Plain-language overview: We collect the information needed to run, secure, support, and improve Point of Sale. We do not sell personal information for money. Businesses using Point of Sale control the customer and employee information they enter; Point of Sale generally processes that information for them.
1. Scope and roles
This Policy explains how the operator identified in your Point of Sale account, order form, or invoice (“Point of Sale,” “we,” “us”) handles personal information when you visit, create an account, use the app, contact support, or interact with our services. It does not cover independent third parties or a merchant’s own privacy practices.
For account, billing, security, site, and support data, we generally decide why and how data is used. For customer, worker, transaction, catalog, and other business data uploaded by a merchant, the merchant generally controls the data and Point of Sale processes it on the merchant’s instructions. Requests about merchant-controlled data should first go to that merchant.
2. Information we collect
- Account and profile: name, email, authentication identifiers, role, organization, profile image, and preferences.
- Business and billing: business name, address, phone, tax details, plan, subscription status, invoices, billing contact, and limited card details such as brand and last four digits. Payment providers process full payment credentials.
- Business content: products, categories, stock, orders, invoices, expenses, receivables, customers, staff, permissions, reports, notes, attachments, and records you choose to enter.
- Support and communications: messages, screenshots, call or ticket details, feedback, and responses.
- Device and usage: IP address, browser, device and app version, language, time zone, identifiers, dates and times, screens and features used, referring pages, diagnostic logs, crash data, and security events.
- Approximate location: inferred from IP or business settings; precise device location only if a feature requests it and you permit it.
- Cookies and local storage: sign-in state, preferences, security tokens, offline data, analytics settings, and similar technologies.
Please avoid entering sensitive personal data unless necessary and lawful. Do not upload payment-card security codes, passwords, government secrets, medical records, or other data the service does not request.
3. Sources
We receive information from you; your employer, business owner, or account administrator; customers or team members using the account; your device and use of the service; authentication, hosting, payment, analytics, app-store, and support providers; integrations you enable; and public or lawful fraud-prevention sources.
4. How we use information
- provide, synchronize, personalize, and maintain the service;
- authenticate users, manage roles, process subscriptions, and provide support;
- create requested orders, records, invoices, exports, analytics, and backups;
- monitor reliability, debug errors, prevent fraud and abuse, and protect users and systems;
- communicate service, security, billing, policy, and support messages;
- understand aggregate usage and improve features and usability;
- enforce terms, establish or defend legal claims, comply with law, and respond to lawful requests; and
- send marketing where permitted, with a way to opt out.
We may create aggregated or de-identified information that is not reasonably linkable to a person and use it for lawful business purposes. We will not attempt to re-identify it except to test safeguards or as permitted by law.
5. Legal bases
Where a legal basis is required, we rely on performance of a contract, legitimate interests (such as security, support, fraud prevention, and service improvement), compliance with legal obligations, protection of vital interests, and consent where requested. You may withdraw consent at any time without affecting earlier processing. The merchant is responsible for choosing a lawful basis for merchant-controlled data.
6. How we disclose information
We may disclose relevant information to:
- Service providers for cloud hosting, databases, authentication, analytics, error monitoring, communications, customer support, payments, and professional advice, under appropriate restrictions.
- Your organization, including owners, administrators, and authorized users according to account permissions.
- Integrations you direct us to connect, subject to their own policies.
- Authorities or others when reasonably necessary to comply with law, protect rights or safety, investigate abuse, enforce agreements, or respond to valid legal process.
- Transaction participants during a merger, financing, reorganization, bankruptcy, sale, or transfer, subject to confidentiality and applicable notice requirements.
We do not sell personal information for money or share it for cross-context behavioral advertising as those terms are defined in certain laws. If our practices change, we will update this Policy and provide required controls.
7. International transfers
We and providers may process information in countries other than yours. Those countries may have different laws. Where required, we use recognized safeguards such as adequacy decisions, contractual clauses, or other lawful transfer mechanisms. Contact support for information about applicable safeguards.
8. Retention
We retain information while the account is active and as reasonably needed to provide services, meet tax and accounting duties, resolve disputes, enforce agreements, prevent abuse, and maintain security and backups. Retention varies by data type, sensitivity, contractual instructions, legal requirements, and technical backup cycles. When no longer needed, information is deleted, de-identified, or isolated until deletion is possible. Merchants should export records they must retain before closing an account.
9. Security
We use administrative, technical, and organizational safeguards designed for the nature of the information, such as access controls, authentication, encryption in transit, provider review, logging, and least-privilege permissions. No system is completely secure. You are responsible for secure devices, strong credentials, appropriate roles, lawful access, and promptly reporting suspected compromise. If a breach requires notice, we will notify affected parties or the relevant merchant as required by law.
10. Choices and privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information; withdraw consent; opt out of certain marketing or sharing; and appeal or complain to a regulator. Rights can be limited by law, other people’s rights, security, and our role as a processor.
Update account information in settings or submit a request through in-app Help & Support. We may verify identity and authority. Authorized agents must provide valid authorization. For merchant-controlled data, contact the merchant first; we assist merchants as legally and contractually required. You can control cookies through browser or device settings, but disabling essential storage may prevent sign-in or offline features.
11. Children
Point of Sale is a business service and is not directed to children under 18. Do not create an account or submit a child’s information without a valid legal basis and all required guardian notices or consents. If you believe a child provided account information improperly, contact us.
12. Changes to this Policy
We may update this Policy as services, providers, and laws change. We will post the new effective date and give additional notice of material changes where required. Earlier versions may be requested through support.
13. Contact and complaints
For privacy questions, requests, complaints, or data-protection contacts, use Help & Support inside the app and label the request “Privacy.” You may also complain to the data-protection authority where you live or work. If your request concerns a merchant’s records, identify that merchant so it can be routed correctly.
Implementation note: Before launch, qualified privacy counsel should insert the actual legal entity, physical and privacy email addresses, hosting locations, named subprocessors, jurisdiction-specific disclosures, cookie controls, and any required data-processing agreement.