Skip to content

Privacy Policy

Last Updated: July 30, 2026

This Privacy Policy explains how Trust POS ("the Service") handles information. Trust POS is business software licensed to shops and organisations ("Stores"). A Store's own records — its customers, stock, and accounts — belong to that Store, which is the controller of that data; Trustworth Labs processes it on the Store's behalf.

1. Information We Collect

A. Account Data

  • Staff Accounts: Name, email address, password hash, and role (owner, admin, or staff) for each person a Store gives access to.
  • Store and Organisation Data: Store name, business type, enabled modules, and subscription tier.

B. Store Records

Records a Store enters in the course of its business, which may include customer names and contact details, items and stock levels, sales, invoices, expenses, cheques, balances owed, supplier details, and employee and payroll entries. Where a Store enables a vertical module, this may include trade-specific data — for the optical module, prescription measurements.

C. Technical and Usage Data

  • Request Metering: Counts of API calls per organisation per calendar month, used to apply subscription limits.
  • Usage Analytics: An event log of actions taken in the app. Depending on the capture level configured for the deployment, events may include the contents of the records involved. The default retention period for this log is 365 days.
  • Session Data: Access and refresh tokens, and basic device and browser information.

2. How We Use Information

  • To provide the Service's selling, stock, customer, staff, and accounting features.
  • To authenticate staff and keep each Store's data separated from every other Store's.
  • To allocate invoice and receipt numbers, and to compute reports on request.
  • To meter usage against the Store's subscription tier and enforce its limits.
  • To diagnose faults and improve reliability and performance.

We do not sell Store records, and we do not use them to build advertising profiles.

3. Data Separation and Security

  • Tenancy: Every data request is pinned to the signed-in Store at the data-access layer. There is no interface through which one Store can read another's records.
  • Authorisation: Payloads are validated against strict schemas that discard unrecognised fields, so a client cannot assign itself a different Store, role, or document number.
  • Transport: Data is encrypted in transit using industry-standard protocols.
  • Tokens: Access tokens are short-lived; refresh tokens are held in secure storage.

4. Hosting and Sub-Processors

The Trust POS API is self-hosted. Where Trustworth Labs operates a deployment on a Store's behalf, infrastructure providers for hosting, database, and cache services act as sub-processors. Where a Store hosts its own deployment, Trustworth Labs does not receive that Store's records at all.

5. Data Retention and Export

  • Store records are retained for as long as the Store's account is active.
  • A Store may export its records as spreadsheets at any time from within the app.
  • On termination, a Store may request export or deletion of its data. Usage analytics expire on the configured retention schedule.

6. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, export, or delete personal data held about you. If you are a customer or employee of a Store, that Store controls your records — direct such requests to the Store, which we will assist as its processor.

7. Children's Privacy

The Service is business software and is not directed at children. We do not knowingly collect personal information from children.

8. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to Store administrators.

9. Contact Us

For questions about this Privacy Policy, contact: abdalladimes@gmail.com