CeylonPOS

Privacy Policy

Last updated 30 August 2026

CeylonPOS is point-of-sale software for shops. This policy explains what we do with personal information — both yours, if you run a shop with us, and your customers', which you enter into the system.

CeylonPOS is currently operated as a trading name rather than a registered company. Enquiries about this policy, or any request described in it, go to [email protected].

Two different relationships

It matters which of these applies, because it decides who answers to whom.

What the software stores

About the people who work in a shop

A name, an email address, a username and a password. Passwords are stored only as a one-way hash — we cannot read them, and neither can you.

About a shop's customers, when the shop enters it

Name, phone number, email address, postal address, an optional company name and tax number, an account number, loyalty points, free-text notes, and a consent flag. None of it is required to ring up a sale: a shop can trade entirely with walk-in customers and hold nothing about anybody.

About trade

Sales and their lines, returns, quotes, payments, cash-ups, expenses, stock movements and purchase orders — the ordinary records of a shop.

Card numbers are never stored. A payment records only how it was made — cash, card, cheque, account, and so on — together with the amount. Card data is handled by whatever terminal or provider the shop uses and does not reach CeylonPOS.

Where it is kept, and who can reach it

Every shop has a database of its own. Shops are not rows in a shared table separated by a filter; they are separate databases, so one shop cannot query another's records even in principle.

Data is held on a managed server. Our staff can reach a shop's data only where it is needed to run the service or to help with a problem you have raised.

The AI features, and what leaves the server

This is the one part of CeylonPOS that sends data to somebody else, so it is worth setting out exactly.

The AI work is an optional add-on and is off unless a shop buys it. A shop that has not bought it sends nothing anywhere. Where it is switched on, the service used is Anthropic's Claude API, and two features use it:

Nothing else in CeylonPOS sends your data outside our server. If you would rather no shop data ever left it, do not enable the AI add-on.

Email

A receipt can be emailed to a customer when they ask for one. That uses the mail provider configured for the shop, and the customer's address is used for that message and kept on their record so the next receipt can be sent.

Cookies

CeylonPOS sets a session cookie so that you stay signed in, and a token used to protect forms against cross-site request forgery. That is all. There is no advertising cookie, and the CeylonPOS website carries no analytics or tracking scripts of any kind.

How long things are kept

A shop's records are kept for as long as the shop is with us, because a point of sale is also a book of account and shops need their history. When a subscription ends you can ask us for an export, or ask us to delete the shop's database; we will do either within a reasonable period of being asked.

Your rights

You can ask us what we hold about you, ask for it to be corrected, or ask for it to be deleted. Write to [email protected].

If your request is about records held by a shop — because you are that shop's customer — the shop is the right place to ask, since the records are theirs and they decide what happens to them. We will help the shop act on your request, but we will not change or delete a shop's records without their instruction.

Changes

If this policy changes, the date at the top changes with it. Where a change materially affects what happens to your data, we will tell shop owners directly rather than relying on you to notice.