Privacy policy PosMasr Cloud
Print1. Who we are
PosMasr Cloud is provided by BYTES GLUE SOFTWARE SERVICES AND SOLUTIONS - FZCO (licence 44334), DSO-THUB-G-D-FLEX-G033D, Dubai Silicon Oasis, Dubai, United Arab Emirates, United Arab Emirates. For the data of your account (who you are, what you pay) we decide how it is used. For the data of your shop (your products, sales, customers) you decide; we only process it on your behalf to run the service. This policy explains both.
2. What we collect
- Account data: the shop's name, the owner's name, e-mail address and phone number, the language you chose, your plan, invoices and payment references. We never see or keep card numbers; Stripe handles the card.
- Shop data you enter: products and prices, stock, sales and receipts, customers and suppliers, expenses, the users you invite (names, roles, till passwords stored hashed), your settings — including an e-mail (SMTP) account if you give one for the daily report; it is stored encrypted.
- Technical data: the IP address and browser or app version of each request, sign-in times, and an activity log of who did what in the account, kept for security and so you can see it on the Team page.
3. Why we use it
To run the service for you; to bill you and keep the records the law requires; to keep the service secure and prevent fraud; to answer your support requests; to send you the transactional e-mails listed below; and to meet legal obligations. We do not use your data for advertising, we do not build profiles from it, and we never sell it.
4. Where it is stored
Your data is stored on Amazon Web Services (AWS) in its Milan, Italy data centres, in DynamoDB and S3. We take a backup every day and keep backups for 35 days.
Card payments are processed by Stripe under Stripe's own privacy policy. The e-mails we send go through AWS; the daily close report of your shop goes out through your own e-mail account when you set one up.
5. How we protect it
Every connection is encrypted (TLS). Each shop's data is isolated from other shops on the server side. Secrets you give us (an SMTP password, tax-authority credentials) are stored encrypted and are never written to logs. Requests from a till are signed with a key that only that till holds. Our staff reach your data only to help you or to fix a fault, and every such access is logged.
6. Who can see it
- Your team, according to the rights you give each user.
- Our support staff, only when you ask for help or when we fix a problem in your account.
- Our processors: AWS (hosting and backups) and Stripe (card payments), each under a contract that limits them to our instructions.
- Authorities, only when the law obliges us.
Nobody else. We do not share your data with advertisers or data brokers.
7. How long we keep it
While your account is active. When a subscription ends or the trial expires, the account is read-only; its data is deleted 90 days later. If you ask us to delete the account, we wait 7 days in case you change your mind and then delete everything; backups expire within 35 days after that. Invoices and payment records are kept for the period accounting law requires (five years).
8. Your customers' and suppliers' data
The people you record in the service — customers with their phone numbers and credit balances, suppliers — are your data, and you are responsible for having the right to enter it. We process it only on your instructions, to run the service; we never contact your customers ourselves. If a customer asks you to see, correct or delete their data, the Customers page and Settings → Data let you do it, and we will help if needed.
9. E-mail we send
Only what the service needs: sign-in codes, invitations, invoices and payment receipts, reminders that a trial or a payment is due, and notices about the service (a planned outage, a change to these policies). We do not send marketing e-mail unless you ask for it, and you can always reply to tell us to stop.
11. Your rights
You can see and correct your account data in Settings, export everything from Settings → Data, and ask us to delete your account. You can also object to a use of your data or ask us questions about it by writing to legal@bytesglue.com. If you think we handled your data wrongly, you may also complain to the data-protection authority of your country.
12. Changes to this policy
We may update this policy; the date at the top says when. A change that affects you is announced by e-mail before it applies.
13. Contact
BYTES GLUE SOFTWARE SERVICES AND SOLUTIONS - FZCO (licence 44334), DSO-THUB-G-D-FLEX-G033D, Dubai Silicon Oasis, Dubai, United Arab Emirates, United Arab Emirates. Privacy questions: legal@bytesglue.com. Support: posmasr.com and the Help page inside the app.
See also: Terms of service Refund policy
