1. Overview & Scope
This Privacy Policy explains how Chimeole Software collects, utilizes, stores, and protects personal and business information when you use the Chimeole POS point-of-sale platform, mobile PWA applications, offline synchronization protocols, and customer-facing digital storefronts.
2. Information We Collect
We collect only the information necessary to provide and operate the platform:
- Business Profile Data: Business name, industry type, branch locations, phone numbers, email addresses, and logo branding.
- Staff & User Accounts: Names, usernames, encrypted password hashes, role assignments (e.g. Cashier, Manager), and activity audit logs.
- Catalog & Inventory Data: Product names, barcodes/SKUs, category hierarchies, wholesale/retail pricing, unit quantities, and supplier records.
- Transaction & Order History: Order timestamp, itemized cart contents, cashier identifier, tender type (Cash, Card, Transfer, Split), Paystack reference tokens, and receipt numbers.
- Customer Data (Optional): Customer name, phone number (for WhatsApp receipts), email address, and loyalty points provided voluntarily during checkout.
3. How Information is Used
Data gathered through Chimeole POS is utilized strictly for:
- Executing retail transactions, printing thermal receipts, and sending digital WhatsApp/Email receipts.
- Maintaining real-time inventory deduction ledgers and generating low-stock alerts.
- Displaying Kitchen Display System (KDS) food orders and table service statuses.
- Producing end-of-day shift reports, profit/loss financial analytics, and gross revenue summaries.
- Synchronizing offline transactions reliably to the central cloud server once connectivity is established.
4. Local Storage & Offline Caching Security
Chimeole POS utilizes client-side IndexedDB and Service Worker Cache to enable full POS checkout without internet:
- Offline transaction queues are stored in isolated local browser storage partitioned strictly to the Chimeole POS domain.
- Once an internet connection is detected, offline sales are cryptographically submitted via secure REST APIs with deduplication checks.
5. Payment Security & Zero-Card Storage
We strictly adhere to zero-card-retention standards. Chimeole POS never receives, processes, or stores complete debit/credit card PAN numbers, CVV security codes, or card PINs on its servers. All digital card and transfer verifications are executed directly through Paystack's tokenized PCI-DSS Level 1 certified gateway.
6. Information Sharing & Third-Party Services
We do not sell, rent, or monetize your store data, customer lists, or sales records to advertisers. Data is shared exclusively with necessary infrastructure providers:
- Paystack: For automated card & transfer payment settlement.
- WhatsApp / Mailgun / SMTP: When you choose to dispatch itemized customer digital receipts.
- Law Enforcement: Only when strictly required by enforceable court orders or national statutory regulatory mandates.
7. Data Retention & Merchant Export Rights
Merchants retain complete ownership of their commercial data. You may at any time export your complete inventory, customer ledger, expense history, and sales transaction logs into open CSV/Excel formats from your admin settings.
8. Merchant & Customer Rights
Under the Nigeria Data Protection Regulation (NDPR) and international privacy frameworks, you have the right to:
- Access and inspect all personal data stored under your tenant profile.
- Request rectification of inaccurate business or staff records.
- Request full data erasure or account deletion upon termination of service.
9. Data Protection Officer & Inquiries
For inquiries regarding data protection, privacy practices, or compliance requests, please contact:
Data Protection Officer • Chimeole Software
privacy@chimeolesoftware.com / dpo@chepos.com
Chimeole POS Operations • Chimeole Software Nigeria