Legal

Privacy Policy.

v1.5.2Effective 2026-08-25 · Last updated 2026-08-21Puff Geeks LLC · support@puffgeeks.com

1. Introduction & Scope

This Privacy Policy describes how Puff Geeks LLC ("Puff Geeks," "we," "us," or "our") collects, uses, stores, and protects information when you use the Puff Geeks mobile application, our vending kiosks, our operator web dashboard, and any related services (collectively, the "Services"). By creating an account, completing a purchase at a Puff Geeks kiosk, or otherwise using the Services, you acknowledge the practices described in this Policy. If you do not agree with this Policy, please do not use the Services. This Policy applies to consumers, kiosk purchasers (including guests without accounts), and business users (operators and their authorized employees, including field staff who restock machines).

2. Information We Collect — Account Data

When you create an account we collect: your email address, a display name you choose, and a password (stored only as a salted one-way bcrypt hash — we cannot read your password and never store it in plain text). For business accounts (operators and employees), we additionally record your role, your team membership (which operator organization you belong to), and the specific machines you have been granted access to. Operators may also configure fleet-wide restocking preferences (for example, whether our systems should recommend stocking machines to full capacity or to a data-driven forecast) — this is a business configuration setting, not personal data about you. If you request a password reset, we generate a short-lived, single-use reset token tied to your account.

3. Information We Collect — Purchase & Transaction Data

When you buy from a Puff Geeks kiosk we record the transaction: the machine, the items and quantities, prices, tax, discounts applied, the transaction outcome (completed, refunded, failed, etc.), and timestamps. If you are signed in to the app when purchasing (or scan a receipt QR code to claim loyalty points), the transaction is linked to your account so you can view your purchase history. Guest kiosk purchases are not linked to any personal identity. BATTERY RENTALS: renting a battery pack creates the same kind of record — the machine, the pack, the plan you chose, when it was taken out, when it came back, and the resulting charges — linked to your account when you are signed in. The commercial terms of a rental, including any hold or charge placed on your card (our terminals do both — see the Terms of Service, Section 4) and what happens if a pack is not returned, are in the Terms of Service and are shown to you at the machine before you agree to a rental; this Policy covers only what data those events record. IMPORTANT — payment cards: card payments are processed by our third-party payment terminal provider. Your full card number, PIN, and card credentials are handled exclusively by that provider on certified payment hardware. Puff Geeks never receives, stores, or has access to your full card number. SAVED CARDS: if you choose to save a card for future purchases or rentals, the card itself is vaulted by our payment processor, not by us. What we store is a reference to it — an opaque processor token, the processor's customer identifier, and the display details needed to show you which card you picked (brand, last four digits, and expiry month/year). That reference cannot be used to reconstruct your card number and is usable only through our processor, against your own account. You can list and remove your saved cards at any time from your account; removing one deletes our stored reference to it.

4. Information We Collect — Age Verification

Certain products are restricted by law to purchasers 21 years of age or older. Before dispensing an age-restricted product, the kiosk requires identity/age verification through a verification provider. We store only the RESULT of that check — pass or fail, the verification method, and a timestamp — for legal compliance and audit purposes. We do not retain images of your identity document in our systems. We do not sell age-restricted products to anyone who cannot be verified as 21 or older.

5. Information We Collect — Loyalty Program (Puff Points, Reserve Tokens & Pro)

If you participate in Puff Points, we maintain your points balance and a ledger of every points transaction (earnings from purchases, redemptions, bonuses, and expirations) with timestamps and the reason for each entry. The program also includes reservation tokens (reserve tokens and Pro tokens); for these we maintain the same kind of auditable ledger — how each token was earned (for example, completing an optional rewarded advertisement, reaching a purchase milestone, a Pro subscription's recurring grant, or an individual purchase) and how each was spent or refunded. To operate purchase milestones we keep a running count of units you have purchased. If you subscribe to Pro, we store your subscription status, start date, and next token-grant date, and our payment provider processes the subscription charge (we never see your card number — Section 3). If a reservation you hold is ever released to accommodate a Pro reservation, that event, your automatic refund, and your make-good credit are recorded on your reservation and shown to you in the app — nothing about that process is silent. These ledgers exist so your balances are always auditable and disputes can be resolved. Points and tokens are promotional program credits, not money, and have no cash value. Redemption and reservation codes you generate are stored until used or expired.

6. Information We Collect — Support & Communications

When you contact support we collect the content of your ticket (subject, message, category), any machine or transaction you reference, your account identity (or the contact email you provide as a guest), and the conversation history on that ticket. We use this solely to resolve your issue and to maintain a record of the resolution. When you open a ticket you choose which desk it goes to: a ticket about a specific machine is routed to the operator who runs that machine (and the employees they authorized), while a ticket about the platform itself goes only to Puff Geeks. That choice controls who can read it, so a platform ticket is never visible to any operator. NOTIFICATIONS: we send service messages about things you asked us to watch — for example a reservation about to expire, a rental you have open, or an account or security event. Depending on the channel you enable, these go by email, by SMS to a phone number you provide, or as a push notification. To deliver push we store the notification token your device issues, one per device you sign in on, and we delete a token when it stops being valid or when you sign that device out. SMS is delivered by our messaging provider and standard carrier message and data rates may apply. You control channels per event type in your notification settings, and you can turn any of them off; we will still show the message in the app, and we may still contact you by email about security or legal matters affecting your account. We do not use these channels for marketing you have not asked for.

7. Information We Collect — Technical & Security Data

Like virtually all online services, our servers process technical data needed to operate securely: IP addresses (used for abuse prevention and rate limiting), request timestamps, and security-relevant events (e.g., failed login attempts). Vending machines send us operational telemetry — machine status, software versions, inventory levels, and error reports. Machine telemetry describes the MACHINE, not you; it is not linked to consumer identities. Device permissions the app may request: (a) Camera — for CONSUMERS, the camera is used only to scan QR codes (receipt claims and pickup codes); scanning happens on your device and no photos or video are transmitted to or stored by us. BUSINESS USERS (operators and their employees) have one additional, deliberate camera feature: an optional 3D machine scan, in which you walk around one of your own vending machines and the device captures photos and LiDAR depth to reconstruct a 3D model of that machine. In that flow: the reconstruction runs entirely on your device; the captured photographs are used only as reconstruction input and are deleted from the device when the run finishes or fails; the photographs themselves are never transmitted to us; and only the resulting 3D model file is uploaded, where it is visible to your own fleet and to no one else (see Section 8). This feature is never used on the consumer side and is never triggered without a business user starting a scan; (b) Location — used ONLY on your device to show and sort vending machines near you; your location is never transmitted to our servers, never stored, and the app works without it (machines are simply listed unsorted). This on-device-only behavior applies to the consumer-facing "nearby machines" feature. Employees and operators using the fleet route-planning tools described in Section 8 have a separately disclosed location practice. Business users may additionally choose product photos from their device's gallery to publish to their machine catalog; that is a deliberate content upload, not personal data collection.

8. Information We Collect — Fleet Route Planning & Field Operations (Employees & Operators)

This section applies only to employee and operator accounts using our fleet-management tools — it does not apply to consumer accounts. To help field staff plan efficient restocking routes, our systems analyze existing purchase and inventory data (Section 3) at the level of individual machines and product slots — never at the level of an individual consumer — to estimate how quickly each product sells (including how demand shifts by day of the week), rank which machines most urgently need restocking, forecast expected demand, recommend product placement, and flag machines whose sales pattern suggests a mechanical fault (for example, stock that stops moving when it normally would sell steadily). When an employee requests a route plan, our systems use each machine's registered location plus, only if the employee chooses to tap "Start from my location," that employee's current device location; if provided, that location is used solely to calculate that day's route and is not stored as a location history. When an employee checks in or out at a machine to log a restocking visit, we record the machine, the employee's account, and the start and end time of that visit; this creates an auditable service record and helps us estimate future visit durations more accurately — it is a series of discrete, employee-initiated timestamps, not continuous location tracking. Route Sessions (live tracking): separately, and only after an employee has been shown an in-app disclosure and given affirmative one-time consent, an employee may start a "route session" bound to a specific van/run for the day — either by selecting it themselves or by having their operator assign it. While a route session is ACTIVE, the app periodically transmits that employee's device location to our servers, so their operator can see live progress on the fleet map and so we can compare a planned route against what was actually driven to improve future route plans. This tracking is strictly scoped to the session: it starts only when the employee taps "Start Route," and it stops the moment they tap "End Route" or after a period of inactivity causes the session to time out automatically — it is never active in the background outside an ACTIVE session, and an employee may withdraw consent at any time, which prevents any future session from starting. To display fleet maps and calculate driving routes, machine coordinates (and, when provided, an employee's current or route-session location) are sent to a map-tile provider and a road-routing service on our behalf, solely to render map imagery or compute a route; these providers do not receive your name, email address, or other account identifiers. When an employee taps "Navigate" to a machine, the app opens that employee's chosen third-party navigation app (Google Maps or Waze, based on a preference they set on their own device) and shares that machine's location with it; that hand-off happens only when the employee initiates it, and use of the navigation app itself is governed by that app's own privacy policy, not ours. Field-visit and route-session data described above may also feed Cross-Fleet Aggregate Benchmarking, a platform-wide estimate-improvement system for operators; this never exposes your specific routes, times, or identity — see the Terms of Service, Section 11, for the full disclosure. MACHINE 3D SCANS: a business user may optionally scan one of their own machines with a compatible device to produce a 3D model used for AR placement previews and for the operator console's machine view. The capture photographs are reconstruction input only: reconstruction happens on the device, and those photographs are deleted from the device when the run ends and are never sent to us. What we receive and store is the finished 3D model file, plus the machine it belongs to, who uploaded it, and processing status. A scan is scoped to the uploading user's fleet — every teammate on that fleet can see and download it, and no one outside it can, including other operators. A scan is a picture of equipment, not of people; do not deliberately capture bystanders, staff, or customer-identifying surroundings, and note that we cannot detect it if you do. Operators may delete a scan at any time from the console, and scans are also covered by the retention schedule in Section 13.

9. What We Do NOT Collect

We do not collect or store on our servers: full payment card numbers or card credentials (a saved card is held by our processor and stored here only as an opaque token plus brand, last four digits, and expiry — see Section 3); images of identity documents; a consumer's device location (location, if you grant it in the consumer app, is used only on your device to sort nearby machines — see Section 7 — and never reaches our servers); your contacts, your files, or your photo library. No consumer feature sends us photographs at all. The only imagery we ever receive is content a BUSINESS user deliberately uploads: product photos they publish to their own machine catalog, and the machine 3D scan in Sections 7 and 8 — where the capture photographs are deleted on the device and only the reconstructed model reaches us. We also do not use third-party advertising trackers or sell personal information to data brokers. We do not track employee or driver location outside an ACTIVE, employee-initiated route session — see Section 8 for exactly when tracking starts, when it stops, and the consent required before it can start at all. Advertisements shown on kiosks and in the app are served by us based on placement context (which screen, which machine), never on personal profiles.

10. How We Use Information

We use the information described above to: (a) operate the Services — process purchases, dispense products, maintain loyalty balances, honor reservations; (b) comply with law — age-verification records, tax records, and financial audit trails; (c) secure the platform — prevent fraud, abuse, account takeover, and unauthorized access; (d) support you — resolve tickets, process refunds; (e) operate machine fleets — alert operators to low stock, malfunctions, and offline machines; and (f) plan and optimize fleet operations — using aggregated machine and product sales history to rank which machines most need restocking, forecast expected demand, recommend product placement, detect machines whose sales pattern suggests a mechanical fault, generate efficient driving routes for field staff, and — during an ACTIVE route session an employee has started — show that employee's operator live progress on the day's route and measure actual travel time against the planned route to improve future route plans, as described in Section 8. We do not use your personal information for third-party marketing, and we do not sell it.

11. How Information Is Shared

We share information only as needed to operate: (a) Payment processing — transaction amounts are shared with our payment terminal provider to authorize and capture payments; (b) Age verification — verification requests are processed by our verification provider at the moment of purchase; (c) Machine operators — the operator whose machine you purchased from (and employees they have specifically authorized) can see sales and inventory data for THEIR machines, support tickets referencing their machines, and aggregate reports. Operators do not see your password, your full purchase history across other operators' machines, or your loyalty ledger; (d) Mapping, routing, and navigation — to render fleet maps and calculate driving routes, machine coordinates (and, when an employee opts in, that employee's current or active route-session location) are shared with our map-tile and road-routing service providers; when an employee taps "Navigate," a machine's location is shared with that employee's chosen navigation app (Google Maps or Waze) to provide turn-by-turn directions — see Section 8; (e) Live route-session location — while a route session is ACTIVE, that employee's location is shared only with the operator whose team they belong to (never with other operators, and never with third parties beyond the map-tile provider in (d)), so that operator can see live progress on their own fleet map; (f) Card vaulting and payouts — if you save a card, our payment processor stores the card and returns us a token; if you are an operator or a venue partner receiving money from us, the payment or payout provider we use to send it receives the details needed to complete that transfer; (g) Message delivery — the email, SMS, and push providers described in Section 6 receive the message and the address, number, or device token needed to deliver it, and nothing further; (h) Legal requirements — we may disclose information when required by law, subpoena, or to protect the rights, safety, or property of Puff Geeks, our users, or the public. We require any service provider we use to protect your information consistent with this Policy.

12. Access Controls Inside Our Organization

Access to data within the Services is governed by role-based permissions and row-level security: every account (customer, employee, operator, administrator) can access only the data rows its role and grants permit. Customers can access only their own purchase history, tickets, points, and reservations. Employees can access only the specific machines their operator has granted them. Operators can access only machines, sales, ads, and tickets belonging to their own fleet. These controls are enforced server-side on every request — not merely hidden in the user interface. Fleet route plans and field-visit records are scoped the same way — an employee's visit records and route history are visible only within their own operator's fleet. Route-session location is scoped identically: visible only to the driving employee and their own operator, never to other operators or other employees.

13. Data Retention

We retain account data while your account is active. Transaction, tax, and age-verification result records are retained as required by applicable financial and regulatory retention laws, even after account deletion, and are then deleted or irreversibly anonymized. Loyalty and token ledgers are retained while your account is active to keep balances auditable. Support tickets are retained while relevant to service quality and legal defense. Beyond those legally-driven categories, our systems run an AUTOMATED retention schedule that periodically deletes aged-out operational data: machine inventory-change journal entries are deleted after roughly 13 months, field-visit check-in/check-out records and route-session start/end/van summaries after 12 months, raw route-session GPS location pings after 30 days (far shorter — once a session ends, its summary record is what we keep; the underlying breadcrumb trail is not needed long-term), resolved machine-fault alerts after 6 months, settled loyalty claim and discount codes after 90 days, and route-planning decision records after 90 days. A saved-card reference is kept until you remove that card or delete your account, whichever comes first. A push notification token is deleted when the device signs out or the token stops being accepted by the push service, and the log we keep of which notifications were sent (used to enforce the per-event cooldown so we do not message you repeatedly about the same thing) is deleted on the same schedule as other operational records. A machine 3D scan is kept while the machine it belongs to exists, and is deleted when an operator deletes the scan or the machine, or when the operator account is closed. We also keep a persisted security-event log (for example: failed sign-in attempts recorded against the targeted account, account deletions, machine credential rotations, and team-membership changes) used for abuse prevention and incident investigation; those entries are automatically deleted after 12 months, and each automated purge is itself recorded. When retention is no longer required, data is deleted or anonymized.

14. Security Measures

We protect information with industry-standard measures aligned to OWASP guidance, including: passwords stored as salted bcrypt hashes; authenticated sessions via signed, expiring tokens; encrypted transport (HTTPS/TLS) in production; strict server-side input validation on every request; tiered rate limiting to block brute-force and abuse; per-device credentials for vending machines with rotation support; and role- and row-level access controls on all data. No system can be guaranteed 100% secure; if we determine a breach affects your personal information, we will notify you as required by applicable law.

15. Your Rights & Choices

Subject to applicable law (including, where applicable, the California Consumer Privacy Act and similar state laws), you may: request access to the personal information we hold about you; request correction of inaccurate information; request deletion of your account and associated personal information (subject to the legal retention obligations in Section 13); and receive a copy of your information in a portable format. Access, portability, and deletion are available as SELF-SERVICE from your signed-in account: you can download a machine-readable export of your purchase history, loyalty ledger, support tickets, and reservations, and you can permanently delete your account (password confirmation required; personal identifiers are removed immediately and legally retained sales records are anonymized). Additional records tied to a staff account, including the fleet route-planning, field-visit, and route-session location records described in Section 8, can be requested using the contact information in Section 19. An employee may also withdraw route-session location consent at any time from within the app, which stops any future session from starting; this does not delete past session records, which remain subject to the retention windows in Section 13 and can be deleted early on request. We will verify your identity before acting on any request and respond within the timeframe required by law. We do not discriminate against users who exercise privacy rights.

16. Children's & Minors' Privacy

The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. Age-restricted products are sold only to verified purchasers 21 or older. If you believe a minor has provided us personal information, contact us and we will delete it.

17. State & Regional Disclosures

California residents: we do not "sell" or "share" personal information as those terms are defined by the CCPA/CPRA, and we collect only the categories described in Sections 2–8 for the purposes in Section 10. Residents of other U.S. states with comprehensive privacy laws have analogous rights to those in Section 15. If the Services become available to users in other jurisdictions (e.g., the EU/UK), we will process personal data under the lawful bases and rights frameworks those laws require.

18. Changes to This Policy

We may update this Policy as the Services evolve or as legal requirements change. Material changes will be indicated by a new version number and effective date at the top of this Policy, and the app will present the updated Policy. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.

19. Contact Us

Questions, requests, or complaints about privacy can be directed to: Puff Geeks LLC — Privacy, email: support@puffgeeks.com. Please include enough detail for us to locate your account and understand your request. If you are unsatisfied with our response, you may have the right to lodge a complaint with your state attorney general or applicable supervisory authority.