Privacy Policy
Maksud Limited
Last Updated: September 2026
1. Introduction
This Privacy Policy explains how Maksud Limited ("we", "us", or "our") collects, uses, stores, and protects information when you use our EPOS (Electronic Point of Sale) application ("the App"). Section 14 covers this website (maksud.co.uk) separately.
The App is designed for business staff to manage point of sale operations, process orders, and handle payments. By using the App, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Staff Account Information
When business staff use the App, we collect:
- Full name
- Email address
- Staff role (e.g., manager, kitchen staff, owner)
- 4-digit PIN for authentication
- Staff activity logs (orders processed, login times)
2.2 Business Owner Information
When business owners register and manage their account:
- Email address
- Password (stored securely using industry-standard hashing)
- Business name, address, and logo
- Business configuration preferences
2.3 Customer Order Information
When processing customer orders, the App collects:
- Customer name
- Phone number
- Email address (optional)
- Delivery address (for delivery orders)
- Order details (items, quantities, special instructions)
- Payment information (processed securely via Stripe)
2.4 Device Information
To provide the service, we may access:
- Device identifiers for authentication
- Camera (for uploading product images)
- Local storage (for app settings and temporary data)
- Bluetooth (for connecting to receipt printers)
3. How We Use Your Information
We use the collected information to:
- Authenticate users: Verify staff identity and manage access permissions
- Process orders: Create, manage, and fulfil customer orders
- Process payments: Securely handle payment transactions via Stripe
- Send notifications: Deliver SMS notifications for payment links and order updates
- Improve our service: Analyse usage patterns to enhance app functionality
- Maintain security: Detect and prevent fraudulent activity
- Comply with legal obligations: Meet regulatory and legal requirements
4. Third-Party Services
We use the following third-party services to operate the App:
4.1 Stripe (Payment Processing)
- Purpose: Process credit/debit card payments
- Data shared: Customer ID, payment amount, transaction details
- Privacy Policy: https://stripe.com/privacy
4.2 Twilio (SMS Notifications)
- Purpose: Send payment links and order notifications via SMS
- Data shared: Customer phone numbers, message content
- Privacy Policy: https://www.twilio.com/legal/privacy
4.3 Neon (Database Hosting)
- Purpose: Securely store business and order data
- Data shared: All application data (encrypted in transit and at rest)
- Privacy Policy: https://neon.tech/privacy
4.4 Cloudflare (Infrastructure)
- Purpose: Host and secure our API services
- Data shared: API request data
- Privacy Policy: https://www.cloudflare.com/privacypolicy/
4.5 Cloud Storage (S3-Compatible)
- Purpose: Store product images and business assets
- Data shared: Uploaded images and files
- Note: No personal data is stored in image files
5. Data Security
We implement robust security measures to protect your information:
- Encryption: All data is transmitted using HTTPS/TLS encryption
- Secure Storage: Sensitive credentials are stored using platform-specific secure storage (iOS Keychain, Android KeyStore)
- Token-Based Authentication: JWT tokens with short expiry periods (15 minutes)
- Tenant Isolation: Database-level security ensures business data is isolated
- PCI Compliance: Payment card details are handled entirely by Stripe; we never store card numbers
- Access Controls: Role-based permissions restrict data access to authorised personnel
6. Data Retention
We retain your information for as long as necessary to provide our services and comply with legal obligations:
- Active accounts: Data is retained while the account remains active
- Order history: Retained for accounting and legal compliance purposes
- Deleted accounts: Personal data is removed within 30 days of account deletion, except where retention is required by law
- Backup data: May be retained for up to 90 days for disaster recovery purposes
7. Your Rights
Under applicable data protection laws (including UK GDPR), you have the following rights:
7.1 Right of Access
You can request a copy of the personal data we hold about you.
7.2 Right to Rectification
You can request correction of inaccurate or incomplete personal data.
7.3 Right to Erasure
You can request deletion of your personal data, subject to legal retention requirements.
7.4 Right to Restrict Processing
You can request that we limit how we use your data.
7.5 Right to Data Portability
You can request your data in a machine-readable format.
7.6 Right to Object
You can object to certain types of data processing.
7.7 Right to Withdraw Consent
Where processing is based on consent, you can withdraw it at any time.
To exercise any of these rights, please contact us using the details in Section 12.
8. How to Request Data Deletion
To request deletion of your data:
- Email us at privacy@maksud.co.uk with the subject line "Data Deletion Request: Maksud - Restaurant POS"
- Include your name and the email address associated with your account
- We will verify your identity and process your request within 30 days
Data that will be deleted:
- Staff account information (name, email, PIN)
- Business owner account details
- Customer order information associated with your account
Data that may be retained:
- Order history may be retained for up to 7 years for accounting and legal compliance purposes
- Backup data may persist for up to 90 days after deletion
- Anonymised data that cannot be linked back to you
9. Children's Privacy
The App is designed for business use by adult staff members. We do not knowingly collect personal information from children under 13 years of age. If you believe we have inadvertently collected such information, please contact us immediately so we can delete it.
10. International Data Transfers
Your data may be processed in countries outside the UK/EEA, including:
- United States (Stripe, Twilio, Cloudflare, Slack, Umami Software, Inc., and some of Attio's service providers)
- European Union (Database hosting; our Google Cloud analytics warehouse; Attio, our customer relationship management system)
Where data is transferred internationally, we ensure appropriate safeguards are in place, such as the UK International Data Transfer Addendum, the UK-US Data Bridge, or adequacy regulations.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes by:
- Posting the updated policy in the App
- Updating the "Last Updated" date at the top of this policy
- Sending an email notification for material changes
We encourage you to review this policy periodically.
12. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:
Maksud Limited
Email: privacy@maksud.co.uk
14. Website Analytics and Cookies
This website (maksud.co.uk) uses analytics to count visits and understand which pages and links people use, so we can improve the site. We do not use advertising, profiling or cross-site tracking, and we do not sell or share this information with anyone for their own purposes.
14.1 What We Store on Your Device
We store two small values in your browser's local storage. These are not cookies and are never sent to advertisers.
- A random visitor reference — a randomly generated string such as
8f3c1a2e…. It contains no name, email or anything derived from you. Its purpose is to recognise that separate visits came from the same browser and, if you later send us an enquiry, to let us see which pages and links that browser used before getting in touch. It is not linked to you unless you choose to give us your name and email in the contact form. Our basis for this is our legitimate interest in understanding which of our pages lead to enquiries; you can object at any time using the control in 14.3. - How you first found us — the search engine, website or campaign that first brought you here, and the first page you landed on. Recorded once, on your first visit, and never changed.
If you send us an enquiry, we attach how you first found us to your message, together with a random reference for that enquiry alone, so we know which page and which channel brought you to us. The random visitor reference is sent, with each page view and button click, to Umami (our analytics processor, see 14.2); it is not included in your enquiry. It is used only on our behalf and is never shared with anyone for their own purposes.
14.2 Umami (Page Statistics)
- Purpose: Count page visits, referring sites, and which buttons and links are used
- Data shared: Page address and title, referring address, screen size, browser language, browser and device type, your IP address (used by Umami to work out your country and to count visitors; Umami states it does not store it), the name of the button or link you clicked and, where relevant, the product you selected or the error code of a failed submission, the random visitor reference described above and, when you send an enquiry, how you first found us and that enquiry's random reference (see 14.1). Umami does not set cookies.
- We do not send the text you type into the contact form to any analytics tool
- Privacy Policy: https://umami.is/privacy
14.3 How to Object
You can turn analytics off for this browser at any time, free of charge, using the button below. Doing so also deletes the values described in 14.1 from your browser (it does not recall data already sent with an earlier enquiry). We remember your choice by storing a small opt-out setting in your browser, which exists only so we can honour it. Turning analytics off does not change how the website works.
14.4 Contact Form Enquiries
- What we collect: Your name, email address, message, the product you selected, the page you were on, how you first found us, and a random reference for the enquiry (see 14.1)
- Bot protection: The form is protected by Cloudflare Turnstile, which checks that your browser is not an automated program. This sends your IP address to Cloudflare.
- Where it goes: Your enquiry is delivered to our team as a message in Slack (Slack Technologies LLC, part of Salesforce, Inc., United States), which we use as our internal inbox, and recorded in Attio (Attio Ltd), the customer relationship management system we use to follow it up. Attio hosts data on Google Cloud, contracted in Ireland; some of Attio's own service providers are in the United States, covered by the EU Standard Contractual Clauses and the UK Addendum. https://slack.com/privacy, https://attio.com/legal/privacy
- How long we keep it: In Slack, 12 months from your enquiry, after which it is deleted. In Attio, 3 years after our last contact with you if you don't become a customer; if you do, for as long as we work together and afterwards for as long as the law requires
- Why: Our legitimate interest in responding to enquiries about our products
14.5 Where Analytics Data Is Kept, and for How Long
- Where: Copies of the data described in 14.1 and 14.2 are stored in our analytics warehouse on Google Cloud, in the European Union, so we can measure which pages and channels lead to enquiries
- How long: Visit-level analytics data, including the random visitor reference, is kept for 3 years and then deleted automatically. Buying decisions for business software often take many months, and we measure which channels lead to customers over that whole period
- Enquiry outcomes: When we follow up an enquiry, how far it gets (for example a demo or a sale) is copied into our warehouse against the enquiry's random reference, without your name or email, so we can see which channels lead to real conversations
- Totals: Figures that identify no one, such as the number of visits to a page on a given day, may be kept for longer
- Who can access it: Only our team, and only for our own analytics. It is never shared with anyone for their own purposes
This Privacy Policy is effective as of September 2026.