Privacy Policy
This policy explains, at a high level, how BisnesPOS handles business, customer, operational and module-specific data used within the platform. It is written to be transparent without exposing private security architecture.
Last updated: June 30, 2026
Information we collect
We may process business profile information, account users, roles, branch settings, contact details, customer records, appointments, invoices, orders, services, payments, support messages, files, device and browser metadata, audit events and technical data required to operate the platform. If the Legal Services module is enabled, the business may store sensitive legal-service records such as case details, identifiers, notes, reminders, documents and account-access information entered by authorized users.
Where information is stored
Information is stored in protected cloud environments, databases, file storage, logs and operational systems used to provide, secure, troubleshoot and support the service. We do not publish private infrastructure details in this policy because that information could reduce security. Data may be processed in locations where our service providers, infrastructure, support or security operations are available, subject to applicable legal and contractual requirements.
How data is used
Data is used to provide the service, manage business workflows, support customer relationships, send transactional communications, generate receipts and reports, improve reliability, secure accounts, troubleshoot issues and comply with applicable legal or operational obligations.
SMS and email communications
When enabled by a business, customer contact data may be used to send appointment reminders, payment links, invoice notices, service updates or other operational messages tied to the relationship with that business. Businesses are responsible for having any consent or legal basis required for their own communications. We do not share mobile opt-in information, phone numbers, or SMS consent with third parties or affiliates for marketing or promotional purposes.
Data sharing
We do not sell personal information. Limited information may be shared with service providers that help deliver the platform, including hosting, storage, messaging, payment processing, support, security, analytics and infrastructure operations. These providers are used to operate the service and are not authorized by us to sell personal information.
Retention and deletion
Information is retained only as long as reasonably needed for legitimate business, legal, accounting, tax, payment, security, fraud-prevention, dispute-resolution, backup, support or operational purposes. Eligible active records and associated files may be deleted or anonymized after an authorized request is reviewed. Backups, logs and security records may remain for a limited retention period before they age out through normal processes, and some records may be retained when required for fraud prevention, payment disputes, legal obligations, accounting, security investigations or technical integrity.
Security safeguards
We maintain reasonable administrative, technical and organizational safeguards designed to protect data, including access controls, authentication, auditing, tenant separation controls and encryption for selected sensitive workflows. Certain sensitive legal-service records, documents, identifiers, notes and credentials may receive additional encryption or restricted-access handling. No internet service can guarantee absolute security, so businesses must also manage user access carefully and avoid placing unnecessary sensitive data into free-text fields.
Deletion and correction requests
Businesses can request updates, corrections, exports or deletion review where applicable. To request deletion from active systems, contact support with the account or business name, administrator email, associated phone number, your relationship to the account and a clear description of the data you want deleted. End customers should contact the business they interacted with first regarding records created, controlled or imported by that business. We may need to verify authority before acting on a request.
Your choices
Depending on your role and applicable law, you may request access, correction, export, deletion review, communication preference changes or support with account controls. Some requests may be limited by security, legal, payment, accounting, anti-fraud, dispute, backup or technical obligations.
For privacy questions, data handling requests or compliance inquiries, contact support@bisnespos.com.