This Privacy Policy explains how the DukaSale Suite — including the Mobile POS app, Retail POS, Restaurant POS, the Owner App, and the DukaSale operator console — collects, uses, and protects information. By using any DukaSale product, you agree to the practices described here.
We run two delivery modes: a SaaS multi-tenant service hosted by DukaSale, and a standalone white-labeldeployment running on your own infrastructure. Where the two differ, we’ll call it out below.
1. What we collect
When you use DukaSale, you may enter (or your app may automatically generate) the following types of information:
- Business profile — business name, location, contact details, industry type.
- Catalog & pricing — products, variants, SKUs, barcodes, stock levels, costs and prices.
- Sales activity — transactions, payment methods, refunds, voids, discounts.
- Customer records — names, phone numbers, loyalty balances and customer credit (deni).
- Staff & access — team members, roles, PINs, audit logs.
- Financial — expenses, profit and loss, end-of-day reports, tax configuration.
- Hardware bindings — printers, barcode scanners, cash drawer routing.
For the Mobile POS account and trial features, we collect limited usage events such as app activity, completed-sale event counts, upgrade views, checkout starts and migration completion. These events are linked to your account, business and an app-generated device identifier so we can report usage and troubleshoot account access. The events do not contain sale amounts, line items or customer records. This is account-linked usage data, not anonymous telemetry.
Optional Google Analytics: Android version 1.1.0 (20) keeps collection disabled. A later Android release offers a separate opt-in under Settings > Privacy only after an adult age declaration and confirmation that the device is used exclusively by that adult. Shared devices, younger users and unknown-age users cannot opt in. Declining does not restrict app functionality. This is self-declaration, not verified age or identity. Earlier device-wide choices do not activate this feature.
If you opt in, Google Analytics receives app activity, predefined screen names, campaign notification-open events and campaign identifiers, device and app information, approximate location derived from your IP address, and an app-instance identifier. We do not send notification text, URLs, customer names, phone numbers, PINs, sale amounts or transaction contents. Advertising identifier collection and advertising consent remain disabled. Your choice is stored on your device, persists across restarts, and is revoked when you sign out or change the active user. Turn it off before allowing someone else to use the device. Disabling collection resets local Analytics data; it does not erase events Google has already received.
Product image lookup sends the product name to Pexels to find an image. Requests to image providers also expose normal network information such as the IP address. Photos you choose or take for products and logos are stored on your device; cloud product records can contain the image reference. Expo and Firebase Cloud Messaging deliver notifications when enabled. We record campaign notification opens using a hashed installation identifier and a deduplicated event identifier, plus upgrade interactions for service analytics and communications. Opens can be held on-device for up to 30 days for network retries, with a bounded queue. Installation counts do not establish individual people or prove a notification was read; disabling Google Analytics does not disable these operational records.
2. How we use it
Your business data is used to power the features you opted in to:
- Ringing up sales and printing receipts at the till.
- Tracking inventory, purchase orders and stock transfers.
- Sending end-of-day, weekly and monthly reports to the Owner App and (optionally) WhatsApp/email.
- Reminding you about deni balances, low stock, expiring batches and reorder points.
- Powering M-Pesa STK push and reconciling payments to sales.
- Showing every outlet on one screen in the Owner App.
Mobile usage events help us measure account activity, trial-to-paid conversion and migration completion, and troubleshoot the account features. Reports exclude accounts marked as internal tests. We do not use these event records to reconstruct sale details.
3. Where your data lives
It depends on the product:
- Mobile POS (Android) — data is stored locally on the device by default. Cloud backup and Owner-App sync are opt-in.
- Retail POS & Restaurant POS — browser-based, so data is stored in the DukaSale cloud (in our SaaS mode) or on your own server (in standalone mode).
- Owner App — reads from whichever stores are connected to your account.
- DukaSale operator console — plans, billing, entitlement and tenancy data only; we never see your customer transactions through it.
Our cloud infrastructure for SaaS deployments runs in regions chosen for proximity to East Africa. In standalone mode, no DukaSale-hosted servers are involved.
4. M-Pesa & payments
When you use M-Pesa, card or other payment integrations, DukaSale communicates with the payment provider on your behalf. During this process:
- The customer’s phone number or card token and the payment amount are sent to the provider to initiate the transaction.
- Confirmation, receipt number and status are received back and stored on your DukaSale instance.
- We do not store full card numbers, PINs, or M-Pesa user PINs — ever.
Payments are subject to the provider’s own terms (Safaricom for M-Pesa, the acquiring bank for cards). DukaSale acts as a technical conduit, not a payment processor.
6. Security
We take security seriously:
- Passwords are stored hashed with industry-standard algorithms. PINs use one-way hashing.
- All cloud traffic is encrypted in transit (TLS 1.2+); database backups are encrypted at rest.
- Role-based access controls limit what each staff member can see and do.
- Audit logs record sensitive actions (logins, refunds, price changes, employee creation).
- 2FA is available on the operator console and on Owner App accounts.
That said, no system is 100% impenetrable. You’re responsible for the physical security of your devices and the confidentiality of staff PINs and passwords. If you suspect a breach, contact us immediately.
7. Retention
In SaaS mode, your data stays in the system while your subscription is active and for 90 days after cancellation, after which it’s permanently deleted (you can request earlier deletion). In standalone mode you control the retention policy entirely.
For Mobile POS, locally stored business data lives on your device until you delete it or uninstall the app. We recommend regular backups. Account-linked usage events are scheduled for deletion after 90 days. We keep a separate hashed phone number and trial dates while the one-trial-per-phone rule is in operation, including after account deletion, to prevent repeat free-trial claims. Contact us to request a review of information retained about your account.
8. Your rights (Kenya Data Protection Act, 2019)
You have the right to:
- Access — see what data we hold about you. Most of it is already in the app.
- Correction — fix anything inaccurate.
- Deletion — remove records or close your account entirely.
- Portability — export your catalog, sales and customer data as CSV or JSON.
- Object — contact us with a request about analytics or other personal information associated with your account.
- Complain — to the Office of the Data Protection Commissioner (ODPC) in Kenya.
Delete your DukaSale Mobile POS account
To request deletion without opening the app, email support@dukasale.ke with the subject “DukaSale account deletion”. Include the phone number registered to your account and your shop name so we can identify the account. Do not send your PIN, passwords or payment credentials. We verify account ownership before processing the request.
Deletion removes your account profile, memberships and the cloud shops you own, including their synced business records. Shops owned by other people are not deleted. Local records and exported backups on your devices are not erased by a cloud-account deletion request.
A separate hashed phone number and trial dates are retained while the one-trial-per-phone rule operates, including after account deletion, to prevent repeated trial claims. You can request a review of retained information using the same email address. Turning off optional Google Analytics stops future collection and resets locally stored analytics data; it does not automatically remove events already received by Google.
You can also use the same contact to request deletion of particular data without closing your account. Specify which records you want removed.
9. Children & supervised use
The Mobile POS supervised-use release is intended for all ages, with accounts owned by adults aged 18 or over. A parent or guardian must create and manage the account using their own name and phone number, supervise younger users, and manage subscriptions. We do not offer independent child accounts. Do not enter a child’s name, phone number or birth date as account-owner information. Other DukaSale business services continue to require an adult account owner.
The new signup screen asks for an age group locally before displaying personal-detail fields. That choice is not sent to our servers. When an adult creates an account, we record their acceptance of the adult-owner policy and the acceptance time. This declaration is not identity verification or verification of guardianship.
Google Analytics remains disabled for younger users and shared devices. Version 1.1.0 (20) disables it entirely; subsequent versions may offer the adult personal-device opt-in described above. Necessary account, payment and enabled cloud services still process the adult owner’s account and business records described above.
If you believe a child’s personal information has been submitted, contact support@dukasale.ke. We will verify the requester’s authority and review correction or deletion requests. Do not send passwords, PINs or identity documents in an initial request.
10. Changes to this policy
We may update this Privacy Policy as the Suite evolves. When we do, we’ll update the “Last updated” date at the top. Material changes get notified by email or in-app at least 14 days in advance.
11. Contact us
Questions about your data, this policy, or a Data Protection Act request? Reach our team: