paragraph below says “you”, it is talking to the group named in that paragraph's heading or opening words. Where a rule applies to everyone, it says so.
Two roles we play
We handle personal data in two different capacities, and the difference matters for your rights:
- Data we control. Information about Visitors, and the account details and activity of Authorized Users. We decide how this data is used, and this policy is the complete description of that.
- Data we process for Customers. Each Customer enters and owns the records of its own Shoppers. For that data the Customer is the controller: it decides what to collect and why, and we act only on its instructions under the Terms of Use. If you are a Shopper with a question about how a particular store uses your information, that store is the right first contact; we help stores answer such requests.
What we collect
About Visitors
- If you request a demo: your name, work email, store name and anything you write in the message. The website emails this to our sales inbox; it does not store it in a database.
- Standard server logs for every request: IP address, browser type, pages requested and timestamps, used for security and to keep the website running.
About Authorized Users
- Name, work email, role, the stores you are assigned to, and a hashed password and PIN.
- An activity log of significant actions taken under your account (sales, returns, changes to Shopper records, exports, deletions, reviews). This exists so the Customer that employs you can audit its own operations; we read it only for support or security.
- Session cookies (see “Cookies and device storage”), your active store, and which associate is working a shared register after a PIN switch.
About Shoppers (entered by a Customer's staff)
- Contact and profile details: name, email, phone, postal address, birth month and day, household links, free-text notes.
- Sales, layaways, returns, gift cards, loyalty points, repair and lab-order records, including the lens measurements a lab needs to make a pair of glasses. The Service is a retail system, not a medical record: it does not store exams, diagnoses or insurance information.
- Marketing-consent history: every opt-in or opt-out for email and SMS, with the date, the source, the staff member who recorded it and, when consent is captured at the register, the IP address and device. This history is append-only so a store can prove what a Shopper agreed to.
- Photos or scans a store attaches to a lab order or repair.
Payments (Shoppers and Customers)
Card payments are processed by Stripe on the Customer's own Stripe account. We receive and keep the transaction reference, amount, card brand and last four digits so receipts and refunds work. Full card numbers are never sent to or stored on our servers.
Supplier invoices (Customers)
A Customer may upload supplier invoices (images or PDFs) to have their line items read automatically. Those files contain the supplier's and the store's business information, not Shopper records, and are stored under the uploading Customer's private storage area.
How we use data
- To run the Service for Customers: ring up sales, track inventory and lab orders, print and email receipts.
- To deliver messages a Customer sends to its Shoppers: order-status notifications and, only to Shoppers who opted in, marketing campaigns. The Customer chooses the recipients and the content; we provide the delivery.
- To keep every Customer's data separate and secure, detect abuse and investigate incidents.
- To respond to demo requests and support questions.
- To meter usage of paid features (for example the number of invoice pages read by AI).
We do not sell personal data, we do not use Shopper records for our own marketing, and we never contact a Customer's Shoppers on our own behalf.
Who else receives data
We use a small number of service providers. Each processes data only to perform its function for us, under a contract that forbids any other use:
| Provider | Purpose | What they receive |
|---|---|---|
| Stripe | Card payments at the register and refunds | Payment amounts, card-present transaction references, the last four digits and brand of a card. Full card numbers never reach our servers. |
| Resend | Transactional and marketing email | Recipient email address, message content (receipts, order-status updates, campaigns), delivery and engagement events. |
| Twilio | Transactional and marketing SMS | Recipient phone number, message content, delivery status, and STOP/START replies. |
| Anthropic | AI-assisted supplier invoice reading | Images or PDFs of supplier invoices a store uploads, which may contain the supplier’s and the store’s business details. Never customer records. |
Beyond those providers, we disclose personal data only to the Customer that owns it, when the law requires it, to protect the rights or safety of a person, or as part of a merger or sale of our business (in which case this policy continues to apply to the transferred data).
Marketing messages: a Shopper's choices
- Every marketing email a store sends through the Service includes an unsubscribe link and supports one-click unsubscribe. Opting out is recorded immediately and stops that store's future campaign emails to your address.
- Reply STOP to any text to opt out of both marketing and order-status texts from that store; reply START to opt back in. Marketing texts are held during a store's quiet hours.
- Receipts and order-status emails are transactional: they are sent to the address on file for the sale or order and do not depend on marketing consent.
- An opt-out applies to the store you opted out from, not to other stores that use the Service.
Cookies and device storage
- Session cookies (Authorized Users). They keep you signed in and remember your active store and, on a shared register, which associate is currently working it. They are HTTP-only and end on sign-out or after inactivity.
- No tracking (everyone). The website and the Service set no advertising or analytics cookies.
- Register devices store data locally (Customers). So that a register keeps working without an internet connection, the browser on that device holds a cached copy of the store's catalog, prices, Shopper search index and open lab orders, plus any sales or new Shoppers rung up while offline until they sync. This lives only in that browser's storage, is scoped to the signed-in store, and is removed when site data is cleared. A Customer should treat register devices as it treats any device holding business records.
- The light/dark theme preference is kept in the browser (everyone).
Security
Each Customer's data is isolated at the database level with row-level security, so one store's records are never visible to another store, and Authorized Users see only the stores they are assigned to. Passwords and PINs are stored hashed; each Customer's integration credentials (payments, messaging) are stored encrypted. Access to production systems is limited to the people who operate the Service. No system is perfectly secure. If we learn of a breach affecting personal data we will notify the affected Customer without undue delay so that it can notify its Shoppers as the law requires, and we will notify Visitors and Authorized Users directly where their own data is affected.
Retention and deletion
- Authorized User accounts and Shopper records are kept for as long as the Customer's account is active. A Customer may export its data and may delete or anonymize an individual Shopper at any time through the Service; sales and lab records are kept for accounting but stripped of personal details.
- Consent history is retained as long as needed to demonstrate compliance.
- Demo requests are kept in our sales inbox for as long as the conversation is active.
- Server logs are kept for a limited period for security purposes and then discarded.
- When a Customer closes its account, its data is deleted after a short grace period, except where we must keep records to meet legal obligations.
Your rights
Depending on where you live you may have the right to access, correct, export, restrict or delete personal data about you, and to object to certain processing. How to exercise them depends on who you are:
- Shoppers: contact the store you dealt with. Its staff can view, correct, export, delete or anonymize your profile from inside the Service. If the store does not respond, write to us and we will help.
- Authorized Users: your store's owner manages your account and can update or remove it. Write to us for anything the owner cannot do.
- Visitors: write to us to have a demo request or correspondence deleted.
Our address for all of these is privacy@sellwrightpos.com. We do not discriminate against anyone for exercising these rights.
Children
The website and the Service are for businesses and their staff, and we do not knowingly collect personal data from anyone under 16 as a Visitor or Authorized User. A store may, as controller, record a child as a Shopper on a parent's household account (for example a child's glasses); that record is the store's responsibility under this policy's “data we process for Customers” rules.
International transfers
The Service is hosted in the United States and our providers may process data there. If you use the website or the Service from elsewhere, your data will be transferred to and processed in the United States.
Changes to this policy
We will post any changes on this page and update the date at the top. For material changes we will also notify each Customer's account owners by email before the change takes effect; Customers are responsible for passing on to their Shoppers anything that affects them.
Contact
MRX Software LLC
privacy@sellwrightpos.com