Privacy Policy

Applies to AsanPOS 1.8 for Windows · Last updated 12 August 2026

In short: AsanPOS is an offline-first application, and your business data is stored on your own computer. It stays there unless you choose to switch on synchronisation. If you subscribe to AsanPOS Cloud, we host a database for your shop and your records are copied to it, so from that point we do hold your data — section 6 sets out exactly what, where, and for how long. If you do not subscribe, we receive nothing. There is no analytics, advertising, or tracking in the application either way.

1. Who we are

AsanPOS (“the application”, “the app”) is developed and published by SMART DADDY (SMC-PRIVATE) LIMITED (“SMART DADDY”, “we”, “us”). This policy explains how the application handles information. It applies to the AsanPOS application, which is distributed through the Microsoft Store.

2. What we collect, and what we do not

What we never collect, on any plan:

  • No analytics, usage tracking, telemetry, or crash reporting.
  • No advertising identifiers, profiling, or behavioural tracking.
  • No payment details. Subscriptions are bought through the Microsoft Store, so your card details go to Microsoft and never reach us. We never see them.

Without an AsanPOS Cloud subscription, we collect nothing at all. The application does not contact us, you are not asked to create an account, and we have no technical means of reaching the data you enter.

With an AsanPOS Cloud subscription, the application talks to our service in order to provision and reach your hosted database. From that point we hold both a small amount of account information and — because we host it — your business records. Section 6 sets this out in full.

3. Information the application stores on your device

To do its job, the application saves the following in a local database in your Windows user profile’s application-data folder. This information stays on your computer unless you enable synchronisation (sections 6 and 7).

Business recordsProducts, variants, categories, brands, units, stock movements, sales and invoices, purchase orders, and their line items.
Contact recordsNames, phone numbers, and addresses of the customers and suppliers you choose to enter, together with their ledger entries and balances.
User accountsThe staff accounts you create: full name, username, role, and a cryptographic hash of the password. Passwords are never stored in readable form.
SettingsYour store name, address, phone number, currency, receipt preferences, theme, the signed-in session, and — if configured — your encrypted database connection details.
Cloud device tokenIf you subscribe to AsanPOS Cloud, the token that identifies this counter to our service. It is encrypted with the Windows Data Protection API and never leaves the device except as the credential for our own API.
Activity logA local diagnostic log of what the application has been doing, viewable in the app with Ctrl+Shift+L. It is written to your computer only and is never transmitted anywhere. If you send us an extract when reporting a problem, you choose what to send.

You are the controller of this information. Where the records include personal data about your customers or staff, you are responsible for handling it in line with the laws that apply to you.

4. Network connections the application makes

The application declares internet access and uses it for these purposes only:

  • AsanPOS Cloud — only if you subscribe. The application contacts our service at api.asanpos.pk to register the counter, confirm your subscription with the Microsoft Store, and collect the short-lived credentials it needs for your hosted database. It then connects to that database directly. See section 6.
  • Synchronisation with your own database server — only when you have configured it and enabled it. The connection is made directly from your computer to the server address you entered, and is always encrypted with TLS. See sections 7 and 9.
  • Confirming your subscription — the application asks Windows about the licences and add-ons attached to your Microsoft account, and asks the Store for the price to display in your own currency. This is a call to Microsoft, not to us.
  • Checking whether the computer is online — so the application can show an online/offline indicator. This asks Windows whether a network connection is available; it sends nothing and contacts no server.
  • Sending documents on WhatsApp — only when you have linked a WhatsApp account. The connection is made directly from your computer to WhatsApp. See section 5.

The application makes no other outbound connections. It does not check for updates over the network, and — unless you subscribe to AsanPOS Cloud — it does not contact us at all.

5. Sending receipts and ledgers on WhatsApp

This feature is optional and does nothing until you link a WhatsApp account. When you link one, the application connects to WhatsApp in the same way WhatsApp Web does — your computer becomes a linked device on your own account.

  • This is not an official WhatsApp integration, and it is not affiliated with or endorsed by WhatsApp or Meta. WhatsApp’s terms prohibit unofficial clients, and WhatsApp may restrict or ban accounts that use them. The application tells you this before you link, and only sends receipts and account statements to customers already saved in your records, a few at a time. It has no facility for bulk or marketing messages.
  • What reaches WhatsApp: the customer’s phone number, the receipt or statement document, and the message text. Once sent, that information is held by WhatsApp/Meta under their privacy terms, not ours. We never see any of it.
  • The login stays on your device. The credentials created when you scan the QR code are encrypted and stored on that computer, for that Windows user only. They are never synchronised to your database server, and never sent to us.
  • Documents waiting to be sent are written to a folder on your computer and deleted once delivered. Anything left over is removed when the application next starts.
  • You can unlink at any time in the application’s settings, which deletes the stored login from your computer. You should also remove AsanPOS from Linked devices in WhatsApp on your phone.

6. AsanPOS Cloud

AsanPOS Cloud is an optional paid subscription. Until you buy it, nothing in this section happens and the application never contacts us. If you do subscribe, we create a PostgreSQL database for your shop, host it, and back it up — which means we hold your business records. This section says exactly what we hold and why.

What we hold about your account

AccountYour shop name, an identifier for the Microsoft account that owns the subscription, and an email address if you give us one so we can warn you before the subscription lapses.
SubscriptionWhich plan you are on, whether it is active, when it renews or expires, and when we last confirmed it with the Microsoft Store. We receive this from Microsoft. We never receive your card details.
Each counterA token identifying the device, a label, the application version, when it was last seen, and when its database credentials expire. To help you tell one till from another in a list, the application also reports the computer's name, manufacturer, model, Windows version, and processor architecture. This is for legibility only — no access decision is made on any of it, so replacing a broken till never locks you out.
Audit logA record of provisioning, credential issue, suspension, and deletion events against your account, kept so that we can investigate problems and account for access.

Your business records

Your products, sales, customers, suppliers, ledgers, purchase orders and staff accounts are copied to the database we host for you, so that every counter sees the same information. Each shop gets its own separate database. We do not read, mine, analyse, or sell what is in it, and we do not use it to train anything. Our staff access it only where necessary to operate the service, to take backups, or to investigate a fault you have reported to us.

A complete copy also remains on each of your own computers, so cancelling the subscription, or losing your connection, never leaves you without your records.

Where it is hosted

Your database runs on Microsoft Azure. If you need to know the hosting region for your own compliance purposes, ask us and we will tell you in writing.

How access is controlled

A counter is never given a permanent database password. It leases credentials that renew while your subscription is active and expire on their own if it is not, so access ends by default rather than by us remembering to end it. Each counter gets its own credentials, and connections are encrypted in transit.

Backups

We take a backup of your database each night so that we can restore it after a failure. Backups are held for a limited period and are protected in the same way as the live database.

7. Synchronising to your own server

As an alternative to AsanPOS Cloud, the application can synchronise to a PostgreSQL database that you own or rent. This option is not on the normal setup path and is enabled on request — see the Support page.

  • The database is not provided or operated by us. We never see its address, its credentials, or its contents.
  • Data travels directly between your computer and your server. It does not pass through any system of ours.
  • The security, availability, backup, and legal compliance of that server are your responsibility, or that of whichever hosting provider you choose. Their own privacy terms will apply to the data you keep there.
  • You can stop synchronising at any time in the application’s settings.

8. Importing data from another system

The application can import a database backup file that you select from your computer, so that records from a previous system carry over. The file is read and converted entirely on your computer. It is not uploaded anywhere, and it is not sent to us.

9. Security

  • Staff passwords are stored as salted PBKDF2 hashes, never as readable text.
  • If you use AsanPOS Cloud, each counter holds only a short-lived lease rather than a standing database password, and each counter has its own. The token identifying a counter to our service is stored encrypted on that computer, and we keep only a hash of it.
  • If you configure synchronisation, the database credentials are encrypted at rest using the Windows Data Protection API, so they can only be decrypted by your Windows user account on that computer. The remembered sign-in session is protected the same way.
  • Synchronisation always uses an encrypted (TLS) connection to your server. By default the server’s certificate must also be valid for the address you entered, which protects the connection against interception. If your server uses a self-signed certificate you can say so in the connection settings; the traffic stays encrypted, but that identity check is skipped.
  • The account recovery code is stored only as a hash, so it is displayed once — when you generate it — and cannot be read back off the device afterwards.
  • Your local database is protected by the security of your Windows user account and device. We recommend using a device password, full-disk encryption, and regular backups.

No method of storage or transmission is completely secure. We cannot guarantee the security of data held on devices or servers that are outside our control.

10. Retention and deletion

On your own computers. Your records remain for as long as you keep them:

  • Delete individual records inside the application at any time.
  • Uninstalling the application removes it from that computer. Its records are held in your own Windows user profile, so if any remain after uninstalling, you can delete them yourself.
  • If you synchronised to your own server, data there is removed by you, on that server.

On AsanPOS Cloud. If your subscription ends, whether you cancel it or a payment fails:

  • The application keeps working on every one of your computers, with all of its data. You lose synchronising between counters, not your records.
  • There is a short grace period during which synchronising continues, so a failed payment does not cut you off while you fix it.
  • After that the credentials stop being renewed and expire, and your hosted database is suspended but kept for 90 days, so that resubscribing picks up where you left off.
  • At the end of that period the database is deleted. A backup copy is taken first and held for a limited further period, in case a deletion turns out to have been a mistake.
  • You can ask us to delete your hosted data sooner. Write to us and we will do it.

Account and audit records are kept for as long as your account exists, and for a period afterwards where we need them for accounting, tax, or fraud-prevention purposes.

11. Third parties and processors

The application includes no third-party analytics, advertising, or tracking components. We do not sell, rent, or trade your information, and we do not share it except as set out here.

AsanPOS is distributed through the Microsoft Store, so Microsoft handles the distribution, licensing, updates, and all payment, and its own privacy statement covers that relationship. From Microsoft we receive confirmation of whether a subscription is active and an identifier for the account that owns it — never card or bank details. We also receive the aggregate, anonymous reports the Store gives developers, such as install and crash counts, which contain no personal information and no business data.

If you subscribe to AsanPOS Cloud, Microsoft Azure provides the hosting and storage for your database, acting as our processor under contract. No other party has access.

We may disclose information where we are legally required to, or to establish or defend legal claims. If we are ever compelled to disclose data belonging to a customer, we will tell you unless the law forbids it.

12. Children

AsanPOS is a business tool intended for use by businesses and their staff. It is not directed at children, and we do not knowingly collect information from anyone.

13. Your rights

Data-protection laws give people rights to access, correct, export, and erase their personal data. How you exercise them here depends on where the data is:

  • Records on your own computers or your own server. Exercise these directly in the application. No request to us is needed, and there is nothing we could produce or delete on your behalf.
  • Records we host on AsanPOS Cloud, and your account information. Write to us and we will provide a copy, correct it, or delete it. We may need to confirm that you own the account before acting.

Where you hold personal data about your own customers or staff in AsanPOS, you are the controller of that data and we act as your processor for the part we host. Requests from those people should be directed to you, and we will assist you in answering them.

14. Changes to this policy

If the application’s behaviour changes in a way that affects this policy, we will update this page and revise the date at the top. Significant changes will also be noted in the application’s release notes.

15. Contact

Questions about this policy, requests about data we hold, or anything else about how the application handles information: support@smart-daddy.com