Privacy Policy
Last updated: August 2026
Qubetex POS is a point-of-sale product for retail shops (website, desktop app, and Android mobile app). This page explains what data we collect, where it is stored, and how it is used — including what the Play Store / mobile app asks permission for.
1. What we collect
- Shop owner / staff account: name, email, shop name, phone (if provided), and password (stored with one-way hashing — we never store or see the plain password).
- License + activation: license key, device identifiers used for activation, and IP + user-agent of activations / API logins.
- Shop business data: products, categories, brands, units, customers/suppliers, sales, returns, payments, cheques, journal entries, stock, expenses, settings, and receipt details — whatever you enter into the POS.
- API / app tokens: access tokens for the desktop and mobile apps (stored as secure hashes after issuance).
- Mobile app local data: login token (secure device storage), cached catalog / offline sale queue, language and branch preferences on the device.
- Logs: server request logs (IP, URL, status, time) for debugging and abuse detection. Rotated regularly (about 30 days).
2. Android / Play Store permissions
The Qubetex POS Android app may request the following. Each is optional for many workflows and is used only for the stated POS feature — never for advertising.
- Camera: scan product barcodes at checkout and (if you choose) take a product photo. Images you attach become part of your shop catalog on our servers.
- Photos / media (when you pick an image): set a product image from your gallery.
- Contacts (optional): import a phone contact as a customer or supplier. Only contacts you select are saved into your shop’s party list on our servers. We do not upload your entire address book in the background.
- Biometric unlock (optional, device feature): Face ID / fingerprint to unlock the app on your device. Biometric data stays on the device; we do not receive fingerprint or face templates.
- Internet: sync with
qubetexpos.comfor login, sales, stock, and reports.
We do not request microphone access for recording. We do not use continuous background location tracking.
3. What we do NOT collect
- Customer-facing ad trackers (no Google Analytics ads, no Facebook Pixel, no ad networks).
- Card PAN / CVV. Card / bank / JazzCash / EasyPaisa are recorded as payment method + amount only.
- Your full contacts list unless you explicitly import selected contacts into the POS.
- Anything from the desktop app’s local SQLite database except what you explicitly sync to the cloud.
4. Where your data lives
- Cloud (qubetexpos.com): MySQL on our Hostinger server. Backed up regularly. Encrypted at rest by the hosting provider.
- Android app: auth token in secure storage; temporary offline catalog / queued sales on the device until sync.
- Desktop: SQLite on each PC/Mac under the Qubetex application data folder. We cannot read it unless you sync or send a backup.
- Sessions + cookies (website): HTTPS-only cookies with strict same-site protection.
5. Multi-tenant isolation
Every shop’s data is isolated so one shop cannot see another’s records. This is enforced on every request. Vendor super-admin access is only for support and account management.
6. Third parties
- Hostinger — hosts the web app + database. Their privacy policy.
- Google Play — distributes the Android app; Google may process install / crash / update metadata under their policies.
- FBR (Federal Board of Revenue, Pakistan) — only if your shop opts into FBR invoicing; sale records are sent as required by tax law.
- OpenFoodFacts — optional barcode lookup for new products. Only the barcode is sent; no customer data.
7. Security measures
- Passwords hashed with strong one-way algorithms.
- API tokens hashed; expire / rotate per device.
- HTTPS enforced for the website and API.
- Security headers, rate limits on login and sensitive APIs.
8. Children’s privacy
Qubetex POS is a business tool for shop owners and staff. It is not directed at children under 13. We do not knowingly collect personal data from children.
9. Your rights
You may request an export or deletion of your shop account and associated data by emailing contact@qubetexpos.com, or use our public form page: https://www.demo.qubetex.com/delete-account. You can also uninstall the mobile app at any time; uninstalling removes local device data but does not delete your cloud shop until you request account deletion.
10. Changes to this policy
Material changes will be posted here with an updated date. We will notify shop owners when a change affects what we collect or who we share with.
11. Contact
Questions or requests: contact@qubetexpos.com · website qubetexpos.com · Contact page.