← Back home

Privacy Policy — TikalPOS

Last updated: June 1, 2026

This Privacy Policy describes how Servicios Avanzados en Tecnología, S.A., operator of the TikalPOS platform, handles information in relation to the merchants that subscribe to the service. TikalPOS is a point-of-sale (POS) platform for businesses and includes a web admin application, a tablet point-of-sale application operated by merchant staff, and a local print middleware.

1. Who we are and scope

TikalPOS is operated by Servicios Avanzados en Tecnología, S.A., a Guatemalan corporation. This policy applies to merchants ("franchises") that use the platform and to their authorized staff. TikalPOS and TikalLoyalty (the loyalty app for end-customers) are separate services that interact with each other; each has its own privacy policy.

For any privacy question, contact us at soporte@tikalpos.com.

2. Our role: controller and processor

For the merchant account data and its staff data, we act as the data controller. For the data a merchant captures and processes about its own end-customers through the platform (orders, customers, loyalty transactions, tax data), we act as a processor handling that data on the merchant’s behalf and per its instructions; the merchant is the controller toward its customers.

3. Information we handle

  • Merchant account data: business name, tax ID (NIT) and tax data, address, contact details, and subscription plan.
  • Authorized staff: names, emails, roles, and credentials (PIN or password) to operate the web admin app and the tablet app.
  • Enrolled devices: identifiers of enrolled tablets, enrollment status, device tokens, and operational telemetry (network, battery, and performance state) used for diagnostics and reliability.
  • Merchant operational data: orders, menu/products, customers (guests), loyalty transactions, and reservations — including those generated from the tablet app at the location, even when created offline and synced later.
  • Tax data (FEL): NIT and data needed to issue electronic invoices through the merchant’s certifier.
  • Payment data: payments are currently recorded manually; integration with processors (e.g., Stripe) is planned.

4. How we use the information

We use the information to:

  • Provide the service through the web app and the tablet app (POS operation, menu, orders, loyalty, reservations, reports).
  • Enroll and manage the merchant’s devices (tablets) and maintain offline-first synchronization.
  • Bill the subscription and calculate transaction overages per plan.
  • Provide technical support and diagnose issues using device telemetry.
  • Maintain security, integrity, and data isolation between merchants.

5. Tablet app (point of sale)

Merchant staff operate the point of sale from the tablet app at the location. Regarding this app:

  • The merchant enrolls its tablets; each enrolled device is tied to the merchant account and can be un-enrolled by the merchant.
  • The app can operate without an internet connection and sync orders and changes when connectivity returns (offline-first synchronization).
  • The app can scan the redemption QR codes generated by the customer’s TikalLoyalty app to apply loyalty rewards at the point of sale.
  • We collect operational device telemetry (network, battery, state) solely for diagnostics, reliability, and support — not to profile individuals.

6. The merchant’s end-customer data

When a merchant captures data about its end-customers (for example, a customer’s name or email, or a tax ID for an invoice), we process it as a processor on the merchant’s behalf, only to provide the service. The merchant is responsible for having a legal basis and informing its customers about that processing.

7. Interaction with TikalLoyalty

End-customers may use the TikalLoyalty app to earn and redeem points at merchants. When a customer redeems a reward at the location, the tablet app validates the QR code against the platform to apply it. TikalLoyalty has its own privacy policy aimed at end-customers.

8. Who we share with / sub-processors

We rely on providers that process data on our behalf:

  • DigitalOcean: hosting of the infrastructure and database.
  • SendGrid (Twilio): transactional email delivery (receipts, verifications, operational notifications).
  • Apple, Google, and Expo: distribution of the mobile apps and notification delivery.
  • FEL certifiers (INFILE, DIGIFACT, GUATEFACTURAS): issuance of electronic invoices when the merchant requests them.

We do not sell merchant data or their end-customers’ data.

9. FEL and tax data

When a merchant issues electronic invoices, we transmit the necessary data to the FEL certifier the merchant uses. The relationship with the certifier and tax compliance are the merchant’s responsibility.

10. Data retention

We keep data while the merchant account is active or as needed to provide the service and meet legal and accounting obligations. On termination, we delete or anonymize data as described in the Terms, except what the law requires us to retain.

11. Security

We apply reasonable technical and organizational measures, including data isolation between merchants (multi-tenant), encryption in transit, secure credential storage, and role-based access controls.

12. Rights

The merchant may access, correct, export, or request deletion of its data. To exercise these rights, contact us at soporte@tikalpos.com. Requests from the merchant’s end-customers are channeled through the responsible merchant.

13. International transfers

Some of our providers process data outside Guatemala, mainly in the United States. By using the platform, the merchant accepts these transfers necessary to provide the service.

14. Changes to this policy

We may update this policy. We will post the current version on this page with its update date. Continued use of the service after a change means you accept it.

15. Contact

For any question about this Privacy Policy, contact us at soporte@tikalpos.com.