Privacy policy
NexudoPOS is a point-of-sale for businesses. This policy explains what we collect from the shops that use it, why, and the choices you have. The short version: your shop's data belongs to your shop, we never sell it, and card numbers never touch our servers.
What we collect
Account data: the owner's name and email address. Sign-in uses one-time codes sent to that email; no password is stored.
Store data: the store name, address, phone, VAT registration (TRN) and settings you enter.
Operational data your shop chooses to sync on Cloud plans: sales, catalog, inventory, bookings, and staff names, roles and commission settings.
Billing state: your plan, its renewal date and a Stripe customer reference. Never card numbers.
Technical data needed to run the service: device model, app version and diagnostic logs.
What never leaves the till
Staff PINs are stored only on the register itself, hashed. They are never uploaded, so nobody outside your shop can learn them, including us.
On the Local plan, all operational data (sales, catalog, staff, bookings) stays on the tablet. Only your store details are kept in the cloud as the license identity.
How we use data
To run the service: syncing between registers, cloud backup, the owner app, receipts and reports.
To bill you, through Stripe, and to keep your subscription state accurate.
To support you and to keep the service safe: abuse prevention, debugging and audit trails.
We do not sell personal data and we do not run third-party advertising.
Payments
All payments are processed by Stripe. Card details are entered into Stripe's own secure fields and never pass through or rest on our servers. We receive only the payment outcome and a customer reference.
Sharing
We share data only with the processors that run the service (cloud hosting and Stripe for payments), each bound by contract to use it solely for us, and with authorities where the law requires it.
Retention and deletion
We keep your data, and the backups of it, while your account is active.
When you close your account, or on request, we delete your cloud data within 30 days, except records we must keep by law (for example tax records).
Security
Data is encrypted in transit. Every business's rows are isolated from every other business at the database level. Access inside Nexudo is limited to what operating the service requires.
Your rights
You can access, correct, export or delete your shop's data at any time by contacting us. If you are in a jurisdiction with data-protection rights (including the UAE), we honour them.
Changes
If this policy changes materially, we will tell you in the app or by email before the change takes effect.
Questions? Write to support@nexudo.tech.