Apscode does not sell personal data. We use account, business, operational, payment-reference and technical data to provide and protect One-POS, meet legal obligations and support customers. PayHere processes card details on its own checkout.
1. Scope and our data roles
This Privacy Policy applies to visitors to apscode.lk and users, administrators and purchasers of Apscode One-POS. It should be read with our Terms of Service.
For Apscode account registration, billing, licensing, website security and support, Apscode determines the purposes of processing. When a subscribing business enters information about its own customers, employees, suppliers and transactions, that business ordinarily determines why the information is processed and Apscode provides the technical service on its behalf.
Each subscribing business remains responsible for its own privacy notices, lawful basis, access permissions, retention decisions and category-specific obligations.
2. Personal data we collect
Information you provide
- Administrator and user identity, username, verified email address, contact number and account-security information.
- Business name, category, address, registration/tax details, branches, authorised users and subscription choices.
- Support messages, policy or billing requests and information supplied when diagnosing an issue.
- Data entered into enabled POS modules, which may include customer, employee, supplier, product, invoice, payment-reference, loyalty and operational records.
Information collected automatically
- Device/browser type, application version, IP-derived security information, request time, error and audit events.
- Session, terminal, branch, licence and synchronization identifiers needed to authenticate and operate the Service.
- Essential browser storage used for sign-in state, preferences, offline working data and service continuity.
The public homepage currently does not use advertising cookies. If optional analytics or marketing technology is introduced, this notice and any required consent controls will be updated first.
3. Why we use personal data
Depending on the context and applicable law, processing is necessary to perform a contract, take requested pre-contract steps, comply with law, protect legitimate security/business interests or act with consent. We use data to:
- register and authenticate accounts and separate each business workspace;
- provide POS, stock, purchasing, reporting, finance, licensing and support functions;
- process subscription checkout status, issue receipts and reconcile payments;
- send verification, password-reset, service and security communications;
- prevent fraud, investigate misuse, maintain audit trails and secure the platform;
- back up, restore, troubleshoot, measure reliability and improve the Service;
- meet accounting, tax, consumer-protection, legal and regulatory duties.
We do not use tenant customer transaction data for unrelated advertising.
5. Payment information
Subscription checkout is hosted and processed by PayHere. Apscode sends the order reference, amount, currency and customer contact/order details required for checkout. PayHere returns payment identifiers and status information used for reconciliation and licence activation.
Apscode does not store your full card number, PIN or card security code. PayHere’s handling of information is also governed by its own legal and privacy terms.
6. Hosting and cross-border processing
The cloud staging and production infrastructure may process encrypted or access-controlled data outside Sri Lanka, including in the selected Malaysia hosting region. Email, security and support providers may also process limited data in other jurisdictions.
Where cross-border processing applies, we use reasonable contractual, access, encryption and vendor-management safeguards appropriate to the data and applicable law. Businesses with regulated or highly sensitive data must enable only certified feature packs and agree any additional sector-specific controls before production use.
7. Retention and deletion
We retain personal data only for as long as reasonably needed for the Service, the customer contract, security, backup restoration, dispute handling and applicable accounting or legal obligations. Retention varies by record type:
- active account and operational records are retained while the account or contracted service requires them;
- payment, licence, invoice and audit records may be retained for legal, reconciliation, fraud-prevention and dispute periods;
- expired sessions and routine security logs are removed or aggregated according to operational schedules;
- backup copies age out through controlled backup cycles rather than being edited individually.
Cancellation does not automatically delete business records. An authorised account representative may request closure or deletion, subject to identity verification, other users’ rights and records we must lawfully retain.
8. Your choices and rights
Subject to the Personal Data Protection Act No. 9 of 2022, as amended, and other applicable law, you may have rights to request information or access, correction, completion, erasure, restriction or objection, and to withdraw consent where consent is the basis of processing. You may also have rights concerning certain automated decisions and complaints.
We may need to verify your identity and authority before acting. For data controlled by a subscribing business, contact that business first; we will assist it as required. Lawful exceptions, the rights of others and mandatory retention may limit a request.
9. Security and incident response
We use measures designed to protect the Service, including encrypted transport, password hashing, scoped access, tenant separation, audit records, restricted database access, backups and security monitoring. No internet or storage method is completely risk-free, so absolute security cannot be guaranteed.
Users must protect passwords and devices, assign minimum necessary privileges, install trusted updates and report suspected incidents promptly.
10. Children
The Service is intended for business operators and authorised staff, not for children. A person creating an account or purchasing a plan must be at least 18 years old.
11. Policy changes
We may update this policy for Service, provider or legal changes. The current version and effective date will remain available on this page. Material changes will be communicated reasonably where practicable.
12. Privacy contact
To ask a privacy question or exercise an applicable right, contact: