Legal
Privacy policy.
What we hold, and why.
Written from the code rather than from a template. It says what NexusTill actually collects, names every outside company that touches it, and is equally clear about what we do not do.
Last updated 28 July 2026
Who we are, and what this covers
NexusTill is point-of-sale and business-management software for shops, restaurants, wholesalers and pharmacies. You use it in a web browser and through the NexusTill Android app. This policy covers both, and it covers our marketing site.
It is written in plain English and it describes the product as it is built today, not as it might be one day. If we add something that changes what we collect, this page changes first.
Two kinds of data, treated differently
There is personal data about you, and there is personal data about your customers. They are not the same thing and we do not treat them the same way.
- Your data. You, your business and your staff. You give it to us to open and run an account, we decide how it is handled, and this policy governs it.
- Your customers data. The names, phone numbers, addresses, notes and customer-credit balances you record about the people who buy from you. That belongs to your business, not to us. We store and process it only so the product works for you. We do not use it for our own purposes, we do not contact your customers except when the product does it on your instruction, and we never sell it.
What we collect
Only what the product needs. Grouped by where it comes from:
Your account and business. When you register: your first name, last name, email address, an optional username, an optional phone number, and a password. For the business: business name, trade name, business type, business email and phone, and your country, currency, language and timezone. If you upload a shop logo, we store the image.
Staff you add. Their name, email, phone and role. There is also an optional profile your business may choose to fill in — job title, national ID number, date of birth, gender, address and city, an emergency contact name and phone, hire date and a short bio. Every one of those is optional and the product works with all of them blank. Only enter what your business genuinely needs to hold.
Customers and suppliers you record. Name, and optionally email, phone, tax number, addresses and free-text notes. For suppliers we also store named contact people. This is data about other people, entered by you.
What you do in the product. Sales, quick and tax invoices, returns, payments taken at the till, purchase orders, stock movements, customer-credit balances, expenses and accounting entries. This is your business record, and keeping it is the entire point of the product.
Branch details. The address of each shop, including map coordinates and a Google Maps link if you type one in. This describes your premises and you enter it by hand. Neither app ever reads your device location.
Sign-in records. The date and time you last signed in. Access tokens for the web and the app are stored as one-way hashes and expire after seven days without use.
An audit trail. When someone in your business creates, changes or deletes a sale, an invoice, a return, a product, a customer, a payment, a stock adjustment or a stock movement, we record who did it, what changed, the time, the IP address, and the browser or app the device reported. Each entry is chained to the one before it so the trail cannot be quietly edited — that is what makes it worth having when there is a dispute about who voided a sale. Signing in and out is not recorded in this trail.
Messages the product sends. When NexusTill emails a receipt, a customer-credit reminder, a password reset or an account notice, we keep a log of the recipient address, the subject and the content, so you can show that a reminder was actually sent.
AI assistant conversations. If your plan includes the assistant and you use it, your questions and its answers are stored so the conversation has a history. You can delete a conversation, and deleting it is permanent.
Subscription payments. Because you pay us by bank transfer, we store the payment method you used, the transaction reference you give us, and the screenshot of the transfer if you upload one. The screenshot is deleted as soon as we approve or reject the payment. We never see or store card numbers, because there is no card payment anywhere in NexusTill.
What the Android app keeps on your phone
Three things, and this is the complete list:
- Your sign-in token, held in the Android Keystore — the operating system protected store — so you are not asked for your password every time. It is deleted when you sign out.
- Sales you made while offline, waiting to sync. These sit in the app private storage as ordinary app data, not separately encrypted by us, and contain product IDs, quantities, prices and payment amounts, plus the customer reference number from your own records if you attached one. They contain no customer names, no phone numbers and no card details. Each one is removed once it has synced.
- Whether you chose light or dark mode.
The app keeps no local copy of your products, customers, staff or reports. Everything else is fetched from your account when you open a screen. Uninstalling the app removes all three of the above from the phone.
What we do not collect, and do not do
This part matters as much as the last one, and every line has been checked against the code:
- The Android app contains no analytics, no tracking and no crash-reporting SDK. We do not measure how you use the app.
- There is no advertising in NexusTill, no ad network, and we neither read nor use your advertising ID.
- We do not use your device location. The app requests no location permission and contains no location library.
- We do not access your camera, microphone, contacts, photos or files, and nothing from any of them is sent to us.
- The app sends no push notifications and asks for no notification permission. The notifications you see inside NexusTill are messages fetched from your own account.
- NexusTill does not send SMS or WhatsApp messages. Email is the only channel that leaves our servers.
- We do not collect card numbers, CVV codes or bank login credentials anywhere in the product.
- We do not sell, rent or trade personal data — not yours and not your customers.
- We do not build advertising or marketing profiles out of your business data.
Why we collect it
- To run the product you signed up for: taking a sale, producing an invoice, tracking stock, keeping customer credit straight.
- To let you sign in, and to keep everyone else out of your shop data.
- To send the emails the product exists to send — receipts, customer-credit reminders, password resets and account notices.
- To answer you when you contact support, and to investigate a problem you report.
- To take payment for your subscription and keep a record that you paid.
- To keep the audit trail, so an argument inside your business can be settled with a fact instead of a memory.
- To protect the service from abuse: rate limiting, and a challenge on the sign-in, registration and password-reset forms to keep automated attacks out.
Where the law that applies to you requires a legal basis, ours is the contract between us — we cannot provide the product without this data — together with our legitimate interest in keeping the service secure and accountable.
Who else touches your data
We keep the list of outside companies as short as we can. This is all of them, and what each one actually receives:
- Railway — hosting. Our application, database and cache run on Railway infrastructure, so Railway stores everything described above.
- Cloudflare — the Turnstile challenge on our sign-in, registration and password-reset forms. Cloudflare receives your IP address and the challenge response and tells us whether you look like a person or a bot. It runs on those three forms and nowhere else.
- Resend — email delivery. When NexusTill sends an email, Resend receives the recipient address and the content. If you email a sale receipt to a customer, that means Resend sees that customer email address and what they bought.
- Anthropic — the AI assistant, on the plans that include it. When you ask it a question we send your question, the earlier messages in that conversation, your business name and business type, and the figures needed to answer: things like sales totals, outstanding balances, stock counts, and product names and SKUs. We do not send your customers names, emails or phone numbers, and we do not send staff records. If your plan does not include the assistant, or you never use it, nothing is sent at all. The assistant on this website — the chat bubble that answers questions about the product before you sign up — also uses Anthropic: it sends only the messages you type into it, nothing else, and it has no access to any shop or account. Your chat transcript stays in your own browser.
There are no other integrations. If we ever add a processor, this page changes before we switch it on.
Separately, we will disclose data if the law genuinely requires it — a court order or a lawful demand from an authority. If that happens we will tell you, unless we are forbidden from doing so.
Where your data is stored
NexusTill runs on Railway, a hosting platform operated from the United States, using its managed PostgreSQL database and Redis cache. Your data is therefore stored in the cloud, on servers Railway operates. Email passes through Resend and the sign-in challenge through Cloudflare, both cloud services of their own.
If you need the exact data-centre region for a compliance requirement of your own, email us and we will tell you which one your account sits in.
Because our hosting and these services run in the cloud, your data may be stored and processed in a country other than your own. By using NexusTill you agree to that transfer. Wherever your data physically sits, this policy and the protections in it follow it, and we only work with providers that commit to protecting it.
How it is protected, honestly
What is actually true, rather than a list of reassuring words:
- Passwords are stored as bcrypt hashes. We cannot read yours, and nobody here can tell you what it is — a reset is the only way back in.
- Access tokens are stored as one-way hashes, expire after seven days of inactivity, and can be revoked from the Tills screen at any time.
- Traffic between your browser or phone and our servers is encrypted with HTTPS, and we instruct browsers to refuse an unencrypted connection to us for a year.
- On your phone, the sign-in token lives in the Android Keystore rather than ordinary app storage.
- Any payment-provider credentials your business saves in Settings are encrypted in our database.
- Inside the product, access is controlled by roles and permissions, and every business data is separated from every other business at the server, not in the browser.
And here is what we are not going to claim. Apart from those payment credentials, we do not add an application-level encryption layer on top of the database. Your records sit in a managed PostgreSQL database on Railway, protected by Railway platform controls and by our own access controls — not by field-by-field encryption. If you are thinking of entering something highly sensitive, a staff national ID number for instance, that is worth knowing, and it is a good reason to record only what you genuinely need.
No system is perfectly secure. If we discover a breach that affects you, we will tell you what happened, what was affected and what to do about it, as fast as we can establish the facts rather than after we have finished writing a statement.
How long we keep it
- While your account is open we keep your business records for as long as you keep them. They are your books; deleting them is your decision, not ours.
- When you delete a record in the product — a customer, a product, a staff member — it disappears from the app but the underlying row is retained, so that invoices and ledger entries which refer to it do not break. Ask us if you need it removed outright.
- The audit trail is append-only by design and is not edited or deleted, including the IP address and device it records. That is what makes it trustworthy, and it is the one place a deletion request cannot be fully honoured.
- Bank-transfer screenshots are deleted as soon as the payment is approved or rejected.
- AI conversations are kept until you delete them, and deletion is permanent.
- Server logs rotate and are removed after 30 days.
Your rights, and what we will actually do
Whatever the law where you are requires of us, if you ask we will, free of charge:
- Tell you what we hold about you.
- Correct anything wrong — most of it you can fix yourself in the app.
- Send you a copy of your business data in a machine-readable file.
- Delete your account and data, subject to the audit-trail exception above.
- Stop sending you anything that is not essential to running the service.
- Take a complaint seriously, and escalate it to the people who built the product rather than a script.
We aim to answer within 30 days. Be aware that there is no self-service export button and no self-service delete button in the product yet — a person on our side does both by hand when you ask. We would rather say that plainly than imply a button exists.
Deleting your account and your data
Email us from the address on the account, with your business name, and say that you want the account closed. We will confirm it is really you, offer you a copy of your data first, and then delete it.
What gets deleted: your account, your staff accounts and their profiles, your customers, suppliers, products, sales, invoices, payments, customer-credit balances, AI conversations and your shop logo.
What does not: entries in the tamper-evident audit trail, and the minimum record needed to show that a subscription was sold and a payment was made. That residue is not used for anything else.
Uninstalling the Android app removes what the app stored on your phone. It does not close your account — email us for that.
Children
NexusTill is business software sold to businesses. It is not directed at children, we do not market it to them, and we do not knowingly collect personal data from a child. If you believe a child has given us personal data, email us and we will delete it.
If your business employs someone under 18 and you add them as a staff member, you are responsible for having the right to record their details.
Changes to this policy
If we change this policy we change the date at the top. If the change is significant — a new processor, a new category of data, a new permission in the app — we email account owners before it takes effect. The current version always lives at nexustill.com/privacy.
Contact us
Questions about this document, a request about your data, or a complaint about how we have handled it — email us and a person will read it. We have no designated data protection officer; this inbox reaches the people who built the product.
NexusTill, Global