Privacy Policy
Last updated: April 28, 2026
1. Who are we?
HandLit is a point-of-sale (POS) software published by Letservu, headquartered in Cameroon. We provide a mobile app, web dashboard and backend API to help merchants manage their sales, inventory and teams. Contact: customerservice@handlitpos.tech
2. Data we collect
When you register and use HandLit, we collect: • Account information: name, email address, phone number, country code, store name, city, business type. • Sales data: recorded transactions, products, amounts, payment methods. • Subscription payment data: Mobile Money or card transaction references — we never store full card numbers. • Technical data: IP address, device type, access logs for security and debugging purposes.
3. Purposes of processing
Your data is used to: • Provide and maintain the HandLit service. • Manage your subscription and process payments. • Send you service notifications (trial expiry, renewal). • Respond to your support requests. • Improve our products and detect fraud. We never sell your data to third parties.
4. Sharing with third parties
We share data only with providers necessary to deliver the service: • CamPay — MTN MoMo and Orange Money payment processing (Cameroon). • Flutterwave — card payments for the diaspora. • Paystack — payments in Nigeria. • Amazon Web Services (AWS SES) — transactional email delivery. • Supabase — PostgreSQL database hosting. Each provider is subject to their own privacy obligations.
5. Data retention
Your account data is retained as long as your account is active. Upon account deletion, your data is deleted within 90 days, unless required by law. Transaction data may be retained longer for accounting purposes.
6. Your rights
You have the following rights: • Access: obtain a copy of your data. • Rectification: correct inaccurate data. • Deletion: request deletion of your account and data. • Portability: receive your data in a structured format. To exercise these rights, contact us at customerservice@handlitpos.tech.
7. Security
We use TLS encryption for all communications, hashed passwords (bcrypt), time-limited JWT tokens, and strictly role-limited data access. Despite these measures, no system is infallible.
8. Changes
We may update this policy at any time. For material changes, we will notify you by email or via the app. The last updated date is shown at the top of this page.
9. Contact
For any questions about this policy: HandLit — customerservice@handlitpos.tech www.handlitpos.tech