Privacy Policy
Last updated: 13 July 2026
This policy explains how PrintaPos handles personal information when you visit our website, create an account, install the Agent, capture receipts, use the dashboard, or contact us.
1. Information we collect
| Category | Examples |
|---|---|
| Account information | Name, email address, password hash, account language, account status, and login/security information. |
| Business and device information | Restaurant or venue name, vendor ID, timezone, POS type, device labels and tokens, Agent version, device status, printer channel, and health reports. |
| Receipt data | Raw printer output, receipt identifiers and times, printer details, order items, prices, taxes, payment method, table or zone, customer or employee names, and any other information printed on a receipt. |
| Derived information | Orders, invoices, menu items, employees, classifications, totals, and other information created by automated receipt extraction. |
| Contact information | Name, email, message, IP address, and submission time when you use a contact form. |
| Technical information | IP address, browser and device details, request times, error and security logs, and information stored in the browser as described in the Cookie Policy. |
2. How we collect information
We receive information directly from you, from other users authorised by your business, from the PrintaPos Agent installed on your POS computer, and automatically when you use our website, dashboard, or APIs.
3. Why we use information
- to create and protect accounts and authenticate devices;
- to capture, store, decode, extract, display, and report receipt information;
- to operate, troubleshoot, secure, and improve the Service;
- to enforce usage limits and prevent abuse or fraud;
- to reply to questions and provide support;
- to meet legal, accounting, security, and dispute-resolution obligations; and
- to send service communications and, where permitted, information you have requested.
Depending on the context and applicable law, we rely on performance of a contract, steps requested before entering a contract, legitimate interests in operating and protecting the Service, compliance with law, and consent where consent is required.
4. Receipt data and your responsibilities
Receipt data can contain personal information about customers and staff. Customers using PrintaPos are responsible for ensuring that receipt capture is lawful, providing required privacy notices, limiting receipt content where appropriate, responding to data-subject requests, and giving us lawful instructions. Do not upload sensitive information that is not needed for the Service.
5. Automated extraction
PrintaPos may send receipt content to configured AI providers to convert printer data into structured business records. This processing can produce errors and is not used by PrintaPos to make decisions that have legal or similarly significant effects on individuals. Customers should review important extracted information.
6. When we share information
We may share only the information necessary with:
- hosting, database, security, monitoring, and infrastructure providers;
- AI processing providers used for receipt extraction, currently including OpenRouter and model providers routed through it;
- Google reCAPTCHA, which helps protect signup and contact forms from abuse;
- Telegram, when configured, to notify our support team of contact messages;
- professional advisers, insurers, auditors, or transaction partners under appropriate confidentiality duties; and
- courts, regulators, or law enforcement when legally required or necessary to protect rights and security.
We do not sell personal information.
7. International transfers
Some service providers may process information outside your country or the European Economic Area. Where required, we use an approved transfer mechanism and appropriate safeguards. Provider privacy terms may also apply to their processing.
8. How long we keep information
We keep information for as long as needed to provide the Service, maintain security and records, resolve disputes, and comply with law. Receipt and account information is normally retained while the customer account is active. Removing a venue in the dashboard may hide and deactivate it while retaining data for recovery. Individual receipts can be deleted from the dashboard.
Contact messages and technical logs are retained only as long as reasonably needed for support, security, and record keeping. Deleted information may remain in restricted backups for a limited period before normal rotation removes it.
9. Security
We use access controls, encrypted network connections, password hashing, scoped device credentials, rate limits, backups, and other reasonable organisational and technical measures. No electronic service can be guaranteed completely secure. You are responsible for securing your account, POS computer, and device keys.
10. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or obtain a copy of your personal information; object to certain processing; withdraw consent; and complain to a data-protection authority. These rights may be limited by law and by the role PrintaPos has for the relevant data.
For information contained in a business customer’s receipts, contact that business first. It is normally the controller and will tell us what action to take. For PrintaPos account, website, or contact data, send a request through our contact form. We may need to verify your identity.
11. Children
The Service is designed for businesses and is not directed to children. We do not knowingly create accounts for anyone under 18.
12. External links
Our website may link to services we do not operate. Their privacy practices are governed by their own policies.
13. Changes to this policy
We may update this policy when the Service, our providers, or applicable law changes. We will post the current version here and update the date above. We will provide additional notice where required.
14. Contact and complaints
For privacy questions or requests, use the PrintaPos contact form. You may also complain to the data-protection authority in your country.