Privacy & Data Security

Privacy Policy

Last Updated: August 12, 2026

1. Introduction

At Prum POS, we respect your privacy and are committed to protecting your personal and operational business data. This Privacy Policy explains how our application collects, uses, stores, and safeguards your information when you use our mobile software.

2. Information We Collect

A. Account & Profile Information: When signing in (e.g. via Google Sign-In or Apple Sign-In), we receive basic authentication profile details such as your name, email address, and user identifier.

B. Operational Business Data: Products, categories, sales orders, inventory stock levels, customer profiles, payment options, and tax configuration presets created inside the app.

C. Device Permissions & Media:

  • Camera Access: Used exclusively for scanning product barcodes, QR codes, and member account identity codes.
  • Photo Library Access: Used only when you choose to upload product images, business logos, or payment option logos ("Prum POS accesses your photos to let you add product images and business logos").
  • Bluetooth & Location: Required for connecting to local ESC/POS thermal receipt printers and scanning nearby printers.

3. Local Storage & Offline Cloud Sync

Prum POS utilizes an offline-first architecture. All transaction logs and business records are stored locally on your device in a secure SQLite database. When internet connectivity is available, data syncs securely over encrypted HTTPS connections to your backend storage server.

4. Security of Your Information

Authentication credentials and access tokens are stored securely in device hardware keychains (iOS Keychain / Android Encrypted Shared Preferences). We implement industry-standard encryption protocols during data transit and rest.

5. Data Retention & Account Deletion Rights

You retain full control over your data. You may request permanent deletion of your account and associated business records via the in-app account settings. Upon requesting deletion, data is marked for permanent erasure after a 30-day safety period, during which you can restore access if requested.

6. Third-Party Services

We do not sell your personal or business data to third parties. We use trusted infrastructure providers (such as Cloudflare Workers and Turso Database) solely to facilitate cloud synchronization and authentication services.

7. Updates to This Policy

We may update this Privacy Policy from time to time to reflect software updates or legal compliance requirements. Revised policies will be posted on this page with an updated timestamp.

8. Contact Us

If you have any questions or privacy concerns regarding this policy, please reach out to us at privacy@prumpos.com.