Privacy — the kwitto app
Version of 11/08/2026. This document also exists in French and Dutch. The French version is the authoritative one.
In short. kwitto is a professional point of sale: the data it holds — the shop’s team, the customers on a delivery round — belongs to the merchant, not to us. The app has no advertising, no trackers, no analytics; nothing is sold, rented or exchanged. Everything is encrypted on the device, everything travels over HTTPS, and deletion happens in the merchant’s back office.
1. What this document covers
This statement covers the kwitto point-of-sale app, installed on a shop’s terminals and phones (iOS and Android). The kwitto.be website has its own statement.
The app is a professional tool, handed by a merchant to their team. Nobody creates a personal account in it: terminals are enrolled by the shop, and sellers are added by the shop, in its back office.
2. Who is responsible for what
Two roles, which the GDPR distinguishes and which we keep separate:
- The merchant is the data controller for the data of their team and their customers. They decide who appears in their till, and why.
- JW Consulting & Services SRL, Rue Henri Maubel, 106 - 1190 Bruxelles, company number BE0817.628.341, is the data processor: we process that data on the merchant’s behalf, under their instructions, within the data processing agreement (art. 28 GDPR) that comes with the service contract.
One exception: the diagnostic data (§ 3.d), which we collect on our own account to keep the software working. For that data, the controller is us.
For any question about this document: bonjour@kwitto.be.
3. The data the app processes
a) The shop’s team
To open a seller session and attribute each sale to the right person, the app receives from the back office: each seller’s name, their role (cashier, manager…) and, if they have one, their badge number.
The app does not know a seller’s PIN code: it only receives a cryptographic fingerprint of it (bcrypt), which lets it verify the code without ever storing or transmitting it in the clear.
The Belgian national registry number (NISS) appears in one case only: a shop subject to the registered cash register system (SCE/GKS, the hospitality sector’s fiscal “black box”), where the law requires each user of the till to identify themselves to the fiscal module. Outside that regime, the national number never reaches the device: the field is not transmitted at all — not sent empty, not sent.
- Why: running the till, and, under the fiscal regime, meeting the legal identification duty.
- Legal basis (the merchant’s): performance of the employment contract (art. 6.1.b GDPR) and, for the national number, the legal obligation (art. 6.1.c).
b) Delivery customers
When the shop uses delivery rounds, the driver’s phone receives, for each stop: the customer’s name, address and phone number, the order references and, where present, the message accompanying a gift parcel.
- Why: delivering to the right address, and being able to reach the customer at the door.
- Legal basis (the merchant’s): performance of the customer’s order (art. 6.1.b).
c) Delivery proof photos
At the door, the driver may photograph the spot where a parcel was left, or damaged goods, as proof attached to the delivery note. The photo is taken with the camera, never from the gallery: the app has no access whatsoever to the phone’s personal photos. The instruction shown to the driver: photograph the place or the goods — not people.
- Why: proving the delivery if it is disputed.
- Legal basis (the merchant’s): their legitimate interest in proving delivery (art. 6.1.f).
d) Diagnostic data
When the app hits an error, a technical report goes to our monitoring tool (Sentry). That report is configured as soberly as possible:
- the tool’s default sending of personal data is switched off;
- the only “user” attached to a report is the terminal identifier — a machine, not a person;
- a filter strips everything else from the report before it is sent.
A report contains: the error, the app version, the device model and its OS version, the terminal identifier. It contains no sale, no name, and nothing typed on screen.
- Why: knowing the app has a problem before someone has to tell us.
- Legal basis: our legitimate interest in keeping the software working (art. 6.1.f). Controller: us.
4. What the app does not do
- No advertising, no advertising SDK, no advertising identifier.
- No selling, renting or exchanging of data. To anyone, ever.
- No trackers, no analytics, no user profiling.
- No access to the phone’s contacts, location, microphone or photo gallery. The camera serves only for delivery proof, at the moment the driver asks for it.
- No automated decisions about people.
5. Where the data lives, and how it is protected
- On the device: in an encrypted database (SQLCipher). The encryption key never leaves the device’s secure chip (Keystore on Android, Secure Enclave on iOS).
- Out of backups: the app’s data is excluded from OS backups and from device-to-device transfers.
- In transit: exclusively over HTTPS, between the device and the shop’s back office.
- On the servers: the back office is hosted at Scaleway (Online SAS), serveurs situés en France.
6. For how long, and how to delete
Team and customer data is managed in the merchant’s back office. Removing a seller, correcting or deleting a customer record: that is where it happens, and the change reaches the terminals at the next synchronisation. What the app keeps on the device is only a working copy.
Two limits, set by law rather than by us:
- the till journal is an accounting and fiscal record: the merchant must keep it for as long as Belgian accounting and tax law requires;
- that journal is immutable by design: deleting a customer record does not erase past sales — it is a ledger, not a profile.
Diagnostic reports are kept for 90 days by our monitoring tool, then deleted.
Uninstalling the app deletes the encrypted local database from the device.
7. Your rights
If you work in a shop that uses kwitto, or if you are a customer of such a shop: your rights of access, rectification, erasure, restriction and objection are exercised with the merchant, who is the controller of your data. We assist them in answering, as the data processing agreement provides.
For the diagnostic data, for which we are the controller: write to bonjour@kwitto.be. We answer within a month.
If the answer does not satisfy you, you may turn to the Belgian Data Protection Authority:
Autorité de protection des données / Gegevensbeschermingsautoriteit — Rue de la Presse 35, 1000 Brussels, Belgium contact@apd-gba.be — +32 (0)2 274 48 00 — dataprotectionauthority.be
8. Who else sees this data
| Provider | For what | Where the data is |
|---|---|---|
| Scaleway (Online SAS), serveurs situés en France | Hosting the back office the app synchronises with | France (European Union) |
| Sentry (Functional Software, Inc.) | Receiving the diagnostic reports — without personal data, see § 3.d | United States |
The transfer to Sentry is governed by the European Commission’s standard contractual clauses and by the provider’s participation in the EU–US Data Privacy Framework.
We pass nothing to anyone else. Neither Apple nor Google receives shop data through the app; the app stores see what every store sees — the download.
9. Changes
We may evolve this statement. The date at the top indicates the latest version. If a change alters what the app does with data already collected, the merchants concerned are notified before it goes live.