Privacy Policy for KvPOS System
Last updated: July 2026
KvPOS System (“we”, “our”, “us”) operates a Point of Sale application intended for use by authorized staff of Kaimosi Vert Hotel and Eutopian Tech (“the Business”). This Privacy Policy explains what information the App collects, how it is used, who it is shared with, and how long it is kept.
The App is an internal business tool — it is not directed at the general public or at children, and it is not used to collect data from hotel guests or customers beyond what is strictly necessary to process a payment (see Section 4).
- Email address – used for account creation, login, and email verification.
- Username – used to identify you within the App.
- Phone number – optional, stored on your profile.
- Profile picture – optional, used for personalization. Stored in Firebase Storage.
- Role – your assigned permission level (e.g. Admin, CEO, Manager, Head Staff, Staff), which controls what you can see and do in the App.
For staff verification and compliance purposes, the App may collect:
- National ID or passport number
- KRA PIN (tax identification number)
- Photos of your ID document (front and back)
- A selfie photograph for identity confirmation
This information is visible only to you and to Admin-level users, and is used solely for internal HR and compliance verification. It is not shared outside the Business.
Content you create in the App
- Chat messages you post in the internal staff messaging feature (“Whiteboard”), including text, replies, emoji reactions, and any images or videos you attach. Messages are visible to other authenticated staff using the App and include your username as the author.
- AI assistant conversations — if you are an Admin or CEO user, questions you ask the built-in AI assistant, any images you attach to a query, and the AI’s responses. See Section 5 for how this data is processed.
- Photos you upload for menu items, expense records, stock items, or reports.
Operational and financial data
- Orders, room bookings, stock records, expense records, and other business transaction data you enter or that is generated by your use of the App. This data is tied to your username for audit purposes.
- Push notification token (FCM token) – used to deliver notifications (e.g. low-stock alerts, order issues, new chat messages) to your device. Tokens are linked to your account and removed when you sign out.
- Crash and error reports – if the App crashes or encounters an error, basic diagnostic information (device type, OS version, and a stack trace) is automatically sent to our crash-reporting provider to help us fix bugs. We do not deliberately include your username, email, or other personal data in these reports.
- We do not collect your precise location or GPS data.
- We do not use advertising SDKs or advertising identifiers.
- We do not collect data through analytics/tracking SDKs beyond the crash reporting described above.
We use the information described above to:
- Create and maintain your staff account, and control access based on your role.
- Verify your identity for HR and compliance purposes.
- Operate core POS functionality: orders, room bookings, stock management, expense tracking, and financial reporting.
- Process customer payments via M-Pesa (see Section 4).
- Enable internal staff communication through the Whiteboard chat feature.
- Power the optional AI assistant for Admin/CEO users, which can answer questions about business data already visible to that user’s role.
- Send push notifications relevant to your role (e.g. stock alerts, order issues, new messages).
- Diagnose and fix crashes and bugs.
- Print receipts to a paired Bluetooth thermal printer (receipt data is sent directly from your device to the printer and is not transmitted to us).
We do not sell or rent your personal data. We do not share it with third parties for their own marketing or advertising purposes.
3. Device Permissions
The App requests the following device permissions, only for the purposes stated:
| Permission |
Purpose |
| Camera |
Taking photos for menu items, ID verification, expense/stock reports, and chat attachments. |
| Photo Library |
Selecting existing images for menu items, profile pictures, reports, and chat attachments. |
| Microphone |
Recording video attachments (e.g. in the Whiteboard chat feature). |
| Face ID / Biometrics |
Optional quick unlock of the dashboard using your device’s biometric authentication. Biometric data itself never leaves your device and is never seen by us — we only receive a pass/fail result from your device’s operating system. |
| Bluetooth |
Connecting to a paired thermal printer to print order and room receipts. |
| Notifications |
Delivering push notifications relevant to your role. |
When a customer pays via M-Pesa, the App sends the customer’s phone number and the payment amount to Safaricom’s Daraja API to initiate an STK push payment prompt on the customer’s phone. Safaricom processes the payment directly with the customer — the App and our servers never see or store the customer’s M-Pesa PIN, card details, or bank information. We receive back only the payment status and an M-Pesa receipt number, which is stored as part of the order/financial record.
5. Third-Party Services
We use the following third-party service providers to operate the App. Each processes data only as needed to provide their service to us, under their own privacy and security terms:
- Google Firebase (Authentication, Firestore database, Cloud Storage, Cloud Functions, Crashlytics, Cloud Messaging, App Check) — our core backend infrastructure. Firebase stores your account data, business data, and uploaded files, sends push notifications, and reports crashes.
- Safaricom (M-Pesa / Daraja API) — processes customer mobile payments as described in Section 4.
- OpenRouter (AI model routing service) — if you are an Admin or CEO user and choose to use the in-app AI assistant, your questions, any attached images, and relevant business data needed to answer your question (which may include staff usernames, roles, or guest names already visible to your role) are sent to OpenRouter, which routes the request to an underlying AI language model to generate a response. This only happens when you actively use the AI assistant feature.
We do not use advertising networks, third-party analytics/tracking SDKs, or data brokers.
6. Data Storage and Security
Your data is stored on Google Firebase infrastructure and is accessible only to authorized personnel based on your assigned role. We use industry-standard encryption and authentication mechanisms (including Firebase App Check) to protect data in transit and at rest, and Firestore security rules to enforce role-based access control.
7. Your Rights and Account Deletion
You can:
- View and edit your account information (username, phone number, profile picture) directly within the App.
- Request deletion of your account from within the App by navigating to Settings → Delete Account.
What account deletion removes: Your login credentials (Firebase Authentication record) and your core profile document (email, username, phone number, profile picture reference, role) are permanently deleted.
What account deletion does not remove:
- Identity verification records (ID number, KRA PIN, ID photos, selfie) are retained for HR/compliance purposes and can only be removed by an Administrator on request.
- Chat messages you have posted in the Whiteboard feature remain visible to other staff, as they form part of a shared conversation history.
- Financial, order, and audit records (e.g. sales totals, expense records, stock transaction history) associated with your account activity are retained. These records are immutable by design and required for the Business’s accounting, tax, and legal-audit obligations, and are not deleted when you delete your account.
If you would like verification photos or chat messages removed in addition to the automatic deletion above, contact us using the details in Section 9 and we will action this manually where legally permitted.
8. Data Retention
Account and profile data is retained for as long as your account is active. Financial and audit records are retained indefinitely (or for the period required by applicable accounting/tax law) even after account deletion, as described in Section 7. Crash reports are retained by our crash-reporting provider according to their standard retention policy.
9. Children’s Privacy
The App is an internal business tool intended solely for authorized adult staff. It is not directed at children, and we do not knowingly collect data from anyone under the age of 18.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to the App or applicable law. Any changes will be reflected in this document, and the “Last updated” date above will be revised accordingly.
If you have any questions or concerns about this Privacy Policy, or wish to request removal of retained data described in Section 7, please contact us at:
📧 dev@eutopiantech.com