Legal

NovaKasse

Point-of-sale system for hospitality and retail

Privacy policy

Last updated: 5 September 2026

NovaKasse is a business application for companies, not for private individuals. For the business’s own data (account, staff, subscription) we are the controller. For everything the business records in operation — in particular customer data, orders and staff hours — we act as processor and the business is the controller. We process that data only on the business’s instructions and never for our own purposes.

1. Data controller

Company
Babala Özdemir (Einzelunternehmen)
Address
Unterer Rainweg 22
4414 Füllinsdorf
Schweiz
E-mail
info@babala.ch
Phone
076 222 45 99
Company ID
CHE-322.105.560
App identifier
iOS: ch.babala.kasse.swiftui
Android: ch.babala.kasse

We have not appointed a data protection officer or an EU representative because we do not reach the relevant thresholds. Please address all requests to the contact above.

2. What data we process

Data Purpose Stored where Retention
Business account: company name, address, e-mail, phone Contract, invoicing, support Our server (EU data centre) Term of contract + 10 years for records
Staff: name, PIN (hashed), working hours, payroll data POS access, time tracking, the business’s payroll Our server, on behalf of the business As instructed by the business; statutory periods reserved
The business’s customers: name, phone, address, orders, balance, loyalty points Order processing, delivery, the business’s customer account Our server, on behalf of the business As instructed by the business; records 10 years
Payment data (card, Tap to Pay) Card payment at the device At Stripe; with us only amount, status, reference and the last four digits 10 years (accounting obligation)
Fiscal journal and audit log Traceability of POS transactions (Swiss GeBüV) Our server 10 years — not deletable for legal reasons
Device push token Notification about new online orders Our server; delivery via Google or Apple Until the device is signed out
Product photos and scanned menus Creating items; text recognition runs on the device Device; the final product image on our server Until the business deletes it

What we explicitly do not collect

3. Permissions on your device

The app requests only the following permissions. Each of them can be revoked at any time in your device settings; the app remains usable afterwards, with reduced functionality.

4. Legal bases

We process personal data under the Swiss Federal Act on Data Protection (revFADP). Where the GDPR applies, we rely on:

A data processing agreement governs the data we process on behalf of the business; it forms part of the novakasse.ch terms and is issued separately on request. Data subjects (for example a business’s guests) should address access and deletion requests to that business; we support the business in handling them.

5. Recipients and third parties

We do not sell data and do not disclose it for advertising purposes. Data is disclosed only to the following parties, and only where required for operation:

Recipient Location Purpose
Hetzner Online GmbH Gunzenhausen (Germany), data centre inside the EU Operation of our servers. Hetzner processes data solely on our behalf and is contractually bound to confidentiality.
Stripe Payments Europe Ltd. / Stripe Inc. Dublin (Ireland) / San Francisco (USA) Card payment processing. Card data is collected by Stripe directly; we never receive or store full card numbers, only payment references (tokens), amount, status and the last four digits.
Firebase Cloud Messaging (Google Ireland Ltd.) Dublin (Ireland) Delivery of push notifications to Android devices. A device token and the message content are transmitted.
Apple Push Notification service (Apple) Cork (Ireland) / USA Delivery of push notifications to Apple devices. A device token and the message content are transmitted.
Apple MapKit Cork (Ireland) / USA Map rendering. When loading map tiles Apple receives the IP address and the visible map region.
OpenStreetMap Foundation Cambridge (United Kingdom) Map rendering. Loading map tiles transmits the IP address to the tile server.
Apple Inc. / Apple Distribution International Ltd. Cupertino (USA) / Cork (Ireland) App Store distribution, processing of in-app purchases and subscriptions, and crash reports if you have enabled them with Apple.
Google Ireland Ltd. / Google LLC Dublin (Ireland) / Mountain View (USA) Google Play distribution, purchase processing via Google Play Billing, crash reports according to your Play settings.

Authorities and courts receive data only where we are legally obliged to provide it.

Transfers abroad

Some of the recipients listed above process data outside Switzerland and the EEA, in particular in the United States. We base such transfers on the European Commission’s Standard Contractual Clauses with the Swiss adaptations recognised by the FDPIC and, where applicable, on the EU-US Data Privacy Framework. We will provide information on the safeguards in place on request.

6. Retention and deletion

We retain a business’s data for the duration of the subscription and delete it on request after the subscription ends, at the latest 90 days after the final invoice — except for records that we or the business must keep for 10 years under Swiss accounting and retention rules (CO 958f, GeBüV). These include POS receipts, the fiscal journal and payroll records. Server logs expire after 14 days.

Step-by-step instructions are available at Delete data.

7. Children and young people

This app is not directed at children. We do not knowingly collect personal data from children under 16. If we learn that such data has been submitted without parental consent, we delete it without delay.

8. Data security

Wherever the app transmits data at all, connections are encrypted via HTTPS/TLS. On the server side we use access restrictions, tenant separation and regular backups. Nobody can, however, guarantee absolute security for data transmission over the internet.

Every business is a separate tenant: each database query is scoped to the business identifier, so no business can see another’s data. Access can be protected with two-factor authentication and idle timeout; POS transactions are recorded in a continuously chained journal.

9. Your rights

An informal message to info@babala.ch or a call to 076 222 45 99. We normally respond within 30 days. To verify your identity we may request suitable proof. You may also lodge a complaint with a supervisory authority (Switzerland: FDPIC; EU: your competent authority).

10. Changes to this policy

We may adapt this policy when the app or the legal framework changes. The version published on this page, with the date shown above, is the applicable one. We announce material changes inside the app.

← Back to the app overview