Privacy Policy
Last updated: 29 August 2026 · This page is the English original. 이 페이지는 영문 원문입니다.
This policy covers the goldenkeypos.com website and the SimplePOS point-of-sale system supplied by GOLDEN KEY TPS. It says what we hold, why we hold it, who else sees it and how to have it removed.
1. Two different roles
We handle information in two distinct capacities, and the difference decides who you should ask about what.
- As controller — for what you give us directly through this website, and for the accounts of shops that use SimplePOS. This policy governs it.
- As processor — for the transaction and customer records a shop creates on its own POS terminals. That data belongs to the shop. We hold it on the shop’s behalf, act on the shop’s instructions, and do not use it for our own purposes. If you are a shopper asking about a purchase, ask the shop; we will forward a request we cannot answer.
2. What we collect
From this website
- Your name, and your shop or business name if you give one.
- Your mobile number and, if you give one, your email address.
- Whatever you write in the message field, and the number of POS terminals on a quote request.
- Whether you ticked either text-message consent, the exact wording shown beside the box at that moment, and the date, time and IP address the submission came from. This is retained as evidence of consent.
From the point-of-sale system
- Sales, refunds, voids and settlements — what was sold, at what price, when, and how it was paid for.
- Customer records a shop chooses to keep: phone number, and optionally name, address, postal code and birthday, along with a points balance and the two message consents.
- A log of what each POS did with money and with the card terminal, kept for six months.
- Which build each POS is running, and when it last spoke to the server.
3. What we never hold
- No card numbers. The card terminal talks to the card network itself; SimplePOS is not in that conversation. Terminals mask their own numbers, and the POS log is scanned for anything resembling a card number and masked to its last four digits — on the tablet before it is sent, and again on the server on arrival.
- No card PINs, magnetic-stripe data or CVV, at any point.
- No location data, no contacts, no device identifiers taken from the tablet.
4. Why we hold it
- To answer a request you sent us, and to set up and support a shop’s system.
- To send the text messages you consented to, described on the SMS Terms page.
- To operate the POS: to price an order correctly, to reconcile card batches, and to let a shop find a receipt or make a refund.
- To keep the service secure and working — the POS log exists so that a payment which went wrong can be traced.
- To meet tax, accounting and card-scheme record-keeping obligations.
5. Text messages
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All other categories of information are excluded from any text-message originator opt-in data and consent; this information will not be shared with any third parties.
Consent to account and transaction messages and consent to marketing messages are recorded separately, and each can be withdrawn on its own. Replying STOP to any message withdraws both immediately. Full details, sample messages and frequency are on the SMS Terms page.
6. Who else sees it
We do not sell personal information, and we do not share it for anyone else’s marketing. It reaches others only as follows:
- Messaging providers — to deliver the text messages you asked for. They act strictly as processors and may not use the numbers for their own purposes.
- Payment processors and card networks — through the terminal, which conducts that exchange itself.
- Hosting — the server the shop’s data runs on, whether hosted by us or by the shop.
- The shop — where the record is one the shop created on its own POS.
- Law — where we are legally required to disclose, and only to the extent required.
7. How long we keep it
- Website submissions: for as long as needed to answer them, and afterwards for as long as the consent record has to be produceable — 5 years from the date consent was given or withdrawn, whichever is later.
- POS log: 6 months, swept daily.
- Sales and settlements: for as long as the shop’s account is open, and afterwards for the period tax and card-scheme rules require.
- Customer records: for as long as the shop keeps them. A customer who has never bought can be deleted outright; one who has is deactivated instead, so their past receipts stay intact.
8. Security
- Traffic to the website and the API is over HTTPS.
- Each POS carries its own key, bound to a single installation. A key that turns up on a second device is flagged, and any key can be revoked on its own without touching the others.
- Administrator passwords are stored as PBKDF2-HMAC-SHA256 hashes with a per-password salt, never in a form they can be read back from.
- Each shop’s data is separated at the database layer, on every read and on every write, rather than by each query remembering to ask.
9. Your rights
You may ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, or withdraw a consent you gave. Write to info@goldenkeypos.com. We answer within 30 days. Where the record belongs to a shop rather than to us, we will tell you which shop to ask and pass the request on.
We will not discriminate against you for exercising any of these rights.
10. Children
The service is for businesses. It is not directed at children under 13 and we do not knowingly collect their information. If you believe we have, write to us and we will delete it.
11. Cookies
The public pages of this website set no cookies and carry no analytics or advertising trackers. The administrator site sets one session cookie, which is what keeps an administrator signed in; it is essential to that function and is not used for tracking. Your language choice is kept in your own browser’s local storage and is never sent to us.
12. Changes
We may update this policy. The date at the top is when it last changed.
13. Contact
GOLDEN KEY TPS · info@goldenkeypos.com · +1 (888) 992-1715 · 2730 N. Berkeley Lake Rd. NW, Suite B100, Duluth, GA 30096, USA