Skip to content
MegalEPOS
Privacy Policy Account Deletion

Megal Software Limited

Megal EPOS Privacy Policy

Effective date: 18 August 2026

This privacy policy explains how Megal Software Limited ("Megal Software", "we", "us" or "our") handles information when you use the Megal EPOS Android or Windows application, Megal Back Office, our licensing services, website, support and related services (together, the "Services"). Megal EPOS is a business point-of-sale service and is not intended for children.

1. Who we are

Megal Software Limited is a company registered in England and Wales under company number 17078983. Our registered office is 25 Reynolds Road, Stoke-On-Trent, United Kingdom, ST6 7AU. For privacy questions or requests, email info@megalsoftware.com.

2. Information handled by the Services

Account and licence information

We collect the billing email address you enter, licence code, trial and subscription status, agreement acceptance records, till name and business location label. We also receive platform and app version, licence-check events, IP address, user-agent information and a derived device fingerprint used to bind a licence to a till and prevent trial or licence abuse. On Android, that fingerprint is derived from the Android ID and basic device build information and is transmitted as a one-way hash rather than the original Android ID.

Point-of-sale and Back Office information

Most till data is stored locally on the device. If Back Office synchronisation is enabled, the Services receive the business data needed to provide it, which can include sales and refund records, products and line items, tender types and amounts, transaction references, open-order or table information, customer names entered on an order, staff names and numbers, attendance records, stock records and movements, till status, layout and configuration data, and printer configuration. Your organisation controls the information entered into these fields and is responsible for telling its customers and staff how it uses their information.

Hosted online-ordering information

When a customer uses a Megal EPOS hosted ordering page, we process the order contents, name, email address, phone number, customer or delivery address, fulfilment instructions, transaction status and references needed to submit, deliver and reconcile the order for the relevant business. The checkout separately records whether the customer affirmatively chose promotional email from that outlet or from Megal EPOS, together with the wording version and time. Neither promotional choice is required to order, and withdrawn choices are retained only as suppression evidence so they are not accidentally re-enabled or mailed.

Payment-provider information

Megal EPOS can connect to SumUp for card-reader setup and payment processing. SumUp may receive merchant, reader, transaction, Bluetooth and location-permission information needed to provide those features. Megal EPOS stores payment status and transaction references but is not designed to receive or store full payment-card numbers or card security codes. Licence subscriptions purchased outside the Google Play edition are processed by PayPal; PayPal handles the payment credentials and provides us with subscription identifiers, status, dates and amounts.

Bluetooth, location and local network access

The Android app requests foreground Bluetooth and location permissions only when a user chooses SumUp card-reader features, so the SumUp SDK can discover and connect to nearby readers. Megal Software does not use device location for advertising and does not send GPS coordinates to its own licensing or Back Office servers. The app can also discover and connect to receipt or kitchen printers on the user's local network or over Bluetooth or USB. Printer addresses and settings are normally stored on the till and may be included in Back Office configuration when synchronisation is enabled.

Support and security information

If you contact us, we handle the information in your message and any diagnostic information you choose to provide. Our servers may also create security and operational logs containing timestamps, IP addresses, request metadata, error details and administrative actions.

3. How we use information

  • to create, activate, secure and administer trials, licences and Back Office access;
  • to synchronise the till with Back Office and provide reports, configuration and support;
  • to connect to supported card readers and printers when the user requests those features;
  • to process and reconcile subscription status and transaction results;
  • to submit and administer hosted collection or delivery orders and send essential order or payment messages;
  • to send promotional email only where the recipient made the corresponding separate choice, and to honour withdrawals and suppression records;
  • to prevent fraud, repeated trials, licence sharing, misuse and security incidents;
  • to diagnose faults, answer support requests and improve reliability; and
  • to meet legal, tax, accounting and contractual obligations and establish or defend legal claims.

We do not sell personal information and we do not use it for third-party advertising.

4. When information is shared

We share information only as needed to provide or protect the Services, including with:

  • SumUp, when a business configures or uses SumUp reader, hosted checkout or payment features;
  • PayPal, for licence subscriptions purchased through our website or direct-download edition;
  • hosting, email, infrastructure and technical service providers acting for us under appropriate obligations;
  • professional advisers, regulators, courts or law-enforcement bodies where reasonably necessary or legally required; and
  • a buyer or successor in connection with a genuine corporate transaction, subject to appropriate notice and safeguards.

5. Legal bases

Where UK or European data-protection law applies, we process information to perform our contract with the customer, for our legitimate interests in operating and securing a business service, to comply with legal obligations, and with consent where consent is the appropriate basis. A business using Megal EPOS is generally responsible for the customer and staff information that it chooses to enter, while Megal Software processes that information to provide the Services.

Promotional email choices are based on consent. Outlet and Megal EPOS promotional choices are separate, optional and may be withdrawn independently. Withdrawing promotional email does not stop essential transactional messages about an order or payment.

6. Security

Network requests to Megal Software and supported payment-provider APIs use HTTPS. The Android app stores the local licence cache using encryption backed by the Android Keystore where available, and Back Office passwords are stored as password hashes. Access is restricted according to operational need. No system is completely secure, so customers should also protect their devices, administrator codes, email accounts, networks and exports.

7. Retention

We keep account, licence, subscription, support and synced Back Office information for as long as needed to provide the Services and administer the customer relationship. Information may then be retained where reasonably necessary for tax, accounting, contract, fraud-prevention, security or legal purposes, normally for no longer than six years after the relevant relationship or transaction unless a longer period is required by law or an unresolved claim. A minimal derived device or trial-abuse record may be retained after account deletion to prevent repeated trials or licence fraud. Backups are overwritten through the normal backup cycle.

Customers can clear synced Back Office sales data from the Back Office retention settings. Data stored only on a till remains on that device until an authorised user deletes or resets it, or the app is uninstalled and its app data is removed. Businesses may need to retain sales and tax records under applicable law before deleting them.

Hosted order and customer contact records follow the relevant business's documented retention duties. Removing a customer membership from one outlet stops that outlet's promotional consent but does not itself erase accounting records or records belonging to another outlet. Where erasure applies, contact details can be deleted or anonymised while legally required transaction records and minimal email-suppression evidence may be retained. Backup copies expire through the normal backup cycle.

8. Your choices and rights

You may ask for access to, correction of, restriction of, objection to, portability of or deletion of personal information where applicable. You may also complain to the UK Information Commissioner's Office or another competent regulator. To make a request, email info@megalsoftware.com. We may need to verify that you control the relevant billing email or business account.

To withdraw promotional email choices, request a secure one-use link on the email-preferences page. The page can withdraw outlet choices independently from the Megal EPOS choice and never subscribes an address to new email.

To request deletion of a Megal EPOS account and associated server-side data, use our Megal EPOS account-deletion page. Some records may be retained for the legitimate reasons described above.

9. International processing

Some providers may process information outside the United Kingdom. Where required, we use an applicable legal transfer mechanism and take reasonable steps to protect the information. Payment providers process information under their own terms and privacy notices.

10. Changes to this policy

We may update this policy when the Services, providers or legal requirements change. We will publish the updated policy here and change the effective date. Material changes may also be communicated through the Services or to the account email where appropriate.

Contact

Megal Software Limited
25 Reynolds Road
Stoke-On-Trent
United Kingdom
ST6 7AU

info@megalsoftware.com

Copyright © Megal Software Limited 2026.
Privacy Policy Account Deletion