Privacy Policy

Last updated: January 31, 2026

Table of Contents

  • 1. Introduction
  • 2. Information We Collect
  • 3. How We Use Your Information
  • 4. Data Sharing and Disclosure
  • 4a. Third-Party Integration Data
  • 5. Data Security
  • 6. GDPR Compliance
  • 7. Cookies and Tracking
  • 8. Your Rights
  • 9. Contact Us

1. Introduction

SmartPOS AI ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our point of sale platform and related services.

2. Information We Collect

Account Information

When you create an account, we collect:

  • Name and email address
  • Business name and contact information
  • Payment and billing information
  • User preferences and settings

Transaction Data

When you use our POS system, we process:

  • Sales transactions and receipts
  • Product and inventory information
  • Customer data you input
  • Employee access records

Technical Data

We automatically collect:

  • IP address and device information
  • Browser type and version
  • Usage patterns and feature interactions
  • Error logs for troubleshooting

3. How We Use Your Information

We use your information to:

  • Provide and maintain our services
  • Process transactions and send related information
  • Send administrative information (updates, security alerts)
  • Respond to inquiries and provide customer support
  • Improve our services and develop new features
  • Detect and prevent fraudulent activity
  • Comply with legal obligations

4. Data Sharing and Disclosure

We do not sell your personal information. We may share information with:

  • Service Providers: Third parties that perform services on our behalf (payment processors, hosting providers)
  • Legal Requirements: When required by law or to protect our rights
  • Business Transfers: In connection with a merger, acquisition, or sale of assets

4a. Third-Party Integration Data

When you connect third-party services (such as QuickBooks Online, PayPal, WooCommerce, or Shopify) to your SmartPOS AI account, we access and process data from those services on your behalf.

What Data We Access

Depending on the integration, we may access:

  • QuickBooks Online: Sales receipts, invoices, customers, items/products, chart of accounts, and company information
  • PayPal: Transaction history, invoices, customer information, and account balance
  • WooCommerce/Shopify: Products, orders, customers, and inventory data

How We Use Integration Data

All data retrieved from third-party integrations is:

  • Used solely for your benefit to provide synchronization and reporting features within SmartPOS AI
  • Not shared with any other customers, third parties, or external services
  • Not sold or used for advertising, analytics, or any purpose other than providing the Service to you
  • Stored securely in our database, isolated by your tenant account

Token and Credential Storage

OAuth tokens, API keys, and other credentials used to connect to third-party services are:

  • Stored securely in our database and are not accessible to other users
  • Used only to maintain the active connection and perform data synchronization
  • Immediately revoked and deleted when you disconnect an integration
  • Automatically refreshed as needed to maintain the connection (e.g., OAuth token refresh)

Disconnection and Data Deletion

When you disconnect a third-party integration:

  • All access tokens and credentials are immediately revoked and permanently deleted
  • No further data is retrieved from the disconnected service
  • Previously synchronized data may remain in your SmartPOS AI account for historical continuity
  • You may request complete deletion of all integration-related data by contacting support@smartposai.com

5. Data Security

We implement appropriate security measures including:

  • SSL/TLS encryption for data in transit
  • Encryption at rest for sensitive data
  • Regular security audits and penetration testing
  • Access controls and authentication
  • Regular backups and disaster recovery procedures

6. GDPR Compliance

For users in the European Economic Area (EEA), we comply with GDPR requirements:

  • Lawful Basis: We process data based on contract performance, legitimate interests, and consent
  • Data Minimization: We only collect data necessary for our services
  • Data Portability: You can request your data in a portable format
  • Right to Erasure: You can request deletion of your data
  • Data Protection Officer: Contact us at info@smartposai.com

7. Cookies and Tracking

We use cookies and similar technologies for:

  • Essential Cookies: Required for the platform to function. These include session management, security tokens, and basic site functionality. Cannot be disabled.
  • Analytics Cookies: Help us understand how visitors interact with our website by collecting anonymous usage data. This helps us improve our services. Optional.
  • Preference Cookies: Remember your settings and preferences such as language selection, theme, and display options for a personalized experience. Optional.

When you first visit our website, a cookie consent banner allows you to accept all cookies, reject non-essential cookies, or customize your preferences. You can change your cookie preferences at any time by clicking the cookie icon in the bottom-left corner of any page, or by clicking the button below.

Manage Cookie Preferences

You can also manage cookies through your browser settings. Note that disabling essential cookies may prevent the website from functioning properly.

8. Your Rights

You have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of your data
  • Object to processing of your data
  • Data portability
  • Withdraw consent at any time

9. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

  • Email: info@smartposai.com
  • Address: SmartPosAi LLC, Dubai Silicon Oasis, DDP Building A2, Dubai, UAE

For GDPR-related inquiries: admin@smartposai.com