Privacy Policy
On this page
1. Who we are and what this covers
Poslytic is a restaurant point-of-sale platform operated by POSLYTIC Private Limited, 59 B Johar Town, Lahore, Pakistan ("Poslytic", "we", "us").
This policy covers three products:
- Poslytic POS — the till, kitchen display and back office, used in a browser or as a Windows desktop application by restaurant staff.
- Poslytic Rider — an Android app used by delivery riders employed or contracted by a restaurant.
- Poslytic Owner — an Android app that gives a restaurant owner or manager read access to their own venue's reports.
The Rider and Owner apps are secure wrappers around the same Poslytic web application; they do not collect anything beyond what is described here.
These are business applications. They are not consumer apps. You sign in with a staff account created for you by the restaurant you work for. There is no public sign-up.
2. Our two different roles
The distinction below decides who you should contact about a given piece of data, so it matters:
- We are the data controller for staff accounts — the login details of the cashiers, managers, riders and owners who use Poslytic, plus the technical logs our servers generate.
- We are a data processor for everything a restaurant records about its own customers — names, phone numbers, delivery addresses, order history, loyalty balances and credit ledgers. That data belongs to the restaurant. We store and process it strictly on that restaurant's instructions, and we do not sell it, rent it, or use it to build advertising profiles.
If you are a diner and want your details removed from a restaurant's records, contact that restaurant directly — they control that data. We will help them action it, but we cannot act on it unilaterally.
3. What we collect
From staff who use the apps
| Data | Why |
|---|---|
| Name, email address, phone number, role, branch assignment | To create and identify your staff account and apply the right permissions. |
| Password and, where used, a numeric manager PIN — both stored only as salted hashes, never in readable form | To authenticate you and to authorise sensitive actions such as refunds, voids and discounts. |
| Shift, attendance and activity records: clock-in and clock-out times, orders you rang up, cash-drawer counts, and an audit trail of sensitive actions | So the restaurant can run payroll, reconcile the till and investigate discrepancies. This is a core purpose of a POS. |
| Approximate location derived from your IP address, and the fact that a sign-in came from an unfamiliar address | To flag suspicious sign-ins in the security audit log. |
| Rider app only: precise device location — see section 4 | To dispatch deliveries and let the restaurant track an active delivery. |
Restaurant customer data we process on a restaurant's behalf
Depending on how a restaurant configures Poslytic, this can include a customer's name, phone number, email address, delivery address, date of birth, order history, loyalty points, outstanding credit balance, and tax registration identifiers for business invoicing. Restaurant staff enter this; we do not collect it from diners directly, except through a restaurant's own QR ordering page where a diner supplies their own name, phone and address to place an order.
Enquiries from our website
If you submit the demo-request form on poslytic.com we receive the name, restaurant, email address, phone number and message you enter, solely so we can reply to you and keep track of the enquiry. It is emailed to our own inbox and recorded as a row in a private Google Sheet that only our team can open. It is not added to any restaurant's customer database, not used for advertising, and not shared with anyone else. Ask us at contact@poslytic.com and we will delete your enquiry from both.
Technical data
Our servers keep standard application and error logs — request paths, response codes, timestamps and device or browser type. These help us keep the service running and diagnose faults.
4. Location data in the Rider app
The Rider app collects precise location. Here is exactly what happens to it.
When a rider is signed in and on duty, the app reads the device's GPS position and sends it to the restaurant's dispatch board so staff can see where an active delivery is and give customers an accurate arrival estimate.
We store only the single most recent position for each rider. Each update overwrites the last one. We do not build or retain a location history, journey trail, or any record of where a rider has been. Live position is broadcast to that restaurant's dispatch screen only, and never leaves the restaurant's own account.
Location is never collected from the Owner app or the POS. Android requires your explicit permission before any location is read, and you can withdraw it at any time in your device settings — the rest of the Rider app continues to work, but the restaurant will no longer see live tracking for your deliveries.
5. Push notifications
If you allow notifications, we store an anonymous push subscription endpoint issued by your browser or device so we can alert a rider to a newly assigned delivery even when the app is closed. This endpoint identifies a device, not a person, and contains no message content. Revoking notification permission, or signing out, stops it; we also automatically discard endpoints that the push service reports as expired.
6. How we use data
We use the data described above to:
- Operate the POS — take orders, route tickets to the kitchen, take payments, print receipts and manage deliveries.
- Authenticate staff and enforce the permissions the restaurant has granted them.
- Produce the reports, sales analytics and payroll data a restaurant needs to run its business.
- Send transactional messages that a restaurant has configured — for example an order confirmation or a delivery notification by SMS or WhatsApp to that restaurant's own customer.
- Detect and investigate fraud, cash discrepancies and suspicious sign-ins.
- Maintain, secure, debug and improve the service.
- Comply with tax, accounting and other legal obligations.
We do not sell personal data, and we do not use it for advertising or share it with advertising networks. We do not use it to train machine learning models.
7. Who we share it with
We share data only with the service providers needed to make the product work, and only to the extent each one needs:
| Provider | What it receives |
|---|---|
| Google Maps Platform | Addresses and coordinates, to draw maps, geocode a delivery address, autocomplete an address and calculate routes. |
| Meta (WhatsApp Business Cloud API) | A customer's phone number and message content, when a restaurant has enabled WhatsApp notifications. |
| The restaurant's chosen SMS gateway | A customer's phone number and message content, when SMS notifications are enabled. |
| Browser and device push services (for example Google, Mozilla or Apple) | The push endpoint and the notification payload, in order to deliver a notification. |
| Google (Sheets / Apps Script) | The details you type into the demo-request form on our website, recorded as a row in our own private spreadsheet so we can track the enquiry. This applies to that form only — no restaurant or diner data is sent there. |
| Our hosting provider | Hosts the servers and database. Data is stored on servers we control. |
We may also disclose data where we are legally required to, or to establish or defend a legal claim. If our business is ever sold or merged, data may transfer to the acquirer under the terms of this policy.
Each restaurant's data is isolated from every other restaurant's at the database level. One venue cannot see another venue's data.
8. Payment information
Poslytic does not store card numbers, CVV codes or cardholder data. Card payments are taken on the restaurant's own card terminal or payment provider. Poslytic records only the outcome of a payment — the amount, the tender type (cash, card, transfer, credit), and a reference — so the bill can be settled and reconciled.
9. How long we keep it
- Staff accounts — for as long as the account is active. When a restaurant deactivates a staff member, the account is disabled; see section 12 for deletion.
- Rider location — only the latest position is stored, and it is overwritten by the next update. No history is retained.
- Orders, payments and tax records — retained for as long as the restaurant's own legal and accounting obligations require, which is typically several years. These records cannot be deleted on request where the law requires the restaurant to keep them.
- Audit and security logs — retained for a limited period for fraud investigation.
- Push subscriptions — until you revoke permission, sign out, or the endpoint expires.
- Website enquiries — kept while we are in contact with you about Poslytic, and deleted on request.
10. How we protect it
- All traffic between the apps and our servers is encrypted in transit with HTTPS/TLS.
- Passwords and manager PINs are stored only as salted hashes, and cannot be read back by us or by anyone else.
- Repeated failed PIN and password attempts are rate-limited and locked out to frustrate brute-force attempts.
- Access inside the product is controlled by role-based permissions that the restaurant configures.
- Sensitive actions — refunds, voids, discounts, drawer discrepancies — are recorded in an audit log.
- Each restaurant's records are isolated at the database layer.
No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your data we will notify affected restaurants and, where required, the relevant authority.
11. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to have it deleted, to restrict or object to how it is used, and to receive a copy in a portable format. You may also lodge a complaint with your local data protection authority.
To exercise any of these rights, contact us at support@poslytic.com. We will respond within the period required by applicable law. We may need to verify your identity first. If your request concerns data a restaurant controls, we will pass it to that restaurant and support them in answering it.
12. Account and data deletion
Poslytic staff accounts are created by the restaurant that employs you, not by you, so deletion is requested rather than self-served.
To request deletion of your staff account and its associated personal data:
- Email support@poslytic.com from the address on your account, with the subject line "Account deletion request", and include your full name and the name of the restaurant you work or worked for.
- Alternatively, ask the owner or manager of that restaurant to raise the request on your behalf.
We will confirm receipt and complete verified requests within 30 days.
What is deleted: your account, your name, email address, phone number, password and PIN hashes, your push notification subscriptions, and your last known rider location.
What is retained, and why: completed sales, invoices, tax records and the audit trail must be kept to satisfy the restaurant's accounting and tax obligations. Where those records reference you, we replace your identity with a non-identifying internal reference so the financial record stays intact and auditable while ceasing to identify you.
To delete a restaurant's entire account and all of its data, the account owner should contact us from their registered address.
13. Children
Poslytic is a workplace tool intended for adults. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child's data has reached us, contact us and we will remove it.
14. Changes to this policy
We may update this policy as the product changes. We will revise the "last updated" date above, and for material changes we will notify restaurant account owners by email or through the product before the change takes effect.
15. Contact us
Questions, requests or complaints about privacy:
Email: support@poslytic.com
Phone / WhatsApp: +92 335 1805 111
Postal: POSLYTIC Private Limited, 59 B Johar Town, Lahore, Pakistan