Privacy policy.
What Scale POS and the Scale dashboard collect, why, who else touches it, and how you get it deleted. Written to be read, not to be survived.
- We do not sell your data, and we run no advertising or tracking SDKs in the apps.
- Your sales, staff and catalogue records belong to your business. We hold them to run the service for you.
- The apps never see card numbers, PINs, or bank credentials — a payment is recorded as a type and an amount.
- You can ask for a copy of your data, or its deletion, at any time.
01Who we are, and what this covers
Scale builds and operates business software from Phnom Penh, Cambodia. In this policy, “Scale”, “we” and “us” mean Scale; “you” means the person using one of the products below, and “your business” means the merchant organisation an account belongs to.
Products this policy covers
| Product | What it is | Where it runs |
|---|---|---|
| Scale POS | The point-of-sale till app: checkout, catalogue, inventory, shifts, receipts, printing. | iPhone and iPad (App Store), Android phones and tablets (Google Play), and Windows desktop |
| Scale Dashboard | The back office a merchant signs into: reporting, catalogue, stores, staff, settings. | Web browser |
| Scale QR ordering | The menu and order page a diner opens by scanning a table QR code. No account, no sign-in. | Web browser |
| scalekh.com | This marketing site, including its contact, quote and careers forms. | Web browser |
App store distribution
Scale POS is distributed through Scale’s developer accounts on the Apple App Store and Google Play. Those accounts are held individually, so the name shown as the developer on a store listing is the account holder’s. Whatever name appears there, the party responsible for the data described in this policy is Scale, contactable at the address in section 17.
02Whose data is whose
A point-of-sale system holds two different kinds of information, and they carry different rights. Keeping them apart is the most important thing on this page.
| Kind of data | Who decides what happens to it | Our role |
|---|---|---|
| Your business records — sales, staff, catalogue, stock, shifts, tables | Your business. You enter it, you correct it, you decide who on your team sees it, and you can ask us to export or erase it. | We hold and process it on your instruction, so you can run your shop. We do not use it for our own purposes. |
| Your account with us — the owner’s name, phone, email, business name, plan and billing state | Us, together with you. | We decide what is needed to give you an account, keep it secure, and bill it. This is the data we are directly responsible for. |
| Diagnostics — error codes, app version, and a scrubbed hint | Us. | We decide what is recorded, and we keep it deliberately thin (section 03). |
If you are an employee whose name and PIN sit in a Scale POS till, your employer put them there and your employer is who decides about them. Write to us anyway if you cannot get an answer — see section 11.
03What we collect
Account and business information
- Owner name, phone number and email address, used to create the account and to sign you in.
- Business name, store names, city, currency (USD and/or KHR), tax settings, opening hours and day-end time.
- Your plan, the modules switched on for your stores, and the state of your onboarding.
Sign-in is by phone number with a one-time SMS code, or by phone number and password. The one-time code is delivered by our SMS provider (section 07). Passwords are never stored in a readable form.
Staff information
- The name and role your business gives each staff member, and which stores and registers they are assigned to.
- A staff PIN, stored only as an Argon2id hash. The digits themselves are never written to our database and never leave the device in readable form.
- A record of PIN attempts (which staff record, when, and whether it succeeded), kept so a till can lock itself after repeated failures.
- Which staff member rang up a sale, opened a shift, approved a void or a refund — the audit trail a shop needs to reconcile a drawer.
Transaction and operational records
- Sales and refunds: line items, quantities, modifiers, discounts, taxes, totals and currency.
- Payments: the tender type (cash, KHQR or card), the amount, the currency and an optional reference your staff type in.
- Shifts and cash movements, cash-drawer counts, voids, edits and their approvals.
- Catalogue and stock: products, categories, bundles, modifiers, prices, stock levels and movements, purchase orders, and vendor contact details you enter.
- Restaurant operations if you use them: floor plans, tables, order tickets and table state.
Photos you choose to upload
If you add a picture to a catalogue item, that single image is uploaded to our image storage and served back to your tills and dashboard. We read no other photo. The apps do not browse your photo library and do not upload anything you have not picked for an item.
QR ordering — what a diner gives us
- The table the QR code belongs to, and the items ordered.
- A name, only for takeaway orders and only if the diner types one, so staff can call the order.
A diner creates no account, and we ask for no phone number, email address or payment detail on that page.
Device and diagnostic information
When the app shows a person an error, it can file a short report so we find out that something broke. A report carries which app it was, the app version, a stable error code, the HTTP status if there was one, and a hint of up to 300 characters. The hint is scrubbed on arrival: phone numbers, email addresses, tokens and record identifiers are replaced before the row is written, because error text is where personal data hides in plain sight.
Our servers also see the IP address a request came from, as every internet service does. We use it to rate-limit abuse and to keep short security logs. It is not attached to your sales records.
Website visitors and enquiries
- If you send a message, request a quote or apply for a role, we receive what you typed: your name, email, and — depending on the form — company, phone number, industry, what you want help with, a link, and your message.
- Anti-spam checks on those forms are run by Cloudflare Turnstile, which does not use tracking cookies.
- We measure traffic with privacy-preserving analytics that set no cookies and build no cross-site profile: Vercel Analytics and Speed Insights, and optionally Cloudflare Web Analytics.
04Device permissions, and what we never touch
Scale POS asks for the narrowest set of permissions that lets a till work. Each one is requested at the moment it is first needed, and the app keeps working without it — a barcode can always be typed.
| Permission | Why | What leaves the device |
|---|---|---|
| Camera | Scanning a barcode at checkout, or when counting stock. | Nothing. Frames are decoded on the device and discarded. No image is saved or uploaded. |
| Photos | Picking one picture for a catalogue item. | Only the image you selected. |
| Bluetooth | Talking to receipt printers and cash drawers. | Print jobs to your own hardware. On Android the app declares that Bluetooth is never used to derive location. |
| Local network | Talking to a Wi-Fi or LAN receipt printer at your counter. | Print jobs to your own hardware. |
What the apps do not do
- No location. The app requests no location permission, coarse or fine, and derives none from Bluetooth scanning.
- No microphone. Audio recording is explicitly blocked in the app’s build configuration.
- No contacts, no calendar, no call logs, no SMS reading.
- No advertising identifier, no ad SDK, no third-party analytics or attribution SDK inside the apps. There is nothing in Scale POS that tracks you across other companies’ apps or websites, which is why iOS never shows you a tracking prompt for it.
05What we use it for
- Running the service: taking payments through your till, syncing your tills and dashboard, printing receipts, calculating your reports.
- Signing you in and keeping the account secure: one-time codes, passwords, staff PINs, lockouts after repeated failures, rate limits against abuse.
- Keeping your data intact across devices, including everything a till records while the internet is down.
- Support: when you ask us for help, we look at your account and its recent errors to answer you.
- Fixing and improving the product: diagnosing errors, finding which release broke something, and understanding which features are used enough to keep.
- Sending the notifications you switch on — Telegram sale and shift alerts, if and only if you connect them.
- Billing, invoicing, and the tax and accounting records a Cambodian business is required to keep.
- Meeting legal obligations, and defending or making a legal claim where we have to.
Where a law such as the GDPR applies to you, our grounds are: performing our contract with you (running the service and billing it), our legitimate interests (security, fraud and abuse prevention, product diagnostics, direct replies to your enquiries), your consent where we ask for it (optional Telegram alerts, marketing email), and compliance with legal obligations.
06What we never do
- We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have never done so.
- We do not run advertising in the apps, and we place no ad or tracking SDK in them.
- We do not use your sales, staff or customer records to profile you or to build products for anyone else.
- We do not read your data for our own commercial purposes. Access by our staff happens for support, security and maintenance — and is limited to the people who need it.
07Who else touches your data
We keep the list short on purpose. Every company below processes data on our instruction, under a contract, for the single job named beside it.
| Provider | What it does for us | What it sees |
|---|---|---|
| Supabase (on AWS, Singapore) | Our database, authentication and API. | Account, staff, catalogue and transaction records; sign-in credentials in hashed form. |
| Vercel | Hosting for the dashboard, the QR ordering page and this website. | Requests to those sites, including IP address and standard server logs. |
| Cloudflare | Image storage for catalogue photos, anti-spam checks on our forms, and cookieless site analytics. | Item images; a spam-check token; aggregate page views. |
| Twilio | Delivering one-time sign-in codes by SMS. | The phone number the code is sent to, and the code. |
| Telegram | Delivering sale and shift alerts — only if you connect a Telegram account. | The alert content you chose to receive, and your Telegram chat identity. A cashier’s name is left out unless the recipient explicitly turns it on. |
| Mailjet | Sending email from this website’s forms and our replies to them. | The name, email address and message you submitted. |
| Apple, Google | Distributing and updating the apps. | Their own install, purchase and crash data, under their own policies. |
Other cases where data leaves us
- When you tell us to — for example, connecting Telegram alerts, or asking us to send an export to your accountant.
- When the law requires it: a valid order from a competent authority. We check that a request is lawful and no broader than it has to be.
- To protect people or the service: investigating fraud, abuse, or a threat to someone’s safety.
- In a merger, acquisition or sale of assets, in which case we will tell you before your data moves and the buyer inherits these commitments.
08Where your data is stored
Your database records are stored in Singapore (AWS ap-southeast-1). The dashboard, ordering page and website are served from our hosting provider’s global network, and catalogue images sit in Cloudflare’s object storage. Our SMS, messaging and email providers operate internationally.
That means data about you may be processed outside Cambodia, and outside the country you are in. Where a transfer of this kind needs a legal safeguard — for example under the GDPR — we rely on our providers’ standard contractual clauses and equivalent terms.
A copy of your recent business data also lives on each device you use, so a till keeps selling when the internet does not. See section 14.
09How long we keep it
| What | How long |
|---|---|
| Sales, refunds, shifts and the audit trail | For as long as your account is open, because they are your accounting records. Deleted on request, subject to any retention a tax authority requires of us. |
| Catalogue, stock, staff and store settings | For as long as your account is open, or until you delete the record. |
| Account and contact details | For as long as your account is open, and up to 12 months afterwards so an account can be restored and a billing dispute answered. |
| In-app notifications | Automatically purged after 90 days. |
| Diagnostic error reports | Up to 12 months. They are already scrubbed of identifying text when written. |
| Security and rate-limit logs | Short-lived — hours to days for rate-limit windows; up to 12 months for security logs. |
| Website enquiries, quotes and job applications | Up to 24 months from your last contact with us, so we can pick up a conversation where it left off. Sooner on request. |
When a retention period ends, or when you ask us to delete, records are deleted or irreversibly anonymised. Backups roll off on their own schedule, within 30 days.
10How we protect it
- Everything in transit is encrypted with TLS. Data at rest is encrypted by our hosting providers.
- Every tenant’s rows are separated in the database and enforced at the database itself, not only in application code, so one merchant cannot read another’s data even if a query goes wrong.
- Staff PINs are stored as Argon2id hashes. Passwords are stored hashed by our authentication provider. Neither is recoverable in readable form — not by us either.
- Sign-in tokens are held in the device’s own secure storage: the iOS Keychain, the Android Keystore, or the operating system’s encrypted credential store on desktop.
- Error text is scrubbed of phone numbers, email addresses, identifiers and tokens on the server, before it is written down.
- Sign-in, one-time codes and public endpoints are rate-limited, and a till locks itself after repeated wrong PINs.
- Internal access is limited to the people who need it for support, security or maintenance.
No system is perfectly secure, and we will not pretend otherwise. If a breach affects your data and puts you at risk, we will tell you and the relevant authority without undue delay, with what we know and what we are doing about it.
11Your choices and your rights
- Access — ask what we hold about you, and get a copy.
- Correction — have anything wrong put right. Most of it you can edit yourself in the dashboard.
- Deletion — have your account and its data erased. See section 12.
- Export — get your business records in a machine-readable file you can take elsewhere.
- Objection and restriction — object to processing we base on legitimate interests, or ask us to pause it while a dispute is resolved.
- Withdraw consent — turn off Telegram alerts or unsubscribe from marketing email at any time, without affecting what was already sent.
- Complain — to us first, and to your data protection authority if you are somewhere that has one.
Write to us at the address in section 17 and we will answer within 30 days. We may need to confirm who you are before we act — it is the only thing standing between your records and someone who says they are you. Exercising a right never costs you anything, and never gets you worse service.
If you are a staff member and the data concerns your employer’s till, ask your employer first: they control that record. Tell us if you get nowhere, and we will help.
If you are in California: we do not sell or share personal information as those terms are defined there, and we do not use or disclose sensitive personal information beyond what is needed to provide the service.
12Deleting your account and your data
You can have your Scale account and the data in it deleted, whether or not you keep using the app.
How to ask
- Email [email protected] from the address on the account, or from the phone number on it, with the words “delete my account”. Tell us whether you want the whole account gone, or only certain records.
- We confirm within 5 business days, and complete the deletion within 30 days.
What gets deleted
- Your sign-in credentials, owner contact details, and the business, store and staff records under your account.
- Your catalogue, stock, sales, refunds, shifts and audit trail.
- Catalogue images you uploaded.
- Any Telegram connection, which also stops the alerts.
What we may keep, and why
- Records we are legally required to keep — invoices and tax records, for the period Cambodian law sets.
- Anonymised or aggregated figures that can no longer identify you or your business.
- Backups, until they roll off on their own schedule, within 30 days.
13Children
Scale POS and the Scale dashboard are tools for running a business. They are not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child’s data has reached us, write to us and we will delete it.
14Data on your own device
Scale POS is built to keep selling with no internet, so each device holds a local copy of what it needs: your catalogue, prices, staff list with hashed PINs, and any sales rung up since the last sync. When the connection comes back, the queued sales are sent and the copy is refreshed.
- That local copy lives in the app’s private storage, inside the sandbox the operating system gives it.
- Sign-in tokens are kept in the device’s secure credential store, not in the local database.
- On Android, the app opts out of the operating system’s automatic cloud backup, so your till data is not copied into a Google account.
- Signing out, or deleting the app, removes the local copy from that device.
Because the data is on hardware you control, physical security of your tills is yours to manage: use a device lock, and remove a device from your account when it leaves your shop.
15App store disclosures
What follows restates the sections above in the categories Apple and Google use, so what you read on a store listing and what you read here agree.
Apple App Store — App Privacy
| Category | Collected | Purpose | Linked to you | Used to track you |
|---|---|---|---|---|
| Contact info — name, email, phone | Yes | App functionality | Yes | No |
| User content — item photos, catalogue and order text | Yes | App functionality | Yes | No |
| Identifiers — account, business and staff IDs | Yes | App functionality | Yes | No |
| Purchases — the transaction records your till writes | Yes | App functionality | Yes | No |
| Diagnostics — error codes, app version, scrubbed hint | Yes | App functionality, analytics | Yes | No |
| Location | No | — | — | — |
| Financial info — card numbers, bank credentials | No | — | — | — |
| Contacts, health, browsing history, advertising data | No | — | — | — |
Google Play — Data safety
| Data type | Collected | Shared | Required | Purpose |
|---|---|---|---|---|
| Personal info — name, email, phone, user IDs | Yes | No | Required | App functionality, account management |
| Photos — item images you pick | Yes | No | Optional | App functionality |
| Financial info — other financial info (your sales records) | Yes | No | Required | App functionality |
| App activity and app info — diagnostics, error logs | Yes | No | Required | App functionality, diagnostics |
| Location, contacts, calendar, messages, audio, device IDs | No | No | — | — |
16Changes to this policy
We update this page when the product changes what it does with data. The date at the top of the page always says when it last changed. If a change materially affects your rights, we will tell you in the app or by email before it takes effect, not after.
17Contact us
Questions about this policy, a request to see your data, or a request to delete it — all go to the same place, and a person reads it.
- [email protected]
- Post
- Scale, Phnom Penh, Cambodia
- Response time
- Within 30 days, and usually within one business day.
Scale · Phnom Penh, Cambodia · This policy was last updated on 11 August 2026.