SaaS Ranking

Lolly

itslolly.com · Restaurant point of sale · checked 2026-09-14

17/100FBand F

Rank 14 of 42 in Restaurant point of sale, where the median is 11.

We measured 12 of 12 criteria for Lolly on 2026-09-14. We found 3 with a source and did not find 9 at the addresses we checked. That is a transparency score of 17 out of 100, band F.

Overview

1 day since the newest finding, 1 since the oldest. 12 of 12 criteria measured in the last 30 days.

Evidence freshness is a statement about our measurement and is kept apart from the transparency score, which is frozen at v1. How good our own measurement is.

Transparency labelsaas-ranking.com

Lolly

itslolly.com · Restaurant point of sale

  1. A
  2. B
  3. C
  4. D
  5. E
  6. F
F 17of 100 Rank 14 of 42

Published commitments2 of 9 found

Measured behaviour1 of 3 found

Checked 2026-09-14. Every line links the page we found it on. A cross means we found nothing at the addresses we checked, not that the vendor has no such document. A transparency score, not a product rating.

The evidence pack carries every criterion with its source, the addresses we checked, the date and the data snapshot id – the four things a procurement file needs and a screenshot loses. We do not issue badges: a badge is the first step towards a paid placement, and there is none here.

The label is the whole measurement in one object: every criterion with its weight, the band, and the date. Public transparency score, not a product or security rating.

Every line in it links the page we found the result on, or lists the addresses we checked. A cross means we found nothing there, not that Lolly has no such document.

Where Lolly sits in Restaurant point of sale

  1. A0 0%
  2. B1 2%
  3. C1 2%
  4. D3 7%
  5. E7 17%
  6. F30 71%
42 vendors with a score; 6 more without a score because we could measure too little. Bands have fixed thresholds, see how the score works.

The band of Lolly is marked. Vendors without a score are the ones where we could measure too few criteria to rank them – a gap on our side, counted separately.

What they state

The exact figures and names we read off the pages linked below, with the sentence they stand in. This is what they publish, not what we verified about their systems.

Gaps, heaviest first

Data processing agreement

weight 3 of 3

No data processing agreement found.

Checked 8 addresses on 2026-09-14.

Show the 8 addresses we checked
  1. https://itslolly.com/legal/dpa – reached, no match (HTTP 404)
  2. https://itslolly.com/dpa – reached, no match (HTTP 404)
  3. https://itslolly.com/legal/data-processing-agreement – reached, no match (HTTP 404)
  4. https://itslolly.com/data-processing-agreement – reached, no match (HTTP 404)
  5. https://itslolly.com/legal/data-processing-addendum – reached, no match (HTTP 404)
  6. https://itslolly.com/legal/gdpr – reached, no match (HTTP 404)
  7. https://itslolly.com/trust/dpa – reached, no match (HTTP 404)
  8. https://itslolly.com/privacy/dpa – reached, no match (HTTP 404)

Is this wrong? Send us the URL

Subprocessor list

weight 3 of 3

No subprocessor list found.

Checked 7 addresses on 2026-09-14.

Show the 7 addresses we checked
  1. https://itslolly.com/legal/subprocessors – reached, no match (HTTP 404)
  2. https://itslolly.com/subprocessors – reached, no match (HTTP 404)
  3. https://itslolly.com/sub-processors – reached, no match (HTTP 404)
  4. https://itslolly.com/legal/sub-processors – reached, no match (HTTP 404)
  5. https://itslolly.com/trust/subprocessors – reached, no match (HTTP 404)
  6. https://itslolly.com/privacy/subprocessors – reached, no match (HTTP 404)
  7. https://itslolly.com/legal/subprocessor-list – reached, no match (HTTP 404)

Is this wrong? Send us the URL

Data location stated

weight 3 of 3

We found this behind a sign-in, so it is not published openly.

Seen at https://www.itslolly.com/privacy-policy · checked 2026-09-14

Show the 7 addresses we checked
  1. https://itslolly.com/security – reached, no match (HTTP 200)
  2. https://itslolly.com/trust – reached, no match (HTTP 404)
  3. https://itslolly.com/legal/privacy – reached, no match (HTTP 404)
  4. https://itslolly.com/privacy – reached, no match (HTTP 404)
  5. https://itslolly.com/privacy-policy – found, but behind a sign-in
  6. https://itslolly.com/compliance – reached, no match (HTTP 404)
  7. https://itslolly.com/legal/privacy-policy – reached, no match (HTTP 404)

Is this wrong? Send us the URL

Status page with history

weight 2 of 3

No public status page found.

Checked 3 addresses on 2026-09-14.

Show the 3 addresses we checked
  1. https://status.itslolly.com/ – The name "status.itslolly.com" could not be resolved.
  2. https://itslolly.com/status – reached, no match (HTTP 404)
  3. https://itslolly.com.statuspage.io/ – Could not be fetched: fetch failed.

Is this wrong? Send us the URL

Public pricing

weight 2 of 3

No public pricing with figures found.

Checked 5 addresses on 2026-09-14.

Show the 5 addresses we checked
  1. https://itslolly.com/pricing – reached, no match (HTTP 404)
  2. https://itslolly.com/pricing/ – reached, no match (HTTP 404)
  3. https://itslolly.com/plans – reached, no match (HTTP 404)
  4. https://itslolly.com/en/pricing – reached, no match (HTTP 404)
  5. https://itslolly.com/pricing-plans – reached, no match (HTTP 404)

Is this wrong? Send us the URL

No third-party tracking before consent

weight 2 of 3

Third-party requests seen on the first load, before any interaction.

Checked 1 address on 2026-09-14.

Show the 1 address we checked
  1. https://itslolly.com/ – third-party requests before any interaction: accounts.finsweet.com, api.zuko.io, app-widgets.jotform.io, assets.zuko.io, cdn.jotfor.ms, cdn.jsdelivr.net, cdn.prod.website-files.com, challenges.cloudflare.com, csp.withgoogle.com, d3e54v103j8qbb.cloudfront.net, events.jotform.com, form.jotform.com, pagead2.googlesyndication.com, region1.analytics.google.com, region1.google-analytics.com, stats.g.doubleclick.net, whoshouldisee.co.uk, www.google.com, www.google.de, www.googletagmanager.com, www.gstatic.com

Is this wrong? Send us the URL

Notice before subprocessors change

weight 2 of 3

No commitment to give notice before subprocessors change found.

Checked 8 addresses on 2026-09-14.

Show the 8 addresses we checked
  1. https://itslolly.com/legal/subprocessors – reached, no match (HTTP 404)
  2. https://itslolly.com/subprocessors – reached, no match (HTTP 404)
  3. https://itslolly.com/sub-processors – reached, no match (HTTP 404)
  4. https://itslolly.com/legal/dpa – reached, no match (HTTP 404)
  5. https://itslolly.com/dpa – reached, no match (HTTP 404)
  6. https://itslolly.com/legal/data-processing-agreement – reached, no match (HTTP 404)
  7. https://itslolly.com/trust/subprocessors – reached, no match (HTTP 404)
  8. https://itslolly.com/legal/sub-processors – reached, no match (HTTP 404)

Is this wrong? Send us the URL

Uptime SLA with a figure

weight 1 of 3

No uptime figure found.

Checked 6 addresses on 2026-09-14.

Show the 6 addresses we checked
  1. https://itslolly.com/legal/sla – reached, no match (HTTP 404)
  2. https://itslolly.com/sla – reached, no match (HTTP 404)
  3. https://itslolly.com/legal/service-level-agreement – reached, no match (HTTP 404)
  4. https://itslolly.com/trust/sla – reached, no match (HTTP 404)
  5. https://itslolly.com/uptime – reached, no match (HTTP 404)
  6. https://itslolly.com/legal/uptime-sla – reached, no match (HTTP 404)

Is this wrong? Send us the URL

security.txt (RFC 9116)

weight 1 of 3

No security.txt found.

Checked 1 address on 2026-09-14.

Show the 1 address we checked
  1. https://itslolly.com/.well-known/security.txt – reached, no match (HTTP 404)

Is this wrong? Send us the URL

Evidence

The full source lists sit behind these two groups, so that the answer above stays readable.

Published, with a source 3

HTTPS enforced with HSTS

weight 2 of 3

HTTP redirects to HTTPS and the HSTS header is set.

  • HSTS max-age 31536000 seconds (365 days).
    Show the exact wording

    max-age=31536000; includeSubDomains; preload

    Read at https://itslolly.com/
  • HSTS options includeSubDomains, preload.
    Show the 2 exact wordings

    max-age=31536000; includeSubDomains; preload

    Read at https://itslolly.com/

    max-age=31536000; includeSubDomains; preload

    Read at https://itslolly.com/

Source: https://itslolly.com/ · checked 2026-09-14

Certifications named

weight 1 of 3

SOC 2 or ISO 27001 named on a public page.

  • Named on that page Cyber Essentials, ISO 9001, ISO/IEC 27001 (not counted: the sentence does not carry it), PCI DSS. The sentence we kept does not carry this finding on its own, so it counts in no list and no figure.
    Show the 4 exact wordings

    Cyber Essentials & Cyber Essentials Plus We are certified under both Cyber Essentials and CE+, demonstrating strong,

    Read at https://www.itslolly.com/security

    ISO 9001:2015 Quality Management We are certified to ISO 9001:2015, demonstrating our commitment to deliveri

    Read at https://www.itslolly.com/security

    ISO/IEC 27001:2022 Information Security Management We operate in alignment with ISO/IEC 27001:2022, the internati

    Read at https://www.itslolly.com/security

    Payment Security Lolly is fully compliant with PCI DSS v4.0 across both physical and digital payment channels.

    Read at https://www.itslolly.com/security

Source: https://www.itslolly.com/security · checked 2026-09-14

Named privacy contact

weight 1 of 3

A data protection officer or a dedicated privacy address is named.

Source: https://www.itslolly.com/privacy-policy · checked 2026-09-14

History

Not enough completed runs yet to draw a line. The next runs fill this in.

Compare

A shortlist holds up to six vendors across categories and lives entirely in the address of its page: share the link, bookmark it, put it in a ticket. Nothing is stored, so we do not know it exists.