Skip to content
Legal

Privacy Policy

This policy explains what personal data we handle, why, and what control you have over it. It covers two distinct situations: data about you as our customer, and data about your customers and staff that you process using SumPOS. Those are treated differently, and the distinction matters.

Last updated 1 September 2026Effective 1 September 2026

1. Who we are and the two roles we play

SumPOS Technologies operates the SumPOS platform. For questions about this policy, contact privacy@sumpos.com.

When we are the controller

For information about you and your team as our customer - your account details, billing information, support conversations, marketing preferences and how you use our website and product - we are the data controller. We decide why and how that data is processed, and this policy governs it.

When we are the processor

For the data you put into SumPOS about your own customers, suppliers and employees - names, phone numbers, purchase histories, loyalty balances, payroll records - you are the controller and we are your processor. We process that data only on your documented instructions, which are the instructions implicit in your use of the product's features, plus anything separately agreed in a data processing agreement.

2. What we collect

Information you give us

  • Account and identity: name, business name, email address, telephone number, job role, country.
  • Billing: billing address, tax registration numbers, and payment method details. Full card numbers are handled by our payment processor and are never stored on our systems.
  • Content you submit: product catalogues, transactions, inventory, financial records, and any other Customer Data you enter or import.
  • Communications: the content of support tickets, emails, chat messages, demo requests and survey responses.
  • Recruitment: if you apply for a role, the information in your application and any assessment materials.

Information we collect automatically

  • Usage data: features used, actions taken, timestamps and performance metrics, used to operate and improve the product.
  • Device and technical data: IP address, device identifier, operating system, application version, browser type, screen size and crash diagnostics.
  • Log data: requests to our servers, including endpoints called, response codes and latency.
  • Cookies and similar technologies on our website - see our Cookie Policy for the full detail and your choices.

Information from third parties

  • Payment processors confirm whether a payment succeeded and may share limited fraud signals.
  • Integration partners you connect - such as e-commerce platforms or messaging providers - return data you have authorised them to share.
  • Publicly available business information used to verify a company during onboarding or to prevent fraud.

We do not seek to collect special category data (such as health, biometric or religious data) about you as our customer. Where you use biometric attendance features within the product, that data belongs to your processing as controller, and you are responsible for the lawful basis and any consent required.

3. Why we use it, and our lawful bases

PurposeLawful basis
Providing the Platform, your account and supportPerformance of our contract with you
Billing, collections and financial record-keepingContract, and legal obligation for tax and accounting records
Securing the Platform, preventing fraud and abuseLegitimate interests in protecting our service and our customers
Improving the product and diagnosing faultsLegitimate interests in operating and improving our service
Service announcements about outages, changes and securityContract, and legitimate interests in keeping you informed
Marketing about our own products to business contactsLegitimate interests, or consent where required by local law
Responding to legal requests and enforcing our termsLegal obligation, and legitimate interests in establishing or defending claims

Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights, and we have concluded they are not. You can ask us for our reasoning, and you can object - see section 8.

4. Data you process through SumPOS

When you use SumPOS to record a sale, add a loyalty member, run payroll or send a WhatsApp receipt, you are processing personal data about other people. In that processing:

  • You determine the purpose and means. You are responsible for having a lawful basis, for giving those individuals appropriate notice, and for obtaining consent where the law requires it - particularly for marketing messages.
  • We process only on your instructions, and only to provide, secure and support the Service.
  • We apply appropriate technical and organisational security measures, described in section 7.
  • We will assist you, so far as reasonably possible, in responding to requests from individuals and in meeting your own obligations, including breach notification.
  • We will not use that data for our own purposes, will not sell it, and will not use it to train third-party AI models.
  • On termination we will delete or return it in accordance with our Terms.

Customers subject to the GDPR, UK GDPR or an equivalent regime can request our standard data processing agreement, which includes the required contractual terms and our current subprocessor list.

5. Who we share data with

We do not sell personal data. We share it only in the following circumstances:

  • Service providers and subprocessors who help us operate the Platform - cloud hosting, error monitoring, email delivery, payment processing, customer support tooling and analytics. Each is bound by contract to process data only on our instructions and to protect it appropriately.
  • Integration partners you connect, and only the data necessary for that integration to function.
  • Government and tax authorities, where you have configured an e-invoicing integration and the data is transmitted as part of your compliance obligation.
  • Professional advisers such as lawyers, auditors and accountants, under duties of confidentiality.
  • Acquirers, in connection with a merger, acquisition or sale of assets - with notice to you and no reduction in the protection applied to your data.
  • Law enforcement or regulators, where we are legally compelled. We review every such request, push back on those that are overbroad, and notify you unless legally prohibited.

A current list of subprocessors is available on request, and we will give notice before adding a new one that processes Customer Data.

6. International transfers

We operate internationally, and personal data may be transferred to and processed in countries other than your own. Where we transfer personal data out of the European Economic Area, the United Kingdom or Switzerland, we rely on an appropriate safeguard - the European Commission’s Standard Contractual Clauses with the UK Addendum where applicable, an adequacy decision, or your explicit consent where permitted. EU and UK customers can request our transfer impact assessment.

Customer Data for EU and UK customers is hosted in the European Union by default. Enterprise customers can pin data to a specific region, or deploy entirely within their own infrastructure, where regulation or preference requires it.

7. How we protect data

  • Encryption in transit using TLS 1.3, and encryption at rest for stored data including local databases on devices.
  • Role-based access control within the Platform, scoped by branch and module.
  • Tamper-evident audit logging of transactions, overrides and administrative actions.
  • Least-privilege internal access to production systems, granted on justification, time-bound and logged.
  • Automated encrypted backups with tested restore procedures.
  • Device registration and the ability to revoke or remotely wipe a lost device.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you without undue delay and, where we act as your processor, within 72 hours of confirming it - with what we know, what we do not yet know, and what we are doing about it.

8. Your rights

Depending on where you live, you may have the following rights over personal data we hold about you as a controller:

  • Access - obtain a copy of the personal data we hold about you.
  • Rectification - have inaccurate or incomplete data corrected.
  • Erasure - have your data deleted where we no longer have a lawful reason to keep it.
  • Restriction - ask us to limit how we use your data while a concern is resolved.
  • Portability - receive your data in a structured, machine-readable format, or have it sent to another provider.
  • Objection - object to processing based on legitimate interests, and to direct marketing at any time and without qualification.
  • Withdraw consent - where we rely on consent, withdraw it at any time without affecting prior processing.
  • Complain - lodge a complaint with your local data protection authority. We would appreciate the chance to address it first.

To exercise a right, email privacy@sumpos.com. We will respond within thirty days, or tell you if we need longer and why. We may need to verify your identity before acting. We do not charge for these requests unless they are manifestly unfounded or excessive.

If your request concerns data held by a business that uses SumPOS - for example a shop's record of your purchases - please contact that business directly. They are the controller of that data; we will forward the request to them if you cannot reach them.

9. If you are in the United States

Residents of California and of other US states with comprehensive privacy laws have specific rights, which we honour regardless of whether we are strictly required to.

  • Know - what categories of personal information we have collected, the sources, the purposes, and who we disclosed it to.
  • Access and portability - obtain a copy in a readily usable format.
  • Delete - request deletion, subject to exceptions such as records we must keep for tax or accounting law.
  • Correct - have inaccurate personal information rectified.
  • Limit - restrict the use of sensitive personal information, though we do not use it for purposes requiring this.
  • Non-discrimination - we will not charge you more or give you a worse service for exercising a right.

We honour Global Privacy Control signals sent by your browser as a valid opt-out request. To exercise any right, email privacy@sumpos.com. An authorised agent may act for you with written permission that we can verify.

10. How long we keep data

  • Account and Customer Data: for the life of your account, then for ninety days after closure to allow export, then deleted from active systems.
  • Backups: purged on a rolling cycle, ordinarily within thirty-five days of deletion from active systems.
  • Billing and financial records: retained for the period required by applicable tax and company law, typically six to ten years.
  • Support conversations: three years from the last message, so we have context if an issue recurs.
  • Marketing contact records: until you unsubscribe, plus a minimal suppression record so that we do not contact you again by mistake.
  • Website analytics: aggregated after twenty-six months.
  • Unsuccessful job applications: twelve months, unless you ask us to keep them for future roles.

11. Marketing and communications

We send two kinds of messages. Service messages - outages, security notices, billing, changes to terms - are part of providing the Service and cannot be opted out of while you have an account. Marketing messages about new features, guides and events can be opted out of at any time, with one click in any message or by emailing us.

We do not sell or rent your contact details to anyone, and we do not send messages on behalf of third parties.

12. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. We use automated systems for fraud and abuse detection, but a person reviews any decision to suspend or terminate an account before it is acted on.

13. Children

The Platform is business software and is not directed at children. We do not knowingly collect personal data from anyone under 16 in our capacity as controller. If you believe a child has provided us with personal data, contact us and we will delete it.

14. Changes to this policy

We will update this policy as our practices or the law change. Where a change is material, we will notify you by email and in the product at least thirty days before it takes effect. The date at the top of this page always reflects the current version, and we keep prior versions available on request.

15. Contact us

Privacy questions, requests and complaints: privacy@sumpos.com. Everything else: hello@sumpos.com. A person reads both.