Point of Sale
Your data

Privacy Policy

How Point of Sale collects, uses, discloses, protects, retains, and responds to requests about personal information.

Effective: August 20, 2026  •  Last updated: August 20, 2026

Plain-language overview: We collect the information needed to run, secure, support, and improve Point of Sale. We do not sell personal information for money. Businesses using Point of Sale control the customer and employee information they enter; Point of Sale generally processes that information for them.

1. Scope and roles

This Policy explains how the operator identified in your Point of Sale account, order form, or invoice (“Point of Sale,” “we,” “us”) handles personal information when you visit, create an account, use the app, contact support, or interact with our services. It does not cover independent third parties or a merchant’s own privacy practices.

For account, billing, security, site, and support data, we generally decide why and how data is used. For customer, worker, transaction, catalog, and other business data uploaded by a merchant, the merchant generally controls the data and Point of Sale processes it on the merchant’s instructions. Requests about merchant-controlled data should first go to that merchant.

2. Information we collect

Please avoid entering sensitive personal data unless necessary and lawful. Do not upload payment-card security codes, passwords, government secrets, medical records, or other data the service does not request.

3. Sources

We receive information from you; your employer, business owner, or account administrator; customers or team members using the account; your device and use of the service; authentication, hosting, payment, analytics, app-store, and support providers; integrations you enable; and public or lawful fraud-prevention sources.

4. How we use information

We may create aggregated or de-identified information that is not reasonably linkable to a person and use it for lawful business purposes. We will not attempt to re-identify it except to test safeguards or as permitted by law.

5. Legal bases

Where a legal basis is required, we rely on performance of a contract, legitimate interests (such as security, support, fraud prevention, and service improvement), compliance with legal obligations, protection of vital interests, and consent where requested. You may withdraw consent at any time without affecting earlier processing. The merchant is responsible for choosing a lawful basis for merchant-controlled data.

6. How we disclose information

We may disclose relevant information to:

We do not sell personal information for money or share it for cross-context behavioral advertising as those terms are defined in certain laws. If our practices change, we will update this Policy and provide required controls.

7. International transfers

We and providers may process information in countries other than yours. Those countries may have different laws. Where required, we use recognized safeguards such as adequacy decisions, contractual clauses, or other lawful transfer mechanisms. Contact support for information about applicable safeguards.

8. Retention

We retain information while the account is active and as reasonably needed to provide services, meet tax and accounting duties, resolve disputes, enforce agreements, prevent abuse, and maintain security and backups. Retention varies by data type, sensitivity, contractual instructions, legal requirements, and technical backup cycles. When no longer needed, information is deleted, de-identified, or isolated until deletion is possible. Merchants should export records they must retain before closing an account.

9. Security

We use administrative, technical, and organizational safeguards designed for the nature of the information, such as access controls, authentication, encryption in transit, provider review, logging, and least-privilege permissions. No system is completely secure. You are responsible for secure devices, strong credentials, appropriate roles, lawful access, and promptly reporting suspected compromise. If a breach requires notice, we will notify affected parties or the relevant merchant as required by law.

10. Choices and privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information; withdraw consent; opt out of certain marketing or sharing; and appeal or complain to a regulator. Rights can be limited by law, other people’s rights, security, and our role as a processor.

Update account information in settings or submit a request through in-app Help & Support. We may verify identity and authority. Authorized agents must provide valid authorization. For merchant-controlled data, contact the merchant first; we assist merchants as legally and contractually required. You can control cookies through browser or device settings, but disabling essential storage may prevent sign-in or offline features.

11. Children

Point of Sale is a business service and is not directed to children under 18. Do not create an account or submit a child’s information without a valid legal basis and all required guardian notices or consents. If you believe a child provided account information improperly, contact us.

12. Changes to this Policy

We may update this Policy as services, providers, and laws change. We will post the new effective date and give additional notice of material changes where required. Earlier versions may be requested through support.

13. Contact and complaints

For privacy questions, requests, complaints, or data-protection contacts, use Help & Support inside the app and label the request “Privacy.” You may also complain to the data-protection authority where you live or work. If your request concerns a merchant’s records, identify that merchant so it can be routed correctly.

Implementation note: Before launch, qualified privacy counsel should insert the actual legal entity, physical and privacy email addresses, hosting locations, named subprocessors, jurisdiction-specific disclosures, cookie controls, and any required data-processing agreement.