Privacy Policy
Last updated 12 September 2026. This policy explains what Korda Technologies (“we”) does with personal data in BillFlow POS, the point-of-sale and billing service at billing.korda.dev.
1. Two kinds of data, two different roles
The distinction below decides who answers a request about a given record, so it comes first rather than buried at the end.
- The shop’s records. Sales, customers, stock, prices and staff activity belong to the business that uses the service. That business decides what is collected and why; we hold and process it on their instructions, and we do not use it for our own purposes.
- Account and operational data. The staff accounts that sign in, the terminals that are paired, and the server logs that keep the service running are ours to decide about, and this policy is the notice for them.
If you bought something in a shop that uses BillFlow POS and want your details corrected or erased, ask the shop — they hold the record, and we act on their instruction. We will help them do it.
2. What we collect
Staff accounts
- A username, display name and role (cashier, manager or admin).
- A password, stored only as a scrypt hash — never in a form we or anyone else can read back.
- An optional manager PIN, stored as a salted PBKDF2 hash so a till can check it while offline.
- An optional email address, used for account alerts and for Google sign-in matching.
- Failed sign-in counts and lockout times, so a run of wrong passwords locks an account instead of being guessed through.
Sign in with Google
Optional, and only when a member of staff chooses it. See section 4 for exactly what Google gives us and what we do with it.
Shop records held on the business’s behalf
- Customers: name, phone number, email address and notes, where the shop records them.
- Telegram receipt delivery: a customer’s Telegram chat identifier, stored only after that customer links it themselves by sending a one-time code to the bot, and removable at any time.
- Bills and invoices: items, quantities, prices, taxes, payment method, the customer name and phone captured on the bill, and which member of staff made the sale.
- Stock, vendors, purchase orders, goods receipts, price history and standing orders.
Terminals
- A record per paired till: terminal code, device name, browser user-agent string, last-seen time and the IP address it last connected from.
- The pairing token is stored only as a SHA-256 hash. The token itself is shown once, at pairing, and never again.
Logs and diagnostics
- Server logs record the time, request path, response status, a request identifier and — where the caller was signed in — the user and device identifier. Passwords, tokens and secrets are removed before a log line is written.
- Web-server access logs record IP addresses and user-agent strings.
- If a page crashes in a browser, the app may send us the error message and the page it happened on, so that faults are fixed rather than merely endured. It is capped per page load and carries no form contents.
We use no advertising trackers and no third-party analytics. The only cookie the application sets is the session cookie that keeps you signed in; it is signed, HTTP-only, and lasts 30 days.
3. What we use it for
- Running the service: signing people in, billing, syncing terminals, printing and sending receipts.
- Security: rate limiting, account lockouts, and investigating suspicious sign-ins.
- Keeping it up: monitoring, error diagnosis, capacity and backups.
- Support, when a shop asks us to look at something.
- Meeting legal obligations, such as tax record-keeping duties that apply to the shop’s invoices.
We do not sell personal data, we do not share it for advertising, and we do not use any of it to train machine-learning models.
4. Sign in with Google
When a member of staff chooses Continue with Google, we ask Google only for the openid, email and profile scopes. From those we receive the Google account’s email address, whether Google has verified it, the display name, the profile picture URL and a stable account identifier.
- The email address is used for one thing: matching the Google account to a staff account that an administrator has already created in this service. If no active staff account has that address, sign-in is refused. Signing in with Google never creates an account and never grants a role.
- The display name and picture are used only to show who is signed in.
- We do not receive, ask for, or have any access to your Gmail, Drive, Contacts, Calendar or any other Google service.
- Google user data is not sold, not transferred to anyone except the infrastructure providers in section 5 that host the service, not used for advertising, and not used to train any model. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- You can disconnect this at any time at myaccount.google.com/permissions. Your staff account and its password sign-in are unaffected.
5. Who else touches the data
We use a small number of service providers. Each gets only what its job needs, and none of them may use it for their own purposes.
| Provider | What for | What reaches them |
|---|---|---|
| Hetzner Online GmbH (Germany) | Servers and database hosting | Everything, at rest on the server |
| Cloudflare | DNS, TLS and protection from attack | Traffic in transit, IP addresses |
| Grafana Cloud | Log and metric storage for diagnosis | Server logs: identifiers, paths, status codes |
| Telegram | Sending a receipt to a customer who asked for one | The receipt and the customer’s chat identifier |
| Google Cloud (Vertex AI) | Reading a vendor’s bill or catalogue when a shop uploads one to import it | The uploaded document only |
| healthchecks.io, Atlassian Statuspage | Uptime monitoring and the public status page | No personal data |
We will also disclose data where the law requires it, and we would tell the affected business unless we were forbidden from doing so. If the service were ever sold or merged, the data would move with it and this policy would continue to apply until you were given notice of a new one.
6. Where it is kept
The application and its database run on a server operated by Hetzner Online GmbH, Falkenstein, Germany. A business in India using this service is therefore storing its records outside India, and the providers above may process data in other countries too. We rely on our contracts with those providers, and on their own safeguards, to keep the protection travelling with the data.
7. How long we keep it
- Bills and invoices are kept for as long as the shop needs them for its tax and accounting obligations. They are the shop’s statutory records, not ours to discard.
- Staff accounts are deactivated, never deleted, because every bill and audit entry names who did the work; erasing the account would falsify the record. A deactivated account cannot sign in.
- Customer records are kept until the shop deletes them. A Telegram link can be undone by the customer or the shop at any time.
- Logs are kept for a limited period for diagnosis and security, then discarded.
8. How it is protected
- All traffic is encrypted in transit with HTTPS.
- Passwords are scrypt-hashed and PINs are PBKDF2-hashed; neither is recoverable.
- Session cookies are signed, HTTP-only, and rejected once altered or expired.
- Access follows the role on the account, checked both at the edge and again at every route.
- Repeated failed sign-ins lock the account and are reported to the shop’s administrators.
- Terminals authenticate with a paired token that is stored only as a hash.
No system is perfectly secure. If a breach affects personal data, we will notify the affected business without undue delay and support them in their own notification duties.
9. Your choices and rights
Depending on where you are, you may have the right to see the personal data held about you, correct it, have it deleted, object to some uses of it, or receive a copy. Staff of a business using the service, and customers of that business, should raise the request with that business first — it holds the record. Write to us at privacy@korda.dev if the request concerns data we decide about, or if the business needs our help to answer it. We answer within the period the applicable law allows, and free of charge for a reasonable request.
10. Children
The service is a tool for businesses and is not directed at children. We do not knowingly collect personal data from a child, and we will delete it if we discover we have.
11. Changes
We will update this page when the service changes, and we will change the date at the top when we do. Where a change materially affects how personal data is handled, we will tell the businesses using the service rather than relying on you to notice.
12. Contact
Korda Technologies · privacy@korda.dev
Registered address available on request from the contact address below.
See also our Terms of Service.