1. Who we are
General POS is built and operated by Velinex Labs Limited ("Velinex Labs", "we", "us"), a company registered in Kenya. This policy covers the General POS desktop application, the General POS Owner mobile app, the managed backend servers we host for each business, VeliPay collections made through General POS, and this website.
2. Our role and yours
Velinex Labs is the data controller for your account, subscription and billing information.
For the business records you keep in General POS, such as customers, sales, receipts, staff and stock, your business is the data controller and Velinex Labs acts as your data processor. We process that data only to provide, secure, support and improve the service for you, or where the law requires it. You are responsible for having a lawful basis to record your customers' and staff members' information and for telling them how you use it.
3. Information we collect
When you register a business
- Business name, trading details, KRA PIN, address, currency and timezone.
- The owner's name, email address and phone number.
- Subscription payment details: the M-Pesa phone number, amount, and transaction reference. We do not receive your M-Pesa PIN.
When your team uses General POS
- Staff accounts: names, email addresses, roles, branch access, sign-in activity, and an audit trail of sensitive actions such as discounts, voids, refunds, price and stock changes.
- Business records: products, prices, stock movements, suppliers, shifts, sales, receipts and reports.
- Customer records you choose to keep, such as a customer's name, phone number, email or KRA PIN, and their purchase and credit history.
- Payments at the till: for M-Pesa and bank STK payments, the payer's phone number, amount, status and provider reference. For VeliPay, your payout destination and settlement and withdrawal records.
- Tax submissions: invoice and receipt details required for KRA eTIMS when you enable it.
From devices
- Desktop tills: workstation name and device identifier, app version, IP address, and technical logs used for syncing, updates and troubleshooting. Sales made offline are stored on the till until they sync.
- Owner app: your sign-in session, stored in the phone's secure storage. The app does not collect your location, contacts or photos and does not show advertising.
4. How we use it
- To provision and run your dedicated server, sync your tills and phones, and deliver updates and backups (performance of our contract with you).
- To process subscription payments, renewals and VeliPay collections and withdrawals, and to prevent fraud (contract and legitimate interests).
- To submit tax documents to KRA when you enable eTIMS, and to meet our own legal, tax and accounting obligations (legal obligation).
- To provide support, investigate problems and keep the service secure (legitimate interests).
- To send service messages such as renewal reminders, security notices and important changes. We do not sell your data or use your business records for advertising.
5. Who we share it with
- Payment providers you use through General POS, such as Safaricom M-Pesa (Daraja), I&M (Tuma), KCB (BUNI) and VeliPay's payment partners, to complete payments and settlements.
- The Kenya Revenue Authority and our eTIMS integration partner, only when you enable eTIMS submission.
- Infrastructure providers that host servers, databases, backups, email and software downloads for us, under contracts that require them to protect the data.
- Authorities, where Kenyan law, a court order or a regulator requires it.
- A successor business, if Velinex Labs is reorganised, merged or sold, subject to this policy.
6. Where it is stored
Each business's data lives on its own dedicated managed server and database, with automated daily backups. Some of our infrastructure providers operate data centres outside Kenya. Where data is transferred outside Kenya we rely on appropriate safeguards as required by the Data Protection Act, 2019.
Your business owns its business data. Supermarkets and other large shops can arrange to host General POS on their own servers at an agreed price, with software development and update delivery from Velinex Labs. For these installations, your service agreement sets out where data is stored, who manages backups and security, and what access we need to provide support and updates.
7. How long we keep it
- Business records are kept for as long as your business uses General POS, including while it is in read-only mode after a lapsed renewal, so you can always view and export your history.
- If you close your account, we give you the opportunity to export your records and then delete or anonymise them within a reasonable period, except where we must keep information longer by law. Tax and payment records, for example, generally have to be kept for at least five years under Kenyan law.
- Technical logs are kept for a limited period for security and troubleshooting.
8. Security
We use encrypted connections (TLS) between tills, phones and your server; store payment-provider credentials encrypted at rest and show them only in masked form; restrict access with role-based permissions and keep an audit trail; sign desktop software updates so tills only install genuine releases; and back up your database daily. No system is perfectly secure, so please use strong passwords, give staff only the access they need, and tell us straight away if you suspect misuse.
9. Your rights
Under the Kenya Data Protection Act, 2019 you have the right to be informed about how your personal data is used, to access it, to object to its processing, to have inaccurate data corrected, to have data deleted where the law allows, and to data portability.
For account and billing data, email [email protected]. If you are a customer or staff member of a business that uses General POS, please contact that business first. It controls those records, and we will help it respond. You may also complain to the Office of the Data Protection Commissioner.
10. This website
This website does not use advertising or analytics cookies. For service reporting, we count likely human page views by public page, day, broad device and operating-system category, and referral source. These aggregate counts do not store IP addresses, raw browser details, full referral URLs, or visitor identifiers; repeat visits count as separate page views. Where enabled, our content delivery network records installer requests, response size, broad operating-system category, country and referral source so we can report download totals. Access logs are restricted and retained for up to 30 days before deletion; aggregate reports are retained for up to 24 months. Our servers may also keep standard access logs for security and reliability.
11. Children
General POS is a business tool and is not directed at children. We do not knowingly collect personal data from children except where a business records it in the normal course of trade.
12. Changes and contact
We may update this policy as the product changes. We will post the new version here with a new effective date, and tell account owners about significant changes in the app or by email.
Questions? Contact Velinex Labs Limited at [email protected] or +254 723 343 392.