Privacy Policy
This Privacy Policy explains what information Innobrains Technologies ("Innobrains", "we", "us" or "our") collects when you use MartPOS, our billing, stock and khata software for kiryana and general stores, grocery stores and mini marts. It also explains how we use and protect that information and the choices you have. It applies to the MartPOS website, the MartPOS Windows app (the till and the store server), MartPOS Cloud and its owner portal, the Cloud edition and the Offline edition (together, the "Service"), and should be read with our Terms & Conditions.
1. Who is responsible for your information
- Your account and billing information: Innobrains Technologies decides how this is used and is responsible for it.
- Your shop's records: the shop decides what is recorded about its customers, staff, suppliers and stock. On the Cloud edition we store and process the records your store PCs send, on the shop's behalf and only to provide the Service.
2. Information we collect
Information you give us
- Account: your name, business name, city, mobile number and email address, and the edition you chose. Your password is stored only as a one-way hash, never in readable form. If you turn on two-step sign-in, its secret and your recovery codes are stored encrypted.
- People you invite: the name, email address and role of each person you invite to the owner portal.
- Billing: your plan, invoices, the payment method and transaction reference you give, and the proof of payment you upload, such as a screenshot or a bank receipt.
- Alerts: if you choose alert emails or texts in the owner portal, your choices (which alerts, quiet hours and language) and the mobile number you confirm for texts.
- Communications: messages you send us through the contact form (your name, email address, optional phone number and business, the topic and your message), support tickets with any files you attach, and email.
Information collected automatically
- Store PCs and licences: for each PC paired with your account, the name it was given, its branch's name and code, when it was paired and last seen, and the licence grants it fetched. We use these to run your licence and to show you which PCs are connected.
- Updates: when MartPOS looks for an update, its version and a random identifier of that installation, which does not identify your business, and afterwards whether the update installed.
- Security log: sensitive actions on your account (such as pairing codes created, PCs revoked, password resets and two-step sign-in changes) with the time, IP address and browser. While you are signed in, your session also records your IP address and browser.
- Trial checks: to keep to one trial per business, mobile number and email address, the IP address a business signed up from, and its mobile number and email address in a standard form.
- This website: see section 10.
3. What your store PCs send
MartPOS keeps your shop's records on your own store PC. What the store PC sends to MartPOS Cloud depends on the edition.
- Cloud edition (and an Offline licence while its cloud add-on runs): the store PC sends the records it posts, so that the owner portal can show them to you and the people you invite. These are sales, returns and voids with their items, prices, discounts, tax and ways of payment; purchases, supplier returns and supplier payments; stock and its movements, by place (such as the shop floor and the godown); items, prices and barcodes; customer and purchase orders; expenses (with their category, payee, reference and notes), cash and bank movements and advances; shifts; and customers' and suppliers' names and khata balances.
- Customers' details: a customer's mobile number reaches MartPOS Cloud only in masked form, with most of its digits hidden, and with a code that lets the portal match the same customer across your branches. The full mobile number, CNIC, address and notes of a customer never leave the store PC.
- Staff, alerts and settings (Cloud edition): the staff list (each person's name, user name, role, whether the account is active and when they last signed in); the alerts the store PC shows, such as low stock, near expiry and customers over their credit limit; and the shop's settings, such as the business name, address and phone, the receipt settings, the NTN and the FBR POS settings. Staff passwords and PINs, and the FBR access token, never leave the store PC.
- Changes from the owner portal: new items, prices and settings you make in the owner portal are sent to the store PC, which applies them with its own checks.
- Offline edition: the store PC is paired once to activate it (sending its branch's name and code and the PC's name), and then checks its licence and looks for updates when it is online. It sends no business records, crash reports or backups to MartPOS Cloud.
- Copies of backups on MartPOS Cloud (Cloud edition, or the cloud add-on; off until the owner switches it on): each copy is encrypted on the store PC with the owner's backup password before it is sent. The password, and the key made from it, never leave the store PC, so we cannot open the copies. We can read only the label on the outside of each file: the business and branch, the date, the backup's label, its size and checksum, and when it was uploaded. If the backup password is lost, no one can open the copies, including us.
- Crash reports. When MartPOS hits a problem it did not expect, the PC notes what went wrong in the program: the MartPOS, Windows and .NET versions, the screen, the error and where in the code it happened, and how often. Customer and supplier names, phone numbers, addresses, passwords, PINs, tokens and pairing codes are taken out on the PC before anything is kept. A store PC that syncs with MartPOS Cloud sends these reports to the MartPOS team only while the owner allows it (Settings › System & updates, "Send crash reports to the MartPOS team"; on unless the owner turns it off). On the Offline edition without the cloud add-on, they stay on the store PC.
- Your shop's records stay on your store PC as well; MartPOS Cloud does not replace them.
4. How we use information
- To provide the Service: signing you in; storing and showing the records your store PCs send; sending the changes you make in the owner portal to your store PCs; keeping copies of backups where you switch them on; delivering licences and updates; and sending the alerts you choose.
- To manage your account: reviewing new accounts, running trials, invoicing, verifying payments, managing licences and paired PCs, and handling refunds.
- To support you: answering questions and solving problems. Where needed, this may include looking at your account with your knowledge.
- To protect the Service: security monitoring, and preventing fraud, trial misuse and licence sharing.
- To communicate: sending service emails, such as password resets, invitations, replies to your messages, and notices about your account and important changes. We do not send marketing messages without your agreement.
- To improve MartPOS: using crash reports, from which customer details are removed before they leave your PC, and the errors our own servers record, from which customer details and secrets are removed.
- To meet legal obligations: for example tax and accounting record keeping, and lawful requests from authorities.
We do not sell personal information, and we never use your shop's records for advertising.
5. Your customers', staff and suppliers' information
When your shop records information about its own customers, staff or suppliers, the shop decides what is recorded and why. The shop is responsible for having a lawful basis to do so and for telling those people where required. We use such information only to provide the Service to your shop. We never contact your customers or suppliers, and we never share their information for anyone else's use.
6. Where your information is stored
- On your store PC: in both editions, the shop's records are kept on the shop's own main PC, which you control. MartPOS takes backups on that PC; keeping a copy somewhere else is up to you.
- MartPOS Cloud: what your store PCs send, and your account and billing information, are stored on servers under our control, run by Innobrains. Inside the database, each business's records are kept separate from every other business's, and database rules enforce this.
- Offline edition: your records stay on your own computer. Only the pairing, licence checks and update checks reach us.
- The service providers in section 7 may process information in Pakistan or in other countries. Wherever your information is processed, we protect it as this policy describes.
7. Who we share information with
- Service providers: a content delivery and security service that carries traffic between you and our servers, an email provider that delivers our emails, and an SMS provider that delivers texts. They receive only what they need to provide their service to us.
- Alert texts and emails: only if a member of your business chooses them in the owner portal. A text goes through our SMS provider (SendPK) with the member's mobile number, the shop's name, the alert's words (for example an item that is low on stock) and a link; so does the code that confirms the number. Alert emails, password resets and invitations go through our email provider.
- The Federal Board of Revenue: only if you switch on FBR POS integration. Your store PC then sends each sale and return to FBR directly, through FBR's online system or FBR's Fiscal Component: the invoice details FBR requires (such as the invoice number, date and time, items, quantities, prices, tax, PCT codes and way of payment) and, for a bill to a named customer, the buyer's details on it (such as the name, NTN or CNIC and phone number, where you recorded them).
- Authorities: when the law, a court or a competent authority requires it, or to protect the rights and safety of our customers, the public or us.
- A successor business: if MartPOS or Innobrains is transferred to another business, your information may be transferred with it. It remains protected by this policy.
8. Access by our team
Only authorised Innobrains staff can access account information. They do so to provide support, verify payments, keep the Service secure or meet legal obligations. Access is limited by role, two-step sign-in is required for our own administrators, and what our staff do to an account is recorded.
9. How we protect information
- Encryption in transit: connections to the website and MartPOS Cloud use encrypted HTTPS. Extra tills reach the store PC over the shop network through an encrypted connection, after pairing with a one-time code.
- Sign-in protection: passwords are hashed, and two-step sign-in is available for owners and the people they invite. Staff passwords and PINs are stored on the store PC only as hashes.
- Separation and permissions: each business's data is kept separate, and each person in the owner portal and on the till has a role that limits what they can see and do.
- Signed licences and updates: licences and updates are signed, so a store PC accepts only a genuine licence and installs only a genuine MartPOS update.
- Encrypted backups: once the owner sets a backup password, backups on the store PC, and any copies on MartPOS Cloud, are encrypted with it.
No system is perfectly secure. If we learn of a security incident affecting your information, we will tell you without undue delay and explain what we are doing about it.
10. This website and cookies
- No trackers: the website uses no analytics, advertising or social media scripts, and loads no fonts or scripts from other companies. It can load Google Analytics only if we switch it on in its settings; it is off, and this policy will say so before it is ever switched on.
- Cookies: a session cookie and a security token that protects forms, both needed for the contact form and for signing in; and, only if you tick "Keep me signed in on this computer", a cookie that keeps you signed in. Pages that only show content are sent without cookies.
- Videos: if a page shows a video, nothing is loaded from YouTube or Vimeo until you press play; from then on, that service's own privacy terms apply.
- Crawlers: for automated crawlers that name themselves (search engines, AI assistants, link previews), we count which public pages they read each day, by the name in their user-agent. Nothing is stored about people's visits.
- Downloads: we count how many times the MartPOS installer is downloaded, without recording who downloaded it.
- Server logs: like any website, our servers and the content delivery service in front of them may record technical details of each request, such as the IP address, the time and the address asked for, to keep the Service running and secure.
- Contact form: with your message we keep your IP address and browser description, to answer you and to stop abuse.
11. How long we keep information
- While you have an account: account information and the records your store PCs sent are kept while your account exists, including after a trial or plan ends, so that you never lose them.
- Copies of backups: MartPOS Cloud keeps as many copies as your store PC's backup settings ask for, up to 30 per branch and none older than a year, within the space your business has.
- After a deletion request: when you ask us to close your account, we delete your account and its records in MartPOS Cloud within 30 days. We keep only what the law requires, such as invoices and payment records for tax and accounting, and the mobile number and email address a trial was used with, only to prevent repeated trials. Copies in any backups of our servers are removed as those backups are replaced.
- Crash reports: these are deleted 90 days after the problem was last seen.
- Messages: contact form messages and support tickets are kept for as long as we need them to help you and for our records. You can ask us to delete them.
- On your store PC: the records stored on your own computer stay under your control.
12. Your rights and choices
You can view, print and export your records in MartPOS on your store PC at any time. You can change or stop alert emails and texts in the owner portal (each alert email also has a link to stop them), switch off crash reports and copies of backups on MartPOS Cloud in the store PC's settings, and remove a person you invited from the owner portal. You may also ask us:
- for a copy of the personal information we hold about you;
- to correct information that is wrong;
- to delete your account and its records in MartPOS Cloud, subject to section 11.
To make a request, use Support in the owner portal or our contact form, giving the email address registered on your account. We may need to verify your identity, and we reply within 30 days. If your request concerns a shop's records about you, for example as its customer, please contact that shop. We will help the shop respond.
13. Children
The Service is meant for businesses and is not directed at children. We do not knowingly collect children's information for our own use. Information a shop records about its customers is handled as described in section 5.
14. Changes to this policy
We may update this policy from time to time. The date of the latest update is shown below, and we will tell you in the owner portal or by email about important changes.
15. Contact
For any question or request about your information: Innobrains Technologies, Jhang, Punjab, Pakistan.
Write to us through our contact form, or through Support in the owner portal if you have an account.
Last updated 5 October 2026. Questions? Contact us.