Last updated: September 2026
M2POS (also shown as MultiPOS) is a cloud point-of-sale and restaurant management service operated by Gemica Tech. This policy explains what we collect, why, and what we never do with it. For questions, contact support@mymultipos.com.
Account details for the people who sign in (name, email, role). Business data you enter: menu items, orders, receipts, payments, inventory, suppliers, customers you choose to record, staff and payroll records if you use the HR module. Technical records needed to run the service: sign-in times, audit entries for sensitive actions, and error logs.
Everything you enter is yours. We do not sell it, rent it, or share it with advertisers, and we do not use one business's data to build products for another. Each business's data is isolated from every other business on the platform.
If you connect Facebook, Instagram, TikTok or Canva in Marketing, we store an access token so we can act on your behalf. Those tokens are encrypted at rest with AES-256-GCM under a key held outside the database. We use them for exactly two things: reading the list of Pages or accounts so you can choose one, and publishing the post you have chosen. We never read your messages, your follower data, or anything else those accounts can see.
Nothing is published automatically. A post goes out only when somebody at your business presses Post, and what goes out is the caption and picture chosen on that calendar event โ read from our own records at the moment of posting, so it cannot be altered in transit. Once a post is live on Facebook, Instagram or TikTok it is governed by that platform, and it can only be removed there.
Disconnecting a social account in Marketing deletes the stored token immediately and permanently. It does not remove posts already published, and it does not by itself revoke the permission you granted on the platform's own settings page โ do that there if you want the approval gone as well.
Business reports and marketing copy are generated with Google Gemini. Only what is needed for the request is sent: sales totals, item names, the event you are writing about, and your brand kit. Customer names, phone numbers, staff records and payment details are never sent to an AI model. AI output is a draft for a person to check, not a decision.
We use service providers to run the platform: Supabase for the database and file storage, Vercel for hosting, Resend for email, Google for AI, and the social platforms you choose to connect. They process data on our instructions to deliver the service and for nothing else. We do not use advertising or tracking networks.
Business data is kept for as long as the account is active. A suspended account keeps its data for 30 days. Published-post records are kept as a history of what was sent. To delete your data: disconnect the account under Marketing โ Marketing Setting, which erases the stored token immediately, and email support@mymultipos.com from the address on the account asking for deletion. We remove the restaurant and everything belonging to it โ staff, sales, designs and post history โ within 30 days and confirm by email. Posts already published to Facebook, Instagram or TikTok stay on those platforms; delete them there.
Access is restricted by role, sensitive actions are written to an append-only audit log, staff PINs are hashed and never stored in readable form, and third-party tokens are encrypted. No system is perfect; if a breach ever affects your data we will tell you.
We may update this policy. Material changes will be announced by email. Continued use after a change means you accept it.
Questions, corrections, or a request to delete your data: support@mymultipos.com.
Questions? Email us at support@mymultipos.com
ยฉ 2026 M2POS ยท MultiPOS โ powered by Gemica Tech