Privacy & Data Protection

Privacy Policy

Last Updated: August 26, 2026 • Effective Immediately

Poslytics is committed to safeguarding the privacy and integrity of your merchant data, operational logs, and customer information. This policy describes our practices regarding data collection, processing, security, and your privacy rights.

1. Introduction & Scope

Poslytics Technologies Ltd. ("Poslytics", "we", "our", "us") provides a comprehensive operational platform for restaurants, retail chains, and multi-branch hospitality businesses. This Privacy Policy governs our collection, storage, use, and disclosure of personal data when you interact with our website, access our SaaS applications, utilize our Point of Sale (POS) terminals, or communicate with our team.

By registering for an account or using our platform, you acknowledge that you have read and understand the practices described in this Privacy Policy.

2. Data Controller vs. Data Processor Roles

Poslytics as Data Controller

We act as a Data Controller for information regarding direct merchant account holders, administrator profiles, billing contacts, login credentials, and our direct website visitors.

Poslytics as Data Processor

When merchants record customer order history, dine-in table reservations, loyalty member profiles, or staff attendance records in Poslytics, the merchant acts as Data Controller, and Poslytics acts as Data Processor.

3. Categories of Information We Collect

We collect personal information across several distinct categories to deliver reliable operational workflows:

CategoryData PointsPurpose
Account & ProfileFull name, business email, phone number, company name, merchant slug, password hashes.User authentication, merchant tenancy routing, account management.
POS & TransactionsOrder items, discounts, table numbers, timestamps, invoice IDs, payment receipt references.Real-time order processing, KDS display, sales reconciliation, inventory deductions.
Staff & PayrollStaff names, branch roles, shift schedules, clock-in/out timestamps, hourly wage rates.Staff attendance tracking, shift scheduling, payroll reporting.
Technical & LogsIP address, browser type, device OS, approximate geolocation (country level), API latency logs.Security monitoring, rate-limiting, error diagnostic analysis, feature optimization.

4. How We Use & Process Data

  • • Service Delivery: Managing cloud synchronization between physical POS terminals, kitchen display monitors, and merchant management dashboards.
  • • Billing & Invoicing: Calculating tier subscriptions, add-on branch fees, and generating invoice receipts.
  • • Security & Fraud Prevention: Monitoring anomalous API request volumes, brute-force attempts, and unauthorized branch access.
  • • System Performance & Support: Diagnosing bug reports, analyzing crash telemetry, and providing prompt technical support.

6. Third-Party Sharing & Sub-Processors

Poslytics partners with trusted third-party service providers (sub-processors) to deliver cloud hosting, database reliability, email delivery, and payment facilitation. All sub-processors are bound by strict Data Processing Agreements (DPAs) requiring equivalent data protection standards.

  • • Cloud Infrastructure & Database Hosting: AWS, DigitalOcean, and Supabase (Encrypted storage and low-latency servers).
  • • Payment Gateways: Stripe, bKash, SSLCommerz (Direct tokenized payment processing; raw card numbers are never stored on Poslytics servers).
  • • Transactional Notifications: SendGrid, Postmark, Twilio (System notifications, password resets, verification emails).
  • • IP & Geolocation: ipapi.co (Client-side country detection for phone dial codes).

7. Data Security & Encryption Standards

We implement comprehensive technical and organizational safeguards designed to protect your data against unauthorized disclosure, alteration, loss, or destruction:

End-to-End Encryption

All data in transit is protected via TLS 1.3. Databases and backups use AES-256 encryption.

Tenancy Isolation

Multi-tenant architecture enforces logical row-level and merchant ID query isolation.

Role-Based Access

Granular permission controls (Admin, Manager, Cashier, Kitchen, Waiter) across branches.

8. Data Retention & Automatic Purge

We retain personal data for as long as your merchant account remains active and in good standing. Following account termination or deletion requests, data is handled according to the schedule below:

• Active Subscriptions: Data retained indefinitely throughout the contract duration.

• Post-Cancellation Grace Period: 30 days for data export before primary database decommissioning.

• Tax & Invoicing Records: Up to 7 years to comply with statutory fiscal and accounting laws.

• Diagnostic Server Logs: Automatically rotated and purged every 90 days.

9. Cookies & Local Storage Technologies

Poslytics uses necessary cookies and browser local storage strictly for operational needs:

  • • Authentication Tokens (JWT / Session Cookies): Maintain secure login state across page views.
  • • Theme Preferences: Stores dark/light mode toggle in local storage.
  • • Offline POS Cache (IndexedDB): Stores active menu catalog and queued orders locally during network interruptions.
  • • Country Dial Cache: Stores resolved IP country locally to avoid redundant API lookup calls on signup forms.

10. Your Privacy Rights & Choices

Depending on your location, you may exercise specific privacy rights regarding your personal data:

Right to Access & Portability

Request a complete copy of all personal and merchant data in machine-readable JSON/CSV format.

Right to Rectification

Update or correct inaccurate profile details directly via your merchant settings.

Right to Erasure ("Right to be Forgotten")

Request complete permanent deletion of your merchant account and associated records.

Right to Restrict or Object

Object to data processing for marketing or non-essential telemetry at any time.

11. Cross-Border Data Transfers

Poslytics operates servers and backup clusters in secure data centers worldwide. When data is transferred across international boundaries, we ensure appropriate safeguards are enacted, including Standard Contractual Clauses (SCCs) and adherence to local cross-border regulations.

12. Protection of Minors

Poslytics is a commercial business-to-business platform designed for merchants, retail operators, and authorized employees. We do not knowingly collect personal data from individuals under eighteen (18) years of age.

13. Updates to this Policy

We may periodically update this Privacy Policy to reflect advancements in technology, legal amendments, or changes in operational practices. When significant updates occur, we will post a prominent notification in the Poslytics admin dashboard and update the effective date at the top of this document.

14. Data Protection Officer & Contact

To exercise any of your data rights, submit privacy questions, or communicate with our Data Protection Officer, please contact:

Poslytics Technologies Ltd. — Privacy & Data Protection Office

Data Protection Officer: dpo@poslytics.io

General Legal Inquiries: privacy@poslytics.io

Website: https://poslytics.io