Privacy Policy

Last updated

How we handle personal information in mPOS, under New Zealand's Privacy Act 2020.

1.About this policy

[legal entity name] ("we", "us") provides mPOS, a cloud point-of-sale and back-office system used by shops in New Zealand and Indonesia. This policy explains how we handle personal information under the Privacy Act 2020.

We have two roles. When a shop records information about its own customers and staff, the shop is responsible for that information. We hold it on the shop's behalf and follow its instructions. If you are a customer or staff member of a shop, please contact the shop first. We are responsible for the account information of shop owners and of the users who sign in.

2.What we collect

We collect only what we need to run the service:

  • Account details: name, email, an optional phone number and your language preference. Accounts are created only when a shop invites you. Your password is stored in a one-way form that we cannot read.
  • Shop details: business and legal name, tax number, address, contact details, bank details shown on invoices, and logo.
  • What a shop enters: customer, staff and supplier records, including purchase history, attendance and rosters.
  • Collected automatically: sign-in sessions with IP address and device details, and a record of who did what and when.

We use one essential sign-in cookie. Your browser also stores simple display preferences on your device. We do not use advertising, analytics or tracking cookies. When you use the camera to scan barcodes, the images are processed on your device and are not sent to us.

3.How we use it

We use personal information to:

  • provide and run mPOS, including sign-in and security
  • keep a shop's sales, accounting and tax records, and work out staff commission for the shop
  • help a shop when it asks for support (our support staff's access is recorded)
  • send service emails, such as invitations, password resets and email verification
  • meet our legal obligations.

We do not sell personal information. We do not use a shop's customer information for our own marketing. We do not store card numbers. Card payments are recorded by reference only.

4.Who we share it with

We share personal information only:

  • with service providers who support our services, such as hosting and email delivery, who must protect it
  • within a shop, with the users the shop authorises, according to the permissions the shop gives them
  • with authorities, when the law requires it.

Some of our service providers are located overseas, so your information may be held and processed outside New Zealand.

5.Keeping it safe

We take reasonable steps to protect information. Passwords and till PINs are stored only in one-way hashed form, and each shop's data is kept separate. Permissions are checked on every request, and connections are encrypted. We limit repeated failed sign-in and PIN attempts, and we keep an audit trail. No system is perfectly secure, so please keep your password and PIN private.

If a privacy breach has caused serious harm, or is likely to, we will notify the Privacy Commissioner and the affected people as soon as practicable. If the breach involves information we hold for a shop, we tell the shop without delay so it can meet its own duties.

6.How long we keep it

We keep information only as long as we need it for lawful purposes. Some records are kept by law and by design:

  • financial records, such as sales, invoices, payments and accounting entries, are kept for 10 years
  • the audit trail is kept permanently and cannot be changed or deleted.

Other information is kept while the shop uses mPOS and afterwards as the shop instructs, subject to the points above. Customer and staff records can be deactivated but not erased.

7.Access and correction

You can ask to see your personal information and ask for it to be corrected (information privacy principles 6 and 7). Email [contact email]. If a shop holds the information because you are its customer or staff member, contact the shop first. Our team handles each request personally.

We will check your identity and respond within 20 working days. We correct information by amending the record or adding a correcting entry, but we do not rewrite financial history. If we do not make a correction you ask for, you can ask us to attach a statement of the correction you wanted. If something has to be kept by law, we will explain why.

8.Changes to this policy

We may update this policy from time to time. We will post the updated version on this page with a new "last updated" date. If we make a significant change, we will tell shop owners by email.

9.Contact us

If you have a question or concern about privacy, please contact our privacy officer:

[legal entity name]
[address]
Email: [contact email]
Privacy officer: [privacy officer]

If we cannot resolve your concern, you can complain to the Office of the Privacy Commissioner at www.privacy.org.nz.