Privacy Policy
Last updated:
1. Who we are
DistrxPos is a point of sale, back office and online store platform operated by distrx. This policy explains what data we handle when you use DistrxPos, how we use it, who we share it with, and the choices you have. It should be read together with our Terms of Service.
Two kinds of people meet DistrxPos. Businesses and their staff use it to sell; for their account details we decide how the data is used. A business’s own customers — the people it sells to at the counter or through its online store — are that business’s customers, not ours: the business decides what is collected and why, and we handle that data on its behalf and on its instructions.
2. Data we handle
- Account and staff data — the business’s name, address, time zone and contact details; each staff member’s name, email address, role and home store; passwords and manager PINs, stored only as hashes; and sign-in records such as the time, IP address and browser.
- Business records — products and prices, stock and its movements, sales, returns, invoices, shifts and cash counts, offers, coupons, gift cards, tax rates and reports.
- Customer data, on a business’s behalf — names, email addresses, phone numbers and delivery addresses; purchase history; store-credit and points balances; gift cards; a tax-exemption certificate number where one is given; and the sign-in codes sent to a shopper of an online store.
- Age checks — when a sale includes an age-restricted product, we record that the check was made, how, and by which staff member. We do not keep the customer’s date of birth or a copy of any ID.
- Messages — the receipts, order updates and sign-in codes a business sends its customers by email or text, and whether they were delivered.
- Plan and payment records — the plan an organization is on and the payments recorded for it. We do not store card numbers.
- Usage data — feature usage, device and browser information, and application logs used to keep the service secure and reliable.
3. How we use data
- to deliver the service: ringing up and recording sales, keeping stock, running the online store, sending receipts and order updates, and producing reports;
- to secure the service: authentication, the audit trail of who changed what, abuse prevention and debugging;
- to run plans: trials, renewals and the record of payments;
- to communicate with businesses about the service — important notices, and product updates you can opt out of;
- to improve DistrxPos using aggregated, de-identified usage patterns.
We do not sell personal data, we do not use a business’s customer data to advertise to those customers, and we never show one business’s data to another — even when the same person shops at several of them.
4. Who we share data with
Running a shop and an online store needs a few trusted services. Data is shared only as far as each one needs:
- Messaging — the email address or phone number and the content of a receipt, order update or sign-in code go to the service that delivers it.
- Online payments — when a shopper pays by card in an online store, the order amount and reference go to the payment service. Card details are entered with that service and do not pass through or rest on our systems.
- Delivery — for an order that is delivered, the recipient’s name, address and phone number go to the delivery service.
- File storage — product photos, logos and other images are kept in object storage.
- Infrastructure — hosting, database and monitoring providers that run the service.
- AI assistants — only if an admin or a manager of a business connects an assistant under AI access: it can then read that business’s data and, if they allowed it, change some of it — never with more than that person’s own permissions. Nothing is connected unless they set it up, they can disconnect it at any time, and every action is logged.
We may also disclose data when the law requires it, or to protect the rights and safety of our users and the service. Each provider handles data under its own contractual safeguards.
5. Storage and security
Data is stored on managed infrastructure and encrypted in transit. Each business’s data is kept apart from every other’s on every read and write. Staff see only what their role allows, sensitive actions at the till need a manager’s approval, and when a member of our team works inside a business’s account to help, it is recorded and time-limited. Passwords and PINs are stored using modern hashing. No system is perfectly secure, but we design for least privilege and review access regularly. If we learn of a breach affecting your data, we will notify you without undue delay.
6. Retention and deletion
We keep data for as long as an organization’s account is active or as needed to provide the service. Sales, invoices and tax records are kept because a business is usually required to keep them. When an organization closes its account, its data is made available for export for a reasonable period and then deleted from production systems, with backups expiring on their rotation schedule. Logs and diagnostic data are kept for a limited period and then deleted or de-identified. To ask for an account or a record to be deleted, email distrx.io@gmail.com.
7. Your rights
Depending on where you live, you may have the right to access, correct, export, restrict or delete personal data held about you, and to object to certain processing. If you are a customer of a business that uses DistrxPos, that business controls your data: ask it first, and we will help it honour your request. If you are a business or a member of staff, email distrx.io@gmail.com.
8. Cookies and storage on your device
DistrxPos uses a small amount of browser storage to keep you signed in, remember preferences such as your theme and which till a device is, and keep the app fast. A till that sells without a connection keeps a copy of the catalog and any sales not yet sent on that device until it reconnects. An online store keeps a shopper’s cart and sign-in on their device. We do not use third-party advertising cookies or cross-site trackers. A business may add its own scripts — analytics or a chat widget — to its back office or its online store; those are governed by that business’s and that provider’s policies.
9. International transfers
Our providers may process data in countries other than yours. Where that happens, transfers rely on appropriate safeguards such as standard contractual clauses or equivalent mechanisms.
10. Children
DistrxPos is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, contact us and we will delete it.
11. Changes to this policy
We may update this policy as the product or the law changes. Material changes are announced in the product or by email before they take effect, and the “Last updated” date above always reflects the current version.
12. Contact
Privacy questions, requests or concerns: distrx.io@gmail.com.
This document is a general template provided for convenience and should be reviewed by legal counsel before being relied upon.