Privacy Policy — InSoft POS
This privacy policy explains how InSoft Online processes personal data in connection with the InSoft POS mobile and tablet application (package de.insoftonline.posapp) for Android and iOS. It supplements our website legal notice and Terms & Conditions.
Version 1.0 · Last updated 15 September 2026
1. Controller
Controller for the app and the related backend services is InSoft Online, Karlstraße 18, 72336 Balingen, Germany. Email: info@insoftonline.de. Phone: +49 151 16908778. Further company details are listed in the Impressum.
2. Who the app is for
InSoft POS is a business point-of-sale app for merchants who already run an InSoft POS / Odoo-based system. Public self-registration is not available. Login credentials (username and password) are created and provided by InSoft for contracted customers.
The app also contains demo accounts so that anyone can open the app and try sample workflows. Demo data is for demonstration only and must not be used for live trading or real personal data of end customers.
3. Purposes of processing
We process data to operate the till: authenticate the merchant account, sync products and settings with the InSoft backend, record sales and payments, print or display receipts, support optional fiscal (TSE) features in Germany, enable offline order queues and later sync, and provide remote support when you request it (for example via AnyDesk).
Legal bases under the GDPR are typically Art. 6 (1) (b) (performance of the contract with the merchant) and Art. 6 (1) (f) (legitimate interests in secure operation, licence checks and support). Where the merchant processes end-customer data in the app, the merchant is usually the controller for that data; InSoft acts as processor under a data processing agreement where required (Art. 28 GDPR).
4. Categories of data
Account and authentication: login email or username, password, access token, company identifiers, selected server region (Germany or Syria host), licence status and app version.
Business and staff data: company name, address, phone, VAT and register details, logo, and POS work users selected after login.
Point-of-sale operations: products, categories, taxes, orders, order lines, discounts, tips, tables, cash movements, reports, and related timestamps.
End customers (if the merchant uses CRM features): name, phone, email, address, VAT ID and price list — stored for the merchant’s sales process and cached on the device.
Payments: tender type (cash, card, wallet/other), amounts and journal entries. Card payments may be handled by SumUp or a local ZVT payment terminal; those providers process payment data under their own terms.
Device and local network: Wi‑Fi address for discovering printers or payment terminals, Bluetooth printer names, camera input for barcode or QR scanning, and optional battery-optimisation settings. Location permission on mobile platforms may be required by the operating system for Bluetooth device discovery; the app does not use continuous tracking or maps advertising.
Fiscal / TSE (when enabled): signatures and related fiscal fields returned by the backend or shown on receipts for German Kassensicherungsverordnung compliance. Responsibility for correct tax registration and retention remains with the merchant.
5. Where data is stored
On the device: preferences (including login details needed for convenience), local databases for the cart, pending offline orders and selected feature data, and a local cache of customers and settings.
On InSoft servers: authentication and Odoo API traffic to hosts such as support.insoftonline.de and support-sy.insoftonline.de (and related customer/licence endpoints). Settings backups and licence checks may be stored in the merchant’s hosted environment.
Transmission uses HTTPS to InSoft backends. Local network traffic to printers or ZVT terminals stays on the merchant’s LAN.
6. Recipients and third parties
InSoft operates the backend used by the app. Card acceptance via SumUp involves SumUp as an independent payment service provider. Printer and terminal manufacturers receive only what is needed for local hardware communication.
We do not use advertising SDKs, Firebase Analytics, Crashlytics or similar consumer analytics packages in the current InSoft POS app build described here. We do not sell personal data.
7. Retention
Merchant account and sales data are retained for the duration of the contract and as required by commercial and tax law (including GoBD / fiscal retention duties that apply to the merchant). Demo accounts and demo data may be reset or overwritten at any time.
Local device caches and offline queues persist until cleared by logout, app uninstall, or sync. Merchants should wipe devices before disposal or staff changes.
8. Your rights
Depending on applicable law, data subjects may request access, rectification, erasure, restriction, portability and objection, and may lodge a complaint with a supervisory authority (in Germany typically the Landesbeauftragte für den Datenschutz of Baden-Württemberg).
Merchant staff should contact their employer (the merchant) for end-customer data held in the POS. For InSoft-held account data, contact info@insoftonline.de.
9. Security
Access is limited to provisioned credentials and an active licence. Merchants must keep passwords confidential and use device lock screens. Because the app can store login data on the device for convenience, protect tablets against unauthorised physical access.
10. Children
The app is intended for business use by adults. It is not directed at children.
11. Changes
We may update this policy when the app or our processing changes. The version date above will be revised. Material changes will be communicated to contracted customers through the usual support channels where appropriate.
12. Contact
Privacy enquiries: info@insoftonline.de · InSoft Online, Karlstraße 18, 72336 Balingen, Germany.