Skip to content

Security

What we store, what leaves the building and to whom, and what we never do. Every line is checked against the code it describes. Last checked 14 September 2026.

What we store

  • Social Security numbers collected for hiring and onboarding are encrypted in our database.
  • API keys you enter under Connections, for your POS and Metrc, are encrypted in our database and shown masked.
  • Account numbers for the vendors you pay by ACH are encrypted, and only their last four digits are ever displayed.
  • In Massachusetts, the log of who received each CORI report is kept for at least seven years, as 803 CMR 2.00 requires.
  • The time clock takes a photo with each punch, so a manager can see who clocked in. Only people who manage the schedule see the photos.
  • BudLogix runs on servers and a managed database at DigitalOcean. The search index behind the help assistant is a managed OpenSearch service at DigitalOcean.

What leaves the building, and to whom

  • OpenAI receives the text of invoices and manifests, to read their lines; SOP and regulation text, to draft SOPs and plans of correction and check coverage; questions you ask the help assistant; product, price and sales figures, for pricing and promotion suggestions; and a promotion's offer with the products it covers, to write promotion copy and draw a product image.
  • OpenAI also receives resumes, to fill in an application's fields. When a resume is screened against an opening, the applicant's name, email, phone and address are removed before the model reads it.
  • OpenAI receives customer review comments, to suggest a reply; a customer's text reply to a review request that is not a plain number, with emails and phone numbers masked, to read the rating it means; and the text of outgoing text messages, which it rewords for carrier rules. A message that contains a customer's first name is sent with it. Your customer list and customer phone numbers are never sent.
  • AWS Textract reads invoice files, in the us-east-1 region. AWS Rekognition finds the face in an applicant or employee profile photo so it can be cropped. Photos of the front and back of an ID are processed on our own servers and are not sent to AWS.
  • Bright Data carries our requests for the public online menus of the competitor stores you name, and for public brand catalogues searched for product pictures. Nothing about your store is sent.
  • Background checks, only after your organization accepts the terms and the applicant signs an authorization: Bright Data carries web searches with the applicant's full name, town and past employers, and PACER, the federal courts' case search, receives the applicant's name and your organization's own PACER login. Date of birth, address, email and phone are never searched.
  • Google: connecting your Business Profile lets BudLogix read and reply to your reviews, and read the listing's daily views, website clicks, direction requests and calls for the weekly brief. Connecting a mailbox for resumes or invoices requests Google's mail access, which BudLogix uses only to read messages.
  • BoldSign, our e-signature provider, receives the signer's name and email and the fields prefilled into CORI, I-9 and W-4 forms, including the Social Security number those forms require.
  • Twilio, EZ Texting, Vonage or Leafbuyer, whichever sends a text, receive the phone number and the message. Resend delivers our email, including the reference-check email that tells a reference the candidate's name and the employer they are asked about.
  • Brands you confirm in BudLogix for brands see, for their own brands only: units sold, their rank against other brands without any other brand's name, stock on hand (unless you switch it off), and sales dollars and budtenders' first names and last initials only if you switch them on. A brand that owes a budtender for a spiff sees that budtender's chosen payment handle until it is paid. Brands never see customers, other brands, your costs and margins, or anyone's pay or other sales.
  • An error-monitoring service receives application error and performance data, so we can find and fix faults.

What we never do

  • Change your POS on a schedule. BudLogix writes to your POS only when one of your users takes an action that sends the change: pushing or rolling back a price event, publishing a product, or adding a product or brand from a delivery or purchase order.
  • Enter your account unrecorded. Every time BudLogix staff enter or leave a customer account, the audit log records who, when, and from which IP address and browser.

Security questions and disclosures: support@budlogix.com