moraPOS — Privacy Policy
Last updated: 14 July 2026
This policy explains what data the moraPOS Android app (com.moracommerce.pos) collects, why it collects it, and how it is used. moraPOS is published by Dabolinux Technologies and is the point-of-sale companion to the moraCommerce ecommerce platform.
1. Who this app is for
moraPOS is a business tool for staff of stores that already use moraCommerce. You log in with credentials issued by your store administrator (your tenant) and use the app to record sales for that store. The app is not aimed at, and not intended for, children under 13.
2. What data we collect
moraPOS collects only what it needs to run the till:
- Account data — your staff email address and the tenant (store) slug you log into. We do not store your password on the device; we store a short-lived access token issued by the moraCommerce API after you sign in.
- Sales data — the products, quantities, prices, taxes, discounts, payment method, and totals of each sale you record. This is your store's own business record of what was sold.
- Customer records — when a sale is tied to a customer, the name and phone number your staff select or enter at the counter. This is data about your store's customers, held on behalf of your tenant.
- Product photos — if a manager adds a photo to a product, the image they capture with the camera or pick from the device (gallery or files) is uploaded and set as that product's image. Photos are only accessed when a manager chooses to add one; the app never scans or indexes your photo library on its own.
- Device technical data — limited diagnostics (app version, OS version) sent with API requests so we can troubleshoot if something breaks.
moraPOS does not collect: your location, your contacts, your messages, your call history, your health data, advertising identifiers, or your web browsing activity. It does not browse or index your photo library; it only receives a photo you explicitly pick or capture to set as a product image.
3. Camera and product photos
moraPOS asks for the camera permission for two things. First, to scan a product barcode when you look up or add a product: the camera opens only on the scanner screen, no images or video are stored or uploaded, and the feed is processed in memory for the barcode then discarded. Second, to take a product photo: a manager can add a photo to a product by capturing one with the camera or choosing an existing image from the device (gallery or files), which is then uploaded and set as the product's image. moraPOS does not request microphone access.
4. Working offline
moraPOS is offline-first. Your tenant's catalogue and customers are synced to the device so you can sell without a connection, and each sale is saved locally the moment you complete it. Queued sales sync to the moraCommerce API when a connection is available. Until they sync, that data lives only on your device.
5. Receipts, printing and sharing
Receipts are generated on the device from the sale you just recorded. When you tap Print, the receipt is handed to your phone's own print system and sent only to the printer you choose. When you tap Share, a PDF is created on the device and sent only to the app you pick (for example WhatsApp or email). moraPOS does not upload receipts anywhere on its own.
6. How your data is used
- To authenticate you against your moraCommerce tenant.
- To sync your tenant's products and customers to your device so you can sell offline.
- To record sales and send them back to your moraCommerce store, where they update inventory, revenue, and reports.
- To investigate bug reports and crash logs you choose to send us.
7. Who your data is shared with
No third parties. Your store's catalogue, customer records, and sales are stored in your moraCommerce tenant and are never sold, shared with advertisers, or made available to other tenants. The data flow is strictly:
moraPOS (your phone) ⇄ moraCommerce API (our servers) ⇄ Your tenant's database
moraCommerce is hosted on infrastructure operated by reputable providers (Vercel, DigitalOcean, Cloudflare). Those providers act as data processors only — they do not access or use your data for their own purposes.
8. How long we keep your data
- On your device: as long as you stay signed in, plus a local cache of products, customers, and any sales not yet synced. Signing out, clearing app storage, or uninstalling the app removes the local copy.
- On our servers: for as long as your tenant exists. Completed sales are part of your store's business records and are retained alongside your order and inventory history.
9. Security
All traffic between moraPOS and the moraCommerce API is encrypted in transit using TLS. Access tokens are stored in the OS-provided secure storage (Android Keystore / iOS Keychain) and never written to plain files.
10. Your rights
You can sign out of moraPOS at any time, which clears the locally cached data. To delete your account or request a copy of your data, contact your store administrator — they own your tenant. If your administrator is unable to help, write to us at moracommerce@dabolinux.com and we will action your request within 30 days.
11. Children's privacy
moraPOS is not directed at children. We do not knowingly collect personal data from anyone under 13. If you believe a child has signed in to moraPOS, please email us so we can remove the account.
12. Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top of the page will change when we do. Material changes will also be flagged in the moraPOS release notes.
13. Contact
Questions or complaints about this policy or how we handle your data: moracommerce@dabolinux.com.
Dabolinux Technologies · Publisher of moraCommerce and moraPOS.