Privacy Policy
Effective July 3, 2026
HeroPOS ("we," "us") is a retail point-of-sale platform operated by Electronic Payments, Inc. This policy explains what we collect, why, and the choices you have. It applies to heropos.net, the HeroPOS mobile apps, and related services.
What we collect
Account information. Name, email address, business name and address, and login credentials when you create a HeroPOS account.
Business data you enter. Your product catalog, prices, inventory, staff records, sales transactions, and the customer records your business chooses to keep (such as names, phone numbers, and house-account balances). For this data, your business is the data controller and HeroPOS processes it on your behalf to run your point of sale.
Payment data. Card payments are processed by our payment partners on certified payment terminals. HeroPOS stores only truncated card references (such as the last four digits and authorization codes) — full card numbers never touch our servers.
Device and technical data. Log and error information (timestamps, app version, error messages) used to keep the service reliable, and — in the mobile apps — a push-notification token if you allow notifications.
Camera. The mobile apps use the camera solely to scan product barcodes at your request. Images are processed on the device and are never stored or transmitted.
How we use it
To provide and operate the point of sale; to process transactions you initiate; to send service communications (receipts your customers request, order-ready notifications, reports you schedule); to secure the service and prevent fraud; and to comply with law. We do not sell personal information, and we do not use your data for third-party advertising.
Service providers
We use a small set of infrastructure providers to run HeroPOS, each bound to use data only to provide their service to us:
- Vercel (application hosting)
- Supabase (database hosting, encrypted at rest)
- Resend (transactional email: receipts, reports, account email)
- Twilio (SMS notifications, where enabled)
- Payment processors and terminal providers (card processing)
- Google Firebase (mobile push-notification delivery)
Security
Data is encrypted in transit (TLS) and at rest. Access within a business is governed by role-based permissions its administrators control, every sensitive action is written to an audit log, and each business's data is isolated at the database layer.
Retention
We retain business records for as long as your account is active. Sales records are business documents — merchants may need them for tax and compliance purposes, so they persist for the life of the account. If you close your account, we delete or de-identify your data within 90 days, except where law requires longer retention.
Your choices and rights
You can access and update your business data in the app at any time. You may disable push notifications in your device settings. Depending on where you live, you may have rights to access, correct, delete, or port personal information — contact us and we will honor applicable requests. If your information was entered by a business using HeroPOS (for example, you are a customer of a store), contact that business first; we will assist them in fulfilling your request.
Children
HeroPOS is a business tool and is not directed at children. We do not knowingly collect personal information from children under 13.
Changes
We will post any changes to this policy here and update the effective date. Material changes will be announced in the app or by email.
Contact
Electronic Payments, Inc. · privacy@heropos.net