Legal

Privacy policy.

What Scale POS and the Scale dashboard collect, why, who else touches it, and how you get it deleted. Written to be read, not to be survived.

Last updated 11 August 2026Effective 11 August 2026
The short version
  • We do not sell your data, and we run no advertising or tracking SDKs in the apps.
  • Your sales, staff and catalogue records belong to your business. We hold them to run the service for you.
  • The apps never see card numbers, PINs, or bank credentials — a payment is recorded as a type and an amount.
  • You can ask for a copy of your data, or its deletion, at any time.

01Who we are, and what this covers

Scale builds and operates business software from Phnom Penh, Cambodia. In this policy, “Scale”, “we” and “us” mean Scale; “you” means the person using one of the products below, and “your business” means the merchant organisation an account belongs to.

Products this policy covers

ProductWhat it isWhere it runs
Scale POSThe point-of-sale till app: checkout, catalogue, inventory, shifts, receipts, printing.iPhone and iPad (App Store), Android phones and tablets (Google Play), and Windows desktop
Scale DashboardThe back office a merchant signs into: reporting, catalogue, stores, staff, settings.Web browser
Scale QR orderingThe menu and order page a diner opens by scanning a table QR code. No account, no sign-in.Web browser
scalekh.comThis marketing site, including its contact, quote and careers forms.Web browser

App store distribution

Scale POS is distributed through Scale’s developer accounts on the Apple App Store and Google Play. Those accounts are held individually, so the name shown as the developer on a store listing is the account holder’s. Whatever name appears there, the party responsible for the data described in this policy is Scale, contactable at the address in section 17.

Apple and Google each collect their own data when you download or update an app — installs, purchases, crash reports through their own tooling. That collection is theirs and is governed by their privacy policies, not this one.

02Whose data is whose

A point-of-sale system holds two different kinds of information, and they carry different rights. Keeping them apart is the most important thing on this page.

Kind of dataWho decides what happens to itOur role
Your business records — sales, staff, catalogue, stock, shifts, tablesYour business. You enter it, you correct it, you decide who on your team sees it, and you can ask us to export or erase it.We hold and process it on your instruction, so you can run your shop. We do not use it for our own purposes.
Your account with us — the owner’s name, phone, email, business name, plan and billing stateUs, together with you.We decide what is needed to give you an account, keep it secure, and bill it. This is the data we are directly responsible for.
Diagnostics — error codes, app version, and a scrubbed hintUs.We decide what is recorded, and we keep it deliberately thin (section 03).

If you are an employee whose name and PIN sit in a Scale POS till, your employer put them there and your employer is who decides about them. Write to us anyway if you cannot get an answer — see section 11.

03What we collect

Account and business information

  • Owner name, phone number and email address, used to create the account and to sign you in.
  • Business name, store names, city, currency (USD and/or KHR), tax settings, opening hours and day-end time.
  • Your plan, the modules switched on for your stores, and the state of your onboarding.

Sign-in is by phone number with a one-time SMS code, or by phone number and password. The one-time code is delivered by our SMS provider (section 07). Passwords are never stored in a readable form.

Staff information

  • The name and role your business gives each staff member, and which stores and registers they are assigned to.
  • A staff PIN, stored only as an Argon2id hash. The digits themselves are never written to our database and never leave the device in readable form.
  • A record of PIN attempts (which staff record, when, and whether it succeeded), kept so a till can lock itself after repeated failures.
  • Which staff member rang up a sale, opened a shift, approved a void or a refund — the audit trail a shop needs to reconcile a drawer.

Transaction and operational records

  • Sales and refunds: line items, quantities, modifiers, discounts, taxes, totals and currency.
  • Payments: the tender type (cash, KHQR or card), the amount, the currency and an optional reference your staff type in.
  • Shifts and cash movements, cash-drawer counts, voids, edits and their approvals.
  • Catalogue and stock: products, categories, bundles, modifiers, prices, stock levels and movements, purchase orders, and vendor contact details you enter.
  • Restaurant operations if you use them: floor plans, tables, order tickets and table state.
We never receive card numbers, expiry dates, CVV codes, card PINs or bank credentials. A card payment is recorded in Scale as a type and an amount — nothing in the system has a field those digits could be stored in. Card processing happens on your own terminal, with your own acquirer.

Photos you choose to upload

If you add a picture to a catalogue item, that single image is uploaded to our image storage and served back to your tills and dashboard. We read no other photo. The apps do not browse your photo library and do not upload anything you have not picked for an item.

QR ordering — what a diner gives us

  • The table the QR code belongs to, and the items ordered.
  • A name, only for takeaway orders and only if the diner types one, so staff can call the order.

A diner creates no account, and we ask for no phone number, email address or payment detail on that page.

Device and diagnostic information

When the app shows a person an error, it can file a short report so we find out that something broke. A report carries which app it was, the app version, a stable error code, the HTTP status if there was one, and a hint of up to 300 characters. The hint is scrubbed on arrival: phone numbers, email addresses, tokens and record identifiers are replaced before the row is written, because error text is where personal data hides in plain sight.

Our servers also see the IP address a request came from, as every internet service does. We use it to rate-limit abuse and to keep short security logs. It is not attached to your sales records.

Website visitors and enquiries

  • If you send a message, request a quote or apply for a role, we receive what you typed: your name, email, and — depending on the form — company, phone number, industry, what you want help with, a link, and your message.
  • Anti-spam checks on those forms are run by Cloudflare Turnstile, which does not use tracking cookies.
  • We measure traffic with privacy-preserving analytics that set no cookies and build no cross-site profile: Vercel Analytics and Speed Insights, and optionally Cloudflare Web Analytics.

04Device permissions, and what we never touch

Scale POS asks for the narrowest set of permissions that lets a till work. Each one is requested at the moment it is first needed, and the app keeps working without it — a barcode can always be typed.

PermissionWhyWhat leaves the device
CameraScanning a barcode at checkout, or when counting stock.Nothing. Frames are decoded on the device and discarded. No image is saved or uploaded.
PhotosPicking one picture for a catalogue item.Only the image you selected.
BluetoothTalking to receipt printers and cash drawers.Print jobs to your own hardware. On Android the app declares that Bluetooth is never used to derive location.
Local networkTalking to a Wi-Fi or LAN receipt printer at your counter.Print jobs to your own hardware.

What the apps do not do

  • No location. The app requests no location permission, coarse or fine, and derives none from Bluetooth scanning.
  • No microphone. Audio recording is explicitly blocked in the app’s build configuration.
  • No contacts, no calendar, no call logs, no SMS reading.
  • No advertising identifier, no ad SDK, no third-party analytics or attribution SDK inside the apps. There is nothing in Scale POS that tracks you across other companies’ apps or websites, which is why iOS never shows you a tracking prompt for it.

05What we use it for

  • Running the service: taking payments through your till, syncing your tills and dashboard, printing receipts, calculating your reports.
  • Signing you in and keeping the account secure: one-time codes, passwords, staff PINs, lockouts after repeated failures, rate limits against abuse.
  • Keeping your data intact across devices, including everything a till records while the internet is down.
  • Support: when you ask us for help, we look at your account and its recent errors to answer you.
  • Fixing and improving the product: diagnosing errors, finding which release broke something, and understanding which features are used enough to keep.
  • Sending the notifications you switch on — Telegram sale and shift alerts, if and only if you connect them.
  • Billing, invoicing, and the tax and accounting records a Cambodian business is required to keep.
  • Meeting legal obligations, and defending or making a legal claim where we have to.

Where a law such as the GDPR applies to you, our grounds are: performing our contract with you (running the service and billing it), our legitimate interests (security, fraud and abuse prevention, product diagnostics, direct replies to your enquiries), your consent where we ask for it (optional Telegram alerts, marketing email), and compliance with legal obligations.

06What we never do

  • We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have never done so.
  • We do not run advertising in the apps, and we place no ad or tracking SDK in them.
  • We do not use your sales, staff or customer records to profile you or to build products for anyone else.
  • We do not read your data for our own commercial purposes. Access by our staff happens for support, security and maintenance — and is limited to the people who need it.

07Who else touches your data

We keep the list short on purpose. Every company below processes data on our instruction, under a contract, for the single job named beside it.

ProviderWhat it does for usWhat it sees
Supabase (on AWS, Singapore)Our database, authentication and API.Account, staff, catalogue and transaction records; sign-in credentials in hashed form.
VercelHosting for the dashboard, the QR ordering page and this website.Requests to those sites, including IP address and standard server logs.
CloudflareImage storage for catalogue photos, anti-spam checks on our forms, and cookieless site analytics.Item images; a spam-check token; aggregate page views.
TwilioDelivering one-time sign-in codes by SMS.The phone number the code is sent to, and the code.
TelegramDelivering sale and shift alerts — only if you connect a Telegram account.The alert content you chose to receive, and your Telegram chat identity. A cashier’s name is left out unless the recipient explicitly turns it on.
MailjetSending email from this website’s forms and our replies to them.The name, email address and message you submitted.
Apple, GoogleDistributing and updating the apps.Their own install, purchase and crash data, under their own policies.

Other cases where data leaves us

  • When you tell us to — for example, connecting Telegram alerts, or asking us to send an export to your accountant.
  • When the law requires it: a valid order from a competent authority. We check that a request is lawful and no broader than it has to be.
  • To protect people or the service: investigating fraud, abuse, or a threat to someone’s safety.
  • In a merger, acquisition or sale of assets, in which case we will tell you before your data moves and the buyer inherits these commitments.

08Where your data is stored

Your database records are stored in Singapore (AWS ap-southeast-1). The dashboard, ordering page and website are served from our hosting provider’s global network, and catalogue images sit in Cloudflare’s object storage. Our SMS, messaging and email providers operate internationally.

That means data about you may be processed outside Cambodia, and outside the country you are in. Where a transfer of this kind needs a legal safeguard — for example under the GDPR — we rely on our providers’ standard contractual clauses and equivalent terms.

A copy of your recent business data also lives on each device you use, so a till keeps selling when the internet does not. See section 14.

09How long we keep it

WhatHow long
Sales, refunds, shifts and the audit trailFor as long as your account is open, because they are your accounting records. Deleted on request, subject to any retention a tax authority requires of us.
Catalogue, stock, staff and store settingsFor as long as your account is open, or until you delete the record.
Account and contact detailsFor as long as your account is open, and up to 12 months afterwards so an account can be restored and a billing dispute answered.
In-app notificationsAutomatically purged after 90 days.
Diagnostic error reportsUp to 12 months. They are already scrubbed of identifying text when written.
Security and rate-limit logsShort-lived — hours to days for rate-limit windows; up to 12 months for security logs.
Website enquiries, quotes and job applicationsUp to 24 months from your last contact with us, so we can pick up a conversation where it left off. Sooner on request.

When a retention period ends, or when you ask us to delete, records are deleted or irreversibly anonymised. Backups roll off on their own schedule, within 30 days.

10How we protect it

  • Everything in transit is encrypted with TLS. Data at rest is encrypted by our hosting providers.
  • Every tenant’s rows are separated in the database and enforced at the database itself, not only in application code, so one merchant cannot read another’s data even if a query goes wrong.
  • Staff PINs are stored as Argon2id hashes. Passwords are stored hashed by our authentication provider. Neither is recoverable in readable form — not by us either.
  • Sign-in tokens are held in the device’s own secure storage: the iOS Keychain, the Android Keystore, or the operating system’s encrypted credential store on desktop.
  • Error text is scrubbed of phone numbers, email addresses, identifiers and tokens on the server, before it is written down.
  • Sign-in, one-time codes and public endpoints are rate-limited, and a till locks itself after repeated wrong PINs.
  • Internal access is limited to the people who need it for support, security or maintenance.

No system is perfectly secure, and we will not pretend otherwise. If a breach affects your data and puts you at risk, we will tell you and the relevant authority without undue delay, with what we know and what we are doing about it.

11Your choices and your rights

  • Access — ask what we hold about you, and get a copy.
  • Correction — have anything wrong put right. Most of it you can edit yourself in the dashboard.
  • Deletion — have your account and its data erased. See section 12.
  • Export — get your business records in a machine-readable file you can take elsewhere.
  • Objection and restriction — object to processing we base on legitimate interests, or ask us to pause it while a dispute is resolved.
  • Withdraw consent — turn off Telegram alerts or unsubscribe from marketing email at any time, without affecting what was already sent.
  • Complain — to us first, and to your data protection authority if you are somewhere that has one.

Write to us at the address in section 17 and we will answer within 30 days. We may need to confirm who you are before we act — it is the only thing standing between your records and someone who says they are you. Exercising a right never costs you anything, and never gets you worse service.

If you are a staff member and the data concerns your employer’s till, ask your employer first: they control that record. Tell us if you get nowhere, and we will help.

If you are in California: we do not sell or share personal information as those terms are defined there, and we do not use or disclose sensitive personal information beyond what is needed to provide the service.

12Deleting your account and your data

You can have your Scale account and the data in it deleted, whether or not you keep using the app.

How to ask

  • Email [email protected] from the address on the account, or from the phone number on it, with the words “delete my account”. Tell us whether you want the whole account gone, or only certain records.
  • We confirm within 5 business days, and complete the deletion within 30 days.

What gets deleted

  • Your sign-in credentials, owner contact details, and the business, store and staff records under your account.
  • Your catalogue, stock, sales, refunds, shifts and audit trail.
  • Catalogue images you uploaded.
  • Any Telegram connection, which also stops the alerts.

What we may keep, and why

  • Records we are legally required to keep — invoices and tax records, for the period Cambodian law sets.
  • Anonymised or aggregated figures that can no longer identify you or your business.
  • Backups, until they roll off on their own schedule, within 30 days.
Deleting the app from a device removes that device’s local copy. It does not delete the account — the records are still on the server for your other tills. Ask us, as above, if you want them gone.

13Children

Scale POS and the Scale dashboard are tools for running a business. They are not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child’s data has reached us, write to us and we will delete it.

14Data on your own device

Scale POS is built to keep selling with no internet, so each device holds a local copy of what it needs: your catalogue, prices, staff list with hashed PINs, and any sales rung up since the last sync. When the connection comes back, the queued sales are sent and the copy is refreshed.

  • That local copy lives in the app’s private storage, inside the sandbox the operating system gives it.
  • Sign-in tokens are kept in the device’s secure credential store, not in the local database.
  • On Android, the app opts out of the operating system’s automatic cloud backup, so your till data is not copied into a Google account.
  • Signing out, or deleting the app, removes the local copy from that device.

Because the data is on hardware you control, physical security of your tills is yours to manage: use a device lock, and remove a device from your account when it leaves your shop.

15App store disclosures

What follows restates the sections above in the categories Apple and Google use, so what you read on a store listing and what you read here agree.

Apple App Store — App Privacy

CategoryCollectedPurposeLinked to youUsed to track you
Contact info — name, email, phoneYesApp functionalityYesNo
User content — item photos, catalogue and order textYesApp functionalityYesNo
Identifiers — account, business and staff IDsYesApp functionalityYesNo
Purchases — the transaction records your till writesYesApp functionalityYesNo
Diagnostics — error codes, app version, scrubbed hintYesApp functionality, analyticsYesNo
LocationNo
Financial info — card numbers, bank credentialsNo
Contacts, health, browsing history, advertising dataNo
Nothing in Scale POS is used for tracking as Apple defines it — no data is linked to third-party data for advertising or measurement, and none is shared with a data broker.

Google Play — Data safety

Data typeCollectedSharedRequiredPurpose
Personal info — name, email, phone, user IDsYesNoRequiredApp functionality, account management
Photos — item images you pickYesNoOptionalApp functionality
Financial info — other financial info (your sales records)YesNoRequiredApp functionality
App activity and app info — diagnostics, error logsYesNoRequiredApp functionality, diagnostics
Location, contacts, calendar, messages, audio, device IDsNoNo
Data is encrypted in transit. You can request that your data be deleted — see section 12. We do not share data with third parties for advertising, and no data is sold.

16Changes to this policy

We update this page when the product changes what it does with data. The date at the top of the page always says when it last changed. If a change materially affects your rights, we will tell you in the app or by email before it takes effect, not after.

17Contact us

Questions about this policy, a request to see your data, or a request to delete it — all go to the same place, and a person reads it.

Post
Scale, Phnom Penh, Cambodia
Response time
Within 30 days, and usually within one business day.

Scale · Phnom Penh, Cambodia · This policy was last updated on 11 August 2026.