Pitis POS (“we”, “our”, “the app”) is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information.
1. Information We Collect
1.1 Data You Enter
When you use Pitis POS, you enter business and operational data such as:
- Business name, Tax Identification Number (TIN), SSM number, MSIC code, and address
- Product names, prices, and categories
- Sales transactions, payment records, and stock movements
- Staff names, roles, and PIN credentials (stored as hashed values)
This data is stored locally on your device and is the primary source of truth. Nothing leaves your device unless you sign in to a cloud account — see section 1.3 for exactly what is sent when you do.
1.2 Device Permissions
Pitis POS requests the following device permissions:
- Bluetooth: Used solely to connect to and communicate with Bluetooth thermal printers and cash drawers. We do not collect or transmit Bluetooth data.
- Camera: Used for two purposes: (a) barcode scanning when adding products to a sale — these frames are processed on your device in real time and are never saved; and (b) taking an optional product photo when you create or edit a product. Product photos you take or choose from your gallery are saved on your device. Once you are signed in to a cloud account, product photos are also uploaded to your own private cloud storage (Cloudflare R2) so they appear on your other devices. Photos are stored under a folder tied to your account and can only be read with your own signed-in session — no other merchant can access them.
1.3 Cloud Sync & Backup (Optional)
Pitis POS includes optional encrypted cloud sync and backup, powered by Supabase for your records and Cloudflare R2 for product photos:
- Signing in to a cloud account is what starts cloud sync — until you do, nothing leaves your device. Once signed in, your catalogue, customers, staff accounts and product photos are kept in sync so they reach your other devices, and completed sales are uploaded whenever you are online.
- On iPhone and iPad you can pause all of that at any time with the Cloud Backup switch in Settings. On Android, signing out stops it.
- This data is used to back up your business and keep your catalogue, customers, staff accounts, product photos and sales in sync across your own devices — and, if you switch on QR Menu, to power your self-order menu (see section 1.4).
- We do not sell, share, or analyse your backup data for any purpose.
1.4 QR Self-Ordering (Optional)
If you switch on the QR Menu, two extra things happen — independently of the Cloud Backup switch, because the feature cannot work without them:
- Your product names, prices and categories are uploaded so the web menu can display them. No cost prices are included.
- When a diner places an order from their own phone, the name and phone number they enter are sent to your account along with the order, and saved to your customer list.
Turning QR Menu off stops both. If you use this feature, you are responsible for telling your own diners how you handle their details.
2. How We Use Your Information
We use your information only to:
- Operate the POS features of the app (sales, stock, reports, receipts)
- Restore your data to a new device, and keep your other devices up to date (if you are signed in)
- Contact you about billing when the paid plan is introduced (email only, with advance notice)
We do not use your data for advertising, profiling, or any purpose beyond operating the app.
3. Data Sharing
We do not sell, rent, or share your personal data with third parties, except:
- Supabase (cloud backup): Acts as a data processor under our instructions for your account, sales and catalogue data. Encrypted in transit and at rest.
- Cloudflare (product photos): Acts as a data processor for product photos only, stored in Cloudflare R2 once you are signed in to a cloud account. Photos are kept under a folder tied to your account and are only served to your own signed-in session.
- Legal requirements: We may disclose data if required by Malaysian law or a valid court order.
4. Data Retention
- Local data: Remains on your device until you uninstall the app or reset your data from Settings.
- Cloud backup data: Retained for as long as your account is active. You may delete your backup data at any time from Settings.
5. Data Security
We take reasonable measures to protect your data:
- Local SQLite database is stored in the app's protected sandbox — iOS Data Protection on iPhone and iPad, and encrypted app storage (SQLCipher) on Android.
- Staff PINs are never stored in plain text. They are stored as PBKDF2-HMAC-SHA256 hashes with a unique random salt per PIN and 100,000 iterations, and are compared using a constant-time check. PIN entry is rate-limited after repeated incorrect attempts.
- Cloud backup data is transmitted over HTTPS and encrypted at rest.
6. Children's Privacy
Pitis POS is intended for business use by adults. We do not knowingly collect personal data from children under 13.
7. Your Rights
You have the right to:
- Access all data you have entered into the app (it's on your device).
- Delete your local data at any time by resetting the app or uninstalling it.
- Request deletion of cloud backup data by contacting us at hello@pitis.app.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via the app or by email. Continued use of the app after changes constitutes acceptance of the updated policy.
9. Contact Us
If you have questions about this Privacy Policy or how your data is handled, please contact:
Pitis POS
Email: hello@pitis.app
Website: pitis.app