kvpos-policies

Privacy Policy for KvPOS System

Last updated: July 2026

KvPOS System (“we”, “our”, “us”) operates a Point of Sale application intended for use by authorized staff of Kaimosi Vert Hotel and Eutopian Tech (“the Business”). This Privacy Policy explains what information the App collects, how it is used, who it is shared with, and how long it is kept.

The App is an internal business tool — it is not directed at the general public or at children, and it is not used to collect data from hotel guests or customers beyond what is strictly necessary to process a payment (see Section 4).


1. Information We Collect

Account information

Identity verification information

For staff verification and compliance purposes, the App may collect:

This information is visible only to you and to Admin-level users, and is used solely for internal HR and compliance verification. It is not shared outside the Business.

Content you create in the App

Operational and financial data

Device and diagnostic information

Information we do not collect


2. How We Use Your Information

We use the information described above to:

We do not sell or rent your personal data. We do not share it with third parties for their own marketing or advertising purposes.


3. Device Permissions

The App requests the following device permissions, only for the purposes stated:

Permission Purpose
Camera Taking photos for menu items, ID verification, expense/stock reports, and chat attachments.
Photo Library Selecting existing images for menu items, profile pictures, reports, and chat attachments.
Microphone Recording video attachments (e.g. in the Whiteboard chat feature).
Face ID / Biometrics Optional quick unlock of the dashboard using your device’s biometric authentication. Biometric data itself never leaves your device and is never seen by us — we only receive a pass/fail result from your device’s operating system.
Bluetooth Connecting to a paired thermal printer to print order and room receipts.
Notifications Delivering push notifications relevant to your role.

4. Payment Information (M-Pesa)

When a customer pays via M-Pesa, the App sends the customer’s phone number and the payment amount to Safaricom’s Daraja API to initiate an STK push payment prompt on the customer’s phone. Safaricom processes the payment directly with the customer — the App and our servers never see or store the customer’s M-Pesa PIN, card details, or bank information. We receive back only the payment status and an M-Pesa receipt number, which is stored as part of the order/financial record.


5. Third-Party Services

We use the following third-party service providers to operate the App. Each processes data only as needed to provide their service to us, under their own privacy and security terms:

We do not use advertising networks, third-party analytics/tracking SDKs, or data brokers.


6. Data Storage and Security

Your data is stored on Google Firebase infrastructure and is accessible only to authorized personnel based on your assigned role. We use industry-standard encryption and authentication mechanisms (including Firebase App Check) to protect data in transit and at rest, and Firestore security rules to enforce role-based access control.


7. Your Rights and Account Deletion

You can:

What account deletion removes: Your login credentials (Firebase Authentication record) and your core profile document (email, username, phone number, profile picture reference, role) are permanently deleted.

What account deletion does not remove:

If you would like verification photos or chat messages removed in addition to the automatic deletion above, contact us using the details in Section 9 and we will action this manually where legally permitted.


8. Data Retention

Account and profile data is retained for as long as your account is active. Financial and audit records are retained indefinitely (or for the period required by applicable accounting/tax law) even after account deletion, as described in Section 7. Crash reports are retained by our crash-reporting provider according to their standard retention policy.


9. Children’s Privacy

The App is an internal business tool intended solely for authorized adult staff. It is not directed at children, and we do not knowingly collect data from anyone under the age of 18.


10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes to the App or applicable law. Any changes will be reflected in this document, and the “Last updated” date above will be revised accordingly.


11. Contact Us

If you have any questions or concerns about this Privacy Policy, or wish to request removal of retained data described in Section 7, please contact us at:

📧 dev@eutopiantech.com