Privacy Policy

Effective date: 12 July 2026

Last updated: 12 July 2026

This Privacy Policy explains how Black Mountain Software Systems Ltd, a company registered in England & Wales (Company No. 17076590) ("JadePos", "we", "us", "our") collects, uses, and protects personal data when you use the JadePos platform and website (the "Service"). We process personal data in accordance with the UK GDPR and the Data Protection Act 2018.

1. Who we are and our roles

We act in two distinct capacities:

  • As a data controller for the personal data of the people who register and use JadePos accounts (business owners, admins, and staff) and visitors to our website.
  • As a data processor for personal data your business records about its own customers inside JadePos — for example a customer name and phone number attached to an order. Your business is the controller of that data and decides why and how it is collected; we process it only to provide the Service.

2. Personal data we collect

Account data (we are the controller):

  • Name, email address, and role for each user account.
  • Password, stored only as a one-way cryptographic hash — we can never read your password.
  • Business name and organisation details.
  • Security data: login attempt records, IP addresses used at sign-in, two-factor authentication status, and time-limited verification codes (stored hashed).
  • Billing data: subscription plan, billing status, and Stripe customer references. Full payment card details are collected and stored by Stripe, not by us.
  • Support correspondence when you contact us.

Your business's data (we are the processor):

  • Order records, which may include an end customer's name and phone number, order contents, notes, and payment method (never card numbers).
  • Menus, categories, pricing, settings, and terminal information.

We do not intentionally collect special category data, and the Service is not designed to store it. Please do not enter such data into free-text fields.

3. How we use personal data and our lawful bases

  • Providing the Service — creating and managing accounts, processing orders, syncing data between terminals (performance of a contract).
  • Security — authenticating logins, two-factor authentication emails, rate limiting, locking accounts after repeated failed logins, and monitoring for abuse (legitimate interests: keeping the Service and your data safe).
  • Billing — managing subscriptions and payments through Stripe (performance of a contract; legal obligation for tax records).
  • Service communications — emails that are part of the Service, such as password resets and verification codes (performance of a contract). We do not send marketing emails without consent.
  • Improving the Service — aggregate, de-identified usage analysis (legitimate interests).
  • Legal compliance — retaining records and responding to lawful requests (legal obligation).

4. Who we share data with

We never sell personal data. We share it only with the service providers we rely on to operate JadePos, under contracts that restrict how they may use it:

  • Amazon Web Services (AWS) — cloud hosting and database infrastructure.
  • Stripe — subscription billing and payment processing. Stripe is an independent controller for the payment data it collects; see the Stripe Privacy Policy.
  • Mailgun — transactional email delivery (password resets, verification codes).
  • Professional advisers, insurers, or authorities where required by law or to protect our legal rights.
  • A buyer or successor in the event of a merger, acquisition, or sale of assets, subject to this policy.

5. International transfers

Our primary infrastructure is hosted in the United Kingdom / European Economic Area. Where a provider processes data outside the UK/EEA (for example some Stripe or Mailgun operations in the United States), we rely on UK adequacy regulations or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, together with additional safeguards.

6. Security

  • All traffic is encrypted in transit (TLS/HTTPS).
  • Passwords and verification codes are stored only as one-way hashes.
  • Password reset tokens are stored hashed and expire after 15 minutes.
  • Each organisation's data is isolated with row-level security enforced at the database layer, in addition to application-level checks.
  • Brute-force protections: rate limiting, account lockout after repeated failed logins, and optional email-based two-factor authentication.
  • Access to production systems is restricted and credentialed.

If we become aware of a personal data breach affecting your data, we will notify you and, where required, the Information Commissioner's Office (ICO) without undue delay.

7. How long we keep data

  • Account and business data — kept while your account is active. After account closure, deleted or anonymised within 30 days.
  • Backups — encrypted backups are overwritten on a rolling basis within a further 30 days of deletion.
  • Billing, tax, and accounting records — retained for up to 6 years from the end of the relevant financial year, as required by UK company and tax law.
  • Security logs (login attempts, IP addresses) — retained for up to 12 months.
  • Verification codes and reset tokens — expire within minutes and are purged routinely.

8. Your rights

Under UK GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased ("right to be forgotten");
  • restrict or object to processing based on legitimate interests;
  • receive your data in a portable format;
  • withdraw consent at any time, where processing is based on consent.

To exercise any right, email support@blackmountaintech.co.uk. We respond within one month. If you are an end customer of a business that uses JadePos, please contact that business directly — they control your data, and we will assist them in fulfilling your request.

You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk, although we would appreciate the chance to address your concerns first.

9. Cookies

JadePos uses only strictly necessary cookies — no advertising or third-party tracking cookies:

  • Session cookie (authjs.session-token) — keeps you signed in; expires after 24 hours.
  • 2FA cookie (2fa-pending) — carries a signed, short-lived token during two-factor sign-in; expires after 10 minutes.
  • CSRF cookie — protects forms against cross-site request forgery.

Because these cookies are essential for the Service to function, they do not require consent under PECR, and there is no cookie banner to dismiss.

10. Children

The Service is for business use and is not directed at children. We do not knowingly collect personal data from anyone under 18 as an account holder.

11. Changes to this policy

We may update this policy from time to time. Material changes will be notified by email or in-app notice at least 30 days before they take effect. The "Last updated" date at the top shows the current version.

12. Contact

Data protection contact: Black Mountain Software Systems Ltd (Company No. 17076590), registered in England & Wales.
Email: support@blackmountaintech.co.uk

See also our Terms of Service.