1. Information we collect
- Account and contact details, including names, email addresses, phone numbers, organization information, and authentication records.
- Subscription, billing, licence, branch, module, and implementation information needed to provide the selected service.
- Operational content entered by an organization and its authorized users, such as product, transaction, staff, customer, school, hospital, inventory, and accounting records.
- Technical and security information, including device, browser, IP address, audit, diagnostic, synchronization, and error records.
- Messages and files submitted through support, contact, import, or implementation workflows.
2. How we use information
We use information to operate and secure the service, authenticate users, provide licensed modules, process synchronization, deliver support, manage subscriptions, communicate service information, investigate errors or abuse, improve reliability, and comply with applicable obligations.
3. Organization-controlled data
Organizations decide which operational records their authorized users enter and which modules, locations, departments, menus, and actions those users may access. CartronPOS processes that content to provide the service and follows the organization's permitted configuration and instructions. Organizations remain responsible for having an appropriate legal basis for the personal information they enter.
4. When information is shared
We do not sell personal information. Information may be shared with service providers that support hosting, email, payment, security, backup, analytics, or customer support; with professional advisers; when required by law or a valid legal request; or as part of a business reorganization. Providers receive only the information needed for their work and are expected to protect it.
5. Retention and deletion
Information is retained while an account or commercial relationship is active and for a reasonable period afterward for service recovery, security, audit, billing, dispute, and legal purposes. Retention varies by record type and an organization's configuration. Hosted account holders may request export or deletion, subject to contractual, backup, security, and legal retention requirements.
6. Security
CartronPOS uses access controls, tenant and location scoping, authentication safeguards, audit records, and operational monitoring intended to protect information. No system can guarantee absolute security. Organizations must protect their credentials, assign access carefully, keep local devices secure, and notify us promptly of suspected unauthorized access.
7. Healthcare and education information
Hospital, pharmacy, and school customers may process sensitive information. Those organizations control why the information is collected, who may access it, and how long it should be retained. They are responsible for configuring access and meeting the legal and professional obligations that apply to their activities.
8. Your choices and rights
Depending on applicable law, individuals may have rights to request access, correction, deletion, restriction, objection, or a copy of their information. Requests concerning records controlled by a CartronPOS customer should usually be directed to that organization first. We may need to verify identity before responding.
9. International processing and changes
Service providers and customers may operate in different countries. Where information is transferred, we take reasonable steps to use appropriate contractual and security safeguards. We may update this policy as the service or legal requirements change and will publish the revised date on this page.

