Zyrace POS is operated by Zyrace.
We take the privacy of your business and your customers seriously. This policy explains what personal data we handle, why, and what your choices are. It is written in line with the Sri Lankan Personal Data Protection Act, No. 9 of 2022.
1. Who is responsible for what
- For the data about you and your staff as users of Zyrace POS (sign-in details, billing contact, how you use the service), we decide how it is used. We are the "controller".
- For the data you enter about your own customers, suppliers and employees, you decide why and how it is used. We process it only to provide the service to you, on your instructions. We are the "processor".
If you are a customer of a shop that uses Zyrace POS, and want to see or correct your data, please contact that shop first.
2. What we collect
About you and your staff
- Name, email address, phone number, role and sign-in method (including Google sign-in, if you use it).
- Your business details: shop name, address, VAT number, logo, receipt settings.
- Billing details: your plan, payment reference and receipts. We do not store card numbers.
Business data you enter
- Products, prices, stock, sales and receipts, expenses and purchases.
- Customers: name, phone number, loyalty points, credit balance and payment history.
- Suppliers and their contact details.
- If you use staff tools: employee name, contact details, NIC number, job title, salary and bank details, and leave records.
Technical data
- IP address, browser type and device, pages used, and an audit log of important actions (who changed what and when).
- Error reports, which tell us when something broke. We limit what these include, and we set them not to include request contents, cookies or user details from the web apps.
Website visitors and partners
- If you request a demo, we receive the name, phone, email and business type you type in.
- If you are a partner in our affiliate programme, we hold your contact details and the bank details we need to pay commission.
3. How we use it
- To provide, secure and support the service, and to send you the sign-in codes and notices you need.
- To manage subscriptions, payments and activation.
- To fix errors, prevent abuse and improve the product.
- To answer you and follow up on demo requests.
- To meet legal duties.
We do not sell personal data and we do not use it for advertising.
4. Who we share it with
We use trusted service providers to run the service. They may only use data to provide their service to us.
| Purpose | Provider (location) |
|---|---|
| Servers and database hosting | Hetzner (Finland) |
| Network protection and delivery | Cloudflare |
| Email delivery (sign-in codes, notices) | Resend |
| Sign-in with Google | Google / Firebase |
| Error monitoring | Sentry (EU) |
| Uptime and server monitoring | Better Stack, Grafana Cloud |
| Encrypted offsite backups | Backup storage provider (data is encrypted before it leaves our servers) |
We may also share data where the law requires it, or to protect our rights. We do not share one shop's data with another shop.
5. Where data is stored
Our main servers are in Finland, in the European Union. Some providers above may process data in other countries. When we use them, we choose providers that protect data to a reasonable standard.
6. How we protect it
- Traffic is encrypted (HTTPS).
- Each shop's data is kept in its own separate database space.
- Staff accounts have permissions, so a cashier sees only what they need.
- Access is by one-time email code; sessions are short.
- We keep an audit log, and we back up every night to an encrypted offsite copy.
No system is perfectly secure. If a breach affects your data, we will tell you without undue delay.
7. How long we keep it
- While your account is active, we keep your data so the service works.
- After you cancel, we keep it for 30 days, then delete it.
- Backups are kept for up to 30 days and then expire.
- We keep some records for longer where the law requires (for example billing records).
8. Your rights
You may ask us to:
- give you a copy of the personal data we hold about you;
- correct it if it is wrong;
- delete it, when we no longer need it;
- stop using it for a particular purpose;
- withdraw consent you gave us.
Email [email protected]. We will reply within a reasonable time. You may also complain to the Data Protection Authority of Sri Lanka.
9. Cookies and browser storage
The Zyrace POS app does not use advertising cookies. It stores your sign-in tokens and preferences in your browser so that you stay signed in, and it can cache pages so that it works faster and briefly offline. Signing out clears your sign-in.
Our public website (pos.zyrace.com) does not use advertising cookies either. It uses Cloudflare Web Analytics to count visits, which works without cookies. If you choose a light or dark theme on the website, that choice is saved in your browser so it stays the same on your next visit.
10. Children
Zyrace POS is for businesses and is not meant for people under 18. We do not knowingly collect data from children.
11. Changes to this policy
If we change this policy in an important way, we will tell you by email or in the app before the change applies. The date at the top shows when it was last updated.
12. Contact
Zyrace · Email: [email protected] · WhatsApp: +94 71 365 9403