Privacy Policy

Effective July 3, 2026

HeroPOS ("we," "us") is a retail point-of-sale platform operated by Electronic Payments, Inc. This policy explains what we collect, why, and the choices you have. It applies to heropos.net, the HeroPOS mobile apps, and related services.

What we collect

Account information. Name, email address, business name and address, and login credentials when you create a HeroPOS account.

Business data you enter. Your product catalog, prices, inventory, staff records, sales transactions, and the customer records your business chooses to keep (such as names, phone numbers, and house-account balances). For this data, your business is the data controller and HeroPOS processes it on your behalf to run your point of sale.

Payment data. Card payments are processed by our payment partners on certified payment terminals. HeroPOS stores only truncated card references (such as the last four digits and authorization codes) — full card numbers never touch our servers.

Device and technical data. Log and error information (timestamps, app version, error messages) used to keep the service reliable, and — in the mobile apps — a push-notification token if you allow notifications.

Camera. The mobile apps use the camera solely to scan product barcodes at your request. Images are processed on the device and are never stored or transmitted.

How we use it

To provide and operate the point of sale; to process transactions you initiate; to send service communications (receipts your customers request, order-ready notifications, reports you schedule); to secure the service and prevent fraud; and to comply with law. We do not sell personal information, and we do not use your data for third-party advertising.

Service providers

We use a small set of infrastructure providers to run HeroPOS, each bound to use data only to provide their service to us:

  • Vercel (application hosting)
  • Supabase (database hosting, encrypted at rest)
  • Resend (transactional email: receipts, reports, account email)
  • Twilio (SMS notifications, where enabled)
  • Payment processors and terminal providers (card processing)
  • Google Firebase (mobile push-notification delivery)

Security

Data is encrypted in transit (TLS) and at rest. Access within a business is governed by role-based permissions its administrators control, every sensitive action is written to an audit log, and each business's data is isolated at the database layer.

Retention

We retain business records for as long as your account is active. Sales records are business documents — merchants may need them for tax and compliance purposes, so they persist for the life of the account. If you close your account, we delete or de-identify your data within 90 days, except where law requires longer retention.

Your choices and rights

You can access and update your business data in the app at any time. You may disable push notifications in your device settings. Depending on where you live, you may have rights to access, correct, delete, or port personal information — contact us and we will honor applicable requests. If your information was entered by a business using HeroPOS (for example, you are a customer of a store), contact that business first; we will assist them in fulfilling your request.

Children

HeroPOS is a business tool and is not directed at children. We do not knowingly collect personal information from children under 13.

Changes

We will post any changes to this policy here and update the effective date. Material changes will be announced in the app or by email.

Contact

Electronic Payments, Inc. · privacy@heropos.net