Legal

Privacy Policy

How EatsPos collects, uses, shares and protects personal data — across our platform, our websites and the EatsPos Terminal app used by restaurant staff.

Last updated:

1. Who we are

EatsPos is a restaurant management and online ordering platform operated by EATSPOS DIGITAL SERVICES LTD (company number 17209570), a company registered in England and Wales, with its registered office at 1st Floor, 6-7 Clock Park Shripney Road, Bognor Regis, England, PO22 9NH, United Kingdom. In this policy, “EatsPos”, “we”, “us” and “our” refer to that company.

For the personal data described in this policy we act either as a data controller (for example, for the restaurant staff accounts we create and for visitors to our own websites) or as a data processor on behalf of the restaurant that uses our software (for example, for the orders and customer details that pass through a restaurant’s own EatsPos account). Where we act as a processor, the restaurant is the controller and its own privacy notice applies to its customers.

2. Scope of this policy

This policy covers two distinct things:

  • A. EatsPos Terminal — our Android point-of-sale application, installed on in-store terminal hardware and used by restaurant staff to receive, accept and print orders. See section 3.
  • B. The EatsPos platform and websites — our online ordering websites, restaurant dashboard and this marketing site. See section 4.

This policy is written for the United Kingdom and reflects our obligations under the UK GDPR and the Data Protection Act 2018.

3. EatsPos Terminal (Android app for restaurant staff)

The EatsPos Terminal app is a staff tool. It is not intended for, and is not distributed to, restaurant customers or members of the public. The description below reflects exactly what the app does.

What the app collects and transmits

  • Staff account credentials. When a staff member signs in, the email address and password they enter are sent over HTTPS to our API so the account can be authenticated.
  • A Firebase Cloud Messaging (FCM) device token. The app registers a push notification token with our API so the terminal can be alerted when a new order arrives. The token identifies the device installation for push delivery only.

What is stored on the device

After a successful sign-in, the authentication token issued by our API is stored locally on the device (in the app’s private storage). It is cleared when the staff member signs out or when the session expires.

Customer order data shown on the terminal

Orders placed with the restaurant — which may include the customer’s name, delivery address, postcode, phone number and email address — are received by the app from the restaurant’s own EatsPos account so they can be displayed on screen and printed on a receipt. The app does not upload, collect or independently transmit customer data.

Third parties used by the app

The only third-party service the app relies on is Google Firebase Cloud Messaging, which delivers new-order push notifications to the device.

What the app does not do

  • No advertising and no advertising identifiers.
  • No analytics SDK.
  • No crash-reporting SDK.
  • No in-app purchases.
  • No access to device location.
  • No access to the camera, contacts or shared device storage.

Network security

All network traffic from the app uses HTTPS. Cleartext (unencrypted HTTP) traffic is disabled in release builds of the app.

4. The EatsPos platform and websites

When a customer places an order through a restaurant’s EatsPos online ordering site, we process the personal data needed to fulfil that order on the restaurant’s behalf:

  • Contact and delivery details — name, delivery address, phone number and email address.
  • Order history — the items ordered, order value, timing and status.
  • Account data — if the customer creates an account, their sign-in credentials and saved addresses.

Payments. Card payments are processed by Stripe. Card details are entered directly into Stripe’s payment interface. EatsPos does not store card numbers.

Restaurant owner and staff accounts. We hold the account details of the restaurant staff and owners who use our dashboard and terminals — name, email address, phone number where provided, and the restaurant they belong to.

This marketing website. If you submit an enquiry or trial request through eatspos.com, we receive the details you provide in that form so we can respond to you.

Cookies. Our ordering websites use cookies to keep you signed in and to remember the contents of your basket. See section 11.

5. Why we process data (lawful bases)

  • Performance of a contract (UK GDPR Art. 6(1)(b)) — to create and authenticate accounts, take and fulfil orders, take payment and provide the software our restaurant customers pay for.
  • Legitimate interests (Art. 6(1)(f)) — to keep our services secure, prevent fraud and abuse, deliver operational alerts such as new-order notifications, and respond to enquiries. We balance these interests against your rights and freedoms.
  • Legal obligation (Art. 6(1)(c)) — to keep accounting and tax records and to respond to lawful requests.
  • Consent (Art. 6(1)(a)) — for non-essential cookies and for any marketing messages, where consent is required. You can withdraw consent at any time.

6. Who we share data with

We do not sell personal data. We share it only with the parties below, and only as far as needed:

  • The restaurant you ordered from — order and delivery details are made available to that restaurant so it can prepare and deliver your order.
  • Stripe — payment processing.
  • Google (Firebase Cloud Messaging) — delivery of push notifications to restaurant terminals and order pads.
  • Our hosting and infrastructure providers — who host the platform, its databases and its file storage under written data-processing terms.
  • Professional advisers and authorities — where we are legally required to disclose data, or to establish or defend legal claims.

7. International transfers

We aim to keep personal data within the UK or the European Economic Area. Some of our service providers — including Stripe and Google — may process data outside the UK. Where that happens, the transfer is protected by an approved safeguard, such as UK adequacy regulations or the International Data Transfer Agreement / the EU Standard Contractual Clauses with the UK Addendum. You can request details of the safeguard used by contacting us at info@eatspos.com.

8. How long we keep data

  • Account data — kept while the account is active, and then for 12 months after it is closed.
  • Order and transaction records — retained for as long as UK accounting and tax law requires (generally six years).
  • Authentication tokens on a terminal — held only for the duration of the session; cleared on sign-out or session expiry.
  • Push notification tokens — held while the device remains registered to a restaurant account, and removed when it is no longer valid.
  • Website enquiries — kept only as long as needed to deal with the enquiry and any follow-up.

9. Security

  • All traffic between our apps and our API uses HTTPS.
  • Cleartext HTTP traffic is disabled in release builds of the EatsPos Terminal app.
  • Accounts are protected by token-based authentication, and sign-in attempts are rate limited.
  • Access to platform data is restricted to the restaurant the data belongs to, and internally to staff who need it.
  • Card details are handled by Stripe, a PCI-DSS compliant payment provider — we never store card numbers.

No system can be guaranteed completely secure, but we keep these measures under review and will notify you and the ICO of a personal data breach where the law requires it.

10. Your rights

Under the UK GDPR you have the right to access your personal data; to have inaccurate data corrected; to have data erased in certain circumstances; to restrict or object to processing; to data portability; and to withdraw consent where processing is based on consent.

To exercise these rights, contact us at info@eatspos.com. If your data was collected by a restaurant using EatsPos — for example, when you placed an order — we act as that restaurant’s processor, so we may forward your request to the restaurant as the controller. We will respond within one month.

11. Cookies and similar technologies

Our online ordering websites use cookies that are strictly necessary to make the service work — keeping you signed in, holding your session and remembering the contents of your basket. These do not require consent.

Where we use any non-essential cookies, we ask for your consent first and you can change or withdraw it at any time. You can also block or delete cookies through your browser settings, though parts of the ordering service may then stop working.

The EatsPos Terminal Android app does not use cookies or advertising identifiers.

12. Children

EatsPos is not directed at children. Our restaurant-facing software, including the EatsPos Terminal app, is intended for use by restaurant staff aged 18 or over, and our ordering services are intended for adults placing orders. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at info@eatspos.com and we will delete it.

13. Changes to this policy

We may update this policy from time to time — for example, if we add a feature that changes what data we process. The “Last updated” date at the top of this page always shows the current version. Where a change is significant, we will take reasonable steps to tell you before it takes effect.

14. Contact us and complaints

For any privacy question, or to exercise your rights, contact:

EATSPOS DIGITAL SERVICES LTD
Company number: 17209570
1st Floor, 6-7 Clock Park Shripney Road, Bognor Regis, England, PO22 9NH, United Kingdom
info@eatspos.com

If you are unhappy with how we have handled your personal data, you can complain to the UK Information Commissioner’s Office at ico.org.uk, or by calling 0303 123 1113. We would appreciate the chance to resolve your concern first.