YOUR DATA, HANDLED RESPONSIBLY

Privacy Policy

This policy explains what information StorePOS Global processes, why we use it, how we protect it, and the choices available to you.

Effective and last updated: July 28, 2026
In plain language: we use personal information to operate and secure StorePOS Global. We do not sell personal information. Businesses using StorePOS Global remain responsible for the customer and employee information they enter into the service.

1. Scope and our role

This Privacy Policy applies to the StorePOS Global website, account registration, point-of-sale service, inventory tools, reports, and related support services (collectively, the “Service”).

StorePOS Global controls the information needed to create, administer, and secure an account. For customer, employee, sales, and operational information entered by a registered business, that business is generally the data controller or responsible party, and StorePOS Global processes the information on its behalf as a service provider or data processor.

2. Information we process

Account and company information

  • Company name, business email address, business address, and company logo.
  • Owner and staff username or email, full name, assigned role, shop access, and account status.
  • Password hashes and email-verification records. We do not store newly created passwords in readable plain text.

Customer and transaction information

  • Customer name and phone number when a business chooses to enter them for a sale.
  • Items purchased, quantities, prices, discounts, totals, sale time, receipt number, cashier, shop, counter, and shift.
  • Payment method, such as cash, card, mobile payment, or bank transfer.

StorePOS Global records the payment method used for reporting. Unless a separate payment integration clearly states otherwise, the Service does not require or store full payment-card numbers, card security codes, or online-banking credentials.

Business operations information

Product, barcode, stock, stock adjustment, supplier or category information; register-session activity; opening and closing balances; reports; tax and currency configuration; and audit information identifying the user who performed an action.

Technical information

Authentication and session-cookie information and, where enabled by the hosting environment, IP address, browser or device details, request timestamps, security events, diagnostics, and error logs. We may also receive information you provide in a support request.

3. How we use information

  • Register companies, verify email addresses, authenticate users, and manage permissions.
  • Provide sales, receipts, inventory, register sessions, and business reports.
  • Maintain tenant separation and show each business only the information it is authorised to access.
  • Deliver service emails and respond to support requests.
  • Detect misuse, prevent fraud, investigate security incidents, and maintain system reliability.
  • Back up and restore the Service and improve its performance and usability.
  • Comply with applicable accounting, tax, legal, and regulatory obligations and enforce our agreements.

5. Cookies and similar technologies

The Service uses an essential, HTTP-only authentication cookie to keep signed-in users authenticated and protect account access. Blocking essential cookies may prevent sign-in or other secured features from working. If optional analytics or advertising cookies are added, this policy and any required consent controls will be updated before those cookies are used.

6. When information is shared

We may disclose only the information reasonably necessary to:

  • hosting, database, backup, email-delivery, security, monitoring, and technical-support providers operating under appropriate obligations;
  • authorised users and administrators of the registered business that supplied the information;
  • professional advisers, auditors, or a successor in a merger, financing, reorganisation, or sale, subject to appropriate safeguards; or
  • courts, regulators, law enforcement, or other parties when required by law or necessary to protect rights, safety, and the Service.

We do not sell personal information. Service providers may process information in countries other than the country where it was collected. Where required, we use contractual or other recognised safeguards for international transfers.

7. How long we keep information

We retain account and business information while the account is active and for a reasonable period afterward when needed to provide recovery, backups, security, dispute resolution, or legal compliance. Transaction and accounting records may be retained for the period required by applicable tax or accounting law. Retention can also be directed by the registered business. When information is no longer required, we delete, anonymise, or securely isolate it until routine backup copies expire.

8. How we protect information

We use administrative and technical measures designed to protect information, including password hashing, access controls, company-level data separation, restricted user roles, essential HTTP-only authentication cookies, and secure production connections. No internet service or storage system can be guaranteed to be completely secure. Registered businesses must protect their credentials, assign access carefully, and notify us promptly of suspected unauthorised access.

9. Your privacy rights and choices

Depending on your location, you may have the right to request access, correction, deletion, restriction, objection, or a portable copy of personal information, and to withdraw consent. You may also have the right to complain to a local data-protection authority.

If your information was entered by a store, employer, or another registered business, contact that business first. We support registered businesses in responding to valid requests. We may verify identity and authority before fulfilling a request, and some information may be retained when required by law or needed to protect legal rights.

10. Children’s privacy

The Service is intended for businesses and authorised workforce users, not for use by children. We do not knowingly ask children to create StorePOS Global business accounts. If you believe a child has provided personal information contrary to applicable law, please contact us so the information can be reviewed and, where appropriate, removed.

11. Changes to this policy

We may update this policy to reflect changes to the Service, providers, or legal requirements. The “last updated” date will change when revisions are published. If a change materially affects how personal information is used, we will provide additional notice through the Service, by email, or by another appropriate method.

12. Contact us

For privacy questions or requests, contact StorePOS Global using the official support contact provided with your subscription or deployment. Include “Privacy Request” in the subject and identify the registered company associated with the request. Please do not send passwords, full payment-card numbers, or other unnecessary sensitive information.

Registered-business users may also contact their company administrator, who can review account permissions and coordinate a request with StorePOS Global.