PEAK POS

Privacy Policy

PEAK POS — operated by Zerowatt Ecology Ltd. · Last updated 22 June 2026

This policy explains what the PEAK POS app and the pos.peakcoffee.cc service (“the Service”) collect and how we use it. The Service is a point-of-sale system used by coffee shops and their staff. Questions: peakcoffee.cc@gmail.com.

Who we are

The Service is provided to participating shops (“Merchants”). For data entered by a Merchant’s staff and customers, the Merchant is the data controller and we process it on their behalf.

What we collect

  • Shop & staff accounts — login email, staff display names, and access PINs (stored only as a salted hash, never in plain text).
  • Loyalty members — a mobile number and optional name, used to award and redeem stamps. Numbers are stored encrypted.
  • Orders & payments — items, amounts, and payment status. Card payments are processed by Stripe; we do not store full card numbers.
  • Camera — used only to scan QR/barcodes at the counter. Images are processed on-device and are not stored or transmitted.
  • Device & usage — basic technical data (app version, device type, logs) to operate and secure the Service.

How we use it

To run the point of sale, process payments, issue receipts and wallet passes, operate loyalty, send transactional or shop-initiated notifications, and keep the Service secure. We do not sell personal data, and we do not use it for third-party advertising.

Service providers we share with

We use trusted processors strictly to deliver the Service: Stripe (payments), Supabase and Vercel (hosting & database), Resend (email), and Apple Wallet / Google Wallet (passes). Each handles data under its own terms and security obligations.

Retention

We keep data for as long as the Merchant’s account is active and as needed for accounting, tax, and legal obligations, then delete or anonymise it.

Security

Data is encrypted in transit (HTTPS) and at rest. PINs and passwords are stored only as salted hashes; loyalty mobile numbers are stored encrypted. Access is restricted to authenticated staff of the relevant shop.

Your choices & deletion

Shops can request deletion of their account and associated data from within the app (Admin → footer → “Request account deletion”) or by emailing us. Customers can ask the shop, or us, to remove their loyalty record.

Children

The Service is a business tool and is not directed to children.

Changes

We may update this policy; material changes will be posted on this page with a new date.

Support · Contact