Privacy — the kwitto app

Version of 11/08/2026. This document also exists in French and Dutch. The French version is the authoritative one.

In short. kwitto is a professional point of sale: the data it holds — the shop’s team, the customers on a delivery round — belongs to the merchant, not to us. The app has no advertising, no trackers, no analytics; nothing is sold, rented or exchanged. Everything is encrypted on the device, everything travels over HTTPS, and deletion happens in the merchant’s back office.

1. What this document covers

This statement covers the kwitto point-of-sale app, installed on a shop’s terminals and phones (iOS and Android). The kwitto.be website has its own statement.

The app is a professional tool, handed by a merchant to their team. Nobody creates a personal account in it: terminals are enrolled by the shop, and sellers are added by the shop, in its back office.

2. Who is responsible for what

Two roles, which the GDPR distinguishes and which we keep separate:

One exception: the diagnostic data (§ 3.d), which we collect on our own account to keep the software working. For that data, the controller is us.

For any question about this document: bonjour@kwitto.be.

3. The data the app processes

a) The shop’s team

To open a seller session and attribute each sale to the right person, the app receives from the back office: each seller’s name, their role (cashier, manager…) and, if they have one, their badge number.

The app does not know a seller’s PIN code: it only receives a cryptographic fingerprint of it (bcrypt), which lets it verify the code without ever storing or transmitting it in the clear.

The Belgian national registry number (NISS) appears in one case only: a shop subject to the registered cash register system (SCE/GKS, the hospitality sector’s fiscal “black box”), where the law requires each user of the till to identify themselves to the fiscal module. Outside that regime, the national number never reaches the device: the field is not transmitted at all — not sent empty, not sent.

b) Delivery customers

When the shop uses delivery rounds, the driver’s phone receives, for each stop: the customer’s name, address and phone number, the order references and, where present, the message accompanying a gift parcel.

c) Delivery proof photos

At the door, the driver may photograph the spot where a parcel was left, or damaged goods, as proof attached to the delivery note. The photo is taken with the camera, never from the gallery: the app has no access whatsoever to the phone’s personal photos. The instruction shown to the driver: photograph the place or the goods — not people.

d) Diagnostic data

When the app hits an error, a technical report goes to our monitoring tool (Sentry). That report is configured as soberly as possible:

A report contains: the error, the app version, the device model and its OS version, the terminal identifier. It contains no sale, no name, and nothing typed on screen.

4. What the app does not do

5. Where the data lives, and how it is protected

6. For how long, and how to delete

Team and customer data is managed in the merchant’s back office. Removing a seller, correcting or deleting a customer record: that is where it happens, and the change reaches the terminals at the next synchronisation. What the app keeps on the device is only a working copy.

Two limits, set by law rather than by us:

Diagnostic reports are kept for 90 days by our monitoring tool, then deleted.

Uninstalling the app deletes the encrypted local database from the device.

7. Your rights

If you work in a shop that uses kwitto, or if you are a customer of such a shop: your rights of access, rectification, erasure, restriction and objection are exercised with the merchant, who is the controller of your data. We assist them in answering, as the data processing agreement provides.

For the diagnostic data, for which we are the controller: write to bonjour@kwitto.be. We answer within a month.

If the answer does not satisfy you, you may turn to the Belgian Data Protection Authority:

Autorité de protection des données / Gegevensbeschermingsautoriteit — Rue de la Presse 35, 1000 Brussels, Belgium contact@apd-gba.be — +32 (0)2 274 48 00 — dataprotectionauthority.be

8. Who else sees this data

Provider For what Where the data is
Scaleway (Online SAS), serveurs situés en France Hosting the back office the app synchronises with France (European Union)
Sentry (Functional Software, Inc.) Receiving the diagnostic reports — without personal data, see § 3.d United States

The transfer to Sentry is governed by the European Commission’s standard contractual clauses and by the provider’s participation in the EU–US Data Privacy Framework.

We pass nothing to anyone else. Neither Apple nor Google receives shop data through the app; the app stores see what every store sees — the download.

9. Changes

We may evolve this statement. The date at the top indicates the latest version. If a change alters what the app does with data already collected, the merchants concerned are notified before it goes live.