Privacy policy — POSMobile and POS.Terminal
Valid from 7 October 2026
This policy covers the POSMobile app for Android, iPhone and iPad, RSIStore — the software of POS.Terminal 2 — and RSI Cloud, the optional sync between them. In short: your shop's data lives on your own device. It leaves it only when you turn RSI Cloud on, and then only to our servers, under your account.
Who we are
MagicWeb.org eOOD, Sofia, Bulgaria, makes POSMobile, RSIStore and RSI Cloud and runs this website. We are the controller of the data this policy describes.
What the apps keep on your device
POSMobile and RSIStore keep the shop's data in a database on the phone or on the terminal's computer: your companies, articles and prices, promotions, customers, sales and receipts, stock and stock movements, the staff with their names and roles, and the shifts. Staff PINs are stored as salted hashes — never the PIN itself.
Nothing of this leaves the device unless you turn RSI Cloud on. The apps show no ads, run no analytics, use no third-party SDKs and sell no data.
RSI Cloud — when you turn it on
RSI Cloud is off until you sign in under Settings › Cloud and press Sync now. It then copies the shop's data — companies, articles, promotions, customers, staff (names, roles, PIN hashes), sales and their lines, vouchers, stock movements, shifts and the time clock — to our servers at magicweb.org, under your account only, so that your phone and your terminal share one shop. Nothing is synced on a timer: every sync is a press of yours.
The servers stand in the European Union (Germany). Signing the device out stops the sync; the data already in the cloud stays until you ask us to delete it (see Retention and deletion).
Your account
You sign in with your pos-systems.eu account: an e-mail address, a name and a password, kept by our identity server at magicweb.org (Keycloak). The account is created on this website.
To keep your device signed in to RSI Cloud, POSMobile keeps the account's password on the device, encrypted with a key that never leaves the phone's secure store (the Android Keystore, the iOS Keychain). It is never written to the database, the settings or a log, and signing out removes it. RSIStore keeps it in a file beside the database that only its user can read.
Permissions and why
- Bluetooth (Nearby devices) — to drive the Daisy Compact M 02 cash register. The app never uses Bluetooth to find out where you are.
- Camera — to scan barcodes. The frames are read on the phone and are never stored or sent.
- Biometrics — to unlock the app with your fingerprint or face instead of the PIN. The app only learns whether the phone recognised you.
- Notifications — so the register can ask for its daily Z report.
- Internet — for the sign-in and for RSI Cloud, when you use them.
Retention and deletion
On your device the data stays as long as the app is installed; uninstalling the app deletes it. In RSI Cloud it stays as long as your account exists. Write to the address below from the account's e-mail and within 30 days we delete your account and everything stored under it, unless a law obliges us to keep a record longer.
No third parties
We hand your data to no one. No advertising network, no analytics service and no third-party SDK is part of the apps or of the cloud. Our servers are rented in the European Union.
This website
pos-systems.eu keeps your language choice and whether you accepted the cookie notice in your browser. The demo form sends what you typed to our mailbox and nowhere else.
Contact
Questions, access to your data, a correction or a deletion: info@magicweb.org
Changes
When this policy changes, the new version appears here with a new date.