Unlock Seamless Payments with Flow Today!

Privacy Policy

FlowPOS Privacy Policy

Tech1 Solutions Ltd 

Company Number: 14854756

Registered Office: Unit 2 Dudley Hill Business Park, Rook Lane, Bradford, West Yorkshire, United Kingdom, BD4 9NU

Website: flowpos.co.uk | Telephone: 0113 547 4030 | Email: [email protected]

Effective Date: 24 August 2026 | Version: 2.0

1. Introduction

Tech1 Solutions Ltd, trading as FlowPOS (“FlowPOS”, “we”, “us” or “our”), is committed to protecting personal data and respecting the privacy of merchants, their customers, website visitors, users of the FlowPOS platform and other individuals whose information we process. This Privacy Policy explains how we collect, use, store, disclose and protect personal data in connection with our electronic point of sale (“EPOS” or “POS”) systems, payment and payment-integration services, payment terminals, merchant management platform, online ordering and e-commerce services, websites and online portals, reporting and analytics services, technical support and managed services, integrations with third-party platforms and payment providers, and other products and services supplied under the FlowPOS brand. This Policy is intended to comply with applicable UK data protection legislation, including the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018, and applicable electronic communications and privacy legislation.

2. Who We Are

FlowPOS is a trading name of Tech1 Solutions Ltd, Company Number 14854756. Registered Office: Unit 2 Dudley Hill Business Park Rook Lane Bradford West Yorkshire United Kingdom BD4 9NU For questions regarding this Privacy Policy or the way we process personal data, please contact us at [email protected], telephone 0113 547 4030, or via flowpos.co.uk.

3. Our Role Under Data Protection Law

3.1 When We Act as a Data Controller

We generally act as a controller where we determine why and how personal data is processed. This may include information relating to our merchant and business customers, prospective customers, merchant owners, directors and authorised representatives, contractual relationships, billing and account administration, fraud prevention and security, legal and regulatory compliance, customer support, marketing, website visitors, and management and security of the FlowPOS service.

3.2 When We Act as a Data Processor

When merchants use FlowPOS to process information about their own customers, employees or transactions, we may process certain personal data on behalf of that merchant. In these circumstances, the merchant will generally determine the purpose for which the information is collected and used and may therefore be the data controller, while FlowPOS acts as its data processor. Where we act as a processor, we process personal data in accordance with the merchant’s documented instructions, our contractual obligations and applicable data protection law. Certain third parties involved in providing payment services may separately act as independent controllers for information they process for their own legal, regulatory, fraud-prevention or payment-processing purposes.

4. Personal Data We Process

4.1 Merchant and Business Information

  • business name and trading name; business and registered addresses; company registration details;
  • names of directors, owners and authorised representatives; telephone numbers and email addresses;
  • account login and user information; billing information; bank or settlement account information where required;
  • contractual information; support correspondence; identity or verification information where required; and
  • information necessary to provide or administer FlowPOS services.

4.2 POS and Transaction Information

  • transaction date and time, amount, products or services purchased, quantities, pricing, discounts, VAT and tax information;
  • store, branch or merchant location; POS terminal or device identifier; transaction/reference numbers; order information;
  • payment method; authorisation or transaction status; refund information; chargeback or dispute information;
  • settlement information and limited payment information supplied by our payment partners.

Depending on how a merchant configures and uses FlowPOS, transactions may also be associated with customer information such as a customer’s name, telephone number, email address, delivery address, collection details or customer account.

4.3 Payment and Card Information

FlowPOS integrates with payment service providers, acquirers and other payment technology partners to facilitate payment acceptance. Information associated with a card transaction may include payment method, card type or scheme, limited or masked card details, transaction identifier, payment authorisation result, payment status, transaction amount, refund information, chargeback information, payment processor references and information required to investigate or reconcile transactions. Where payment card information is captured directly through an approved payment terminal, payment gateway or payment service provider, sensitive cardholder information may be transmitted directly to the relevant payment provider rather than being stored by FlowPOS. FlowPOS does not intentionally store card verification values such as CVV/CVC after authorisation. We seek to minimise our exposure to full payment-card credentials and use payment providers and technical controls designed to protect cardholder information.

5. E-commerce and Online Ordering Data

Where FlowPOS provides or integrates with an e-commerce or online ordering service, we may process customer name, email address, telephone number, billing and delivery information, order details, delivery or collection instructions, transaction amount, payment status, refunds, transaction references and communications relating to the order. The merchant remains responsible for ensuring that it has an appropriate lawful basis for collecting and using customer information through its business.

6. Technical and Device Information

When users interact with FlowPOS systems, websites, applications or portals, we may automatically collect technical information including IP address, browser type, operating system, device type, device identifiers, POS or terminal identifiers, login times, authentication information, system activity, application activity, error and diagnostic logs, security events, approximate location derived from IP or device information where applicable, and website usage information. We use this information to operate, maintain, secure, troubleshoot and improve our systems.

7. Customer Support Data

If you contact FlowPOS for assistance, we may process your name, business name, contact details, support ticket information, correspondence, diagnostic information, account information, device information and other information you provide to us in connection with the support request. Where remote technical support is required, authorised personnel may be provided with temporary or controlled access to relevant systems or information for the purpose of diagnosing and resolving the issue.

8. How We Collect Personal Data

  • directly from merchants and users;
  • through the FlowPOS POS platform, payment terminals and integrations;
  • through e-commerce and online ordering systems;
  • from merchant customers where FlowPOS acts as a processor;
  • through our website;
  • from payment processors and acquiring partners;
  • from technology and integration partners;
  • from fraud-prevention and security providers;
  • through customer-support interactions;
  • from publicly available business sources; and
  • where necessary, from professional advisers, regulatory authorities or other lawful sources.

9. How and Why We Use Personal Data

  • provide and administer FlowPOS services and establish and manage merchant accounts;
  • operate POS systems, facilitate and support payment transactions, and process orders;
  • provide e-commerce functionality, transaction reporting and reconciliation;
  • manage refunds and disputes and provide customer and technical support;
  • authenticate users, protect accounts, detect and investigate fraud or misuse, and maintain system security;
  • troubleshoot technical problems, manage contracts and subscriptions, and issue and manage invoices;
  • comply with accounting, tax and other legal requirements and lawful requests from authorities;
  • establish, exercise or defend legal claims;
  • improve our products and services and communicate service, operational and security information;
  • analyse system performance, manage merchant and partner relationships, and send marketing communications where permitted by law.

10. Lawful Bases for Processing

Under the UK GDPR, we must have a lawful basis for processing personal data. Depending on the circumstances, we rely on the following bases.

10.1 Performance of a Contract

We process information where it is necessary to enter into or perform a contract, including to establish merchant accounts, provide POS and software services, provide payment integrations, provide e-commerce and online ordering services, provide technical support, administer subscriptions and manage our contractual relationship with customers.

10.2 Legal Obligation

We may process information where necessary to comply with obligations imposed on us by law, including applicable tax and accounting requirements, data protection obligations, law-enforcement requirements, court orders and other statutory or regulatory obligations.

10.3 Legitimate Interests

We may process personal data where necessary for our legitimate business interests, provided those interests are not overridden by the rights and freedoms of the individual. These interests may include operating and improving our services, maintaining network and information security, preventing and detecting fraud, investigating suspicious activity, protecting merchants and customers, managing business relationships, maintaining business records, resolving disputes, improving customer service and protecting our legal and commercial interests.

10.4 Consent

Where required, we may rely on consent, particularly for certain marketing communications and non-essential website technologies. Where processing is based on consent, consent may be withdrawn at any time. Withdrawal does not affect processing carried out lawfully before consent was withdrawn.

11. Payment Processing and Payment Partners

FlowPOS provides technology that enables merchants to accept and manage payments. Payment transactions may involve third-party organisations such as acquiring banks, payment processors, payment service providers, card schemes, payment gateways, banking partners, fraud-prevention providers and other organisations necessary to authorise, process, settle or protect a transaction. These organisations may process personal and transaction information in accordance with their own legal obligations and privacy policies. Where a payment provider independently determines how and why it processes personal data, that provider may act as a separate data controller. FlowPOS does not control the independent processing activities of third-party payment providers.

12. Payment Card Security

Protecting payment information is an important part of our security framework. FlowPOS uses technical and organisational measures designed to reduce the risk of unauthorised access to payment and transaction information.

  • secure payment terminals and encrypted communications;
  • tokenisation where supported;
  • access and authentication controls and restricted access to payment information;
  • network and system security controls, monitoring and logging;
  • vulnerability management and use of approved payment providers; and
  • controls designed to support applicable Payment Card Industry Data Security Standard (PCI DSS) requirements.

Where payment-card information is handled by our payment-processing partners, those providers are responsible for maintaining the security and compliance obligations applicable to their respective payment environments. FlowPOS does not intentionally retain sensitive authentication data such as CVV/CVC following completion of a card authorisation.

13. Sharing Personal Data

We do not sell personal data. We may share information where necessary with payment processors, acquiring banks, payment gateways, banking partners, card schemes, cloud and hosting providers, software and technology providers, e-commerce and integration providers, communications providers, security and fraud-prevention providers, professional advisers, accountants and auditors, insurers, law-enforcement agencies, courts, government authorities, regulatory bodies and other organisations where disclosure is required or permitted by law. Where a third party processes personal data on our behalf, we take appropriate steps to ensure contractual and data-protection safeguards are in place.

14. International Transfers

Some of our technology providers or service providers may process personal data outside the United Kingdom. Where personal data is transferred internationally, we take appropriate steps to ensure that the transfer complies with applicable UK data protection law. Depending on the destination and recipient, safeguards may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved Standard Contractual Clauses, or another legally recognised transfer mechanism. Where required, we also consider whether additional technical, organisational or contractual safeguards are appropriate.

15. Data Security

We maintain technical and organisational security measures appropriate to the nature of the information and the risks associated with its processing. These may include encryption in transit and, where appropriate, at rest; authentication and access controls; role-based permissions; secure cloud infrastructure; logging and monitoring; malware and endpoint protection; vulnerability and security management; backups and recovery procedures; employee access restrictions; security policies and procedures; incident-response processes; and supplier security controls. Access to personal information is restricted to authorised persons who require access for legitimate business purposes. No electronic system can be guaranteed to be completely secure. However, we maintain safeguards intended to protect information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

16. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including to satisfy legal, regulatory, accounting, contractual, security and reporting requirements. Retention periods may differ depending on the nature of the information, the service being provided, the duration of our relationship with the merchant, applicable legal and contractual requirements, fraud and security considerations, potential disputes and the need to establish, exercise or defend legal claims. Where information is no longer required, it will be deleted, anonymised or otherwise securely disposed of in accordance with our data-retention procedures.

17. Cookies and Website Technologies

Our website may use cookies and similar technologies, including strictly necessary cookies required for security and core website functionality; functional cookies used to remember preferences and provide requested functionality; analytics cookies used to understand website use and improve performance; and marketing cookies, where used, to measure campaigns or provide relevant advertising. Where required by applicable law, non-essential cookies will only be used with the user’s consent. Users can manage cookie preferences through available cookie controls and browser settings.

18. Marketing Communications

We may send information about FlowPOS products and services where we have an appropriate lawful basis to do so. Where consent is required, marketing will only be sent after appropriate consent has been obtained. Recipients can unsubscribe from electronic marketing communications at any time using the unsubscribe mechanism contained within the communication or by contacting us. Unsubscribing from marketing will not prevent us from sending necessary operational, security, account, payment or service-related communications.

19. Automated Decision-Making

FlowPOS does not ordinarily make decisions about individuals based solely on automated processing that produce legal or similarly significant effects. Automated systems may, however, be used to identify unusual activity, potential fraud, security threats or transaction risks. Payment providers and financial institutions may separately use automated fraud or risk-management systems in connection with payment transactions. Such processing may be governed by their own privacy notices and legal obligations. Where FlowPOS carries out solely automated decision-making falling within the relevant provisions of UK data protection law, we will provide the information and safeguards required by applicable law.

20. Individual Rights

Subject to applicable law and any relevant exemptions, individuals may have the right to request access to their personal data; request correction of inaccurate or incomplete data; request deletion in certain circumstances; request restriction of processing; object to processing based on legitimate interests; object to direct marketing; request data portability where applicable; withdraw consent where processing is based on consent; and exercise applicable rights relating to automated decision-making. To exercise a right, please contact [email protected]. We may need to verify your identity before processing a request. Where FlowPOS processes information solely on behalf of a merchant, we may direct the request to the relevant merchant or assist that merchant in responding to the request.

21. Complaints

If you have concerns about how we process your personal data, please contact us first so that we can investigate the matter. Tech1 Solutions Ltd trading as FlowPOS Unit 2 Dudley Hill Business Park Rook Lane Bradford West Yorkshire United Kingdom BD4 9NU Email: [email protected] Telephone: 0113 547 4030 You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s independent data protection supervisory authority.

22. Children’s Data

FlowPOS services are primarily intended for businesses and are not directed at children. Merchants using FlowPOS remain responsible for ensuring that any personal information they collect through their business, including information relating to children where applicable, is collected and processed lawfully. If we become aware that information has been provided directly to us by a child in circumstances where it should not have been collected, we will take appropriate action.

23. Third-Party Websites and Services

FlowPOS products may contain links to or integrations with third-party websites, applications or services. Those organisations may process personal data independently and maintain their own privacy policies. We encourage users to review the privacy information provided by any third-party service they use. This Privacy Policy does not govern processing independently undertaken by third parties.

24. Data Breaches and Incident Management

FlowPOS maintains procedures for identifying, investigating, managing and responding to suspected personal-data breaches and security incidents. Where a personal-data breach is subject to statutory notification requirements, we will notify the Information Commissioner’s Office and/or affected individuals as required by applicable data protection law. Where FlowPOS is acting as a processor, we will notify and assist the relevant controller in accordance with applicable contractual and legal requirements.

25. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes to our products and services, the way we process information, our technology, our payment partners, legal or regulatory requirements, or improvements to our privacy and security practices. The latest version will be published on the FlowPOS website with its effective date. Material changes may also be communicated to merchants or users where appropriate.

26. Contact Us

Questions, requests or complaints relating to this Privacy Policy or the processing of personal data should be directed to: Tech1 Solutions Ltd trading as FlowPOS Company Number: 14854756 Registered Office: Unit 2 Dudley Hill Business Park Rook Lane Bradford West Yorkshire United Kingdom BD4 9NU Email: [email protected] Telephone: 0113 547 4030 Website: flowpos.co.uk Effective Date: 24 August 2026 Version: 2.0