Mobile App
Web App
Privacy Policy
How Mufungo POS — on mobile (iOS & Android) and web — collects, uses, stores, and protects merchant, staff, and customer data.
Applies to: Mufungo POS (iOS, Android & Web)
·
Last updated: September 13, 2026
Scope — Mobile App & Web App
This Privacy Policy applies to Mufungo POS in all its forms:
Mobile App (iOS & Android)
Downloaded from the Apple App Store or Google Play
Full cloud sync, staff PINs, barcode scanning, and thermal printing
Firebase App Check and Play Integrity security attestation
Web App (Browser)
Available at mufungogeeks.com/apps/pos
Runs in your browser with offline-capable local storage
Receipt printing via the browser print dialog — no app install required
Throughout this policy, "Mufungo POS," "the App," or "the Service" refers to both the mobile application and the web application unless a section specifically distinguishes between them. By creating an account or using either version, you agree to this Privacy Policy.
Data We Collect
We collect the following categories of information to operate Mufungo POS securely and reliably:
2.1 User Account Details
- Store owner or administrator name
- Email address (account login, recovery, and support)
- Store ID (unique identifier linking your account to your business and cloud data)
Web app note: The browser version can be used without a cloud account for local-only operation. Account details are collected when you register for cloud sync across devices.
2.2 Staff Authentication Data
- Staff PIN hashes — cashier and manager PINs are never stored in plain text. We store one-way cryptographic hashes used only to verify staff access at the point of sale (mobile app and cloud-connected web sessions).
2.3 Device Identifiers
- Device identifiers and attestation tokens used for security verification through Firebase App Check and, on Android mobile, Google Play Integrity API
- Browser session identifiers and anonymized analytics IDs on the web app
- These help prevent unauthorized API access, account abuse, and cloned app instances
2.4 Sales & Business Transaction Data
- Sales transaction logs (items, quantities, prices, taxes, discounts, timestamps, payment metadata)
- Product catalog data (names, SKUs, barcodes, prices, stock levels)
- End-of-day reports, receipts, and operational settings tied to your store
Web app note: Transaction data is stored locally in your browser's storage when offline. When cloud sync is enabled, this data is also stored on our secure backend.
2.5 Customer Contact Information (Optional)
- If you issue e-receipts (primarily via the mobile app), we may process customer email or phone numbers solely to deliver the receipt on your behalf
- You, as the merchant, must obtain any required customer consent before collecting this information
2.6 Analytics & Diagnostics
- Aggregated usage events (feature usage, crash reports) to improve stability on mobile and web
- We do not sell your personal information or transaction data to third parties
App Permissions & How We Use Them
Mufungo POS requests only the permissions necessary for core POS functions. Requirements differ by platform:
Mobile App Permissions
Camera — barcode scanning only; no background capture or facial recognition
Bluetooth — thermal receipt printer pairing only
USB — supported thermal printers only; no other USB devices accessed
Internet — account auth, cloud sync, App Check, and e-receipt delivery
Local storage — offline product and sales cache on device
Web App Permissions
Local storage (localStorage) — products, sales, and settings cached in your browser for offline use
Browser print API — receipt and report printing through your system print dialog
Internet — optional cloud sync, analytics, and loading the web application
No camera, Bluetooth, or USB access is requested by the web app
You may deny optional permissions, but features like barcode scanning (mobile), thermal printing (mobile), cloud sync, or offline caching may not work without them.
How We Use Your Information
- Provide, maintain, and improve Mufungo POS on mobile and web
- Authenticate store owners, managers, and staff
- Synchronize sales and inventory across your authorized devices
- Generate receipts, reports, and backups
- Detect fraud, abuse, and unauthorized API access
- Respond to support requests and legal obligations
Third-Party Services & Sub-Processors
Mufungo POS relies on trusted cloud hosting and security providers. These sub-processors may process data on our behalf under contractual data protection obligations:
- Google Firebase / Google Cloud Platform (GCP) — authentication, database storage, serverless backend, analytics, and Firebase App Check (mobile and web)
- Google Play Integrity API — Android mobile device integrity verification
- Apple App Store / Google Play — mobile app distribution (separate privacy policies apply)
- Web hosting (mufungogeeks.com) — delivery of the Mufungo POS web application
Sub-processors are not authorized to use your store transaction data for their own advertising. Material changes to sub-processors will be reflected in an updated version of this policy.
Encryption & Data Security
- Data in transit — all communication between Mufungo POS (mobile and web) and our cloud services is encrypted using HTTPS/TLS
- Database access — cloud databases protected by strict authorization rules. Each store's data is isolated by Store ID and role-based access controls
- PIN security — staff PINs stored as one-way hashes, never as readable passwords
- Device attestation — Firebase App Check and Play Integrity reduce risk of tampered clients accessing backend data (mobile)
- Local web data — browser-stored data remains on your device and is not accessible to other websites. Clearing browser data removes local Mufungo POS records
No method of electronic storage or transmission is 100% secure. You are responsible for securing your devices, manager credentials, staff PINs, and browser sessions.
Data Retention
We retain account and transaction data for as long as your Mufungo POS account is active or as needed to provide the service, comply with legal obligations, resolve disputes, and enforce agreements. Local browser or device data persists until you clear it or delete your account. See our Account & Data Deletion Policy for removal instructions.
Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you or your store
- Correct inaccurate account information
- Request deletion of your account and cloud-stored data
- Export your business data before deletion (available in-app on both platforms)
- Object to or restrict certain processing where applicable under local law
Children's Privacy
Mufungo POS is a business application for merchants and authorized staff aged 18 and older. We do not knowingly collect personal information from children.
Changes to This Policy
We may update this Privacy Policy from time to time. Revised policies will be posted at this URL with an updated "Last updated" date. Continued use of Mufungo POS (mobile or web) after changes take effect constitutes acceptance.
Contact Us
For privacy questions, data access requests, or security concerns:
Email: support@mufungogeeks.com
Subject line: Mufungo POS — Privacy Request
Questions about Mufungo POS?
These policies cover both the mobile app and the web app. Contact us for privacy, legal, or data deletion requests.
© 2026 Mufungo Geeks. All rights reserved.
