Privacy policy
What we do, and do not do, with personal data on this website.
Privacy policy
This website sets no cookies, runs no analytics and carries no advertising or tracking. It does now take orders: a business can configure and buy a Success POS subscription here, and that means there is more to describe than there was. This policy describes exactly what happens when you visit the site, when you contact us, and when you order.
Who is responsible
The controller of the personal data described below is:
Success Payment S.A.
40D Rue de Clairefontaine, L-8460 Eischen, Luxembourg
RCS Luxembourg B299168 · VAT LU36855607
contact@success-payment.com ·
+352 28 14 01 01
For any question about personal data, including to exercise the rights set out below, write to dpo@success-payment.com.
Where this policy does not apply
Success POS is a till system. The information a restaurant records in it about its own staff and its own guests belongs to that restaurant, not to us: the restaurant decides what goes in and why, and we process it only on its instructions. For that data the restaurant is the controller and we are its processor, and the terms that govern it are the Success POS Data Processing Terms, not this policy.
This policy covers the personal data we decide about ourselves: visitors to this website, people who contact us, and the businesses that order from us.
What this website still does not do
- No analytics. No Google Analytics, no Google Tag Manager, no Meta Pixel, no Hotjar, no Matomo, and no other measurement or session-recording tool.
- No cookies. None at all, and therefore no advertising, marketing or tracking cookies.
- No card details on this website. Payment card numbers are entered on our payment provider's own secure page, never on a page we serve. We never see, receive or store a full card number.
- No profiling and no automated decision-making.
- No selling or sharing of personal data with third parties for their own purposes.
What we collect, and why
1. When you contact us
If you email us, telephone us, or ask for a demonstration, we process what you choose to tell us. That is typically your name, your email address, your telephone number, the company you work for, and whatever you write in your message.
Purpose: to answer you, and if the conversation goes further, to prepare a possible contract.
Legal basis: Article 6(1)(b) GDPR, for steps taken at your request before entering into a contract; and Article 6(1)(f) GDPR, our legitimate interest in responding to business enquiries.
Retention: for as long as the exchange is live, and afterwards for up to two years so that we have a record of what was said. Where an enquiry leads to a contract, the correspondence is kept for the duration of the business relationship and then for the periods required by Luxembourg accounting and commercial law.
2. When you configure a Success POS order
The Success POS page lets you build a configuration and buy it. The first step asks who you are, and we receive those details as soon as that step is complete, whether or not you go on to order. Saying so here is the point: it would be easy to leave it out, and it would be misleading.
What we receive at that point is the restaurant name, the company name, the contact name, the email address, the telephone number and the country you entered, together with the configuration you were looking at and the language you were reading in. Your IP address is recorded with it.
Purpose: to prepare and follow up a possible order, and to contact you if you left part-way through.
Legal basis: Article 6(1)(b) GDPR, for steps taken at your request before entering into a contract; and Article 6(1)(f) GDPR, our legitimate interest in following up a business enquiry that was deliberately started with us. This is not consent, and we do not present it as consent.
Retention: up to two years from the last contact, unless the enquiry becomes an order, in which case it follows the retention below. You can ask us to delete it sooner.
Those details are recorded in our own sales system, which is operated by us and runs on the same European infrastructure as the rest of the service. They are not passed to an outside sales or marketing provider.
3. When you place an order
To create an order we process the details above, plus the VAT number and the delivery address where you give them, the configuration you selected, and the amounts calculated by us for that configuration. We generate an order reference and keep an internal record of the order.
Purpose: to enter into and perform the contract, to deliver and install the equipment, to invoice you and to support you afterwards.
Legal basis: Article 6(1)(b) GDPR, performance of a contract with you or your company; and Article 6(1)(c) GDPR for the invoicing and record-keeping the law requires of us.
Retention: for the duration of the business relationship, and afterwards for the ten-year period Luxembourg commercial and accounting law requires for records of that kind.
4. Evidence that you accepted the terms
Before an order can be placed you must tick a box confirming that you accept the Success POS General Terms and Conditions. A contract concluded by a click has to be provable, so we record what was accepted and by whom.
That record contains: the order reference; the identifier, version, effective date and content fingerprint of the terms; the exact sentence you were shown and the language it was shown in; the moment of acceptance in UTC; your company, restaurant, contact name and email address; and the IP address and browser user-agent string of the request that placed the order. We keep a copy of the order as it stood when you accepted it.
Purpose: to be able to prove which terms were agreed, when, and by whom, if that is ever disputed.
Legal basis: Article 6(1)(f) GDPR, our legitimate interest in holding evidence of a contract we concluded electronically. The IP address and user-agent string are kept for that reason and for no other: they are not used to identify, follow or profile anyone.
Retention: for the duration of the contract and afterwards for as long as a claim under it could still be brought. This record is deliberately written once and never altered, so it cannot be corrected after the fact; if it were editable it would not be evidence.
5. Payment
Payment and subscription billing are carried out for us by Stripe. When you continue to payment you are taken to a page hosted by Stripe, where you enter your card details. Those details go to Stripe, not to us. We do not receive, process or store a card number, an expiry date or a security code at any point.
So that Stripe can take the payment and issue the right invoices, we send it your email address, your order reference, the products and amounts, and a short set of references identifying the plan, the pricing version and the version of the terms you accepted. Your company name, restaurant name and contact name are included with those references. Stripe collects your billing address and, if you provide one, your VAT number, directly from you on its own page. Stripe tells us whether the payment succeeded, and sends us the subscription and invoice references, but never the card details.
Purpose: to take payment and to run the subscription.
Legal basis: Article 6(1)(b) GDPR, performance of the contract. Stripe also processes some of this data as a controller in its own right, to meet its own legal obligations under Article 6(1)(c) GDPR, including anti-money-laundering and fraud prevention duties; for that processing Stripe's own privacy notice applies.
Retention: our copy of the payment references is kept with the order. What Stripe keeps is governed by Stripe.
6. When you simply visit a page
Our hosting provider, Eashost, records standard server logs when a page is served. These may include your IP address, the time of the request, the page requested, and your browser's user-agent string. The ordering service records equivalent technical logs, which are deliberately built to exclude the contents of a request so they cannot become a second copy of your data.
Purpose: to deliver the website and the ordering service, keep them available, and protect them against abuse. We do not use these logs to identify or follow visitors, and we do not combine them with anything else.
Legal basis: Article 6(1)(f) GDPR, our legitimate interest in operating a secure and available service.
Retention: the limited period applied by the hosting provider for the website; up to twelve months for the ordering service's own logs.
7. Technical storage on your device
This website does not set cookies. Where a purely functional preference needs to be remembered on your device, such as a language choice or the configuration you were building, it is stored locally in your browser, is never transmitted to us for any other purpose, and is used for nothing else. Storage of that kind is strictly necessary to provide the functionality you asked for, so it does not require your consent, and it is not used for analytics or advertising.
Because there is no non-essential storage and no tracking, this website shows no cookie banner. If that ever changes, we will ask for your consent before anything non-essential is stored, and this policy will be updated before the change goes live.
Who else sees your data
These parties process personal data for us, on our instructions and for no purpose of their own, except where noted:
- Eashost, our website hosting provider, which processes server logs on our behalf.
- Amazon Web Services, which hosts the ordering and billing service. It runs in the Europe (Frankfurt) region, and that restriction is enforced by policy on our accounts rather than left to configuration.
- Stripe, for payment and subscription processing, as described above. Stripe is also a controller in its own right for parts of that processing.
- Microsoft, our email provider, to the extent that a message you send us is necessarily received and stored.
We do not sell personal data and we do not share it with anyone for their own marketing.
Transfers outside the EEA
The ordering and billing service runs in the European Union and its data does not leave it.
Two things reach providers that may process data outside the European Economic Area, and we would rather name them than imply there are none:
- Stripe. Payment processing is operated within a group that processes data outside the EEA. Where that happens it is covered by Stripe's own data processing terms and the European Commission's standard contractual clauses.
- Google Fonts. The typefaces this site uses are served by Google. Loading a page therefore sends your IP address and browser user-agent string to Google, which may process it outside the EEA under the European Commission's standard contractual clauses. No cookie is set and nothing about you is stored by us as a result. We rely on Article 6(1)(f) GDPR for it, our legitimate interest in serving the site as designed. We are looking at serving the fonts ourselves so that this transfer stops happening at all.
Your rights
Under the GDPR you have the right to:
- ask what personal data we hold about you and receive a copy of it (access);
- have inaccurate data corrected (rectification);
- have data deleted where we no longer have a reason to keep it (erasure);
- ask us to restrict how we use it;
- object to processing we carry out on the basis of our legitimate interest;
- receive the data you gave us in a portable, machine-readable format.
Those rights are not unlimited. Where we must keep something to meet an accounting obligation, or to preserve evidence of a contract you entered into, we will say so and explain why rather than delete a record we are required or entitled to keep.
To exercise any of these, write to dpo@success-payment.com. We will respond within one month.
If you are not satisfied with our answer, you may lodge a complaint with the Luxembourg supervisory authority, the Commission nationale pour la protection des données (CNPD), 15 Boulevard du Jazz, L-4370 Belvaux, Luxembourg.
Security
This website and the ordering service are served over an encrypted connection. Order records, the evidence of accepted terms and the operational logs are encrypted where they are stored, using keys we control. Access is limited to the people who need it. Enquiry correspondence is kept to the people who need it in order to answer you.
The measures applying to the Success POS service itself are set out in Annex 2 of the Success POS Data Processing Terms.
Changes to this policy
If this website starts doing something new with personal data, this policy will be updated before that change goes live, not after it.
Last updated: 29 August 2026.