1.Who we are
Petra is developed and operated by Al-Muntaser Smart Solutions (شركة المنتصر للحلول الذكية), Amman, Jordan. In this policy, “we” and “us” mean Al-Muntaser Smart Solutions.
For any privacy question or request, write to info@almountaser.com. You can also call us on +962 77 284 6660 (Jordan) or +49 1515 8886836 (Germany).
2.Who is responsible for which data
- Your shop’s business data. Sales, products, stock, customers, suppliers, employees and everything else a shop enters into Petra belong to that shop. The shop decides what to record and why, so the shop is the controller of this data. We process it only on the shop’s behalf, to provide the service, and we do not use it for our own purposes.
- Account, licence and device data. For the data we need to run the shop’s account, licence, subscription and support, and for this website, we are the controller.
If you are a customer or an employee of a shop that uses Petra and you want to see, correct or delete your data, please contact that shop first. We will help the shop answer your request.
3.What this policy covers
This policy covers the Petra till for Windows; the Petra ERP app for iPhone and Android (the phone till, the waiter and kitchen screens and the owner pages); the web till in the browser; the owner portal; our cloud servers; and the website almountaser.com.
4.Account and licence data
To create and run a shop account we store:
- the shop’s name, phone number, e-mail address, country, tax number, business address and logo, and its branches;
- activation codes, the licence, the subscription (plan, dates, limits, price) and the list of devices activated for the shop;
- the sign-in names of owners and staff, and the password hashes of portal and app users (see section 6);
- an audit log of account actions, with the IP address and the browser or app type used.
With its regular licence check, each till also reports the business name, tax number, address and logo it prints on receipts, so that the account and its devices stay consistent.
5.Device identifiers
A Petra licence is bound to the devices it is activated on. For this:
- Windows till: when a till is activated, it sends a fingerprint (a one-way hash) together with the hardware values it is built from: the Windows machine ID, the computer name, a network adapter (MAC) address, the motherboard or BIOS serial number and the disk serial number, plus the operating system and app version. We store these values with the device record, its public IP address and the time it was last seen. Later licence checks send only the fingerprint hash.
- iPhone and Android: the app creates a random install ID. On Android it also reads the system Android ID; on iPhone it creates a random ID that is kept in the device Keychain. The Android ID and the Keychain ID never leave the phone: only one-way hashes and the random install ID are sent.
We use these identifiers only to activate and protect the licence, to show the owner which devices use the account, and to prevent misuse. We do not use them for advertising or to track you across other apps.
6.Employee accounts, PINs and passwords
- Employee PINs are stored on the till as salted one-way hashes (PBKDF2), not as readable numbers. Older tills that still held a readable PIN convert it into a hash automatically when the app starts.
- When a shop has several devices, a PIN travels between them only as that hash, additionally encrypted with a key that belongs to the shop. Readable PINs are never sent.
- Passwords for the owner portal and the app (user name and password) are stored on our servers as bcrypt hashes.
- Petra records which employee carried out each sale, discount, refund and other action and, if the shop uses these features, attendance, shifts and commissions.
7.Business records the shop enters
Petra stores the records a shop creates while working: sales and receipts, items and payments, products and stock, suppliers and purchases, expenses, shifts and cash, reservations, tables and kitchen orders.
About the shop’s own customers, Petra stores only what the shop enters, for example name, phone number, e-mail, address, tax number, birthday, credit (account) balance, loyalty points and notes. Marketing contact and WhatsApp contact are switched off for every new customer until the shop records that customer’s consent.
For card payments, the card is read by the payment provider’s terminal or payment page. Petra stores only the card brand, the last 4 digits, the authorisation code, terminal and transaction references and the provider’s response. Petra never receives the full card number or the security code.
For online orders placed through a shop’s QR menu, or received from delivery platforms, we store the guest’s name, phone number, delivery address, location (if the guest shares it) and IP address with the order. These personal fields are anonymised automatically after 180 days by default; the shop can choose a different period.
8.Where your data is stored
- Offline edition: the shop’s business data stays on the shop’s own devices. The till still contacts our servers for activation and licence checks, for problem reports (section 11) and, by default, to send the daily sales totals of each device (amounts and counts, no customer data).
- Hybrid and Online editions: business data is also copied to our servers, so that the owner can see reports from anywhere and several devices and branches stay in sync. This includes sales, payments, customers, suppliers, employees, attendance, reservations, loyalty, credit accounts and the audit log. It does not include employee PINs, the employee HR file (national ID, bank account, social security number, salary), tax security device (TSE) data, e-invoicing credentials, card terminal keys or practice sales.
- Germany: the German edition (Petra Kasse) does not copy business data to our servers.
- Backups: the Windows till makes a daily backup on the same computer (the last 14 are kept) and in any folder the owner adds, such as a USB drive. These copies are not encrypted, so the computer itself should be protected.
Our servers are currently hosted by DigitalOcean in New York, United States. Data sent to our cloud is therefore processed in the United States. When personal data from the European Union is transferred there, we rely on the safeguards the law requires for such transfers.
9.Phone permissions
The Petra ERP app asks for a permission only when a feature needs it. You can refuse or withdraw a permission at any time in the phone’s settings; only that feature then stops working.
- Location: used only if the shop has turned on the “Sales location check” feature for the phone till or the web till. The app reads the location once, at the moment of a sale, to check that the sale takes place at the shop. It never tracks the location in the background. The coordinates, their accuracy and the result are stored with the order and, in the Hybrid and Online editions, copied to our servers. The owner can also use the current location once to place the shop on a map. The Windows till never reads the location.
- Camera: used only to scan barcodes and QR codes (products, payments, pairing a device). The image is read in memory; it is not saved or uploaded.
- Photos: the app saves or shares a receipt only when you ask it to. When you choose a logo or a product photo from your gallery, that image is uploaded to the shop’s account.
- Microphone: used only when the owner records a spoken question in “Ask your data” (section 10).
- Local network: used so that the waiter and kitchen screens can talk to the shop’s main till over the shop’s own Wi-Fi.
- Notifications: if you allow notifications, we store a notification token for your device (Firebase Cloud Messaging on Android, or the browser’s push service) together with your language and notification preferences. The token is removed when you sign out. Notifications on iPhone are not active yet.
10.Optional features that share data with other services
These features are off unless the shop turns them on. When a shop uses one of them, the data below goes to the service named:
- “Ask your data” (owner portal): the owner’s question and up to 60 rows of the matching report, which can include the names and phone numbers of customers or employees, are sent to OpenAI or Anthropic to write the answer. A spoken question is sent to OpenAI to be turned into text; we do not keep the recording. Questions and answers are kept in the shop’s history.
- WhatsApp: messages are sent through the shop’s own WhatsApp Business account at 360dialog, and only to customers who agreed to WhatsApp contact. A message can contain the customer’s phone number and name, the shop and branch, and the order number. A digital receipt is stored on our server and opened through a link that is hard to guess. Without this add-on, the app can simply open the phone’s share menu, which involves no server.
- E-invoicing in Jordan (JoFotara): the till sends each invoice directly to the Income and Sales Tax Department: the seller’s tax number, the invoice lines and, when entered, the buyer’s name, phone number, tax number and city.
- Tax security device in Germany (TSE): sales are signed by a local TSE or, if the shop chooses it, by the fiskaly cloud TSE. Only transaction data such as amounts is sent, no customer data. The DSFinV-K tax export is a file created locally.
- Card payments: the payment provider the shop connects (for example SumUp) processes the card under its own privacy policy.
- Delivery platforms (HubRise): if a restaurant connects HubRise, orders (including the guest’s name, phone number and address) and menu data are exchanged with it.
- Maps, location and connection checks: map images come from OpenStreetMap. The Windows till can look up the shop’s approximate position from its internet address at ip-api.com, and our server uses the same service to check the country of an online order. To check the internet connection during activation, the till contacts common services (Cloudflare, Google, ipify). These services see the device’s IP address.
- Fonts: the owner portal (also inside the app) and the Windows till load some fonts from Google Fonts, which sees the device’s IP address. The phone till and this website do not load Google Fonts.
- E-mail: we send alerts, support replies and documents such as purchase orders to suppliers through an e-mail (SMTP) provider.
11.Problem reports
To fix errors quickly, the apps send automatic problem reports to our servers. A report contains the error, the app version, the type of business and the device identifier. E-mail addresses, long numbers and IDs are removed before sending. This is on by default and can be turned off in the settings. Reports are deleted 90 days after the error was last seen.
When you use “Report a problem”, we receive your description, technical details about the device and the app, recent error lines and, if you attach them, a screenshot or pictures. These are kept with the support ticket.
12.This website
- The website sets one cookie, site_lang, to remember your language for one year. It uses no analytics, advertising or social media trackers, and it loads no content from other companies.
- When you send the contact form, we store your name, phone number, e-mail (if given), your business details and message, the language, an estimated country, your IP address and your browser type. We use them only to reply to you and to prepare an offer.
- The owner portal sets one sign-in cookie, petra_portal, only to keep you signed in.
13.No selling, no advertising
We do not sell personal data and we do not share it for advertising. The Petra apps contain no advertising or analytics tools from other companies (no Google Analytics, Facebook Pixel, Firebase Analytics, Sentry or similar).
14.How long we keep data
- Account, licence and device data is kept while the account is active and afterwards for as long as tax and accounting law requires.
- Business data on our servers is kept while the shop’s account is active. Receipts and tax records must be kept for the period the law sets (in Germany, for example, up to 10 years).
- Some data is deleted automatically: problem reports after 90 days, the notification history after 30 days and queued notifications after 7 days. The personal fields of online orders are anonymised after 180 days by default.
- Other data, such as contact form messages, digital receipts and support tickets, is not yet deleted automatically. We delete or anonymise it on request.
- The shop can erase a customer’s personal data at any time under Settings, Advanced, Privacy tools: the name, phone number, e-mail, address and notes are removed, and only the receipts required by tax law remain. In Germany the shop can also have inactive customers anonymised automatically.
15.Security
- All connections between the apps and our servers are encrypted with HTTPS. Inside the shop, the waiter and kitchen screens talk to the main till over the shop’s own network using signed requests.
- PINs and passwords are stored only as one-way hashes, and the licence stored on each device is encrypted.
- Each shop sees only its own data. Inside the shop, access follows the roles and permissions the owner sets, and important actions are recorded in an audit log.
- Only authorised staff have access to our servers.
No system is perfectly secure. If a security incident affects your personal data, we will inform you and the authorities as the law requires.
16.Your rights
You can ask us at any time to show you the personal data we hold about you, to correct it, to delete it, to give you a copy in a common format, or to restrict its use, and you can object to its use. Where we rely on your consent (for example for notifications), you can withdraw it at any time. Write to info@almountaser.com; we reply within one month.
If you live in the European Union (including Germany): we process data to provide the service you signed up for (Art. 6(1)(b) GDPR), to meet legal duties such as tax law (Art. 6(1)(c) GDPR), for our legitimate interest in a secure, working service, for example licence protection and problem reports (Art. 6(1)(f) GDPR), and with your consent where we ask for it (Art. 6(1)(a) GDPR). You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the country where you live or work.
17.Deleting your account
The app does not have a button to delete a shop account yet. To have your account and the data on our servers deleted, write to info@almountaser.com from the e-mail address registered on the account, or call us. We will confirm your identity, delete or anonymise the data, and tell you what we must keep by law (for example tax records) and for how long. Data stored only on your own devices stays there until you delete it or uninstall the app.
An owner can remove an employee’s access to the app in the owner portal at any time.
18.Children
Petra is a business tool for shops and their staff. It is not directed at children, and we do not knowingly collect data from children under 16.
19.Changes to this policy
This is a preliminary version. We will update this policy when Petra changes; the date at the top always shows the current version. If a change is important, we will also inform shop owners in the app or by e-mail.
