Table of Contents
1. Who We Are 2. What Data We Collect 3. VoidPOS Go (Android App) 4. How We Use Your Data 5. Data Storage & Security 6. Data Sharing 7. Cookies & Tracking 8. Your Rights 9. Account & Data Deletion 10. Data Retention 11. Children’s Privacy 12. International Transfers 13. Changes to This Policy 14. Contact UsVoidPOS (“we”, “us”, “our”) operates the VoidPOS Point of Sale web platform and the VoidPOS Go Android application (together, the “Service”). We are the data controller responsible for the personal data processed through both products.
Contact: [email protected]
When you register and use VoidPOS as a business owner, we collect:
| Data | Purpose | Required? |
|---|---|---|
| Email address | Account authentication, communications | Yes |
| Full name | Account identification | Yes |
| Phone number | Account contact, support | Yes |
| Country | Regional pricing, timezone | Yes |
| Business name, address, phone | POS receipts, profile | Optional |
| Password (hashed) | Account security (stored by Firebase Auth) | Yes |
Data you create while using the Service:
This data belongs to you. We process it solely to provide the Service.
Automatically collected when you use the Service:
Payment card details are processed by Paddle and are not stored by VoidPOS. We only store the amount paid and the plan activated.
VoidPOS Go is a separate, offline-first Android point-of-sale app. It shares the data practices described above with some differences specific to a mobile application. This section describes those differences.
VoidPOS Go uses Google Sign-In for authentication (via Firebase Authentication). We receive your Google account’s name, email address, and profile photo at sign-in. We do not receive your Google password.
| Data | Purpose | Required? |
|---|---|---|
| Google account name, email, profile photo | Sign-in and account identification | Yes |
| Business profile (name, address, phone, currency, branding) | Receipts, app customization | Optional |
| Products, categories, orders, order items, expenses | Core POS functionality | Yes |
| Device identifier | Anti-hijack device security — detects sign-in on a new device and locks the previous one | Yes |
| Uploaded photos (store cover, product images, receipt logo) | Stored in Firebase Cloud Storage under a path unique to your business | Optional |
| Team member email & role | Multi-device access on Duo/Team plans | Optional |
| Subscription & billing status | Enforcing plan limits, renewal reminders | Yes |
VoidPOS Go is offline-first: products, orders, and settings are cached in a local database on your device so checkout keeps working without an internet connection. This local cache syncs to Firebase automatically once the device is back online. If you uninstall the app, this local cache is removed from your device, but your cloud data in Firebase is not affected — use the in-app or web deletion flow described in Section 9 to remove your cloud data.
Depending on the features you use, VoidPOS Go may request:
You can grant or revoke each permission at any time from Android Settings → Apps → VoidPOS Go → Permissions. Declining a permission only disables the related feature; it does not prevent you from using the register.
VoidPOS Go sends transactional emails for: invitation to join a business as a team member, and a one-time verification code when you request account deletion (see Section 9). We do not send marketing emails from the app without your consent.
| Purpose | Legal Basis |
|---|---|
| Providing and operating the VoidPOS Service | Contract performance |
| Processing payments and managing subscriptions | Contract performance |
| Sending transactional emails (receipts, account alerts) | Contract performance |
| Customer support and responding to enquiries | Legitimate interest |
| Security monitoring and fraud prevention | Legitimate interest |
| IP-based regional pricing (anonymous) | Legitimate interest |
| Improving the Service (aggregate, anonymised data) | Legitimate interest |
| Sending product updates (with your consent) | Consent |
We do not sell your personal data to third parties. We do not use your data for advertising.
Your data is stored in Google Firebase Realtime Database, located in the Asia Southeast 1 region (Singapore). Firebase is operated by Google LLC and complies with GDPR and international data protection standards.
In the event of a data breach that affects your personal data, we will notify you by email within 72 hours of becoming aware of the breach, as required by applicable law.
We share your data only with the following service providers, and only to the extent necessary to provide the Service:
| Provider | Purpose | Data Shared |
|---|---|---|
| Google Firebase (Google LLC) | Database & authentication (VoidPOS and VoidPOS Go) | All business data |
| Google Firebase Cloud Storage | Storing uploaded photos & files (VoidPOS Go) | Store covers, product images, branding you upload |
| Google Identity Toolkit (Firebase Auth) | Sign-in & account management | Name, email, profile photo, sign-in identifier |
| Paddle | Payment processing | Name, email, billing address, payment |
| ipapi.co / ip-api.com | IP geolocation for pricing | IP address only (anonymous) |
| Google Fonts | Font loading | None (CDN request only) |
| Email delivery provider (Zoho / transactional SMTP) | Sending account, invitation, and deletion-verification emails | Email address, email content |
We may disclose your data if required by law, court order, or to protect the rights and safety of VoidPOS, our users, or the public.
| Cookie | Purpose | Duration |
|---|---|---|
| VOIDPOS_SESS | Session management (keeps you logged in) | Session / 8 hours |
| Firebase auth tokens | Firebase authentication state | 1 hour (refreshed automatically) |
VoidPOS does not use advertising cookies, third-party tracking pixels, or social media tracking.
You can disable cookies in your browser settings. Disabling the session cookie will prevent you from logging in.
Depending on your location, you may have the following rights regarding your personal data:
To exercise these rights, contact us at [email protected]. We will respond within 30 days.
Delete your account and all associated data at any time from Settings → Delete Account in your admin dashboard. Deletion is permanent and irreversible.
VoidPOS Go includes a verified, self-service deletion flow available two ways:
Full step-by-step instructions are published at voidpos.com/go/delete-account, as required by Google Play’s data safety policy.
Deleting your VoidPOS Go account permanently removes: your business profile, products, categories, orders, order items, expenses, subscription and billing history stored in your account, uploaded photos and files in Cloud Storage, pending team invitations, your team member records for that business, and your Firebase Authentication sign-in (you are signed out on every device). If a teammate previously joined your business, deleting your account removes their access to it, but does not delete their own separate Google/Firebase sign-in.
There is no recovery period once deletion is confirmed — the one-time email code and typed confirmation exist specifically to prevent accidental deletion before that point.
We retain your data for as long as your account is active, on both VoidPOS and VoidPOS Go. When you delete your account:
If your subscription expires and you do not reactivate within 90 days, we may permanently delete your account data after sending a 14-day notice email.
VoidPOS is a business tool intended for adults aged 18 and over. We do not knowingly collect personal data from children under 18. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
Your data is stored on Google Firebase servers located in Singapore (Asia Southeast 1). By using VoidPOS, you consent to the transfer of your data to Singapore and to other countries where our service providers operate.
Google LLC participates in and complies with relevant data transfer frameworks. For users in the European Economic Area (EEA), these transfers are governed by Standard Contractual Clauses under GDPR.
We may update this Privacy Policy from time to time. When we make significant changes, we will notify you by email or by displaying a notice in the Service. The “Last updated” date at the top of this page will reflect when changes were made.
Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.
For any privacy-related questions, requests, or complaints, contact us:
If you are in the EU/UK and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.