Privacy Policy

Last updated: August 27, 2026 · Version 2026-08-27

1. Information We Collect

We collect information you provide when creating an account (name, email, organization details), data generated through your use of the service (orders, menu items, staff records), and technical data such as IP addresses, browser type, and usage logs.

2. How We Use Your Information

We use your information to provide and improve the service, process transactions, send service-related communications, generate analytics for your business, and comply with legal obligations. We do not sell your personal data to third parties.

3. Data Storage and Security

Your data is held on servers in the European Union. Traffic between your devices and POSolid is encrypted in transit (TLS); access is controlled by role and permission, and each organization's data is separated from every other, with a dedicated database available on request. We take regular backups and restrict internal access to the few people who need it to operate and support the service. Card details are handled entirely by our payment provider and never reach POSolid. No system is completely secure, and we cannot guarantee absolute security.

4. Data Sharing

We do not share your personal data with third parties except as necessary to provide the service (e.g., payment processors, hosting providers), to comply with legal requirements, or with your explicit consent. All third-party providers are contractually bound to protect your data.

5. What We Never Do With Your Data

The data you and your staff put into POSolid — orders, receipts, menu, inventory, customers, staff records and working time — belongs to your business. We do not sell it, rent it or share it with anyone for their own purposes, including advertising. We do not use it to build profiles, benchmarks, market reports or industry statistics, we do not combine it with the data of other customers, and we do not use it to train artificial-intelligence models. The reports and analytics inside POSolid are produced for your organization alone, from your own data, and are visible only to the users you grant access to. The only parties that ever touch this data are the technical providers listed below, acting on our instructions solely to operate the service, plus any disclosure the law requires or that you have asked us to make.

6. GDPR (EU and EEA)

POSolid is operated from the European Union and personal data is processed in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679). For the data held inside your POSolid account — your guests, your staff and your orders — your organization is the data controller and we act as your processor, handling that data only on your documented instructions. For your own account and billing data — the account owner's name and email address, the subscription and the invoices — we are the controller.

We rely on the following legal bases: performance of our contract with you (Art. 6(1)(b)); our legitimate interest in keeping the service secure and in contacting business customers about their subscription (Art. 6(1)(f)); our legal obligations, such as tax and accounting rules (Art. 6(1)(c)); and your consent, where we ask for it, such as for website analytics cookies (Art. 6(1)(a)), which you may withdraw at any time.

We use a small number of processors to run the service: a hosting provider, which keeps all application data on servers in the European Union; an email delivery provider; a payment provider for card payments; and, for the optional AI menu tools, a translation provider and an image-recognition provider — the last two receive only the menu text or image you submit to those tools, never your sales, customer or staff data. On our public website only, and only after you accept cookies, Google Analytics and Microsoft Clarity also process usage data. Each processor is bound by a data-processing agreement, and the current list, naming each provider and what it does, is available on request at contact@posolid.com. Where a provider processes data outside the European Economic Area, the transfer is covered by the European Commission's Standard Contractual Clauses or by an adequacy decision.

You have the right to access your personal data and to have it rectified, erased, restricted or transferred to another provider, to object to processing based on our legitimate interest, and to withdraw any consent you have given. Write to contact@posolid.com and we will answer within one month. You also have the right to lodge a complaint with your data protection supervisory authority — in Poland, the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw.

We keep your organization's data for as long as the subscription is active, and for 30 days after it ends or a trial lapses so that you can still ask for an export; after that we delete it, and you may ask us to delete it sooner. Deleting an organization removes its data across every part of the platform — export anything you are legally required to keep, such as sales records for tax purposes, before you ask for that. Invoices and accounting records are kept for as long as tax law requires; technical server logs for no longer than 90 days; backups only until they are overwritten in rotation. A data-processing agreement under Art. 28 GDPR is published at /dpa, and we will notify you without undue delay if a personal-data breach affects data we process for you.

7. United States State Privacy Laws

For customers in the United States, POSolid acts as a service provider (a processor) under the California Consumer Privacy Act as amended by the CPRA, and under the comparable laws of Virginia, Colorado, Connecticut, Texas and Oregon. We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined in those laws. We do not retain, use or disclose personal information for any purpose other than performing the service for you, and never outside the direct business relationship between us. We will assist you with consumer rights requests you receive. Our commitments in this policy apply to every customer, wherever they are based.

8. Your Rights

You have the right to access, correct, or delete your personal data at any time. You may export all your business data from the settings panel. To exercise any of these rights or to raise a concern, contact us at contact@posolid.com.

9. Cookies and Analytics

On our public website (home page, feature pages, Help Centre, sign-up and the QR menu) we use Google Analytics and Microsoft Clarity to understand how many people visit us, which pages they read and how those pages are used. These tools set cookies and collect usage data such as approximate location (country and city), device and browser type, pages viewed and interactions with the page. They load only after you accept them in the cookie banner — if you decline, nothing is set. They are not active inside the POS application itself: your operational, staff and customer data is never sent to them. You can change your choice at any time using the “Cookie settings” link in the footer.

10. Contact

If you have questions about this Privacy Policy or how we handle your data, please contact our Data Protection team at contact@posolid.com. We will respond to all inquiries within 30 days.