Last updated: 27 July 2026
Privacy Policy
ENGLISH — CONTROLLING VERSION
N S Vu ("Sen Kasa", "we", "us") provides the Sen Kasa mobile application and website. Contact: privacy@senkasa.com; address: Fijnjekade 187, 2521DT 's-Gravenhage.
1. Scope and current release status
This policy covers the current release. Sen Kasa Pro is an auto-renewable subscription for point-of-sale and business management. Billing is handled by the App Store, Google Play, or — for website purchases — Stripe Managed Payments. The EET fiscal layer is built into the app but is inactive in this release: the app does not transmit any sale to an EET/tax-authority endpoint, and a receipt it produces is not proof that a sale was registered with a tax authority. If we later activate EET, the EET-related processing described below applies.
2. Data processed on your device
The app stores the information you enter to operate the app, including shop and register settings, product catalog, inventory, customer profiles, staff/profile names and PIN-related local settings, transaction and receipt history, VAT/payment details, reports, supplier orders, loyalty/gift-card/promotion records, and offline-retry records. This information is stored locally on your device by default.
Transaction location is optional and disabled by default. If you enable it and grant foreground location permission, the app requests one approximate location when a transaction completes and stores the rounded coordinates, reported accuracy, and capture time with that transaction. A sale always completes if location is denied or unavailable. Sen Kasa does not use this feature for continuous or background tracking.
When you import a .p12 EET certificate, the app reads the certificate and password to create EET requests. The certificate private key is not sent to Sen Kasa. Do not email certificates or passwords to support. The current Android release does not package a shared certificate in the public app.
3. Sen Kasa account and data we store
Sen Kasa Pro requires a Sen Kasa account hosted on Supabase (a managed PostgreSQL service in the EU). When you create an account we store:
- Your email address and authentication details (Supabase Auth).
- Merchant identity: business name, address, tax ID, and contact details you provide.
- Staff memberships: names, roles (owner/manager/cashier), and PIN-related account bindings. We do not store staff PIN values directly.
- Device registrations: platform, app version, and last-seen timestamp for each registered till.
- Completed-sale reporting records, including optional transaction coordinates only when the merchant enabled transaction location and the device supplied a position.
- Subscription entitlement: billing source (Apple, Google, Stripe, or complimentary), status, current period dates, and a provider-specific reference. We do not store complete payment-card details — card processing is handled entirely by Apple, Google, or Stripe under their own privacy terms.
You do not need a Sen Kasa account to apply for the First 25 pilot. If you use the website application form, we process the business name, contact person's name, email address, telephone number, city/postcode, business type, number of checkouts, current hardware choices, preferred language, and any note you choose to provide. We use this information only to assess the pilot application and contact you about the programme.
Your business data remains local on your device unless you explicitly migrate it to your account, use an integration, or choose Sen Kasa Cloud backup. The current managed-backup release covers the catalog, customers, supplier orders, gift cards, promotions, and loyalty balances; it does not yet claim complete sales or accounting recovery. You control when a managed snapshot is uploaded.
4. Network transfers
- Account and entitlement: when you sign in or refresh your subscription, the app sends your account credentials to Supabase and receives your merchant identity, staff list, device registrations, and entitlement status. This synchronisation keeps your POS Pro access, staff permissions, and account state consistent across devices.
- EET (when activated): the EET fiscal layer is inactive in this release, so no transaction data is sent to any EET endpoint. If EET is activated in a future release, choosing Send transmits the signed transaction data required by that service to the selected EET endpoint.
- Apple App Store subscriptions: when you purchase or restore Sen Kasa Pro through the App Store, Apple processes the payment under its own privacy policy. We receive a signed purchase token from Apple to verify your entitlement, and we store the resulting status and period dates. We do not receive your payment-card details.
- Google Play subscriptions: when you purchase or restore Sen Kasa Pro through Google Play, Google processes the payment under its own privacy policy. We receive a purchase token verified through the Google Play Developer API, and we store the resulting status and period dates. We do not receive your payment-card details.
- Stripe website billing: when you purchase Sen Kasa Pro on the Sen Kasa website, payment processing is handled by Stripe Managed Payments under Stripe's privacy policy. We store a Stripe customer identifier, subscription identifier, and entitlement status and period dates. We do not receive or store complete payment-card details. Stripe's processing of your payment data is governed by Stripe's own privacy and subprocessor terms.
- Complimentary access: some accounts receive complimentary Sen Kasa Pro access granted by us. This is recorded as a manual entitlement entry with the grant date, scope, and revocation status. No payment data is involved.
- Offline retry: if a transmission fails because of transport/network conditions, the app retains the necessary transaction data locally for a later retry. Server-side rejection is shown as an error and is not represented as an offline success.
- Optional transaction location: when enabled, the app may include the one-shot approximate coordinates, reported accuracy, and capture time in the merchant's completed-sale reporting record. Turning this setting off stops collection for future transactions.
- Sen Kasa Cloud backup: after an account owner connects the business and chooses Back up now, the supported portable-business data is sent to Sen Kasa's tenant-scoped Supabase infrastructure. The app records the source device, schema version, size, checksum, and backup time so a later download can be checked before restore. Restore is an explicit whole-backup replacement, not automatic background backup or real-time conflict merging. EET certificates, private keys, account sessions, bearer tokens, provider secrets, and payment-card data are excluded.
- Payment and accounting integrations: these transfer configuration and business data only when you configure a provider and actively test or use that integration. A payment provider, accounting provider, or printer-network service has its own privacy terms. Payment capture is not presented as available until its production contract is configured.
- Email support: if you email us, your email and information you voluntarily include are processed to respond. Do not send certificates, passwords, card data, or unnecessary customer data.
- First 25 pilot form: when you submit the public website form, Resend transports the application from Sen Kasa's server to our
support@senkasa.cominbox. Your contact email is set as the reply address so our team can answer you. Do not include certificates, passwords, payment data, fiscal records, or customer data in the optional note.
5. What we do not currently do
The current release does not provide advertising or an analytics SDK. We do not sell personal data. If we add analytics, crash reporting, a payment processor, or another cloud service that changes these practices, we will update this policy and the store disclosures before release.
6. Retention and deletion
Local business data remains on your device until you delete it in the app where that control exists, clear the app's data, or uninstall the app. Deleting the app may not delete files you exported, printer records, or backups held by a cloud provider.
Your Sen Kasa account data (email, merchant identity, staff list, device registrations, entitlement records, and managed backup snapshots) is retained while your account is active, subject to any legally required retention. You may delete your account and associated Sen Kasa-controlled data through the website portal or by contacting privacy@senkasa.com. Account deletion removes the merchant's managed Sen Kasa Cloud snapshots. It does not delete local app data, files you exported, or data controlled independently by Apple, Google, Stripe, or another integration provider.
Support emails are retained only as long as reasonably necessary to resolve the request, maintain security, or meet legal obligations.
Pilot applications are retained only as long as reasonably necessary to assess the application, contact the applicant, operate the pilot, or meet a legal obligation. To request deletion of a pilot application, email privacy@senkasa.com from the address used in the form.
To request access to or deletion of a specific managed backup, provide the account email and relevant reference to privacy@senkasa.com with the subject "Privacy deletion request". We may need to verify account ownership before acting.
7. Security and your responsibilities
Use a device passcode, keep your operating system current, protect certificate files and passwords, enable multi-factor authentication where available, and restrict staff access. No internet transmission or device storage is completely risk-free. We apply reasonable safeguards appropriate to the service, but you remain responsible for your merchant credentials and exported files.
8. Your rights and contact
Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, or portability for personal data we control. Contact privacy@senkasa.com. You may also contact your local data-protection authority. We may need to verify your request and may retain data when law requires it.
9. Changes
We may update this policy when the app or legal requirements change. The updated date identifies the current version.
ČEŠTINA — INFORMATIVNÍ PŘEKLAD
Zásady ochrany soukromí
N S Vu provozuje aplikaci a web Sen Kasa. Adresa: Fijnjekade 187, 2521DT 's-Gravenhage. Kontakt pro soukromí: privacy@senkasa.com.
Aplikace ve výchozím stavu ukládá obchodní údaje lokálně v zařízení. Režim EET je v této verzi neaktivní. Sen Kasa Pro vyžaduje účet hostovaný na Supabase (EU). Ukládáme e-mail, identitu provozovny, seznam zaměstnanců, registrace zařízení a stav oprávnění předplatného. Předplatné může být účtováno přes Apple, Google nebo Stripe — neukládáme kompletní údaje o platebních kartách.
Poloha transakce je volitelná a ve výchozím stavu vypnutá. Po zapnutí a udělení oprávnění aplikace při dokončení transakce jednorázově uloží přibližné souřadnice, přesnost a čas. Prodej funguje i bez polohy a aplikace polohu nesleduje nepřetržitě ani na pozadí.
Certifikát, heslo, token, údaje karty ani zákaznická data neposílejte podpoře. Účet můžete smazat přes webový portál nebo e-mailem na privacy@senkasa.com.
Při přihlášení do pilotu Prvních 25 přes webový formulář zpracujeme název provozovny, kontaktní jméno, e-mail, telefon, město/PSČ, typ provozovny, počet pokladen, zvolené vybavení, jazyk a dobrovolnou poznámku. Resend doručí přihlášku do schránky support@senkasa.com. Údaje používáme k posouzení přihlášky a kontaktování zájemce a uchováváme je jen po přiměřeně nutnou dobu. O výmaz lze požádat na privacy@senkasa.com.
E-maily na podporu uchováváme jen po přiměřeně nutnou dobu k vyřešení požadavku, udržení bezpečnosti nebo splnění právních povinností. Úplná anglická verze je rozhodná; před zveřejněním vyžaduje právní kontrolu.
TIẾNG VIỆT — BẢN DỊCH THAM KHẢO
Chính sách quyền riêng tư
N S Vu vận hành ứng dụng và trang web Sen Kasa. Địa chỉ: Fijnjekade 187, 2521DT 's-Gravenhage. Liên hệ quyền riêng tư: privacy@senkasa.com.
Ứng dụng mặc định lưu dữ liệu kinh doanh cục bộ trên thiết bị. EET trong bản này chưa được kích hoạt. Sen Kasa Pro yêu cầu tài khoản lưu trữ trên Supabase (EU). Chúng tôi lưu email, danh tính cửa hàng, danh sách nhân viên, đăng ký thiết bị và trạng thái đăng ký. Đăng ký có thể được thanh toán qua Apple, Google hoặc Stripe — chúng tôi không lưu thông tin thẻ đầy đủ.
Vị trí giao dịch là tùy chọn và mặc định tắt. Khi bạn bật và cấp quyền vị trí lúc dùng ứng dụng, Sen Kasa chỉ ghi một vị trí gần đúng, độ chính xác và thời gian khi giao dịch hoàn tất. Giao dịch vẫn hoàn tất nếu không có vị trí và ứng dụng không theo dõi liên tục hoặc trong nền.
Không gửi chứng chỉ, mật khẩu, token, dữ liệu thẻ hoặc dữ liệu khách hàng cho bộ phận hỗ trợ. Bạn có thể xóa tài khoản qua cổng web hoặc email tới privacy@senkasa.com.
Khi đăng ký chương trình 25 cửa hàng đầu tiên qua biểu mẫu web, chúng tôi xử lý tên cửa hàng, tên người liên hệ, email, điện thoại, thành phố/mã bưu điện, loại hình kinh doanh, số quầy, thiết bị được chọn, ngôn ngữ và ghi chú tự nguyện. Resend chuyển đăng ký tới hộp thư support@senkasa.com. Chúng tôi chỉ dùng dữ liệu để đánh giá đăng ký, liên hệ và vận hành pilot, đồng thời chỉ lưu trong thời gian hợp lý cần thiết. Bạn có thể yêu cầu xóa qua privacy@senkasa.com.
Email hỗ trợ chỉ được lưu trong thời gian hợp lý cần thiết để xử lý yêu cầu, duy trì bảo mật hoặc đáp ứng nghĩa vụ pháp lý. Bản tiếng Anh là bản áp dụng và cần được tư vấn pháp lý rà soát trước khi phát hành.