Privacy Policy
Last updated: 30 July 2026
ASPOS ("we", "us") provides a cloud point-of-sale and restaurant-management platform to food businesses ("merchants", "you"). This policy explains what data we process, why, and the choices you have. It applies to the aspos.io website, the ASPOS platform, and related services.
1. Data we process
- Account data — merchant and staff names, work email, phone number, role, and login credentials.
- Business data you enter — menus, prices, inventory, orders, tables, employees, and settings.
- End-customer data (processed on your behalf) — names, phone numbers, addresses, loyalty and wallet balances, and order history of your customers. You are the controller of this data; we process it only to provide the service.
- Payment data — card payments are processed by Stripe. We never see or store full card numbers; we store transaction references and statuses only.
- Usage and device data — logs, device/browser type, and diagnostic events used to operate and secure the service.
2. How we use data
- Provide, operate and maintain the platform (orders, payments, reporting, notifications).
- Authenticate users and protect accounts.
- Send service communications (receipts, alerts, billing notices).
- Improve reliability, security and performance.
- Meet legal, tax and accounting obligations.
3. Sharing
We do not sell personal data. We share data only with the subprocessors needed to run the service, under contractual safeguards, for example: payment processing (Stripe), cloud hosting and backups (Hetzner, Backblaze B2 — backups are encrypted before leaving our servers), transactional messaging (SMS/push providers), and error/uptime monitoring.
4. Storage, retention and security
- Data is hosted on infrastructure we operate in the EU, with encrypted off-site backups.
- We retain merchant data for the life of the account; end-customer data is retained per the merchant's configuration and legal requirements.
- We use TLS in transit, encryption for backups at rest, role-based access control, and audit logging.
5. Cookies
We use strictly necessary cookies and local storage for authentication and preferences. We do not run third-party advertising trackers.
6. Your rights
You may request access, correction, export or deletion of your personal data, subject to legal retention duties. Merchants can manage end-customer data from within the platform. Contact us at support@aspos.io for any request.
7. Changes
We will post any changes on this page and update the date above. Material changes will be announced to account owners by email.
8. Contact
ASPOS — Dubai, United Arab Emirates · support@aspos.io
