1. Introduction
Automated Commerce B.V. ("we", "us" or "Tender POS") respects your privacy and is committed to protecting personal data. This privacy statement explains how we handle personal data when merchants, staff members, website visitors, and other users use Tender POS.
This privacy statement applies to all processing of personal data by:
Automated Commerce B.V.
Gerard Doustraat 25 A 1
1072 VK Amsterdam
KvK: 98684213
E-mail: support@tenderpos.io
2. What Data Do We Process?
2.1 Data relating to merchants, staff, and organizations
For customers and authorized users using Tender POS, we process:
Business Data:
- Company name, trade name, Chamber of Commerce number, and organization identifiers
- Business address, billing address, stores, locations, and register information
- VAT number, billing details, contract details, and administrative records
Contact Data:
- First and last name of owners, administrators, staff users, and contact persons
- Email address, account credentials, authentication/session information, and user role
- Phone number and support contact details
- Support, onboarding, billing, and account-management communications
Technical Data:
- API keys, OAuth tokens, refresh tokens, scopes, and provider credentials, stored encrypted where appropriate
- Commerce platform IDs, payment provider IDs, store IDs, location IDs, register IDs, terminal IDs, product IDs, customer IDs, and order IDs
- IP addresses, device identifiers, app version, operating system version, cookies, audit logs, security events, and diagnostic logs
POS, catalog, customer, and transaction data:
- Products, variants, barcodes, prices, discounts, tax data, inventory levels, locations, and related commerce-platform identifiers
- Carts, sales, orders, line items, refunds, receipts, payment methods, synchronization status, and related operational metadata
- End-customer data that the merchant stores, synchronizes, or enters, such as names, contact details, customer IDs, receipt destinations, and order history where enabled by the merchant or connected platform
- Payment intent IDs, payment provider references, terminal references, amount, currency, status, timestamps, and masked card or payment method details where provided by the payment service provider. We do not store raw card numbers, CVV codes, PIN codes, or magnetic stripe/chip data.
2.2 Payment and sensitive data we do not intentionally process
We do not intentionally collect or store:
- Raw card numbers, CVV/CVC codes, PIN codes, magnetic stripe data, chip data, or other full payment instrument data
- The Customer's payment provider login password, online banking credentials, or private banking credentials
- Photos or videos from the camera. Camera access in the POS app is used for barcode scanning; the camera image stream is not stored by Tender POS.
- Data unrelated to providing, securing, supporting, billing, or improving the POS, commerce synchronization, payment, and receipt functionality
3. Purposes of Data Processing
We process personal data for the following purposes:
3.1 Performance of the Agreement
- Providing the Tender POS web dashboard, native POS app, account and organization management, register and location configuration, and staff access
- Synchronizing and mirroring products, variants, prices, discounts, inventory, locations, customers, orders, and related commerce data for fast in-store use
- Building carts, recording POS sales, initiating cash and card payment flows, tracking payment intent and terminal status, sending receipts where enabled, synchronizing sales back to connected platforms, and providing technical support
3.2 Business Operations
- Communication about our services, onboarding, operational changes, incidents, and support
- Invoicing, administration, billing, subscription or usage management, and account administration
- Analyzing system performance, uptime, error rates, security events, and service reliability
3.3 Legal Obligations
- Meeting fiscal and accounting obligations
- Complying with legal retention periods
3.4 Legitimate Interest
- Securing our systems, accounts, devices, registers, and provider connections
- Preventing fraud, abuse, unauthorized access, and misuse
- Improving our services, support, reliability, and business continuity
4. Legal Bases for Processing
We process personal data based on the following legal bases from the General Data Protection Regulation (GDPR):
- Performance of agreement (Article 6(1)(b) GDPR): For providing the Service, account access, support, billing, and requested integrations
- Legal obligation (Article 6(1)(c) GDPR): For compliance with tax, accounting, privacy, security, and other legal obligations
- Legitimate interest (Article 6(1)(f) GDPR): For security, fraud prevention, service improvement, business continuity, and protection of our rights and systems
5. Sharing Data with Third Parties
5.1 Payment Service Providers
At the Customer's direction, we exchange the data necessary to initiate, monitor, and record payments with the Customer's configured payment service providers and terminal providers. These providers process payments under their own terms and privacy notices. Tender POS does not receive or store raw card numbers, CVV codes, PIN codes, or magnetic stripe/chip data.
5.2 Service Providers
We may share data with carefully selected service providers that support us, such as:
- Hosting, database, edge, queue, workflow, storage, monitoring, and security providers
- Commerce platforms, payment service providers, terminal providers, and other integrations connected or authorized by the Customer
- Email, SMS, receipt, support, accounting, billing, and communication service providers
Where a service provider acts as our processor, we use appropriate data processing terms. Customer-connected commerce platforms and payment service providers may also act as independent controllers or processors under their own agreements with the Customer.
5.3 Legal Obligations
We may provide personal data to competent authorities if we are legally required to do so.
5.4 No Sale of Data
We never sell your personal data to third parties.
6. International Transfers
We process and store personal data in the European Economic Area where reasonably available. Some infrastructure, support, payment, communication, or integration providers may process data outside the EEA. Where this happens, we rely on appropriate safeguards such as adequacy decisions, standard contractual clauses, or equivalent protections.
7. Security
We take the protection of your data seriously and have taken appropriate technical and organizational measures, including:
- Encryption: All sensitive data such as API keys are stored encrypted
- Access control: Strict access rights based on function and necessity
- SSL/TLS: All data traffic is secured with modern encryption standards
- Monitoring: Continuous monitoring for unauthorized access
- Backups: Regular backups with encryption
- Incident response: Procedures for handling security incidents
8. Retention Periods
We do not retain personal data longer than necessary:
- Account, organization, user, and contract data: During the term of the agreement and for as long as needed afterward for administration, legal, tax, security, dispute-resolution, and legitimate business purposes
- Catalog, inventory, customer, order, POS sale, receipt, payment status, and synchronization data: For as long as needed to provide the Service, support merchant records, comply with legal obligations, resolve disputes, and maintain security and auditability
- Fiscal data: 7 years in accordance with legal retention requirements
- Log files and security records: Generally up to 12 months unless longer retention is needed for security, fraud prevention, incident investigation, legal obligations, or dispute resolution
After termination or disconnection, we will delete or anonymize data according to the agreement, applicable data processing terms, backup cycles, and legal retention requirements. Provider credentials are deleted or revoked where reasonably possible. Backup copies may remain until they expire in the normal backup cycle.
9. Your Rights
Under the GDPR, you have the following rights:
9.1 Right of Access
You have the right to access the personal data we process about you.
9.2 Right to Rectification
You have the right to have incorrect or incomplete personal data corrected.
9.3 Right to Erasure
In certain cases, you have the right to have your personal data deleted.
9.4 Right to Restriction
You have the right to restrict the processing of your personal data.
9.5 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
9.6 Right to Object
You have the right to object to the processing of your personal data.
9.7 Exercising Your Rights
You can exercise your rights by contacting us at privacy@tenderpos.io. We will respond to your request within one month. We may ask for additional information to verify your identity.
11. Automated Decision Making
We do not use automated decision making or profiling that has legal effects or otherwise significantly affects you.
12. Children's Privacy
Our services are aimed at business users and authorized merchant staff. We do not knowingly create accounts for persons under 16 years of age. Merchants are responsible for ensuring that any end-customer data they collect or synchronize through the Service is collected lawfully, including where it may relate to minors.
13. Changes to This Privacy Policy
We may update this privacy statement from time to time. We will announce significant changes via email to our customers. The most current version can always be found on our website.
14. Complaints
14.1 Contact Us
If you have questions or complaints about the processing of your personal data, please contact us first:
E-mail: support@tenderpos.io
Automated Commerce B.V.
T.a.v. Privacy Officer
Gerard Doustraat 25 A 1
1072 VK Amsterdam
14.2 Data Protection Authority
You also have the right to file a complaint with the Dutch Data Protection Authority:
Autoriteit Persoonsgegevens
P.O. Box 93374, 2509 AJ The Hague, Netherlands
15. Data Protection Officer (DPO)
Given the nature and scope of our data processing, we are not required to appoint a Data Protection Officer. For all privacy-related questions, you can contact our privacy officer at privacy@tenderpos.io.
16. Data Processing Agreements
For business customers using our services where we act as processor for merchant-controlled catalog, customer, order, sale, or receipt data, we have a separate data processing agreement available. You can request this via privacy@tenderpos.io. We act as controller for our own account, billing, security, support, website, and business administration data.
Automated Commerce B.V.
Gerard Doustraat 25 A 1
1072 VK Amsterdam
KvK: 98684213