Privacy & Policy

1. Introduction

This Privacy Policy explains how SEEN Pty Ltd (ACN 621 324 721) trading as JRpos (“SEEN”, “we”, “us” or “our”), the company that builds and operates the JRpos cloud point-of-sale platform, collects, uses, holds, discloses and protects personal information in connection with:

  • our websites at https://jrposnow.com and https://jrpos.app (together, the “Sites”);
  • the JRpos web application and the JRpos mobile applications for iOS and Android (together, the “Platform”);
  • our sales, onboarding, data migration, demonstration, support and marketing activities (including our blog, newsletter, ROI calculator, plan wizard, interactive tour and business intelligence tools); and
  • any other interaction you have with us (together with the Sites and the Platform, the “Services”).

We are committed to handling personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where we process personal data of individuals located in the European Economic Area (EEA), the United Kingdom or other jurisdictions with comparable data protection laws, we also aim to comply with the EU General Data Protection Regulation (GDPR) and the UK GDPR to the extent they apply to us.

By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, please do not use the Services.

2. Our Role: Controller and Processor

JRpos is a business-to-business platform used by retailers, restaurants, cafes, pharmacies, supermarkets and other merchants (“Merchants”). It is important to understand the two different roles we play:

2.1 SEEN as a controller

We act as the data controller (or the equivalent under applicable law) for personal information relating to: visitors to our Sites; prospective customers who book demos, use our plan wizard, calculators or business intelligence tools, or contact us; Merchant account holders and their authorised users (names, logins, billing details); and recipients of our marketing communications.

2.2 SEEN as a processor

When a Merchant uses the Platform to record sales, manage inventory, run loyalty programmes, maintain customer due lists, deliver receipts (including via WhatsApp) or store details about the Merchant’s own customers, suppliers or staff, the Merchant is the controller of that information and we act as a processor (service provider) on the Merchant’s instructions. In that case, the Merchant’s own privacy policy governs how that information is collected and used, and individuals should direct privacy requests to the relevant Merchant in the first instance. We will assist Merchants in responding to such requests as required by law and our agreements.

3. Information We Collect

3.1 Information you provide to us

  • Account and identity information: name, business name, role or job title, email address, phone number, password and login credentials, language and currency preferences.
  • Billing information: billing contact details, billing address, subscription plan, ABN or tax identifiers, and payment method details (processed by our third-party payment providers — we do not store full card numbers on our systems).
  • Enquiry and demo information: information you submit through contact forms, demo bookings, the plan wizard, migration requests, the ROI calculator or live chat, including details about your business size, industry and current POS system.
  • Uploaded documents and data: files you upload to the Services, for example merchant payment statements submitted to the AI Payment Statement Analyzer, or product catalogues, supplier lists, customer databases, opening balances and due lists provided for the “Upload My Data” migration service.
  • Marketing preferences: newsletter subscriptions and communication preferences.
  • Support communications: correspondence with our support team, including via email and WhatsApp, and any information you choose to provide in those communications.

3.2 Information collected automatically

  • Usage data: pages viewed, features used, session duration, clickstream data, referral source and interactions with the interactive tour and other Site tools.
  • Device and technical data: IP address, browser type and version, operating system, device identifiers, screen resolution, time zone and language settings.
  • Platform logs: authentication events, transaction and synchronisation logs, error reports and diagnostic information, including data generated while the Platform operates in offline mode and later synchronises.
  • Cookies and similar technologies: as described in Section 10 (Cookies) below.

3.3 Information from third parties

We may receive information about you from payment processors (payment confirmations and fraud signals), analytics and advertising providers, social media platforms when you interact with our official pages (Facebook, Instagram, X, LinkedIn, YouTube), publicly available sources, and business partners or resellers who refer you to us.

3.4 Merchant Data processed on behalf of Merchants

Depending on how a Merchant configures the Platform, Merchant Data may include end-customer names, contact details, purchase histories, loyalty balances, outstanding amounts (due lists), subscription products, and staff details used for role-based access control. We process this information solely to provide the Services to the Merchant.

4. How We Use Personal Information

We collect, hold and use personal information for the following purposes:

  • to create and administer accounts, authenticate users and provide the Platform and its features (sales and POS, inventory, reporting, loyalty, receipts and related modules);
  • to process subscriptions, billing, GST where applicable, refunds and account management;
  • to deliver requested services such as demos, migrations, onboarding, training and the monthly live Zoom demonstrations;
  • to operate AI-assisted features (see Section 5), including AI product search, predictive analytics, forecasting, and the analysis of uploaded payment statements;
  • to deliver receipts and notifications through channels selected by the Merchant, including WhatsApp;
  • to provide customer and technical support and to respond to enquiries and complaints;
  • to monitor, secure, maintain and improve the Services, including debugging, load management, service analytics and the development of new features;
  • to send service communications (such as maintenance notices, security alerts and changes to terms) and, with your consent or as otherwise permitted by law, marketing communications such as our newsletter and product updates;
  • to detect, investigate and prevent fraud, misuse, security incidents and other unlawful activity;
  • to comply with our legal and regulatory obligations, and to establish, exercise or defend legal claims; and
  • for other purposes described to you at the time of collection or to which you consent.

4.1 Legal bases (GDPR/UK GDPR)

Where the GDPR or UK GDPR applies, we rely on the following legal bases: performance of a contract (providing the Services you or your organisation have signed up for); legitimate interests (operating, securing and improving the Services, and B2B marketing, balanced against your rights); consent (for example, non-essential cookies and email marketing where required); and compliance with legal obligations (tax, accounting and regulatory requirements).

5. AI and Automated Features

The Platform includes AI-assisted features such as AI product search, predictive reorder and stock forecasting, customer segmentation, revenue and growth forecasting, the Business Health Check and the AI Payment Statement Analyzer. In relation to these features:

  • outputs are generated to assist decision-making; they are informational and do not constitute financial, legal or professional advice;
  • we do not use these features to make decisions that produce legal or similarly significant effects about individuals without human involvement;
  • documents you upload for analysis (such as merchant payment statements) are processed to deliver the requested analysis, and are retained and secured in accordance with this Policy; and
  • we may use aggregated and de-identified usage information to evaluate and improve model and feature performance. We do not sell personal information for these purposes.

6. How We Disclose Personal Information

We may disclose personal information to:

  • Service providers and subprocessors: cloud hosting and infrastructure providers, payment processors, messaging providers (including WhatsApp/Meta for receipt delivery and support where you use that channel), email and communication tools, video conferencing providers (for demos), analytics providers and customer support tooling, in each case only to the extent needed to provide their services to us and subject to appropriate contractual protections.
  • Our related bodies corporate and personnel: on a need-to-know basis for the purposes described in this Policy.
  • Professional advisers: lawyers, accountants, auditors and insurers where reasonably necessary.
  • Business transfers: a purchaser or prospective purchaser in connection with a sale, merger, financing or reorganisation of our business, subject to confidentiality obligations.
  • Regulators and law enforcement: where required or authorised by law, court order or enforceable governmental request, or where necessary to protect our rights, users or the public.

We do not sell personal information.

7. Overseas Transfers

JRpos serves Merchants in multiple countries and supports 47+ languages and multi-currency operation. Personal information may be stored and processed in Australia and in other countries where we or our service providers maintain facilities. Where we transfer personal information overseas, we take reasonable steps to ensure the recipient handles it consistently with the APPs and, where the GDPR/UK GDPR applies, we rely on appropriate safeguards such as adequacy decisions or standard contractual clauses. You can contact us for more information about the safeguards applying to specific transfers.

8. Security

We take reasonable technical and organisational measures to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. These measures include encryption of data in transit, access controls and role-based permissions (including Manager PIN approvals within the Platform), network and application security monitoring, backup and recovery processes, and staff confidentiality obligations. No system is completely secure; you are responsible for keeping your login credentials confidential and for the security of devices on which you use the Platform. Please notify us immediately at support@JRposnow.com if you suspect unauthorised access to your account.

9. Data Retention

We retain personal information for as long as needed to provide the Services, comply with our legal obligations (for example, taxation and financial record-keeping requirements), resolve disputes and enforce our agreements. In general:

  • account and billing records are retained for the life of the account plus the period required by applicable law (typically at least seven years for financial records in Australia);
  • Merchant Data is retained while the Merchant’s subscription is active and for a limited wind-down period after termination to allow export, after which it is deleted or de-identified in accordance with our agreements and applicable law;
  • uploaded analysis documents (such as payment statements) are retained only as long as needed to provide the analysis and for reasonable audit purposes; and
  • marketing data is retained until you unsubscribe or ask us to delete it.

10. Cookies and Similar Technologies

10.1 What are cookies?

Cookies are small text files placed on your device when you visit a website. We also use similar technologies such as local storage, pixels, tags and software development kits (SDKs) in our mobile applications. Together, these are referred to as “cookies” in this Policy. The Platform additionally uses local storage on your device to enable offline operation of the POS, with data synchronised to the cloud when connectivity is restored.

10.2 Types of cookies we use

CategoryPurposeExamples
Strictly necessaryRequired for the Sites and Platform to function: authentication, session management, security, load balancing, remembering your cookie choices, and offline data storage.Session/login cookies, CSRF tokens, cookie-consent record, offline cache
Functional / preferencesRemember your settings such as language (47+ supported), currency, region and display preferences.Language and locale cookies, UI preference storage
Analytics / performanceHelp us understand how visitors use the Sites and Platform (pages visited, features used, errors) so we can improve them.First- and third-party analytics cookies and identifiers
Marketing / advertisingMeasure the effectiveness of campaigns, and deliver or cap relevant advertising, including via social media platforms.Ad platform pixels and conversion tags

10.3 Managing cookies

  • Where required by law, non-essential cookies are only set with your consent, which you can withdraw at any time via our cookie banner or preference centre.
  • Most browsers let you block or delete cookies through their settings. Blocking strictly necessary cookies may prevent parts of the Sites or Platform from working, including login and offline operation.
  • You can opt out of certain analytics and advertising cookies through the relevant provider’s opt-out tools and industry opt-out pages available in your region.
  • Our Sites currently respond to consent choices made through our banner; they may not respond to browser “Do Not Track” signals.

10.4 Third-party cookies and embedded content

Some pages embed third-party content, such as YouTube demo videos, social media links and messaging widgets. Those third parties may set their own cookies and collect information in accordance with their own privacy policies, which we encourage you to review.

11. Marketing Communications

If you subscribe to our newsletter or otherwise agree to receive marketing, we may send you insights, product updates and offers by email or other channels you have chosen. Every marketing email includes an unsubscribe link, and you may opt out at any time by using that link or contacting us at support@JRposnow.com. Opting out of marketing does not affect service communications that are necessary for the operation of your account.

12. Your Privacy Rights

12.1 All users

You may request access to, or correction of, the personal information we hold about you at any time by contacting us using the details in Section 16. We will respond within a reasonable period and in accordance with applicable law. We may need to verify your identity before acting on a request.

12.2 Additional rights under the GDPR/UK GDPR

If you are in the EEA or the UK, you may also have the right to: erasure of your personal data; restriction of processing; data portability; objection to processing based on legitimate interests or for direct marketing; withdrawal of consent at any time (without affecting prior processing); and the right to lodge a complaint with your local supervisory authority.

12.3 Requests relating to Merchant Data

If your personal information is held in the Platform because you are a customer, supplier or staff member of one of our Merchants, please direct your request to that Merchant, who controls that data. We will support the Merchant in fulfilling your request as required by our agreement with them and applicable law.

13. Children

The Services are designed for businesses and are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, please contact us and we will take steps to delete it.

14. Data Breach Response

We maintain a data breach response process. If a data breach occurs that is likely to result in serious harm to affected individuals, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth), and will comply with any equivalent notification obligations in other applicable jurisdictions (including the 72-hour supervisory authority notification under the GDPR where it applies).

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies or legal requirements. The current version will always be posted at https://jrposnow.com/privacy with its effective date. For material changes, we will provide reasonable notice, such as by email or an in-Platform notice. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.

16. Contact Us and Complaints

Privacy Officer — SEEN Pty Ltd (JRpos)

If you have a privacy concern or complaint, please contact our Privacy Officer first. We will acknowledge your complaint promptly and aim to resolve it within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or, if you are in the EEA or UK, to your local data protection authority.

Stay in the loop.

Join 5,000+ founders receiving weekly insights on retail scaling and operations.

READY TO BUILD SOMETHING DIFFERENT?

Join thousands of retailers who have made the switch.

START YOUR 30-DAY FREE TRIAL TODAY. NO CREDIT CARD REQUIRED.