RetaillyPOS

Privacy Policy

Last updated: 05 August 2026  ·  Effective: 05 August 2026

← Back to RetaillyPOS
Summary: RetaillyPOS is a multi-tenant, cloud-based Point-of-Sale platform. We collect and process business and personal data to deliver our service. We do not sell your data. You retain ownership of your business data at all times.
Table of Contents
  1. Who We Are
  2. Data We Collect
  3. How We Use Your Data
  4. Data Sharing & Disclosure
  5. Data Retention
  6. Security
  7. Multi-Tenancy & Data Isolation
  8. Your Rights
  9. Cookies & Tracking
  10. Children's Privacy
  11. Changes to This Policy
  12. Contact Us

1. Who We Are

RetaillyPOS ("we", "our", "us") is a Software-as-a-Service (SaaS) Point-of-Sale platform designed for retail businesses. Each business ("Organisation" or "Tenant") operates in an isolated workspace identified by a unique subdomain on our platform.

Our registered business address is available upon request via info@support.ftghana.com.

2. Data We Collect

2.1 Account & Organisation Data

Data TypeExamplesPurpose
Organisation profileBusiness name, subdomain, email, phoneTenant setup, invoicing
User credentialsName, email address, hashed passwordAuthentication
Staff profilesEmployee name, role, department, contactHR management
Subscription dataPlan type, billing dates, payment statusService access, invoicing

2.2 Transactional Business Data

Data TypeExamplesPurpose
Sales recordsItem, price, quantity, payment methodPOS operations
Customer dataName, phone, purchase historyCustomer management
Supplier dataName, contact, invoicesProcurement
Inventory dataProducts, stock levels, expiry datesStock management
Financial recordsExpenses, income, bank accountsFinance reporting

2.3 Technical & Security Data

  • IP addresses and approximate location (country/city)
  • Browser type and operating system (User-Agent string)
  • Session identifiers
  • Login timestamps, failed login attempts, and account lockout events
  • Audit log entries (who did what, when, from where)
  • Two-factor authentication events

2.4 Payment Data

We record payment method type (e.g. Mobile Money, Bank Transfer) and transaction references for subscription payments. We do not store full card numbers, CVV codes, or mobile money PINs. Payment processing is handled by authorised third-party gateways (Flutterwave, MTN MoMo).

3. How We Use Your Data

  • Service Delivery: To operate the POS platform, manage subscriptions, and provide support.
  • Security & Fraud Prevention: To detect brute-force attacks, suspicious login activity, and enforce account lockout policies.
  • Audit Trails: To maintain tamper-evident logs of all create, update, and delete actions within your organisation for accountability and compliance.
  • Notifications: To send subscription renewal reminders, low-stock alerts, and system notifications via email and SMS.
  • Platform Improvement: Aggregated, anonymised usage data to improve features and performance.
  • Legal Compliance: Where required by applicable law.

4. Data Sharing & Disclosure

We do not sell, rent, or trade your personal or business data. We may share data only:

  • With payment processors (Flutterwave, MTN Mobile Money) to process subscription payments.
  • With email/SMS providers to deliver transactional notifications.
  • With cloud infrastructure providers who host our database and application servers under strict data processing agreements.
  • When legally required by a court order, government authority, or applicable law — and only to the minimum extent necessary.
  • In a business transfer — if RetaillyPOS is acquired, tenants will be notified prior to data being transferred.

All third-party processors are bound by Data Processing Agreements (DPAs) consistent with applicable data protection law.

5. Data Retention

Data CategoryRetention Period
Active account dataFor the duration of the subscription + 12 months after termination
Audit logs12 months (application logs), 90 days (security logs)
Payment records7 years (legal/tax requirement)
Session data120 minutes after inactivity, then purged
Backup data30 days from backup creation

Upon subscription termination, you may request export of your data within 30 days. After that window, data is securely deleted from production systems.

6. Security

We implement layered security measures including:

  • HTTPS (TLS 1.2+) encryption in transit for all data
  • Passwords hashed using bcrypt (cost factor 12)
  • PIN codes hashed using HMAC-SHA256 with a server-side secret
  • Two-Factor Authentication (TOTP) available for all users
  • Account lockout after 5 consecutive failed login attempts (30-minute lockout)
  • Rate limiting on login, password reset, and 2FA challenge endpoints
  • CSRF protection on all state-changing operations
  • Role-based access control (RBAC) with organisation-level data isolation
  • Security headers: Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, and others
  • Immutable audit trail for all data mutations
  • Sensitive fields (passwords, PINs, 2FA secrets) excluded from audit logs

Despite these measures, no system is 100% secure. If you discover a vulnerability, please report it responsibly to info@support.ftghana.com.

7. Multi-Tenancy & Data Isolation

RetaillyPOS is a multi-tenant system. Each organisation is assigned a unique subdomain and all data is strictly isolated by organisation ID at the database level. Technical controls include:

  • A global Eloquent scope automatically appends WHERE organization_id = ? to all tenant queries.
  • Route model binding resolves records only within the authenticated user's organisation.
  • Tenant middleware validates that the authenticated user belongs to the subdomain's organisation on every request.
  • Super-admin access to individual tenant data is logged and audited.

One tenant cannot access another tenant's data.

8. Your Rights

Subject to applicable data protection law, you have the right to:

  • Access — Request a copy of the personal data we hold about you.
  • Correction — Request correction of inaccurate data.
  • Erasure — Request deletion of your personal data (subject to legal retention obligations).
  • Portability — Receive your business data in a structured, machine-readable format.
  • Object — Object to certain processing activities.
  • Restriction — Request restriction of processing in certain circumstances.
  • Withdraw Consent — Where processing is based on consent, withdraw it at any time.

To exercise any of these rights, contact us at info@support.ftghana.com. We will respond within 30 days.

9. Cookies & Tracking

We use the minimum cookies necessary to operate the service:

CookiePurposeType
retaillypos_sessionMaintains your login sessionEssential
XSRF-TOKENPrevents Cross-Site Request ForgeryEssential
remember_web_*Persistent login (if "remember me" selected)Functional

We do not use advertising cookies, third-party tracking pixels, or behavioural analytics on tenant-facing pages.

10. Children's Privacy

RetaillyPOS is a business tool intended for use by organisations and adults aged 18 and over. We do not knowingly collect personal data from children under 18. If you believe a child has submitted data, contact us immediately.

11. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or applicable law. When we make material changes, we will notify all Organisation Admins by email at least 14 days before the change takes effect, and update the "Last updated" date at the top of this page. Continued use of the Service after the effective date constitutes acceptance.

12. Contact Us

For privacy-related questions, requests, or complaints:

  • Email: info@support.ftghana.com
  • Platform: https://retailly.app

We aim to respond to all enquiries within 5 business days.

© 2026 RetaillyPOS — Privacy Policy • Terms of Service • Sign In