Security at POS-Sync

See how POS-Sync
protects your account.

How access, customer changes and recovery work in POS-Sync today.

Product safeguards

Control access and see what changed.

Provider sign-in

POS-Sync encrypts provider access tokens before storing them. It keeps them out of support views, analytics and ordinary logs. Only one refresh can run for a connection at a time.

Who can see your data

POS-Sync checks access for every organisation and workspace request. Organisation owners can access their workspaces. Other members need access to a specific workspace. Requests for another organisation’s data are denied.

Before changes go live

New connections start read-only. A verified owner reviews imported customers, where shared details come from, delete settings and costs. Live sync starts after a five-minute cancellation window. A pause stops changes from being sent.

When a sync fails

POS-Sync queues changes and retries failed work a limited number of times. If it still fails, the issue appears in the dashboard. Before retrying an uncertain customer creation, POS-Sync checks whether the provider already created it.

Change history and support

POS-Sync records customer, team, billing and support recovery changes. Support can see IDs and a summary of an issue, but not provider credentials or customer record details.

Operations

POS-Sync is designed to run over HTTPS with encrypted backups and monitored background jobs. Production release still requires the deployment, restore and alert checks in the release procedure.

Have a security question?

Contact POS-Sync →Do not send credentials or customer records.