TillMark ENEL

Privacy

How TillMark handles personal data in TillMark.

This page describes what the software actually does with personal data, drawn from the project's own compliance notes. Have it reviewed against your business before publishing — and see the retention section: the software doesn't set retention periods, your business does.

No registered operating entity is configured for this deployment. The name "TillMark" is used below as a placeholder.

1. Who is responsible

TillMark is point-of-sale software for retail businesses. For the data a shop enters about its own customers and staff, that shop is the data controller. TillMark operates this deployment of the software and acts as a processor on the shop's instructions.

2. What personal data the system holds

The system stores the following categories of personal data:

  • Staff accounts — display name, username, role, store, and hashed login credentials (PIN and password are never stored in plain text).
  • Customer loyalty records, for customers who opt in — name, email, phone, points balance, and the version and timestamp of the consent notice they were shown. Where a shop browses its customer list, only the name and points balance are shown; email and phone are returned only through an audited, manager-restricted export.
  • Tax-free ("VAT retail export") sales, only where a shop enables that feature — the traveller's name, country of residence, and travel-document (passport) number, recorded on the sale as evidence for the VAT-refund claim. The document number is masked except for its last characters everywhere except the single-sale view the till needs to print the refund form. This data is part of the transaction record and has no erasure path (see retention).
  • Sales and stock transactions — these reference a customer only by an internal id, never by name or contact details, so erasing a customer never has to touch a reported sale.
  • Audit log — which staff member performed a sensitive action, when, and against which store or (by internal id) customer. It never contains email, phone, PIN or password. It exists for accountability (GDPR Art. 30).

No payment card data is received or stored. Card payments are handled entirely by a standalone card terminal and by the shop's own online checkout; card numbers, CVVs and terminal authorisation data never reach this system.

3. Why the data is processed, and on what basis

To operate the point of sale: authenticating staff, running the loyalty programme (for opted-in customers), producing receipts and reports, supporting VAT-refund claims where enabled, and maintaining an audit trail. The stated bases are performance of the contract with the shop and a legitimate interest in a secure, auditable system. Loyalty processing for a customer relies on that customer's consent, which is recorded with the notice version and timestamp; withdrawing it stops future points accrual.

4. Retention

Transaction, fiscal and audit data must be kept for the period required by Cyprus tax and fiscal-record law. The software does not set or enforce a retention period, and nothing is deleted automatically. Confirm the required periods with a Cyprus accountant or lawyer — for how long sale and receipt records must be kept, and whether a customer who never returns may have their loyalty record erased proactively rather than only on request — and apply them operationally. Tax-free traveller data follows the fiscal-record retention rule and is not erasable on request.

5. Data-subject rights (customer / loyalty data)

The system provides built-in tools a shop can use to action a request: a full data export (access / portability), in-place rectification of contact details, and erasure — which scrubs personal data while keeping the internal row so past sales stay intact for fiscal record-keeping. A customer can also withdraw loyalty consent without erasing the record of that consent. A customer should contact the shop they deal with; the shop actions the request.

Staff data is retained on the basis of the employment relationship, which under Cyprus and EU labour law generally requires keeping employment records for a period rather than granting erasure on demand. There is no self-service staff erasure, deliberately.

6. Sharing and sub-processors

Personal data is not sold. It is shared only with the infrastructure needed to run the service — hosting is provided by Hetzner Online GmbH (Germany (EU)) — and where required by law. Where a shop enables Shopify synchronisation, order and inventory data flows to that shop's own Shopify account under Shopify's terms. Any email or SMS provider a deployment adds would be a further sub-processor and needs its own data-processing agreement.

7. Security

Access is role-restricted; credentials are stored only as hashes; sensitive actions are written to the audit log. Transport encryption (TLS) is terminated by the deployment's reverse proxy. The certified fiscal device issues the legal receipt independently of this software.

8. Contact

Privacy enquiries:contact address not configured for this deployment.

Last updated: not set.