Legal information

Privacy Policy

This policy explains how CartronPOS handles information when people visit the public website, create an account, contact the team, or use Cartron applications and services.

Last updated: 28 August 2026

1. Information we collect

  • Account and contact details, including names, email addresses, phone numbers, organization information, and authentication records.
  • Subscription, billing, licence, branch, module, and implementation information needed to provide the selected service.
  • Operational content entered by an organization and its authorized users, such as product, transaction, staff, customer, school, hospital, inventory, and accounting records.
  • Technical and security information, including device, browser, IP address, audit, diagnostic, synchronization, and error records.
  • Messages and files submitted through support, contact, import, or implementation workflows.

2. How we use information

We use information to operate and secure the service, authenticate users, provide licensed modules, process synchronization, deliver support, manage subscriptions, communicate service information, investigate errors or abuse, improve reliability, and comply with applicable obligations.

3. Organization-controlled data

Organizations decide which operational records their authorized users enter and which modules, locations, departments, menus, and actions those users may access. CartronPOS processes that content to provide the service and follows the organization's permitted configuration and instructions. Organizations remain responsible for having an appropriate legal basis for the personal information they enter.

4. When information is shared

We do not sell personal information. Information may be shared with service providers that support hosting, email, payment, security, backup, analytics, or customer support; with professional advisers; when required by law or a valid legal request; or as part of a business reorganization. Providers receive only the information needed for their work and are expected to protect it.

5. Retention and deletion

Information is retained while an account or commercial relationship is active and for a reasonable period afterward for service recovery, security, audit, billing, dispute, and legal purposes. Retention varies by record type and an organization's configuration. Hosted account holders may request export or deletion, subject to contractual, backup, security, and legal retention requirements.

6. Security

CartronPOS uses access controls, tenant and location scoping, authentication safeguards, audit records, and operational monitoring intended to protect information. No system can guarantee absolute security. Organizations must protect their credentials, assign access carefully, keep local devices secure, and notify us promptly of suspected unauthorized access.

7. Healthcare and education information

Hospital, pharmacy, and school customers may process sensitive information. Those organizations control why the information is collected, who may access it, and how long it should be retained. They are responsible for configuring access and meeting the legal and professional obligations that apply to their activities.

8. Your choices and rights

Depending on applicable law, individuals may have rights to request access, correction, deletion, restriction, objection, or a copy of their information. Requests concerning records controlled by a CartronPOS customer should usually be directed to that organization first. We may need to verify identity before responding.

9. International processing and changes

Service providers and customers may operate in different countries. Where information is transferred, we take reasonable steps to use appropriate contractual and security safeguards. We may update this policy as the service or legal requirements change and will publish the revised date on this page.