1. Who We Are
Mellotek Cloud POS(“we,” “us,” “our”) provides a cloud point-of-sale and business management platform. This Privacy Policy explains how we collect, use, share, and protect personal data when you use our Service. For privacy questions, contact mellotek1@gmail.com.
2. Data We Collect
- Account data: name, email, phone, business name, business code, hashed password, hashed PIN.
- Business data you enter: products, sales, inventory, purchases, expenses, customers, employees, and related records.
- Technical data: IP address, browser/device info, session cookies, access timestamps.
- Payment data: M-Pesa confirmation details (receipt number, amount, phone). We do not store your full M-Pesa PIN or credentials.
- Communications data: metadata about emails and messages we send you (e.g., OTP delivery, WhatsApp status).
3. Why We Process It (Legal Bases)
We rely on the following legal bases under the GDPR and the Kenya Data Protection Act 2019:
- Contract: to provide the Service you signed up for.
- Legal obligation: to keep tax, accounting, and audit records.
- Legitimate interest: to secure the Service, prevent fraud, and improve reliability.
- Consent: for optional marketing communications and any other use where consent is required by law.
4. How We Use It
We use personal data to operate the Service, generate reports you request, process subscription payments, deliver transactional messages, prevent abuse, comply with legal obligations, and communicate about your account.
5. Sharing & Sub-processors
We share data with the following categories of service providers:
- Safaricom — M-Pesa payments and confirmations
- Google (Gmail SMTP) — transactional email delivery
- Meta (WhatsApp Business API) — WhatsApp messaging you initiate
- OpenRouter — AI analysis requests (only aggregate/anonymised business metrics are sent)
- Cloud hosting provider — infrastructure and database storage
We do not sell your personal data. We disclose data when required by law or to protect our legal rights.
6. International Transfers
Some sub-processors may store or process data outside your country, including in the EU, UK, or US. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses.
7. Retention
- Active account data: for as long as your account exists
- Financial records: at least 7 years (tax compliance)
- Consent logs: 5 years after withdrawal
- Security/access logs: 90 days
8. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, delete, or export your data, to object to or restrict certain processing, to withdraw consent, and to lodge a complaint with a supervisory authority (in Kenya, the Office of the Data Protection Commissioner; in the EU, your local authority).
9. Cookies
We use strictly necessary cookies: auth-token (session), active-branch-id (branch selection), and platform-auth-token (platform admin only). We do not use third-party advertising cookies.
10. Children
The Service is not intended for use by anyone under 18 years old.
11. Security
We use industry-standard measures including bcrypt password hashing, HTTPS/TLS in transit, httpOnly cookies, parameterised database queries, and role-based access control. No system is perfectly secure; report suspected issues to mellotek1@gmail.com.
12. Changes
We may update this policy. Material changes will be communicated by email or in-app. Continued use after the effective date indicates acceptance.
13. Contact
Privacy enquiries: mellotek1@gmail.com