Privacy policy
The data in your POS belongs to you.
This policy is about the GeniusPos system — the customers, the staff and the sales your business puts into it. That is where the data that matters actually is, and it is worth being exact about who holds it, who can reach it, and who decides what happens to it.
Last updated: 29 August 2026.
Who we are
GeniusPos is operated by Genius POS System Sdn Bhd (201501042360 /1167681-H), 5, Tingkat 1, Lorong Alma Jaya 1/1, Taman Sri Rozhan, 14000 Bukit Mertajam, Pulau Pinang, Malaysia. You can reach us on +60 11-3527 3919 or at sales@geniuspos.com.my.
Whose data is whose
This is the part worth reading twice, because everything else follows from it. When a member gives your restaurant a phone number, they give it to your restaurant. You decided to ask for it, you decided why, and it is your business they trusted. Under Malaysia's Personal Data Protection Act 2010 that makes you the one responsible for it.
GeniusPos is the system you keep it in. We hold it on your behalf so the software can do the job you bought it for — ring up a sale, award a point, print a receipt, produce your reports. We do not decide what you collect, what you tell your customers about it, or how long you keep it.
That division is not a technicality, and it cuts both ways. It means we will not go through your customer list, and it means the questions your customers have about their own data are questions for you. What this policy can do is tell you exactly what the system is holding, so that you can answer them.
What the system holds about your customers
Most of what a POS stores is not personal data at all — menu items, stock levels, table numbers, totals. These are the parts that are, and they only exist if you switch them on.
- The customer record itself
- On Pro you can keep member and customer files — whatever details you decide to take when someone signs up. What goes in that record is your decision, not ours. Lite has no member or customer file at all, so a business running Lite holds none of this.
- Points, rewards and anything they have paid for in advance
- Reward points, loyalty tiers, gift cards and top-ups are balances attached to a named person, which is what makes them personal data rather than just numbers. They are also money owed, so they are the records a customer is most likely to ask you to check.
- What they owe you, and what you are holding for them
- Account balances and credit sit against the customer who ran them up. So does custody — a bottle kept behind the bar for a regular is a record about that person, held until the day they claim it, and it stays on your system in the meantime.
- What they ordered, and where it went
- Where a sale is tied to a member, it builds a history: what they buy, how often, and how much. That is what customer spending and item reports are, and what a member sees as their own history in the member portal. If you take deliveries or takeaway orders, the address you keep for them is part of the same record.
If you have taken the online ordering add-on, diners can also order from their own phones. What reaches the system from that is an order, the same as one typed at the counter — it does not require them to hand over anything about themselves unless you have asked them to.
What it holds about your staff
Easy to overlook, because it is collected as a side-effect of running the business rather than by asking anyone for it. It is still personal data, and it is the kind your staff have a direct interest in.
- Who did what
- Every person who works the till signs in as themselves — there is no package that limits how many accounts you can create. A name therefore sits against sales, voids, refunds, discounts and price overrides, and on Pro an action log records changes more broadly.
- When they worked
- Clock-in and clock-out tie a shift to a person, on every package.
- How they performed
- On Pro the system reports on employee performance, employee item sales and commission. This is personal data about your staff, it is the kind that affects their pay, and the same rules in this policy apply to it.
Who inside your business can reach it
You decide. Permissions are set per account, so the owner chooses which employee gets which parts of the system, and Pro go further — you can control who is allowed to open a bill and which areas an account reaches at all. A cashier can ring up a sale without being able to open the takings, read the customer list, or change a price.
This is the single most useful privacy control you have, and it is entirely in your hands. A shared login defeats all of it: if four people use one account, the system can only tell you that the account did something, and none of the records above mean what they should.
Where copies of it exist
The till keeps its own copy and works from it whether or not the internet is behaving. That copy syncs to a cloud copy, on every package, which is what stops a day's takings living on one tablet on one counter. So there is deliberately more than one copy of your data —what that means for keeping it safe is set out here.
Data also leaves the system in ordinary use, and it is worth knowing where: printed bills and invoices carry a customer's details out of the building, reports can be read and taken away by anyone you have given access to, members see their own history when they sign in to the member portal, and on Pro raw data can be exported and re-imported as a spreadsheet file. That export is your data and you are entitled to it — but a spreadsheet of your members on someone's laptop is outside every control described above, and it stays your responsibility.
If you switch on an integration — a delivery service, a payment provider, an accounting package — then by definition something has to be passed to it. Which ones apply to you depends on what you have set up, so ask us about your own configuration rather than reading a general sentence here and assuming it fits.
What we will not do with it
- We do not sell, rent or trade your data, or your customers’ data, to anyone.
- We do not use what is in your system to market to your customers. They are your customers, not a list.
- Your members are not shared with another business. A member of one brand is not a member of another, and nothing in the product pools them.
- Where you run several outlets under one business on Enterprise, members, menu and sales are shared across those outlets — because they are one business, and because you chose that setup.
- We do not change or hand over one of your customers’ records on a request that does not come from you.
What this policy does not decide for you
Because you are the one responsible for your customers' data, several things are yours to settle and cannot be settled here: what you ask your customers for, what you tell them when you ask, how long you keep it, and what happens to it if you close or sell the business.
If you have a specific requirement — from an auditor, a franchisor, a landlord, or your own policy on where records may live and for how long — ask us about your setup rather than reading between the lines. We would rather answer the real question than publish a sentence that turns out not to fit you.
If you are a diner, not a restaurant
If you are a member of a restaurant's loyalty programme and you want to know what is held about you, have it corrected, or have it deleted, ask the restaurant. They hold it, they know why they asked for it, and they are the ones who can act on it. If they need us to help them do it, we will help them.
Your rights, and asking us anything
Under Malaysia's Personal Data Protection Act 2010 you may ask us what personal data we hold about you, ask us to correct it, withdraw your consent at any time, or ask us to delete it. Email sales@geniuspos.com.my or call +60 11-3527 3919 and we will act on it. If we update this policy, the new version is posted on this page with a new date at the top.
Sending us an enquiry through this site is a separate and much smaller matter, covered by the website enquiry notice.