Privacy Policy
Effective August 17, 2026 · Version 1.0
This Privacy Policy explains what data OZ-POS (the “Company”, “we”, “us”, or “our”) collects through the OZ-POS website, desktop application, cloud services, and related services (together, the “Service”), why we collect it, how we use and protect it, and the rights you have over it.
By creating an account or using the Service, you agree to the practices described in this policy. If you do not agree, please do not use the Service.
1. Who we are (data controller)
OZ-POS operates the Service and is the data controller responsible for the personal data described in this policy. You can contact us at any time:
- Email: support@oz-pos.com
- Sales: sales@oz-pos.com
We are committed to processing personal data lawfully, fairly, and transparently in accordance with applicable law, including the EU General Data Protection Regulation (GDPR) where it applies and Indonesia’s Law No. 27 of 2022 on Personal Data Protection (UU PDP) where it applies.
2. What we collect
We collect only the data needed to operate the Service. We do not collect payment card data, and we do not buy or sell personal data.
2.1 Account data (required). When you register, we collect:
- Your email address (used as your login identifier and for verification codes);
- A hashed password (we never store passwords in plain text);
- Your account’s verification status;
- Your subscription plan, license keys, and license activation records.
2.2 Business data you sync (cloud plans only). If you use cloud sync, we store the business data you upload — for example product catalogs, sales transactions, inventory and stock movements, and ledger entries. This data belongs to you (or your business). We process it only to provide the sync feature you asked for and to produce the analytics reports you request. We never use it for advertising or share it with third parties except as described in section 5.
2.3 Usage and technical data (minimal). We keep brief server logs (IP address, timestamp, requested endpoint, response status) to operate, secure, and troubleshoot the Service. Logs are retained for a limited time and are not used to profile you.
2.4 Support and communications. If you contact us, we keep the content of your message and your contact details to answer you and to improve the Service.
2.5 What we do NOT collect. We do not see or store your payment card number, CVV, or bank details. All payments are processed by our payment provider, Paddle, on their own systems. We also do not sell personal data, and we do not use advertising trackers, cookies for advertising, or third-party analytics on the website (see section 9).
3. How we use your data
We use personal data for these purposes:
- To provide the Service — creating and securing your account, verifying your email, issuing license keys, activating your subscription, and delivering cloud sync and reports;
- To process payments — sending Paddle the information needed to create a checkout and to match a completed payment to your account (Paddle processes the actual payment; see section 5);
- To send service messages — verification codes, password-reset codes, payment receipts, and important notices about your account or the Service. We do not send marketing email unless you have separately consented;
- To secure and operate — detecting fraud, abuse, or violations of our Terms of Service, and keeping the Service available;
- To comply with law — keeping records we are legally required to keep and responding to lawful requests from authorities, as permitted by law.
4. Legal bases (GDPR)
Where the GDPR applies, we process personal data on these bases:
- Performance of a contract — processing needed to provide the Service you signed up for (account creation, licensing, sync, billing);
- Legitimate interests — securing the Service, preventing fraud and abuse, and improving reliability, balanced against your rights and interests;
- Legal obligation — where we must keep records or respond to lawful requests;
- Consent — where we ask for it (for example, optional marketing), which you may withdraw at any time without affecting the Service.
5. Who we share data with
We share personal data only with service providers that are necessary to run the Service, and only to the extent each one needs:
| Provider | What they do | What data they see |
|---|---|---|
| Paddle (paddle.com) | Payment processing, subscriptions, and billing | Your email and billing details needed for checkout; the amount and plan purchased. Never your card number. |
| Brevo (brevo.com) | Sending verification and reset emails | Your email address. |
| Northflank (northflank.com) | Hosting the backend (database and API) | Account and synced business data at rest. |
| Cloudflare (cloudflare.com) | Website hosting, CDN, and security | Standard web request data (IP, headers) for delivery and protection. |
We require every provider to process data only on our documented instructions, to protect it with appropriate security measures, and to honor your rights requests when we pass them through. We never sell personal data, and we never share it with advertisers.
6. International transfers
We operate globally and some of the providers listed above (and our own infrastructure) are located outside the country where you live. Where we transfer personal data across borders, we rely on appropriate safeguards such as the EU Standard Contractual Clauses or equivalent lawful mechanisms, so your data is protected to a comparable standard.
7. Retention
- Account data is kept while your account is active and for a short period after you request deletion to allow for recovery and to comply with legal obligations.
- Cloud-synced business data is deleted when you delete your account or cancel your plan, as described in the Terms of Service, except where we are legally required to keep records.
- Server logs are kept for a limited period (typically up to 90 days) and then deleted or anonymized.
- Backups may retain data for a limited additional period for disaster recovery, after which they are purged.
When you ask us to delete your data, we delete or anonymize it within a reasonable time and in any case within the timeframes required by applicable law (generally 30 days for verified requests, except where law requires longer).
8. Security
We apply reasonable technical and organizational measures to protect your data, including:
- Encryption in transit (TLS) for all communication with our servers;
- Passwords stored only as strong one-way hashes (bcrypt);
- Cryptographically signed license keys to prevent tampering;
- Access controls and logging on production systems;
- Restricted access to production data for our team and providers.
No method of transmission or storage is completely secure. You also have a role: use a strong, unique password for your account and do not share it. If you believe your account has been compromised, contact us immediately at support@oz-pos.com.
9. Cookies and tracking
- The website does not use advertising or analytics cookies, and does not use third-party tracking scripts.
- To keep you signed in, the website uses your browser’s session storage (a temporary browser feature that clears when you close the tab or browser). We do not use persistent cookies for this purpose.
- The website stores your theme preference (light/dark) in your browser’s local storage.
Because the Service is primarily a business tool, we do not engage in behavioral advertising and we do not create advertising profiles.
10. Your rights
Depending on where you live, you may have the following rights over your personal data (under the GDPR, the UU PDP, and similar laws):
- Access — a copy of the personal data we hold about you;
- Correction — fix inaccurate or incomplete data;
- Deletion — ask us to erase your data;
- Restriction / objection — limit or object to certain processing;
- Portability — receive your data in a structured, machine-readable format where the GDPR applies;
- Withdrawal of consent — where processing is based on consent;
- Complaint — lodge a complaint with your local data-protection authority (for example, in the EU/EEA) or with Indonesia’s data-protection authority.
To exercise any of these rights, email support@oz-pos.com from the email address on your account. We will verify your identity and respond within 30 days. We may need to keep certain data to comply with legal obligations or to protect our legitimate interests, and we will tell you when that is the case.
11. Children
The Service is intended for businesses and is not directed at children. You must be at least 18 years old (or the age of majority in your jurisdiction) to create an account. We do not knowingly collect personal data from children; if you believe a child has provided us data, contact us and we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced on the website and, where we have your email, by notice to your account email before they take effect. The date at the top of this page shows the latest revision. Continued use of the Service after changes take effect means you accept the updated policy.
13. Contact
Questions, requests, or complaints about this policy or your data:
- Email: support@oz-pos.com
- Subject line: “Privacy request”
We aim to respond to every privacy request within 30 days.
Version history
| Version | Effective date | Summary of changes |
|---|---|---|
| 1.0 | August 17, 2026 | Initial publication. |