Who is responsible
ZenPos is responsible for business account, licensing, billing, device and support information. For customer, order and staff information entered by a restaurant, that restaurant decides why the information is used and ZenPos provides the software service on its behalf.
Information we process
- Business and account details, including business name, owner contact details and login credentials.
- Subscription, invoice and payment status. Card details are entered into Stripe and are not stored by ZenPos.
- Menus, prices, settings, staff names and permissions, orders, tables, receipts, stock and reports used to run the EPOS.
- Gift voucher purchaser and recipient details, voucher values, balances, expiry dates and redemption history.
- Device identifiers, app and operating-system versions, IP address, licence status, diagnostic logs and crash information.
- Support messages, callback details and recent diagnostics submitted with a support request.
Why we use it
We use this information to provide and secure ZenPos, synchronise authorised devices, process subscriptions, deliver vouchers, prevent fraud and duplicate redemption, provide support, diagnose faults, comply with legal obligations and improve service reliability. We do not sell personal information or use it for third-party behavioural advertising.
Camera and local network
Camera access is optional and used only when a user chooses to scan a voucher QR code. Local-network access lets authorised ZenPos devices exchange live order and table updates and connect to configured printers. ZenPos does not use these permissions for advertising or location tracking.
Service providers and international processing
We use service providers only where needed to run the product, including hosting and email delivery, Stripe for billing, and Apple or Google when a voucher is added to a wallet. We require providers handling ZenPos data to use it only for the agreed service and to provide the same or equivalent protection described in this policy, alongside their own privacy terms and applicable safeguards.
Retention and security
Account and operational information is retained while the ZenPos account is active and as needed for support, security and legal obligations. A verified deletion removes the tenant's data from the live ZenPos platform and signs out its devices. Routine infrastructure backups may take a limited period to rotate out. Stripe and other providers may retain transaction records where tax, fraud-prevention or legal rules require it.
ZenPos uses tenant-scoped access controls, authenticated device licences, encrypted HTTPS connections, restricted administration and logging. No internet service can guarantee absolute security, so suspected misuse should be reported promptly.
Your choices and rights
Business owners can update business information in ZenPos, request a copy or correction, object to or restrict certain processing where applicable, withdraw consent for optional processing, and permanently delete the business account. Optional features can be disabled in the business settings, or consent can be withdrawn by contacting privacy support. Staff or restaurant customers should normally contact the relevant restaurant first for data held in that restaurant's ZenPos account.
Account deletion
The owner can delete the complete ZenPos business account without contacting support. Deletion cancels future ZenPos billing, releases every device licence and permanently removes tenant menus, staff, orders, vouchers, settings and operational records.
ZenPos