Privacy Policy
Last updated: 9 June 2026
1. Who we are
easyKiosk is a commerce operating system for businesses. It may include point of sale, EPOS, self service kiosks, SoftPOS, card terminal connectivity, online ordering, QR ordering, stock management, reporting, loyalty, CRM, hotel PMS, integrations, AI tools, marketing tools, delivery connections and related services.
The service is operated by Multi Channel Creative Ltd trading as easyKiosk. In this Privacy Policy, “easyKiosk”, “we”, “us” and “our” means Multi Channel Creative Ltd and any relevant trading names used in connection with easyKiosk.
- Company: Multi Channel Creative Ltd
- Trading name: easyKiosk
- Address: 25 Station Road, Office 5, Kings Heath, Birmingham, B14 7SR, United Kingdom
- Email: [email protected]
- ICO registration reference: ZB394739
2. Purpose of this Privacy Policy
This Privacy Policy explains how we collect, use, store, share and protect personal data when people use our websites, applications, merchant portals, payment related services, integrations, support services and related products.
It applies to:
- Merchants and business customers who sign up to easyKiosk.
- Staff, users, administrators and authorised users of merchant accounts.
- Customers of merchants where easyKiosk processes customer information on behalf of the merchant.
- Website visitors and people who contact us.
- Suppliers, partners, integration providers and prospective customers.
- Applicants who apply to work with us or become partners, where relevant.
3. Controller and processor roles
Depending on the activity, we may act either as a data controller or as a data processor.
3.1 Where we act as controller
We usually act as controller when we decide why and how personal data is used. This includes data used for merchant signup, account administration, billing, customer support, sales, marketing, fraud prevention, website analytics, security, legal compliance and service improvement.
3.2 Where we act as processor
We usually act as processor when we process personal data on behalf of a merchant using the easyKiosk platform. This may include customer names, contact details, order history, loyalty data, delivery details, booking details, table orders, hotel guest related data, CRM records and similar data entered into the system by the merchant or generated through the merchant’s use of the platform.
Where we act as processor, the merchant is responsible for telling its customers and staff how their data is processed and for having a lawful basis for the processing. Our processing will be governed by our agreement with the merchant and any applicable data processing terms.
4. Personal data we collect
The personal data we collect depends on how the service is used. It may include the following categories.
| Category | Examples |
|---|---|
| Identity data | Name, business name, job title, username, account owner details and authorised user details. |
| Contact data | Email address, telephone number, postal address, billing address and support contact details. |
| Business data | Company number, VAT number, trading address, store locations, sector, opening hours, staff roles, merchant settings and business profile information. |
| Account data | Login details, permissions, account preferences, subscription plan, product usage and security settings. |
| Payment and billing data | Invoices, billing history, transaction references, subscription status, chargeback or dispute data. We do not normally store full card numbers where payments are handled by payment providers. |
| Transaction and order data | Orders, refunds, products, services, baskets, table orders, bookings, loyalty activity, receipts, delivery details and fulfilment information. |
| Customer and CRM data | Customer names, contact details, preferences, loyalty points, marketing preferences, order history and notes added by merchants. |
| Device and technical data | IP address, device type, operating system, browser type, app version, device identifiers, logs, crash reports and security events. |
| Location data | Store location, delivery location, parcel shop or locker location, approximate location derived from IP address and any precise location only where enabled and necessary. |
| Communications data | Emails, support tickets, calls, chat messages, meeting notes, feedback, surveys and correspondence. |
| Marketing data | Marketing preferences, campaign engagement, website forms, event attendance and responses to communications. |
| AI and content data | Prompts, generated outputs, campaign drafts, product descriptions, summaries, analytics requests and other content processed through AI features. |
5. How we collect personal data
- Directly from merchants, users, customers, partners and website visitors.
- When an account is created or a merchant signs up.
- When someone uses the website, dashboard, apps, EPOS, kiosk, QR ordering, payment, delivery or integration features.
- From payment providers, app stores, integration providers, delivery providers, hardware providers and commerce platforms.
- From cookies, analytics tools, logs and similar technologies.
- From support requests, demos, sales enquiries, events and communications.
- From publicly available sources, business directories, Companies House, social media and professional networks where lawful and relevant.
6. How we use personal data and lawful bases
Under UK data protection law, we must have a lawful basis for using personal data. The table below summarises common purposes and lawful bases. The exact lawful basis may depend on the context and the relationship we have with the individual.
| Purpose | Examples | Lawful basis |
|---|---|---|
| Account setup and administration | Creating accounts, verifying users, managing subscriptions and providing access. | Contract, legitimate interests and legal obligation where applicable. |
| Providing the platform | Operating POS, EPOS, ordering, loyalty, CRM, delivery, reporting, integrations and AI tools. | Contract and legitimate interests. Where acting as processor, the merchant’s lawful basis applies. |
| Billing and payments | Invoices, subscriptions, receipts, refunds, failed payments, disputes and payment provider connections. | Contract, legitimate interests and legal obligation. |
| Support and service communications | Responding to enquiries, troubleshooting, training and account notices. | Contract and legitimate interests. |
| Security and fraud prevention | Monitoring abuse, protecting accounts, preventing unauthorised access and investigating suspicious activity. | Legitimate interests and legal obligation. |
| Product improvement | Analysing usage, fixing bugs, improving performance and developing new features. | Legitimate interests. Consent where required for non essential cookies or similar technologies. |
| Marketing | Sending product updates, offers, partner news and event invitations. | Consent or legitimate interests depending on the recipient and communication type. PECR rules may also apply. |
| Legal and regulatory compliance | Tax, accounting, law enforcement requests, disputes, regulatory obligations and record keeping. | Legal obligation, legitimate interests and establishment or defence of legal claims. |
| AI features | Generating content, summaries, recommendations, analytics and campaign ideas. | Contract and legitimate interests. Where merchant customer data is used, we may act as processor. |
7. Merchant customer data
Merchants may use easyKiosk to process information about their own customers. This may include order details, delivery details, loyalty records, marketing preferences, CRM notes, bookings, receipts and customer support information.
In most cases, the merchant is the controller of this data and easyKiosk is the processor. Merchants must ensure that their own privacy notices explain how they use easyKiosk and any connected providers. Merchants must not upload or process personal data through easyKiosk unless they have the right to do so.
We may process merchant customer data only to provide, secure, support and improve the service, to comply with law, to follow merchant instructions, or as otherwise permitted under our contract with the merchant.
8. Payments, SoftPOS and financial providers
easyKiosk and related products may connect with payment providers and financial technology partners, including providers of online payments, SoftPOS, Tap to Pay, card terminals, pay by link and payment processing services.
Payment providers may act as independent controllers for some processing, particularly where they carry out onboarding, know your customer checks, fraud prevention, compliance, payment processing, disputes and settlement. Their own privacy policies and terms will apply.
We do not normally store full card numbers or sensitive payment authentication data where payment processing is handled by regulated payment providers. Tokenised references, transaction IDs, status information and limited payment data may be processed to operate the service.
9. Integrations and third party services
easyKiosk may integrate with third party services such as payment providers, delivery platforms, ecommerce platforms, marketplace connectors, inventory tools, accounting tools, app stores, hardware manufacturers, analytics providers, communication providers and AI service providers.
Examples may include Stripe, Worldpay, NatWest, Elavon, Global Payments, Worldline, Shift4, Ingenico, Phos, Verifone, PAX, Castle, SUNMI, iMin, Epson, Star Micronics, Linnworks, Deliverect, Google, Apple, Visa, Mastercard and other providers used from time to time.
Where a merchant enables an integration, relevant data may be shared with that provider to deliver the requested functionality. Merchants are responsible for reviewing and approving any integrations they connect to their account.
10. AI features
easyKiosk may include AI powered tools to help merchants generate content, create campaigns, analyse data, summarise information, build product descriptions, improve customer engagement and support business decisions.
Users should not submit unnecessary personal data, special category data, payment card details, passwords or confidential information into AI prompts unless the feature is specifically designed and approved for that purpose.
Where AI features use third party AI providers, data may be shared with those providers subject to contractual safeguards. We will aim to configure AI providers so that customer data is not used to train public models unless we have a lawful basis and appropriate permissions.
11. Cookies and similar technologies
Our websites and apps may use cookies, pixels, SDKs, local storage and similar technologies. These may be used to keep the site working, remember preferences, analyse performance, improve services, prevent fraud and support marketing.
Strictly necessary technologies may be used without consent where they are required to provide the service requested. Analytics, advertising and other non essential technologies will be used only where we have the required consent or another lawful basis where permitted.
Users can manage cookie choices through our cookie banner or settings tool where available. Browser settings may also allow users to block or delete cookies, although some service features may not work properly if necessary cookies are disabled. See our Cookie Policy for more detail.
12. Direct marketing
We may send marketing communications about easyKiosk, easyPay, easyDelivery, easyMarketing, related products, partner offers, events and service updates.
Where consent is required, we will ask for it. Where permitted, we may rely on legitimate interests for business to business marketing or soft opt in rules for existing customer relationships. Recipients can unsubscribe or opt out at any time by using the link in our messages or contacting us.
13. When we share personal data
We may share personal data with:
- Payment providers, acquiring banks, SoftPOS providers, card terminal providers and financial technology partners.
- Delivery, courier, parcel, locker and fulfilment providers.
- Ecommerce, marketplace, inventory, accounting, marketing, CRM and integration providers.
- Hosting, cloud, database, security, monitoring, email, SMS, WhatsApp, analytics and support providers.
- AI service providers where AI features are used.
- Professional advisers, insurers, auditors, accountants and legal representatives.
- Regulators, tax authorities, courts, law enforcement and public authorities where required or permitted by law.
- Potential investors, buyers, sellers, group companies or advisers in connection with a business sale, investment, restructuring or corporate transaction.
- Merchants and authorised users connected to the relevant account.
14. International transfers
We may process or transfer personal data outside the United Kingdom where our suppliers, partners, cloud providers or support teams are based in other countries. Where required, we will use appropriate safeguards such as adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or other lawful transfer mechanisms.
15. Data retention
We keep personal data only for as long as necessary for the purposes described in this policy, including providing the service, meeting legal, accounting and tax obligations, resolving disputes, enforcing agreements, maintaining security and improving the platform.
Typical retention periods may include:
- Merchant account data for the life of the account and for a reasonable period afterwards.
- Billing, invoice, tax and accounting records for up to 6 years or longer where required by law.
- Support records for as long as needed to resolve the issue and maintain business records.
- Security logs for a limited period unless needed for investigation or legal purposes.
- Marketing data until the person opts out or the data is no longer needed.
- Merchant customer data in accordance with the merchant’s instructions, account settings, contract and applicable retention rules.
Where we cannot specify a fixed period, we decide retention by considering the nature of the data, the purpose, legal requirements, risk, user expectations and whether the data can be anonymised.
16. Security
We use appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure. These may include access controls, encryption, secure hosting, monitoring, backups, audit logs, staff training and supplier due diligence.
No system is completely secure. Merchants and users must keep login details confidential, use strong passwords, restrict account permissions and notify us promptly if they suspect unauthorised access.
17. Individual rights
Depending on the circumstances and the lawful basis for processing, individuals may have the right to:
- Access their personal data.
- Correct inaccurate personal data.
- Request deletion of personal data.
- Restrict processing.
- Object to processing.
- Request data portability.
- Withdraw consent where processing is based on consent.
- Complain to the Information Commissioner’s Office.
Requests can be sent to [email protected]. We may need to verify identity before responding. Some rights may be limited where we act as processor for a merchant, where legal obligations apply, or where the request affects the rights of others.
Individuals also have the right to complain to the UK Information Commissioner’s Office at www.ico.org.uk.
18. Children
easyKiosk is intended for business users and is not directed at children. Merchants must not knowingly use easyKiosk to collect children’s personal data unless they have appropriate authority, a lawful basis and any required safeguards.
19. Automated decision making
We may use automated systems to support fraud prevention, security monitoring, risk checks, account protection, product recommendations and operational insights. We do not intend to make solely automated decisions that produce legal or similarly significant effects on individuals unless this is necessary, authorised by law, based on explicit consent, or covered by appropriate safeguards.
20. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The latest version will be published on our website. Where changes are significant, we may notify merchants or users by email, dashboard notice or another appropriate method.
21. Contact us
Questions about this Privacy Policy or how personal data is handled should be sent to:
- Privacy contact: [email protected]
- Postal address: Multi Channel Creative Ltd trading as easyKiosk, 25 Station Road, Office 5, Kings Heath, Birmingham, B14 7SR, United Kingdom
- ICO registration reference: ZB394739