For businesses

Your Data: Who Can See It, and Who It Belongs To

Mosey · 22 September 2026 · 5 min read

Most "security and trust" pages are written to reassure rather than to inform, and they are mostly a list of words. This one is a list of decisions, because decisions can be checked.

Your customer relationships are yours

The customers who order from you, book with you and rate you are your customers.

You can see who your regulars are, what they spend, how often they come and what they order. You can message the ones who agreed to hear from you. If you stop using Mosey, those relationships do not evaporate, because they were never held hostage in the first place.

This is the opposite of the delivery-platform arrangement, where the customer belongs to the platform and you are told a number. It is also the main reason most of the rest of the product exists: a loyalty programme, a customer list and a win-back message are only worth anything if the relationship is yours.

Card details never touch Mosey

Every payment goes through Stripe. Card numbers are entered into Stripe's fields, stored by Stripe, and charged by Stripe.

A "saved card" on Mosey is a reference — a token that lets a charge be made against a card Stripe holds. Mosey never sees or stores a card number, which means there is no card data here to lose.

Your money follows the same logic: it lands in your Stripe account rather than in a Mosey balance. If Mosey disappeared tomorrow, your money would be in your account, because it already is.

There are no third-party trackers

This is the claim most worth checking, because almost nothing else in this industry can make it.

Mosey uses no third-party analytics SDKs. Not Google Analytics, not Mixpanel, not Amplitude, not Segment, not PostHog, not Firebase Analytics. None of them, anywhere in the product.

What that means practically: your customers are not being profiled by an advertising company while they look at your menu, and their behaviour on your listing is not being sold on or combined with data from somewhere else. Product measurement is internal and exists to make the thing work.

It also explains something people notice and assume is an oversight: there is no cookie banner. With no third-party analytics, the only non-essential cookies are map tiles, and consent for those is collected once at account creation rather than by interrupting every visit. The banner is absent because the tracking is absent, not the other way round.

Your team sees what their role allows

Everybody on your account has their own login and their own role.

  • Staff see their own shifts and documents, and can serve customers.
  • Managers do manager things — the rota, leave, the day-to-day — without seeing billing.
  • Owners see money.

Two things follow that are worth stating plainly. Nobody shares a password, so there is no single credential that opens everything and no need to change it when somebody leaves. And a staff PIN is not a security boundary — it identifies who did what on a shared till, which is attribution, not authorisation. A four-digit code typed in front of customers could never be an access control, so it is not used as one.

What your customers control

A customer can delete their account from the app, and it removes their data rather than hiding it from view. That is a legal requirement under GDPR and it is implemented as one rather than as a support ticket.

Customers also control what they hear from venues. An offer can only be sent to somebody who agreed to marketing — which is why you will sometimes see a lapsed customer you cannot message. That is the system working, and it is the same protection your own customers would expect from anywhere else.

Where your data actually lives

Two systems, and it is worth knowing which is which when something needs checking.

Stripe holds the payment side: card details, transactions, payouts and disputes. It is your account, in your name, and you can log into it without asking anybody here.

Mosey holds the trading side: your menu, your bookings, your orders, your loyalty and your staff records. Everything on that list is about your business rather than about a card.

The split is not decorative. It is why a security incident at Mosey could not expose card numbers — there are none here to expose — and why losing access to Mosey would not lose you access to your money.

What Mosey does not claim

No ISO 27001. No SOC 2. Mosey does not hold those certifications and does not imply otherwise, because a claimed certification is worse than an absent one.

What is on this page instead is a description of how the platform is actually built — where card data lives, what trackers exist, who can see what — which is checkable in a way that a badge is not.

What it connects to

Questions

Common questions

Who owns my customer data?

You do. The customers who order, book and rate at your venue are your relationships, and you can see who they are, what they spend and how often they come.

Does Mosey store my customers’ card details?

No. Card details go to Stripe and never touch Mosey. A saved card is a reference held by Stripe, not a card number held by us.

Do you use Google Analytics or similar?

No. Mosey uses no third-party analytics SDKs at all — no Google Analytics, Mixpanel, Amplitude, Segment, PostHog or Firebase Analytics. Product measurement is internal only.

Why is there no cookie banner?

Because there is almost nothing to consent to. With no third-party analytics, the only non-essential cookies are map tiles, and consent is collected once at account creation rather than through a banner on every visit.

Can my staff see everything I can see?

No. Roles decide it. A member of staff sees their own shifts and can serve customers; a manager can do manager things; billing and payouts are owner-only.

What does a staff PIN protect?

Nothing, and that is deliberate. A PIN identifies who did what on a shared device. What somebody is allowed to do is decided by their role, because a four-digit code on a counter is not an access boundary.

Can a customer delete their account and data?

Yes, from the app, and it removes their data rather than hiding it. That is a legal requirement and it is implemented as one.

What happens to my data if I stop using Mosey?

It remains yours. Your money is already in your own Stripe account rather than held by us, which is the part that matters most if you leave.

Is Mosey ISO 27001 or SOC 2 certified?

No. Mosey holds no such certification and does not claim one. What is described on this page is how the platform is actually built, which you can check.

More like this

Read next

Get started

List your place on Mosey

Free to list. Order Ahead is 1.5% commission, and there is no monthly fee to start.