Legal · v2.4.0
Privacy Policy
Effective 2026-08-24
1. Document Control
Version: v2.4.0
Effective Date: 2026-08-24
Last Updated: 2026-08-24
Revision Summary: Clarify HonorBot live voice uses OpenAI Realtime audio (not on-device speech recognition) when the merchant activates HonorBot; retain Terminal/location and camera disclosures.
2. Who We Are
This Privacy Policy explains how Marcus Coffman DBA HonorBox (“HonorBox”) collects, uses, shares, stores, and protects information when you use HonorBox.
3. Roles
HonorBox provides merchant software. Merchants remain responsible for their own customer-facing notices where required by law.
4. Information We Collect
Depending on use, we may collect account/auth data; business profile and settings; catalog/inventory and images; orders and payment metadata (not full card PANs); expenses and receipt images; AI/Business Advisor/HonorBot prompts and conversations; weather ZIP codes; limited device/platform metadata; and Stripe billing/Connect operational metadata. On supported Android/iOS kiosk devices, HonorBox may request precise and/or approximate location and Bluetooth permissions while the app is in use so Stripe Terminal can discover and connect to nearby card readers. If location permission is already granted, HonorBot may also use a foreground location reading to estimate a nearby ZIP code when you ask about local weather (HonorBox does not request background location for this purpose). HonorBox may also use the device camera and photo library so Merchants can capture expense receipts and upload product, logo, Design Studio, and Honor Payment QR images. When you intentionally activate HonorBot live voice and grant microphone permission, HonorBox may transmit microphone audio from your device to OpenAI Realtime services so your spoken request can be processed (see section 4A).
4A. Microphone and HonorBot Live Voice
HonorBot is an optional assistant. Microphone access is requested only when you activate HonorBot voice (for example by deploying HonorBot) and grant permission. HonorBox does not secretly or continuously record you in the background, and does not turn the microphone on without that user action and permission. On supported devices, HonorBot live voice uses a realtime audio connection (WebRTC) so spoken audio may be transmitted from the device to OpenAI’s Realtime services to understand your question and generate a spoken reply. Related operational context (such as the question text derived from the session and business context needed to answer) may also be sent through HonorBox backends to OpenAI. HonorBox does not claim to store raw microphone audio recordings as a separate product feature. Conversation content (such as questions and answers retained for the HonorBot/Business Assistant experience) is treated as merchant operational content and is subject to the AI/conversation retention and deletion rules below. Microphone capture for HonorBot is intended only while HonorBot is actively deployed for conversation and should stop when you close/hide HonorBot, end the voice session, or the app leaves the foreground.
5. Payment Card Data
HonorBox does not store full card primary account numbers. Stripe handles card credentials for eligible payments. HonorBox stores limited payment metadata needed for operations and reconciliation.
6. How We Use Information
We use information to operate HonorBox, authenticate users, enforce legal/access gates, process orders/refunds, support Terminal workflows (including reader discovery via location/Bluetooth where required by the reader SDK), power OCR, Business Advisor, and HonorBot features (including live voice and weather-informed guidance when weather context is available), communicate service notices, detect fraud/abuse, and meet legal obligations.
7. Receipt OCR and AI
Receipt scans may send receipt images to OpenAI (via HonorBox backends) to extract expense fields for Merchant review. Business Advisor and HonorBot may send prompts and operational context to OpenAI. When HonorBot live voice is used, spoken audio may also be processed by OpenAI Realtime as described in section 4A. Outputs are informational and are not legal, tax, accounting, or financial advice.
8. Sharing
Processors include Supabase (authentication, database, and storage); Expo / EAS (application build and distribution infrastructure); Stripe; and OpenAI (receipt image OCR extraction, Business Advisor answers, and HonorBot live voice / conversational answers, via HonorBox edge functions and OpenAI Realtime where voice is used); Open-Meteo (weather forecasts derived from merchant-entered ZIP codes and, when already authorized, approximate device location ZIP estimates for HonorBot weather questions). We may disclose information when legally required, to protect rights/safety, or in a corporate transaction. We do not sell personal information as a consumer data broker.
9. Communications
Transactional/service email for account, billing, security, deletion, and material legal-policy notices Stripe receipt-email tooling for eligible card payments No marketing/promotional email program is currently operated.
10. Voluntary Account Deletion
Merchants may schedule account deletion in Settings → Account → Privacy & Account Deletion. Deletion is scheduled for 7 days after confirmation. Successful sign-in before the scheduled date automatically cancels pending deletion. If no successful sign-in occurs before the deadline, HonorBox permanently deletes account-specific content it does not need to retain. Permanent deletion cannot simply be undone. Merchants may also email deletion requests to the contact below.
11. Limited Retention After Deletion
Some records may be retained in minimized form where needed for tax, accounting, chargebacks, payment disputes, fraud prevention, security, legal claims, or regulatory obligations. Exact retention duration depends on those requirements. Retained records are not intended to function as an active merchant account.
12. Inactivity
HonorBox may initiate inactivity-deletion procedures after prolonged subscription inactivity (currently measured as 12 consecutive months), subject to required advance notice and available notice-delivery mechanisms. Permanent inactivity deletion does not proceed unless required notice has been successfully delivered through a configured notice channel. Sign-in or reactivation during a notice period cancels inactivity deletion.
13. Security
HonorBox uses commercially reasonable safeguards (including HTTPS transport and authenticated access controls). Absolute security is not promised. HonorBox does not claim SOC 2, ISO 27001, HIPAA, or PCI DSS certification in this Policy.
14. Children
HonorBox is a business tool and is not directed to children.
15. Changes
Material Privacy changes will be noticed in-app and by email and may require reacceptance where appropriate.
16. Contact
Marcus Coffman DBA HonorBox
119 Wainwright Rd, Oak Ridge, TN 37830
Email: blanche04tj@gmail.com