Legal
Privacy Policy
How Cinder POS collects, uses, and protects information when you visit our website, use our point-of-sale platform, or accept payments through our services.
Last updated: July 28, 2026
1. Scope and our role
Cinder POS ("Cinder," "we," "us," or "our") provides point-of-sale, inventory, reporting, and related retail technology services. This Privacy Policy explains how we handle personal information when you visit our websites, contact us, or use Cinder services.
For our website, sales, account administration, and direct business relationships, Cinder determines why and how personal information is processed. When Cinder processes a merchant's customer or employee data to provide the platform, the merchant generally determines the purposes of that processing and Cinder acts as its service provider or processor. Merchants are responsible for their own privacy notices and lawful instructions.
2. Information we collect
2.1 Website, sales, and support information
- Name, business name, email address, phone number, and message content;
- Plan interest, register count, equipment preference, and estimated monthly card volume;
- Support communications, demo requests, and onboarding notes; and
- Technical and usage information such as IP address, browser or device type, requested pages, timestamps, referral information, and security logs.
2.2 Merchant accounts and platform use
- Business profile, contact, billing, tax, banking, and merchant-account information;
- Administrator and staff names, email addresses, roles, authentication activity, and account settings;
- Products, categories, prices, inventory, suppliers, customers, receipts, invoices, shifts, sales, refunds, and reports;
- Records generated when users configure or operate registers and related devices; and
- Support communications, implementation details, and service diagnostics.
2.3 Payment information
Cinder's current Deluxe integration supports in-store card-present transactions. Cinder may receive and retain transaction amount, date and time, status, processor and authorization references, card brand, last four card digits, terminal and batch identifiers, and processor response data. Payment credentials and full card numbers are submitted to Deluxe and its financial-services partners rather than intentionally stored by Cinder in readable form. Deluxe independently handles information under its own agreements and privacy practices.
2.4 Age-verification records
For products marked as age restricted, the register can parse identification data locally to evaluate age and expiration. Cinder does not provide a dedicated field for storing the raw identification scan or full date of birth. The order may retain the verification result, method, time, operator, register context, notes, and compliance audit events. Merchants control use of this feature and remain responsible for legal compliance.
2.5 Merchant customer and storefront information
Depending on enabled features, merchants may enter customer names, contact details, addresses, loyalty identifiers, tax information, notes, and purchase history. If a merchant operates a Cinder-powered storefront, Cinder may process account, cart, order, billing, shipping, and delivery information on the merchant's behalf. Customers should contact the relevant merchant first about an order or merchant privacy practice.
3. Sources of information
We collect information from you, your employer or merchant account administrator, customers who transact with a merchant, the Cinder platform and connected devices, Deluxe and other service providers, and public or government sources where needed for business verification or legal compliance.
4. How we use information
- Provide, configure, support, secure, and improve Cinder services;
- Create accounts, authenticate users, and apply role-based permissions;
- Operate checkout, inventory, reporting, customer, invoicing, and optional storefront features;
- Route card-present transactions to Deluxe and reconcile transaction status;
- Support merchant age-verification and compliance workflows;
- Respond to inquiries and send service, support, billing, and security communications;
- Detect errors, abuse, fraud, and security threats; enforce our Terms and Conditions; and
- Comply with legal, tax, accounting, payment-network, and regulatory obligations.
5. How we disclose information
We may disclose relevant information to:
- Deluxe and financial-services partners to authorize, settle, refund, and reconcile card-present transactions;
- Hosting and operations providers, including cloud hosting, database, backup, email, security, and support vendors;
- Hardware and implementation providers when needed to fulfill or support a merchant's requested setup;
- Professional advisors, such as legal, accounting, insurance, and security advisors;
- Authorities and affected parties when reasonably necessary to comply with law, protect rights or safety, investigate misuse, or respond to a security incident; and
- Transaction participants in connection with a financing, merger, acquisition, reorganization, or sale of all or part of our business, subject to appropriate safeguards.
We do not sell personal information or share it for cross-context behavioral advertising. We do not use third-party advertising trackers on the Cinder marketing website.
6. Cookies and local storage
Cinder and the underlying platform use cookies and similar storage for sign-in sessions, security, form operation, downloads, and user preferences such as color scheme and interface settings. These technologies are necessary or functional rather than used by Cinder for third-party behavioral advertising. Browser controls can block or delete them, but some features may then stop working correctly.
7. Data retention
We retain information while an account is active and as reasonably needed to provide services, maintain transaction and compliance records, protect the platform, resolve disputes, enforce agreements, and satisfy legal, tax, accounting, and payment-network obligations. Retention varies by record type and merchant configuration. Deleted data may remain temporarily in encrypted backups until those backups expire or are overwritten.
8. Security
We use safeguards designed to protect information, including access controls, tenant separation, encrypted infrastructure, restricted administrative access, and protected backups. Payment processing relies on controls operated by Deluxe and its partners. No transmission or storage system is completely secure. Merchants should use strong credentials, promptly remove former users, and limit access according to job duties.
9. Privacy rights and choices
Depending on your location and relationship with Cinder, you may have the right to request access to, correction of, deletion of, or a portable copy of certain personal information, or to object to or restrict certain processing. These rights may be subject to exceptions, identity verification, and record-retention obligations.
Merchants and staff can update many details through the platform. To make a request about information Cinder controls directly, use Contact Us. If your request concerns data held for a Cinder merchant, contact that merchant first; we will assist the merchant as required by our agreement and applicable law. We will not discriminate against you for exercising an applicable privacy right.
10. Children's privacy
Cinder's websites and services are directed to businesses and are not intended for children under 13. We do not knowingly collect personal information directly from children under 13 through our marketing website. Contact us if you believe a child submitted such information.
11. United States processing
Cinder is based in the United States, and our primary production infrastructure is located in the United States. If you access the services from another country, your information may be transferred to and processed in the United States or where our service providers operate, subject to applicable law.
12. Other websites and services
Cinder services may link to or integrate with services operated by merchants or third parties. Their privacy practices are governed by their own notices, not this Policy.
13. Changes to this Policy
We may update this Privacy Policy as our services or legal obligations change. We will post the revised version and update the date above. Where appropriate, we may also provide notice by email or within the service.
14. Contact us
Questions or privacy requests may be submitted through Contact Us or by mail to Cinder POS, 9016 E 46th St, Tulsa, OK 74145.