PaynEat POSPrivacy policy

This app sends nothing to us

PaynEat POS is free, open-source software. Its developer runs no server the app talks to, holds no user accounts and never sees your restaurant's data. That data lives only on the server the restaurant sets up.

  • No ads
  • Nothing sent to the developer
  • No account with the developer
  • Open source

Effective 27 September 2026

Who makes the app and what this covers

This policy covers the PaynEat POS Android app (Google Play), the web app and the demo on this site. The developer is Suruch Chakrapeesirisuk, who publishes all of the code under the Apache License 2.0 at github.com/SuruchBoss/PaynEat.

The app is a tool for restaurants: staff take orders, send them to the kitchen and take payment. The restaurant that runs the PaynEat server controls that data, not the developer.

What the app never does

  • Send any data to the developer. The developer runs no server the app connects to.
  • Show ads, or include any analytics or crash-reporting tool. The one piece of third-party code that sends anything off the device is Google ML Kit in the barcode scanner (next section).
  • Ask for your location, contacts, microphone or advertising ID.
  • Sell data, or track you across other apps and websites.
  • Load fonts from the internet: every font ships inside the app.

The barcode scanner uses Google ML Kit (Android)

On Android, the barcode and scale-label scanner uses Google ML Kit to read camera frames on the device. Camera images never leave the device. When the scanner is used, ML Kit sends Google diagnostic data: device model and OS version, the app's name and version, a per-installation identifier, performance figures and error codes. It is encrypted in transit, and Google uses it to maintain and improve ML Kit as described on ML Kit's data disclosure page. The developer does not receive it.

What stays on the device

  • The language and high-contrast mode you chose.
  • The receipt printer address you set.
  • The sign-in token, name and role of the signed-in staff member, removed on sign-out.
  • Orders taken while the network was down, until they reach the restaurant's server.

All of it lives in the app's own storage on this device and is removed when the app is uninstalled.

Demo mode (the build now in testing on Google Play)

The build now in testing on Google Play runs in demo mode: the restaurant, menu, customers and orders are made up, created and kept on your device only. The app calls no server in this mode (apart from ML Kit's diagnostics above when the scanner is used, and receipts sent to a printer if you set one up yourself). Anything you type in is gone when you close or uninstall the app.

When the app is connected to a restaurant's server

Connected to the restaurant's PaynEat server (at an address the restaurant sets), the app sends data to that server only, so the restaurant can work. For example:

  • Staff usernames and passwords when signing in (the app never keeps the password on the device).
  • Orders, payments, receipts and tax invoices.
  • Loyalty members' names, phone numbers and points, if the restaurant uses loyalty.
  • Menu photos taken or picked on the device, only when an admin saves a menu item.

The restaurant decides how long this data is kept, who can see it and when it is deleted. To see or delete your data (for example your loyalty record), contact the restaurant: the developer does not have it.

A restaurant may turn on optional features on its own server, which send data to providers the restaurant chooses, not to the developer: the AI assistant (the restaurant's server sends questions and sales figures to Anthropic with the restaurant's own API key) and emailing documents (through the restaurant's mail server). Both stay off until the restaurant sets them up.

Android permissions

  • Internet — to reach the restaurant's server, and to send receipts to a printer on the restaurant's network at the address the restaurant set.
  • Camera — to scan barcodes or scale labels and to photograph menu items. Scanning happens on the device; scanned images are neither sent nor kept. A menu photo goes to the restaurant's server only when it is saved.

The camera permission is asked for only the first time you use it. You can refuse it and the rest of the app keeps working.

Security

Servers inside a restaurant usually use a plain http address on the restaurant's Wi-Fi, which is not encrypted. A server outside the restaurant should use https. Safe set-up and how to report a vulnerability are in SECURITY.md.

Children

The app is made for restaurant staff. It is not designed for children and does not knowingly collect data from children.

Changes to this policy

If the app changes how it handles data, this page is updated before that version ships and the effective date above moves. Every change is visible in this page's source file on GitHub.

Contact

Questions about this policy: bossxiii@gmail.com or GitHub Issues (please do not post personal data in Issues; they are public).