PDPA · Data Protection

Privacy Policy

Last updated: 1 September 2026 · Applies to kanipos.com and {merchant}.kanipos.com

KaniPOS Singapore is operated by Testing Pte Ltd. We process business and customer data to provide cloud POS, restaurant billing, and online shop services for merchants in Singapore.

1. Data we collect

2. Purpose of collection

We use data to operate your tenant, generate GST tax invoices, send receipts, provide support, prevent fraud, and meet legal record-keeping obligations (GST records: 7 years).

3. Cross-border hosting

Production servers are hosted with Contabo GmbH, Germany (EU). Data may be transferred outside Singapore. We use encryption in transit (HTTPS/TLS), access controls, daily backups (14-day retention), and tenant database isolation as reasonable protection measures under the PDPA.

4. Payment processing

PayNow QR codes are generated for your UEN; payment confirmation is manual unless you connect a PSP. We do not store card PINs or full bank login credentials.

5. Your rights (PDPA)

You may request access to, correction of, or withdrawal of consent for personal data we hold about you or your customers (subject to legal retention). Email our Data Protection Officer (see below).

6. Retention

7. Breach notification

We assess suspected breaches within 72 hours. If criteria under the PDPA are met, we will notify the PDPC and affected individuals without undue delay.

8. Data Protection Officer

DPO: Testing Pte Ltd · [email protected] · Tel +65 1234 5678

9. Contact

General enquiries: [email protected] · Terms of Service