Privacy policy
Last updated 10 August 2026
Who we are
Raqam POS is provided by Raqam (Pty) Ltd, registration number 2026/602450/07, of South Africa. In this policy, we and us mean that company.
We are the responsible party for the personal information described here, which is the term the Protection of Personal Information Act uses for whoever decides why information is handled and how.
Our Information Officer is Hafiz Rahat Baig, reachable at hello@raqam.co.za. Write there about anything in this policy, including a request to see, correct or delete what we hold. If our answer does not satisfy you, the last section says where to take it.
What this policy covers
This policy covers this website, the customer portal where you manage your account, and the billing we run for your subscription. It forms part of our terms of service. Your service agreement refers to it as published from time to time rather than fixing a copy inside itself, and a copy of it as it stood on the day you signed is stored with your signature.
It does not cover what your business records inside the till software about your own customers and staff. That is yours rather than ours, and the section headed Your trading data explains the difference and who answers for what.
We sell to businesses. The service is not for children, and we do not knowingly collect information about anyone under eighteen.
When you contact us
The contact form asks for your business name, your name, your email address, your phone number, roughly how many locations you run, and whatever you write in the message. We use it to reply to you and, if you go ahead, to set you up.
Two things happen that you would not see. The address your request arrives from is counted briefly, so the form cannot be used to flood us, and that count usually clears within a day. Separately, a one way fingerprint of that address is stored on the enquiry itself. It is computed with a secret key, so it cannot be turned back into an address, and the fingerprints we keep for different purposes are computed differently so they cannot be matched to each other.
We email you about your enquiry and about your account, and that is all. We do not add you to a marketing list, we do not market to people who did not ask, and anything we do send carries a way to stop it.
When you have an account
An account holds your business name, your contact name, your email address, your phone number, your billing address, your status with us, and a reference linking you to your installation of the till software. It also holds the branch and till counts your subscription is charged on.
Some of it you cannot read from the portal yourself: a notes field our staff use for working notes about your account, and the internal references that tie your account to your installation. Ask us what any of it says and we will tell you.
Billing adds your invoices and the record of what was charged and when, including whatever a bank told us about a payment that failed. Each invoice freezes its own copy of the name and address it was issued to, so a customer who moves premises cannot download last year's invoice and find themselves somewhere they never were.
For your card we hold a record of when you authorised us and its date, which version of the consent wording you were shown, and a token from our payment provider that charges that one card and nothing else. We do not hold your card number, and for a card added through our current provider not even its last digits: no brand, no expiry, no PIN, no code on the back. The card itself lives with the provider. Where a card was added through a previous provider, its brand and last digits may remain on the record until that card is removed.
We do not collect identity numbers, and we do not collect any of the categories the Act treats as special: health, beliefs, politics, race, biometrics or criminal history.
When you sign the agreement
Accepting the service agreement records the name you typed, the capacity you signed in, the date and time, which version of the document you were shown, a fingerprint of the address you signed from, and your browser's identification string.
It also stores a complete copy of the document exactly as it appeared to you, together with a digest of that copy, and a copy of this privacy policy as it stood on the day.
The copies are the point. A version number on its own is a pointer at a file that could later change; a stored copy is evidence of what you actually read. It is kept for as long as the agreement could matter, and while it is the only record of an agreement between us it is not something we can delete on request.
Signing in, and keeping the service safe
Signing in sets a cookie. There are two kinds and both are strictly necessary: one for customers signing in to the portal, issued by the service that handles our customer logins, and one for our own staff signing in to the operator console, which expires after twelve hours. They carry a session, not a profile.
There are no advertising cookies, no analytics and no third party tracking on this site. That is why nothing has asked you to accept anything. Nothing here follows you to another website and nothing measures you on anyone else's behalf.
Our servers keep short lived technical logs. The login pages and the contact form count requests by address so they cannot be attacked by guesswork, and those counts clear in about a day.
Your browser also reports to us when a page loads something our security policy does not expect. Those reports are written to a log and stored nowhere.
What you have to give us
Nothing is needed to read this site.
To use the contact form we need your name and a way to reply. Without those we cannot answer you.
To hold an account we need your business details and a billing address, because an invoice missing them is not a valid document, and we need a card, because a subscription is charged to one. To accept the agreement you have to type your name, which is what makes the signature yours.
None of this is collected because a law compels you to hand it over. It is collected because the service cannot be provided without it, and you are free to decide not to.
Where the law requires us to keep records
Some of what we hold stays even if you ask us to remove everything else, because South African law requires it.
Company law requires a company to keep its accounting records, and the tax rules require the records supporting a return. Between them those cover your invoices and what was paid against each one. The Electronic Communications and Transactions Act is why an electronic signature is worth keeping in a form that can be produced later.
Nothing compels us to keep a contact form enquiry, which is why that is the one thing here with an end date.
Who else holds it
Four companies help us run this service. Each is bound by its agreement with us to protect what it holds and not to use it for its own purposes.
Supabase hosts the database and handles customer sign in. It holds your account, your invoices and your signed agreement.
Vercel hosts and serves this website and runs the code behind it, including storage for images our staff upload.
Payfast is our payment provider. It captures your card on its own page, holds the card itself, and charges the token it gave us when we ask. It receives your name and your email address so it can recognise you.
Resend sends our email: invitations, password resets and payment notices. It receives the address we are writing to and what we write. Invoices are not emailed; you download them from your account area.
We also give information to our professional advisers where we need advice, and to anyone the law requires. We do not sell your personal information, and we do not share it for anybody else's marketing.
Where it is kept, and when it leaves South Africa
Personal information described in this policy is stored and processed outside South Africa. We would rather say that plainly than leave you to work it out.
The database and the sign in service run in the European Union, in Ireland, and the code behind this site runs in the same place. The pages themselves are served from wherever is nearest to you, which is what keeps the site quick.
The Act permits this where the receiving country has a law upholding principles for handling personal information that are substantially similar to our own, and that restricts passing it on again. The European Union's General Data Protection Regulation does both, and that is the ground we rely on.
If you hold an account there is a second and separate ground: taking your payment and running your subscription cannot be done without the transfer, so it is also necessary in order to carry out our agreement with you. That ground does not reach the contact form, which is why the first one is given first.
Our payment provider and our email provider each process outside South Africa too, and not necessarily in the European Union. Where any part of this reaches a country with no such law, the protection is our written agreement with that supplier, which binds it to look after the information and restricts it passing it on.
How we protect it
Specifics, rather than an assurance that we are careful.
Card numbers never reach our systems. Capture happens on our payment provider's own page, and what we keep is a token that charges one card and nothing else.
Staff passwords are stored as a slow one way hash, deliberately expensive to test, at six hundred thousand rounds. A staff session is a signed cookie tied to our own domain that we can revoke from the server without waiting for it to expire.
Where we keep any record of the address a request came from, it is a one way fingerprint rather than the address itself.
The database refuses the keys a browser holds, so customer facing code cannot read another customer's row even if it asked for it. Payment notifications are checked against a signature before they are believed. The site declares to your browser what a page is expected to load, and we are told when a page departs from it. Every action our staff take on a customer account is written to a trail with no edit route and no delete route, deliberately, because a trail somebody can tidy is not a trail.
If personal information is ever reached by somebody who should not have it, we will tell the Information Regulator and, where the Act requires it, we will tell you, and we will say what happened rather than the least we can get away with.
Your trading data, and the people in it
Two different roles, and which one applies decides who answers to whom.
For your account and billing details, we are the responsible party, and this policy is ours.
For what your business records in the till software, your products, your sales, and the details of your own customers and staff, you are the responsible party and we are your operator. We hold it to run the software for you. We process it on your instructions, we do not use it for our own purposes, we do not sell it, and we do not decide what you collect or how long you keep it. The law also requires us to keep it secure and to tell you if somebody reaches it who should not have, and we will.
Deciding what to record about your customers and your staff, telling them about it, and having a lawful basis for holding it, are yours. If one of your customers writes to us about their information we cannot answer them, because it is not ours to answer. We will send them back to you and help you find whatever you need.
Where your trading data is kept. The till software runs on its own separate system, and that system is hosted in Singapore. It is not the database this website and your billing use, which is the one described further up. We are telling you because you are the responsible party for that information: whether you are content for it to be processed outside South Africa, and telling your own customers and staff about it, are decisions only you can make, and you cannot make them without knowing where it is. Our agreement with you binds us to protect it wherever it is held.
This section describes the split. The terms that govern it are in your service agreement, and nothing here changes them.
How long we keep it
Contact enquiries are deleted twenty four months after they arrive. An enquiry is also emailed to us when it arrives, so a copy sits in our own mailbox until it is cleared out there.
Account and billing records are kept while you are a customer, and afterwards for the periods company law and the tax rules require of accounting records, which is at least five years.
Your signed agreement is kept for as long as it could be needed to show what was agreed.
The record of what our staff did on your account is kept indefinitely. There is no route anywhere in this service to edit it or delete it, and nothing prunes it, which is the entire point of keeping it.
The counts our login pages and contact form keep usually clear within a day.
Your trading data is dealt with in our terms, which commit us to keeping it for ninety days after a subscription ends so you can still ask for a copy.
What this means for a deletion request. We delete what we are free to delete. An issued invoice, a signed agreement and the staff trail are not among those, and once an invoice has been issued the database itself refuses to remove the account behind it. That is deliberate: a tax record that disappears when somebody asks is not a tax record. Ask us and we will tell you exactly what we can remove and what we cannot, and why.
Your rights
You can ask what we hold about you and receive a copy. You can ask us to correct anything wrong or out of date. You can ask us to delete what we are not required to keep. You can object to a particular use, and where you gave consent, you can withdraw it.
We will ask you to confirm who you are before we act. Handing your information to somebody claiming to be you would be the worse failure of the two.
We answer within thirty days. Where we have to refuse part of a request, we say which part and why rather than going quiet.
There is also a formal route under the Promotion of Access to Information Act, which has its own form and may carry a prescribed fee. Writing to our Information Officer is quicker and costs nothing, so start there.
If you want to complain
Write to our Information Officer at hello@raqam.co.za. We acknowledge within two business days and answer within ten.
If that does not resolve it, you can complain to the regulator directly:
Information Regulator (South Africa) JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 PO Box 31533, Braamfontein, Johannesburg, 2017 POPIAComplaints@inforegulator.org.za 010 023 5200
You do not have to come to us first. We would prefer it, because most things are quicker to fix than to adjudicate, but the choice is yours and the right is not ours to condition.
Changes to this policy
We update this policy as the service changes, and the date at the top says when it last changed. Where a change materially affects you we will tell account holders rather than rely on you noticing.
Changing this policy does not change your service agreement. That changes only when we issue a new version and ask you to accept it. When you accept one, a copy of this policy as it stood that day is stored with your signature, so what you were told is a matter of record rather than of memory.