Privacy Policy - Point of Sale (POS)
Last updated : June 2026
This notice explains what data KiftMe processes when you use the KiftMe point of sale in store, why, on what basis and for how long. It is intended for the merchant and their operators (cashiers). It is separate from the Terms of use, the Legal notice and the Cookie policy.
1. Data controller and contact
RELOKE LTD, a company registered in England and Wales (company number 17037940), operating the service under the trading name “KiftMe”, is the controller of the personal data described in this notice. The full details of the publisher (name, legal form, registered office, registration) as well as those of the host are set out in the Legal notice (separate document).
No data protection officer (DPO) has been appointed to date. A dedicated data protection contact handles your requests: for any question about this notice or to exercise your rights, write to this contact at the address shown at the bottom of this page.
2. Who this notice is for
This notice applies to the following natural persons, in connection with the use of the KiftMe point of sale in store:
- The merchant: the person who operates the business and puts the point of sale into service.
- In-store operators (cashiers): the team members who open a session on the terminal to collect Kifts.
The individual customer who pays in store is covered by the Privacy Policy - Consumers (/privacy). The management of the professional account (catalogue, team invitations, payouts) is covered by the Business Notice (/privacy/business).
3. Data processed, purposes, legal bases and durations
The table below summarises, for each point-of-sale processing operation, the purpose pursued, the legal basis, the data used and its source. Device location is covered in a dedicated section (see §4).
| Processing | Purpose | Legal basis | Data used | Source |
|---|---|---|---|---|
| POS device enrolment and identification | Recognise the trusted device authorised to collect and prevent another device from impersonating it | Performance of contract (running the point of sale) + legitimate interest (security, fraud prevention) | Device identifier and fingerprint, device label, platform (iOS, Android, browser), application version, device model | The operator / the merchant (directly, at enrolment) |
| Operator session | Open and keep a session for the operator connected on the terminal | Performance of contract | Connected operator identifier, session token and refresh token, session status and duration | The operator (directly) |
| POS action log | Trace the actions performed at the point of sale, detect abuse and secure collections | Legitimate interest (security and fraud prevention) | Action performed, timestamp, device and operator identifier, anti-replay tokens, action result | Derived from terminal usage |
| Contactless payment / Tap to Pay | Collect a Kift in person, at the counter | Performance of contract | Operation reference, amounts; card data is processed directly by Stripe | Stripe |
Mandatory nature of the data (art. 13). Identifying the enrolled device, opening a session for the operator and checking the device’s location are necessary to run the point of sale securely: without them, the terminal cannot collect. This notice is information provided to you; it does not in itself constitute a basis for processing.
Data processed by Stripe (art. 14). During a contactless collection, the customer’s card data is processed directly by Stripe, as payment provider, and is neither collected nor stored by KiftMe; Stripe sends us the reference and status of the operation. The source of these items is Stripe.
4. Device location and geofencing
To prevent fraud and prevent a terminal from being used outside its store, KiftMe checks the POS device’s location against an authorised area defined for the business. This check takes place when the operator logs in and at the time of collection actions.
This location data may make it possible to situate the POS device, and therefore the operator using it at that moment. We process it for the sole purpose of securing collections and preventing use of the terminal outside the authorised store.
- Purpose: secure in-person collections and prevent a terminal from being used outside its store.
- Legal basis: legitimate interest (Article 6(1)(f) of the GDPR). The legitimate interest pursued is fraud prevention and payment security, for the benefit of the business, customers and KiftMe.
- Consequence: if the device is used repeatedly outside the authorised area, it is frozen automatically and can no longer collect until a review (see §7).
Proportionality and operators’ rights. The location check is occasional: it takes place at login and at the time of collections, and does not constitute continuous tracking. KiftMe builds no history of the operator’s movements or itinerary; only the device’s compliance with the authorised area is assessed. Our legitimate interest is balanced against operators’ rights by limiting this processing to this occasional check and to this sole purpose.
Informing employees. Where the operator is an employee of the merchant, the merchant, as employer, must inform their operators of this device geolocation mechanism, through the appropriate internal information channels.
The exact thresholds (number of times the area is left, area perimeter, time window) are not published for security reasons: disclosing them would make the anti-fraud mechanism easier to circumvent. For any question about this processing, write to us at the contact address shown in §1.
5. Recipients and processors
Your data is never sold. It is shared only with the processors necessary to run the point of sale, named below, and limited to what is useful to them:
- Stripe - in-store contactless collection (Stripe Terminal / Tap to Pay). KiftMe requests connection tokens from Stripe, declares locations and associates readers to make collection possible. The customer’s card data is processed directly by Stripe; KiftMe neither collects nor stores it.
- Supabase - database, authentication and file storage. Processes point-of-sale data (enrolled devices, sessions, action logs).
- Application hosting infrastructure - runs and serves the application (servers, code execution, technical logs). In that capacity, this provider may process the data that passes through the application.
Your data may also be disclosed to administrative or judicial authorities where the law requires it.
6. Data transfers outside the European Union
One processor handles data outside the European Union:
| Processor | Country | Data concerned | Safeguard |
|---|---|---|---|
| Stripe | United States | Reference and amounts of the collection operation, card data processed by Stripe | Standard contractual clauses (art. 46) |
Adequacy and safeguards. The United States does not benefit from a general adequacy decision of the European Commission: the transfer to Stripe therefore relies on standard contractual clauses (art. 46 of the GDPR).
You can request a copy of the safeguards applicable to this transfer at the contact address shown in §1.
7. Automated decisions and profiling (GDPR Article 22)
The point of sale uses one fully automated processing operation that may significantly affect use of the terminal: the automatic freezing of the POS device. In accordance with Article 22 of the GDPR, here is its logic, its consequences and your safeguards.
7.1 Automatic freezing of the POS device
When the POS device repeatedly leaves the authorised area defined for the business, it is frozen automatically: the terminal can no longer collect until a review and a reactivation.
- Logic: the decision is based on location signals, namely the repetition of departures from the authorised area observed during the terminal’s actions. The precise thresholds (number of departures, perimeter, time window) are not published for security reasons.
- Consequence: while frozen, the device can no longer collect Kifts. Collection becomes possible again after the device is reviewed and reactivated.
- Safeguards (GDPR art. 22(3)). You have the right to obtain human intervention, to express your point of view and to contest the decision. In practice, write to the contact address (§1): an internal KiftMe team reviews the situation, can take your explanations into account and reactivate the device.
This fraud-prevention processing is not based on sensitive data (Article 9 of the GDPR).
8. Your rights and how to exercise them
You have the following rights over your data. To exercise them, write to the contact address in §1.
- Right of access: you can obtain confirmation that your data is processed and receive a copy of it.
- Right to rectification: you can request correction of your inaccurate data by writing to us at the address in §1.
- Right to erasure: you can request deletion of your data, subject to the retention periods imposed by security, traceability and our legal and accounting obligations (see §9).
- Right to object: you can object, for reasons relating to your particular situation, to processing based on our legitimate interest - in particular device location (see §4) - by writing to the address in §1; we then stop the processing unless there are compelling legitimate grounds or the defence of a legal claim. As regards the POS action log, your objection may be limited: these records are kept as an unalterable register for security, traceability and evidentiary purposes, an obligation we cannot derogate from for this register.
- Right to restriction of processing: send your request to the address in §1.
- Right to portability: for the data you provided to us and processed on the basis of the contract, you can request to receive it in a structured, machine-readable format.
Exercising your rights is free of charge. To protect the point of sale, we may need to verify your identity before responding. We handle your requests within one month of receiving them; this period may be extended by two months for complex or numerous requests, in which case we inform you.
If you consider that your rights are not being respected, you may at any time lodge a complaint with the CNIL (see §13).
9. Retention periods
We retain point-of-sale data for the following periods:
| Data | Duration |
|---|---|
| Operator session | Duration of the session (then deletion or revocation) |
| POS action log | Kept in an unalterable manner, for security, traceability and evidentiary purposes (a register that cannot be modified or erased). |
| Authentication logs | 12 months |
| Accounting data related to collections | 10 years (accounting and legal obligations) |
10. Security
We implement technical and organisational measures suited to protecting point-of-sale data:
- Enrolled, trusted devices: only a recognised device, identified by its fingerprint, can open a session and collect.
- Anti-replay tokens for sensitive actions, to prevent the same action from being replayed.
- Access control and data partitioning between businesses and between roles.
- Encryption of communications (HTTPS/TLS) between the device and our servers.
- Logging of point-of-sale actions, to trace and detect abuse.
- Internal access to data strictly limited to authorised staff who need it.
11. Local storage and trackers (point of sale)
The point of sale places no advertising trackers and no audience-measurement tools. The items stored on the device are strictly necessary for the terminal to operate and exempt from consent:
| Purpose | Type | Duration | Consent |
|---|---|---|---|
| Identify the enrolled POS device (device identifier and fingerprint) | Local storage on the device | As long as the device remains enrolled | Exempt |
| Keep the connected operator’s session (session token) | Local storage on the device | Session duration | Exempt |
None of these items is subject to consent: no banner (CMP) is therefore required for the point of sale. Details are in the Cookie policy (separate document).
12. Changes to this notice
We may change this notice to reflect a change in the service or in regulation. The last-updated date appears at the top of the document. In the event of a substantial change, we inform you by an appropriate means (by email or in the app) before it takes effect.
13. Complaint to the CNIL
If you consider that the processing of your data does not comply, you can lodge a complaint with the French data protection authority (CNIL): 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 - www.cnil.fr.
GDPR contact : [email protected]