Privacy Policy
What data SmarterPOS collects, how it's used, and the choices you have — whether you run a business on SmarterPOS, work as staff, or just filled in a form on this site.
Last updated September 28, 2026
Overview
This Privacy Policy explains what personal data SmarterPOS collects, how we use it, who we share it with, and the choices you have — whether you're a business using SmarterPOS to run your shop, a staff member using a till under that business's account, or someone filling in a form on this website.
We're guided by Uganda's Data Protection and Privacy Act, 2019, and its regulations, including in places we operate beyond Uganda's borders. This policy applies to the SmarterPOS desktop app, the web portal, and this website.
Who we are
SmarterPOS is the data controller for the account, staff, and website data described in this policy. For the sales, stock, and customer data your business enters into SmarterPOS to run your shop, your business is generally the data controller, and we act as the data processor on your behalf — you decide what customer information to collect from the people you serve, and we process it to provide you the Service.
If you have questions about how your data is handled, start with whichever business issued you a receipt or employs you as staff — they control that data. For questions about SmarterPOS as a company, use the contact details in the final section of this policy.
What we collect
Account and business information: business name, business type, branch and terminal details, and owner or manager contact details (name, phone, email, city).
Staff information: names, roles, PINs (stored securely, never as plain text we or you can read back), and activity logs of actions taken on the till or portal — entered by the business that employs them.
Transaction and sales data: what was sold, when, for how much, by which cashier and terminal, and the payment method used — including the mobile money phone number and transaction reference for MTN Mobile Money or Airtel Money payments, captured to reconcile the sale, not to access the funds themselves.
Customer data entered by a business: whatever a business chooses to record about its own customers — a name and phone number for a credit sale, for example. For pharmacies, this can include prescription-related information tied to a sale, entered at that business's discretion. We store this as instructed by the business; we don't independently collect or use it.
Device and technical data: basic information about the terminal or browser used to access the Service, sync status, and error logs, used to keep the Service running and to diagnose problems.
Website and form data: information you submit through a form on this website — for example, a demo request (name, business name, phone, email, business type, city) — used to respond to that request.
How we use it
We use the data described above to:
- Operate the Service — run checkout, sync your till to the cloud, generate your reports and dashboard, and keep your account working.
- Respond to demo requests and other enquiries submitted through this website.
- Maintain security, diagnose and fix problems, and improve the Service over time.
- Meet legal, tax, or regulatory obligations that apply to us.
- Communicate with you about your account, billing, or material changes to the Service or this policy.
We don't use your business's sales or customer data to advertise to you, and we don't sell it to third parties.
International data transfers
Because we rely on third-party hosting and infrastructure providers, your data may be stored or processed on servers located outside Uganda. Where that happens, we take reasonable steps to ensure it's handled with a comparable level of protection to what this policy describes, regardless of where it physically sits.
Data retention, and what happens if your subscription expires
We keep your data for as long as your account is active, and afterward according to this schedule:
- Active subscription: your data is retained and available for as long as your business keeps using the Service.
- Grace period (first 14 days after a lapsed subscription): nothing changes — your data remains fully accessible while we attempt to process renewal.
- Suspended (days 15–90): cloud sync and portal write-access pause, but your data isn't deleted. You can still log in to export your records during this window.
- After 90 days of non-renewal: following a final notice, we may permanently delete your account's stored data, except where we're legally required to keep certain records (for example, financial or tax-related records) for longer.
You can request export or deletion of your data earlier than this schedule at any time — see Your rights below. Demo request and website form submissions are kept only as long as reasonably needed to respond to the enquiry, and for a limited period afterward for our own records, unless you ask us to delete them sooner.
How we protect your data
We apply reasonable technical and organizational safeguards, including encrypting data in transit, restricting internal access to what's needed for a given job, and relying on infrastructure providers who maintain their own security certifications and practices. Staff PINs are stored so that even we can't read them back in plain text.
No system is completely secure. If we become aware of a data breach that's likely to put your data at meaningful risk, we'll notify affected businesses and, where required by law, the relevant regulator, without undue delay.
When our team accesses your data
We don't access your business's stored data — sales records, stock, customer or patient information — as a matter of routine, and nobody on our team browses it out of curiosity or for any purpose unrelated to running the Service.
The only time someone on our team looks at your specific data is to investigate an issue you've reported and reproduce it well enough to diagnose and fix it. Where that's necessary, we'll let you know we're doing it, and access is limited to what's needed for that specific issue — not a general look through your account.
Everyone on our team who could potentially access customer data has signed a confidentiality agreement (NDA) as a condition of working with us. This matters most for sensitive information like a pharmacy's prescription-related records: that data is only ever seen by the specific person handling your support case, bound by that confidentiality commitment, not by staff who have no reason to be looking at it.
Sensitive data (health and prescription information)
Pharmacy businesses using SmarterPOS may record prescription-related details against a sale — for example, that an item required a prescription. This is a category of sensitive personal data under Uganda's data protection law, and it's collected and controlled by the pharmacy business itself, at its own discretion, not by us. If your business handles this kind of data, you're responsible for having a proper legal basis to collect it (such as the patient's consent) and for meeting any additional obligations that apply to health-related data in your jurisdiction. We store it securely on your business's behalf as part of the ordinary operation of the Service, under the access rules described in When our team accesses your data.
Your rights
Depending on your relationship to SmarterPOS, you generally have the right to:
- Access the personal data we (or, for your customers, the business using SmarterPOS) hold about you.
- Correct inaccurate data.
- Export your data in a usable format.
- Request deletion of your data, subject to the retention schedule above and any legal obligation we have to keep certain records.
- Object to or restrict certain processing, and withdraw consent where processing is based on consent.
- Complain to Uganda's Personal Data Protection Office (PDPO) if you believe your data has been mishandled.
If your data was entered into SmarterPOS by a business you're a customer or staff of, start with that business — they control it day to day. For data SmarterPOS controls directly (your account details, or a demo request you submitted), contact us using the details below.
Children's data
SmarterPOS is a business tool and isn't directed at children. Staff accounts should only be created for people old enough to be legally employed in their jurisdiction. We don't knowingly collect personal data from children through this website.
Changes to this policy
We may update this Privacy Policy as the Service, our providers, or the law change. We'll post the updated version here with a new effective date, and for material changes, we'll make a reasonable effort to notify account owners directly.
Contact us
For questions about this policy, or to exercise any of the rights above, email us at support@smarterpossug.com or message us on WhatsApp at +256 759 130 054. If you're not satisfied with our response, you can also contact Uganda's Personal Data Protection Office (PDPO) under the National Information Technology Authority – Uganda (NITA-U).