Last updated: July 30, 2026
Short summary
CafePOS is an offline-first point-of-sale app. Most store and sales data remains on your device. Optional features such as Online Ordering, Feedback, iCloud Backup, and Telegram receipts send the information needed for those features to external services. CafePOS does not sell data, use it for advertising, or track users across apps or websites.
Information stored on your device
When you use CafePOS, the app may store the following information on your iPhone or iPad:
- Store details such as store name, phone number, logo, and PromptPay number
- Menu data, categories, product images, prices, options, discounts, tables, and payment methods
- Sales data such as orders, line items, payment totals, discounts, taxes, service charges, shifts, and reports
- Inventory data such as stock counts, receiving records, adjustments, waste, expiry dates, and stock history
- Customer and loyalty point data if you choose to use loyalty features
- Staff profiles and PIN verification data, with PINs stored in a protected form rather than plain text
- Printer, receipt, language, and other app settings
QR Online Ordering
When a store enables Online Ordering, CafePOS sends the information needed to developer-operated systems hosted through Cloudflare and Supabase so the app can publish a menu, open QR sessions, accept orders, and return status updates to the POS device.
- Store name, menus, categories, prices, options, item availability, tables, and product images. Product images in a published online menu are available through a public link
- QR sessions, carts, ordered items, quantities, options, customer-entered notes, totals, order status, and related timestamps
- Store, device, and installation identifiers, App Attest information, and APNs push tokens used to verify devices, prevent abuse, and notify the POS of new orders
- Network and technical logs needed for service security, troubleshooting, and reliability
Feedback and attachments
If you choose to submit Feedback, the app sends the feedback category and message, the active staff name, app and operating system versions, device model, locale, store/device identifiers, and up to five photos you select. This information is used only to respond, investigate issues, and improve the product. Feedback images are stored in a private, non-public bucket.
Other features that send information off the device
The app sends information outside the device when required by a feature you choose or an operating system service.
- CafePOS Pro purchases, subscriptions, entitlement restoration, and trials are handled through Apple App Store and StoreKit
- If iCloud Backup is enabled, store backups, settings, and sales history are stored in your iCloud account
- Telegram receipt delivery sends order details, items, totals, and payment methods to the bot/chat you configure
- PDF, CSV, Excel, or configuration sharing sends files to destinations you choose, such as AirDrop, Files, LINE, or email
- Printer connections may use Bluetooth or the local network to discover and print to devices
Retention and deletion
Information on your device remains until you delete it in the app or remove the app. iCloud backups must be deleted from the app's iCloud Backup screen or from your iCloud account.
Transient Online Ordering data, including QR sessions, carts, orders, and events, is closed when it expires or payment begins and is automatically removed after the 30-day retention period following session closure or expiry. Feedback submissions and their attachments are automatically deleted after 30 days.
Current store data, the current menu and product images, and device registration information are retained while the store continues to use Online Ordering so existing QR and notification features keep working. Old menu versions are progressively removed. To delete this information from developer-operated systems, contact us. Verified requests will be completed within 30 days.
Information you send to Telegram or a file-sharing destination is governed by that destination's policies and your settings.
Third-party services
External services that may process information include Apple (App Store, StoreKit, App Attest, APNs, and iCloud), Cloudflare (Worker, network, and security services), Supabase (database and object storage), Telegram, and file-sharing services you select. Each provider may retain technical information under its own policy.
Security
CafePOS uses SwiftData, Keychain, UserDefaults, signed requests, and Apple App Attest where appropriate. Internet traffic uses HTTPS, and Feedback images are stored in a private bucket. No system can be completely secure, so users should lock their devices, protect bot tokens, and handle exported files carefully.
Your rights and choices
You may ask us to review, correct, or delete information CafePOS stores on developer-operated systems by using the contact details below. We may request information needed to verify that the request relates to your store or device before acting on it.
Children
CafePOS is a business operations app and is not directed to children. If you believe child data has been stored inappropriately, please contact us for review.
Changes to this policy
We may update this policy when features are added or data processing changes.
Contact us
For privacy questions, contact us at [email protected] or LINE OA https://lin.ee/Qc2Xxzs