NCEBoxOffice Privacy Policy

Published by Cobalt Ridge LLC  ·  Effective September 11, 2026  ·  Last updated September 11, 2026

This policy describes how the NCEBoxOffice application (package com.cobaltridgellc.nceboxoffice, the “App”) handles personal information. The App is developed and published by Cobalt Ridge LLC (“we,” “us”). It applies to the Android version of NCEBoxOffice distributed through Google Play.

NCEBoxOffice is a point-of-sale and box-office tool used by staff of a venue or business (the “merchant”) to sell tickets and merchandise, take card payments through a Stripe card reader, print receipts, and email receipts to buyers. It is not a consumer shopping app. Two groups of people are covered here: the staff who operate the App, and the customers whose purchase details staff enter at checkout.

Who controls the data

The merchant that installs and operates NCEBoxOffice decides what customer information is collected and how long it is kept. The merchant is the data controller for that information. Cobalt Ridge LLC provides the software and, where the merchant has configured it, the receipt and synchronization backend; in that role we act on the merchant's instructions.

Cobalt Ridge LLC does not operate a central database of end-customer records gathered from all installations of the App, and does not combine merchant data across customers.

Information the App handles

Customer name and email address
Entered by staff at checkout, or selected from the merchant's own saved customer list. Used to address and deliver an email receipt, and to attach the sale to a customer record in the merchant's records. Providing this is optional at the point of sale.
Order and transaction records
Items purchased, quantities, prices, discounts, totals, date and time, payment method, order status, and a transaction identifier. Stored so the merchant can look up, reprint, and refund sales.
Limited payment details
Card brand, the last four digits of the card, and the cardholder name as returned by the payment processor after a transaction completes. These are used to identify a transaction on a receipt and in the order history.
Full card numbers, magnetic stripe data, PINs, and CVV codes
Never collected, transmitted, or stored by the App. Card data is captured by the Stripe card reader hardware and travels directly to Stripe. It does not pass through NCEBoxOffice.
Product catalog and images
Product names, prices, categories, and any image the merchant chooses from the device when creating a product. The App reads only the specific image a staff member selects. It does not scan, index, or upload the device photo library.
Merchant and device configuration
Business name and branding, checkout and display settings, the merchant's Stripe account identifier, the address of the merchant's own backend if configured, and the identifier of a paired card reader or receipt printer.

What the App does not do

Device permissions and why they are needed

Bluetooth (connect, scan, and on older Android versions the legacy Bluetooth permissions)
Required to discover and pair with the Stripe card reader and the Bluetooth receipt printer. Bluetooth is used only for communication with that payment and printing hardware.
Precise location
Android requires location permission before an app may scan for nearby Bluetooth Low Energy devices, and the Stripe Terminal SDK requires it in order to connect a reader. The App uses this permission solely so that reader and printer discovery will function. It does not read, log, store, or transmit your coordinates, and it does not request background location.
Photo or media selection
Used only when a staff member taps to attach an image to a product. The App receives the single file that was picked.
Network access
Used to obtain payment authorization tokens, process card payments through Stripe, send email receipts, and — when the merchant has enabled it — synchronize products, customers, and orders with the merchant's own server.

Where information is stored

By default, products, orders, customer entries, and settings are stored in the App's private storage on the device itself. This storage is not readable by other apps.

If the merchant enables remote synchronization and supplies a server address in the App's settings, the App will also send products, customer entries, and completed orders to that server, and will send receipt requests to it. The merchant chooses and controls that server. Where the merchant uses a backend operated by Cobalt Ridge LLC, transfers are made over HTTPS.

Who information is shared with

Stripe, Inc.
Processes all card payments and supplies the card reader software. Transaction amounts and payment metadata are sent to Stripe, and the card itself is read by Stripe hardware. Stripe handles that information under its own privacy policy, available at stripe.com/privacy.
The merchant's own backend or email service
Receives customer name, customer email, and order details when remote synchronization or backend email receipts are enabled, so that receipts can be delivered and records kept.
The device's email application
If no backend is configured and a staff member sends a receipt, the App hands the receipt to whatever email app is installed so the staff member can send it. That email app handles the message under its own terms.
Legal disclosure
We may disclose information where we are required to by law, or where necessary to investigate fraud, abuse, or a threat to safety.

Retention and deletion

The App has no user accounts and requires no registration to use. Data kept on the device remains until the merchant deletes the individual record in the App, clears the App's storage from Android settings, or uninstalls the App. Uninstalling removes all locally stored products, orders, customer entries, and settings from that device.

Where records have been synchronized to a merchant-operated server, retention is set by that merchant. Customers who want their details removed from a venue's records should contact that venue. If you are unsure who to contact, write to us at the address below and we will direct your request.

Security

Payment card data is handled by Stripe's certified hardware and services and is out of scope for the App. Network requests made by the App use HTTPS. On-device records are held in application-private storage. No method of storage or transmission is completely secure, and we cannot guarantee absolute security. Merchants are responsible for protecting the devices the App runs on, including using a device passcode and keeping Android up to date.

Children

NCEBoxOffice is a business tool intended for use by staff aged 18 or over. It is not directed to children, and we do not knowingly collect personal information from children. If you believe a child's information has been entered into the App, contact the merchant operating it, or write to us and we will assist.

Your rights

Depending on where you live, you may have the right to request access to the personal information held about you, to have it corrected or deleted, to object to or restrict certain processing, and to receive a copy in a portable form. Residents of California may additionally request disclosure of the categories of personal information collected and may opt out of sale or sharing — we do not sell or share personal information as those terms are defined under California law.

Because the merchant controls the records created through the App, requests are usually fastest when made directly to the venue or business you purchased from. You may also contact us and we will pass the request on or respond directly where we hold the data.

International use

The App and its supporting services are operated from the United States. If you use the App or make a purchase through it from outside the United States, information may be processed in the United States, where data protection law may differ from that of your country.

Changes to this policy

We may update this policy as the App changes or as the law requires. The revised version will be posted at this address with a new effective date. Material changes will be reflected in the App's Google Play listing.

Contact us

Cobalt Ridge LLC
Email: info@cobaltridgellc.com
Regarding: NCEBoxOffice, Android

We aim to respond to privacy requests within 30 days.