ShadowPOS LLC

Privacy Policy

Last Updated: May 7, 2026

The Gist

We are ShadowPOS LLC, the company behind the ShadowPOS point-of-sale (POS) system. Our mission is to provide retail businesses with powerful, easy-to-use software as a service (SaaS) to manage sales, inventory, and customer relationships effectively.

This Privacy Policy applies to information we collect when you use our SaaS POS system and related services (collectively, our "Services"). This policy explains how we collect, use, disclose, and safeguard your information.

This Privacy Policy is part of our Terms of Service. By using our Services, you agree to the practices described here. If you do not agree, please do not use our Services.

We may update this policy occasionally. Most changes are minor, but we will notify you of material changes by posting updates, adjusting the "Last Updated" date, and, where appropriate, sending emails or in-app notices. Continued use of the Services constitutes acceptance of the new policy.

1. Who We Are and What This Policy Covers

ShadowPOS LLC ("we," "us," or "our") provides a POS system for retail businesses.

This Privacy Policy covers how we handle information collected through our Services. It does not apply to third-party services, such as our payment processing partner GPS Pay, which have their own privacy policies.

ShadowPOS LLC does not provide legal, tax, or accounting advice.

2. Information We Collect

We only collect information when necessary—for example, to provide our Services, communicate with you, or improve functionality. We collect information:

  • Directly from you
  • Automatically through our Services
  • From outside sources

We do not knowingly collect information from children under 18.

Information You Provide to Us

Basic Account Information

Includes email, password, business name, and related setup details.

Payment and Contact Information

If you subscribe, you may provide name, card info, billing address, and contact details. We do not store full payment card numbers—those are handled securely by third-party processors (e.g., GPS Pay) in compliance with PCI DSS.

Business and Transaction Data

Information you input, such as:

  • product details
  • inventory
  • transaction records
  • customer names, emails, and purchase history

Communications

Messages, support tickets, survey responses, and feedback.

Information We Collect Automatically

Log Information

Examples: browser type, IP address, device IDs, language, referrer, timestamps, OS, mobile network details.

Usage Information

Interactions with the interface (clicks, scrolls), feature usage patterns, and performance data.

Location Information

Approximate location from your IP address.

Cookies & Similar Technologies

Used for authentication, performance, security, analytics, and ad measurement.

Types we use:

  • Essential cookies – login, core features
  • Performance cookies – analytics (e.g., Google Analytics)
  • Advertising cookies – ad measurement and campaign reporting (e.g., Google Ads and Meta Pixel)

Where required, we ask for consent before enabling optional Google and Meta cookies. We also honor Global Privacy Control signals where applicable.

Information From Other Sources

We may receive data from:

  • Payment processors (GPS Pay)
  • Third-party catalog providers (product images, descriptions, pricing)
  • Services you connect to your account

These third parties retain all rights to their data and trademarks. We do not guarantee their accuracy.

3. How We Use Your Information

We process information for legitimate business purposes, based on:

  • fulfilling our obligations
  • legal compliance
  • protecting vital interests
  • our legitimate interests
  • your consent

Why We Use Information

  • To provide and maintain our Services
  • To improve functionality, performance, and user experience
  • To analyze retention and user behavior
  • To market our Services (you may opt out)
  • To detect and prevent fraud or abuse
  • To communicate with you (alerts, updates, account notifications)
  • To anonymize and aggregate data for analytics and industry insights

We collect only what is necessary and never sell personal information.

Aggregated data is fully de-identified.

4. How We Share Your Information

We do not sell personal information. We share it only when necessary and with safeguards. Some analytics and advertising tools may be considered "sharing" under certain privacy laws; you can manage optional Google and Meta cookies through Your Privacy Choices.

We may share with:

  • Subsidiaries and contractors
  • Third-party vendors (e.g., GPS Pay, AWS, email providers)
  • Providers of third-party catalog data
  • Courts or authorities when required
  • Parties involved in protecting rights or preventing fraud
  • Buyers or successors in business transfers
  • Others, only with your consent

Aggregated or De-Identified Data

May be shared for analytics, benchmarking, or in exchange for catalog data—never in identifiable form.

5. How Long We Keep Information

Retention depends on:

  • business needs
  • account status
  • legal requirements

Typical durations:

  • Data deleted or anonymized within 30 days after termination
  • Backups retained up to 90 days
  • Financial/tax records kept 7 years

6. Security

We implement measures like:

  • encryption
  • access controls
  • regular audits
  • PCI DSS compliance for payment data

No system is 100% secure. You must protect your account with strong credentials.

If a breach occurs, we will notify you and authorities as required (e.g., within 72 hours under GDPR).

7. Choices You Have

  • Limit optional information you provide
  • Opt out of marketing communications
  • Reject optional cookies through Your Privacy Choices
  • Request account deletion

8. Your Rights

Depending on your location (GDPR, CCPA, etc.), you may have rights to:

  • Access your data
  • Correct your data
  • Delete your data
  • Request portability
  • Withdraw consent
  • Object to processing
  • Opt out of "sales" or "sharing" where those terms apply under privacy law

To exercise rights: privacy@shadowpos.com

(We respond within 30–45 days.)

If your employer controls your data, contact them first.

9. Children's Privacy

Our Services are not intended for individuals under 18. We delete data collected from minors if discovered.

10. Transferring Information

Our Services operate in the United States. If you are outside the US, your data may be transferred and stored in the US.

Safeguards (e.g., Standard Contractual Clauses) apply for EEA/UK/Swiss users.

11. Third-Party Software and Services

If you use third-party services (GPS Pay, etc.):

  • You may provide data directly to them
  • Their practices are governed by their own policies
  • We are not responsible for their actions

Links to other sites are provided for convenience only.

12. Controllers and Responsible Companies

ShadowPOS LLC is the controller of your personal information.

13. How to Reach Us

ShadowPOS LLC

8 The Green, Ste B

Dover, DE 19901

Email: privacy@shadowpos.com

We respond promptly to complaints and requests.

This policy is governed by Delaware law, consistent with our Terms of Service.