BabulPOS · Legal
Privacy Policy
BabulPOS holds your shop's books and your staff's account details. This page says exactly what that means: what is collected, where it lives, who can reach it, and what you can do about it.
Last updated 18 September 2026
In short
BabulPOS is business software. It holds the records your shop already keeps - what you sold, what you stock, who owes you money - and the account details of the people who sign in to it. We do not sell any of it, we do not use it for advertising, and no other shop can see it.
Who is responsible for your data
BabulPOS is published by BabulTech. For the records your shop enters - your customers, your sales, your stock - you are the one deciding what is collected and why; we hold it on your behalf and act on your instructions. For the account details we need to run the service, we are responsible ourselves.
What we collect about the people who sign in
When a shop signs up, and when an owner adds a salesperson, we collect:
- Name, phone number and email address.
- CNIC, where it is given at sign-up. It is checked for format only - we cannot and do not verify it against NADRA.
- The shop name, business type, address and business code.
- Role (owner or salesperson), whether the account is active, and the time of the last sign-in.
We need these to create the account, to tell two staff members apart on a receipt, to let an owner see who sold what, and to contact you about the service.
What you enter about your business
Everything the app is for: products, categories, prices and stock levels; sales, refunds and receipts; udhari (credit) balances and customer ledgers; vendors, receivings and payables; expenses and reports.
Your customer and vendor records - names, phone numbers, balances - are entered by you. You are responsible for telling those people that you keep their details, and for having a reason to. BabulPOS never contacts them.
What the app collects by itself
- Sync and device information needed to keep your data consistent across the devices signed in to your shop.
- A push notification token, on Android, so an owner can be alerted to a sale, a low stock item, a customer over their credit limit, or a salesperson signing in. This is owner-only and can be turned off in your phone settings.
- Crash and error reports, so that an app that closes by itself on a shopkeeper's phone is something we can see and fix.
Crash reports, and what is stripped out of them
Crash reporting is deliberately narrow. We do not attach screenshots, and we do not send the device or user identifiers the crash-reporting tool would attach by default. CNIC numbers, Pakistani mobile numbers and email addresses are redacted from any free text before a report leaves the device, and the fields that could carry a customer ledger are dropped entirely rather than trimmed.
This is enforced in code and covered by tests that fail if the protections are removed, because a crash report is exactly the kind of thing that quietly carries more than it should.
How your data is kept separate from other shops
Every record carries the shop it belongs to, and the database itself - not just the app - refuses to return a row belonging to a different shop. A request made with another shop's credentials returns nothing, so a bug in the app cannot expose your shop to another one.
Where it is stored
Two places, on purpose. A copy lives on your own device so the app keeps working with no internet, and a copy lives on our cloud infrastructure (Supabase, hosted on Amazon Web Services) so that a lost or broken device does not mean lost records. The two reconcile automatically when the connection returns.
Data in transit is encrypted (HTTPS/TLS), and data at rest on our servers is encrypted by the hosting provider. The copy on your own device is protected by your device - which is why a shop phone or counter PC should have a screen lock.
Who else can see it
Our infrastructure providers, because they run the servers and the push notification delivery: Supabase (database, storage and sync), Amazon Web Services (the underlying hosting), Google Firebase (Android push notifications) and Sentry (crash reports). Each processes data on our instructions only.
A small number of BabulTech staff can access shop records where it is needed to support you or investigate a fault, and that access is logged.
We will disclose data if the law requires it. We do not sell data, share it with advertisers, or use it to train anything.
How long it is kept
Your business records are kept for as long as your shop uses BabulPOS, because they are your books and you may need them years later. When an account is deleted, they are handled as described on the account deletion page.
Crash reports are kept for a limited period and then discarded. An administrative log noting that an account action happened is kept as a record that it was honoured.
Your choices
- Correct or update anything about your shop or staff from Settings.
- Export your sales history to CSV from Reports, on the plans that include it.
- Turn off notifications from your phone settings at any time.
- Disable a staff account instantly - a disabled account is locked out on the next check, on every device.
- Ask for a copy of your data, or ask us to delete it, by writing to us.
Children
BabulPOS is software for running a business and is not directed at children. We do not knowingly create accounts for anyone under 18.
Changes to this policy
If we change how BabulPOS handles data, this page is updated and the date at the top changes with it. A change that materially affects you will be told to you in the app or by email rather than left here to be discovered.
Contact
Questions about this policy, a request for a copy of your data, or a complaint: contact@babultech.com. We answer within a few working days.