Contact mellotek1@gmail.com with questions.
← Back

Privacy Policy

Mellotek Cloud POS · Last updated 2026-10-04

1. Who We Are

Mellotek Cloud POS(“we,” “us,” “our”) provides a cloud point-of-sale and business management platform. This Privacy Policy explains how we collect, use, share, and protect personal data when you use our Service. For privacy questions, contact mellotek1@gmail.com.

2. Data We Collect

  • Account data: name, email, phone, business name, business code, hashed password, hashed PIN.
  • Business data you enter: products, sales, inventory, purchases, expenses, customers, employees, and related records.
  • Technical data: IP address, browser/device info, session cookies, access timestamps.
  • Payment data: M-Pesa confirmation details (receipt number, amount, phone). We do not store your full M-Pesa PIN or credentials.
  • Communications data: metadata about emails and messages we send you (e.g., OTP delivery, WhatsApp status).

3. Why We Process It (Legal Bases)

We rely on the following legal bases under the GDPR and the Kenya Data Protection Act 2019:

  • Contract: to provide the Service you signed up for.
  • Legal obligation: to keep tax, accounting, and audit records.
  • Legitimate interest: to secure the Service, prevent fraud, and improve reliability.
  • Consent: for optional marketing communications and any other use where consent is required by law.

4. How We Use It

We use personal data to operate the Service, generate reports you request, process subscription payments, deliver transactional messages, prevent abuse, comply with legal obligations, and communicate about your account.

5. Sharing & Sub-processors

We share data with the following categories of service providers:

  • Safaricom — M-Pesa payments and confirmations
  • Google (Gmail SMTP) — transactional email delivery
  • Meta (WhatsApp Business API) — WhatsApp messaging you initiate
  • OpenRouter — AI analysis requests (only aggregate/anonymised business metrics are sent)
  • Cloud hosting provider — infrastructure and database storage

We do not sell your personal data. We disclose data when required by law or to protect our legal rights.

6. International Transfers

Some sub-processors may store or process data outside your country, including in the EU, UK, or US. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses.

7. Retention

  • Active account data: for as long as your account exists
  • Financial records: at least 7 years (tax compliance)
  • Consent logs: 5 years after withdrawal
  • Security/access logs: 90 days

8. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, delete, or export your data, to object to or restrict certain processing, to withdraw consent, and to lodge a complaint with a supervisory authority (in Kenya, the Office of the Data Protection Commissioner; in the EU, your local authority).

9. Cookies

We use strictly necessary cookies: auth-token (session), active-branch-id (branch selection), and platform-auth-token (platform admin only). We do not use third-party advertising cookies.

10. Children

The Service is not intended for use by anyone under 18 years old.

11. Security

We use industry-standard measures including bcrypt password hashing, HTTPS/TLS in transit, httpOnly cookies, parameterised database queries, and role-based access control. No system is perfectly secure; report suspected issues to mellotek1@gmail.com.

12. Changes

We may update this policy. Material changes will be communicated by email or in-app. Continued use after the effective date indicates acceptance.

13. Contact

Privacy enquiries: mellotek1@gmail.com

Terms & Conditions · Back to sign in