SmartEPOS Dashboard – Privacy Policy
Last updated: 11 August 2026
1. About this Privacy Policy
This Privacy Policy applies specifically to the SmartEPOS Dashboard ("the Dashboard"), an internal business application operated by Smart Epos Limited ("Smart EPOS", "we", "our" or "us").
The Dashboard is intended solely for authorised Smart EPOS employees and is used to access, organise, analyse and present information relating to Smart EPOS's own business operations.
This Privacy Policy supplements the general Smart EPOS Privacy Policy available on the Smart EPOS website.
The Dashboard is not provided to Smart EPOS customers or members of the public.
2. Who We Are
Smart Epos Limited is a company registered in England and Wales under company number 09292144.
For questions concerning this Privacy Policy or the handling of information through the Dashboard, please contact:
Email: info@smartepos.co.uk
Website: www.smartepos.co.uk
3. QuickBooks Online Integration
The Dashboard connects exclusively to Smart EPOS's own QuickBooks Online account using the QuickBooks API provided by Intuit.
This connection enables authorised Smart EPOS employees to retrieve and view relevant accounting and business information through the Dashboard for internal management, reporting and administrative purposes.
The Dashboard is not designed to connect to QuickBooks accounts belonging to Smart EPOS customers or other third parties.
4. Information Accessed from QuickBooks
Depending on the Dashboard functionality being used, information accessed from Smart EPOS's QuickBooks Online account may include:
-
invoices;
-
sales and payment information;
-
expenses and purchases;
-
customer and supplier records;
-
transaction information;
-
account balances;
-
profit and loss information;
-
financial reports; and
-
other accounting or operational information made available through the QuickBooks API.
Some records held within QuickBooks may contain personal data, such as the names and contact details of customers, suppliers or other business contacts.
The Dashboard is intended to access only information reasonably necessary for its internal business functions.
5. How We Use QuickBooks Information
Information obtained through the QuickBooks API may be used to:
-
provide internal financial and management reporting;
-
aggregate accounting and operational information;
-
analyse business performance;
-
produce internal dashboards, summaries and statistics;
-
assist with reconciliation and financial administration;
-
identify trends, changes or discrepancies;
-
support management decision-making; and
-
reduce manual administrative work.
Information accessed through the Dashboard is used solely for legitimate Smart EPOS business purposes.
6. QuickBooks Authorisation and OAuth
The Dashboard uses Intuit's OAuth 2.0 authorisation framework to establish an authorised connection with Smart EPOS's QuickBooks Online account.
Following authorisation, Intuit provides the application with OAuth credentials which allow the Dashboard to make authorised requests to the QuickBooks API.
OAuth credentials, including access and refresh tokens where applicable, are stored securely as application runtime environment variables and are not embedded within publicly accessible application source code or intentionally exposed to users of the Dashboard.
The Dashboard does not store the password used to access Smart EPOS's QuickBooks Online account.
Access to QuickBooks through the Dashboard is limited to the permissions authorised through Intuit's OAuth process.
7. Storage and Processing of QuickBooks Data
The Dashboard retrieves information from QuickBooks through the QuickBooks API when that information is required for its functionality.
QuickBooks remains the underlying accounting platform and primary source of the accounting information accessed by the Dashboard.
The Dashboard is not intended to create or maintain a separate permanent copy of Smart EPOS's complete QuickBooks accounting database.
Information retrieved through the API may necessarily be processed temporarily within application memory, application state or temporary storage while requests, calculations, reports or Dashboard views are being generated.
Smart EPOS aims to minimise the amount of QuickBooks information retained separately from QuickBooks and does not retain such information for longer than reasonably necessary for the operation, security, maintenance or troubleshooting of the Dashboard or to satisfy applicable legal obligations.
8. Application Architecture and Access
The Dashboard operates as a private internal Smart EPOS application.
It is not offered as a publicly accessible software service and is not intended to provide access to Smart EPOS customers or members of the public.
Access to the Dashboard is restricted to authorised Smart EPOS personnel.
QuickBooks API credentials and OAuth tokens are maintained within the application's protected runtime configuration rather than being embedded in client-side code or publicly accessible source code.
If the hosting architecture, accessibility or purpose of the Dashboard materially changes in the future, Smart EPOS will review this Privacy Policy and its associated security and data-protection arrangements.
9. Software Development and AI-Assisted Development Tools
Smart EPOS may use software development tools, including AI-assisted software development tools, to assist with developing, reviewing, testing or maintaining the Dashboard.
The use of such development tools does not mean that information retrieved from QuickBooks is automatically transmitted to those services.
The Dashboard is not currently designed to transmit QuickBooks accounting data to OpenAI, ChatGPT, Codex or another generative artificial intelligence service as part of its normal operation.
If Smart EPOS introduces functionality in the future which intentionally submits QuickBooks information to an external artificial intelligence or machine-learning service for processing, Smart EPOS will review the relevant privacy, security and contractual requirements before introducing that functionality and will update this Privacy Policy where appropriate.
10. Lawful Basis for Processing
Where information accessed through the Dashboard constitutes personal data, Smart EPOS processes that information under the lawful basis appropriate to the underlying business activity.
These may include:
Contractual necessity – where processing is necessary in connection with a contract with a customer, supplier or other party.
Legal obligation – where processing is required to comply with accounting, taxation or other legal obligations.
Legitimate interests – where processing is necessary for legitimate business purposes including financial management, administration, reporting, business analysis, security, fraud prevention and improving internal processes, provided those interests are not overridden by the rights and interests of the individual concerned.
The Dashboard provides an additional internal means of accessing and analysing information already processed by Smart EPOS and does not, by itself, change the underlying purpose for which that information was originally collected.
11. Sharing of Information
Information accessed through the Dashboard is not sold.
Information may be processed by or disclosed to third parties where reasonably necessary for the operation of Smart EPOS's accounting systems, the provision of professional services or compliance with applicable law.
In particular, the Dashboard relies upon Intuit Inc. and its associated companies, as the provider of QuickBooks Online and the QuickBooks API.
Relevant accounting information may also be accessible to professional advisers or service providers where necessary for services provided to Smart EPOS, including accountants, auditors, legal advisers or authorised IT support providers.
Any such access is subject to applicable contractual, confidentiality and data-protection requirements.
12. Security
Smart EPOS takes reasonable technical and organisational measures to protect information accessed through the Dashboard.
These measures include, where appropriate:
-
restricting Dashboard access to authorised Smart EPOS personnel;
-
using Intuit's OAuth 2.0 authorisation framework rather than storing QuickBooks account passwords;
-
storing API credentials, client secrets and OAuth tokens within protected application runtime environment variables rather than application source code or client-side storage;
-
restricting access to systems and devices on which the Dashboard operates;
-
applying appropriate operating-system, network and device security;
-
limiting access to information according to business need;
-
maintaining appropriate authentication and access controls; and
-
reviewing or removing access where employees leave Smart EPOS or no longer require access to the Dashboard.
No computer system can be guaranteed to be completely secure. Smart EPOS takes measures proportionate to the nature and sensitivity of the information being processed.
13. Data Retention
The primary accounting records accessed by the Dashboard remain subject to Smart EPOS's normal accounting, taxation, legal and business retention requirements and the retention arrangements applicable within QuickBooks Online.
The Dashboard is designed to minimise unnecessary separate retention of information retrieved from QuickBooks.
Temporary information generated during use of the Dashboard will be removed, overwritten or otherwise cease to be retained when it is no longer reasonably required, subject to legitimate security, troubleshooting or legal requirements.
OAuth credentials will be retained only while required to maintain the authorised QuickBooks connection.
If the QuickBooks integration is permanently discontinued, associated credentials will be removed when they are no longer required.
14. Disconnecting QuickBooks
Smart EPOS may disconnect the Dashboard from QuickBooks at any time.
The connection may be revoked through the applicable Intuit or QuickBooks account controls or by otherwise revoking the application's authorisation.
Once authorisation has been revoked, the Dashboard will no longer be able to make authenticated requests to the QuickBooks API unless Smart EPOS subsequently authorises a new connection.
OAuth credentials associated with a permanently discontinued connection will be removed from the application's protected runtime configuration when they are no longer required.
Disconnecting the Dashboard does not delete the underlying accounting records held within Smart EPOS's QuickBooks Online account.
15. International Data Transfers
QuickBooks Online is provided by Intuit and information processed through QuickBooks may be processed using infrastructure, companies or service providers located outside the United Kingdom.
Where personal data is transferred internationally, Smart EPOS will rely upon applicable safeguards and contractual arrangements and take reasonable steps to ensure that transfers are handled in accordance with applicable UK data-protection law.
16. Your Data Protection Rights
Where information processed through the Dashboard contains your personal data, you may have rights under the UK GDPR and Data Protection Act 2018.
Depending upon the circumstances, these may include the right to:
-
request access to your personal data;
-
request correction of inaccurate personal data;
-
request deletion of personal data in certain circumstances;
-
request restriction of processing;
-
object to certain processing;
-
request data portability where applicable; and
-
complain to the Information Commissioner's Office.
These rights are subject to the conditions and exemptions provided by applicable law, including requirements relating to the retention of accounting, taxation and other business records.
Requests concerning personal information can be made to:
17. Complaints
If you have concerns about how Smart EPOS handles your personal information, please contact us so that we can investigate.
You also have the right to make a complaint to the Information Commissioner's Office (ICO), the UK's independent data-protection regulator.
18. Changes to this Privacy Policy
Smart EPOS may update this Privacy Policy where the Dashboard, QuickBooks integration, application architecture, processing activities or applicable legal requirements change.
The current version will be published on the Smart EPOS website and the "Last updated" date at the beginning of this policy will be amended accordingly.
