Skip to main content
Last updated: July 22, 2026. This policy describes the personal data processing carried out by the NowOS point-of-sale app and its associated services.

Data controller

For user accounts, security, support, and improvement of NowOS, the data controller is: EATNOW, a French simplified joint-stock company with share capital of €500, registered with the Paris Trade and Companies Register under number 990 635 096, EU VAT number FR94990635096, with registered office at 60 rue François Ier, 75008 Paris, France. Data protection contact: privacy@eat-now.app. When NowOS processes customer, reservation, order, or sales data on behalf of a merchant using the service, that merchant remains the controller of this business data and EATNOW acts as its processor under the agreement entered into with the merchant.

Data we process

Depending on the features used, NowOS may process the following categories:
  • Account and permissions: name, work email address, internal identifier, role, organization, and assigned location;
  • Device and pairing: device identifier and name, model, operating system and app version, register role, connection status, and technical information required for local-network pairing;
  • Point-of-sale activity: catalog, orders, sales, payment amounts and tender types, refunds, business days, cash movements, stock, printing, and fiscal data;
  • Customers and reservations: name, telephone number, email address, reservation, visit history, prepayment, internal note and, when supplied, allergies or preferences;
  • Invoicing: personal or company name, address, email address, tax identifiers, and VAT number entered to issue an invoice;
  • Diagnostics and usage: pseudonymous technical identifiers, screens and actions used, operation durations, app version, performance, errors, crashes, and connectivity state;
  • Support: problem category, optional comment, and technical context attached to a report.
NowOS does not collect full payment-card numbers, perform advertising tracking, or use screen or audio recording. The camera is used only to scan pairing QR codes and product barcodes; images are not uploaded by this feature. We process this data to:
  • provide, secure, and maintain the service under the agreement with the merchant;
  • enable authorized users to work and allow the register to operate locally;
  • synchronize business data and preserve its integrity;
  • issue sales documents and comply with applicable fiscal and accounting obligations;
  • answer support requests and resolve incidents;
  • perform limited measurement of product reliability and usage in order to improve it, based on EATNOW’s legitimate interest in operating a safe and useful service.

Recipients and service providers

Data is available only to authorized people at the relevant merchant and, when necessary, authorized EATNOW personnel. EATNOW uses technical providers for hosting, update distribution, performance measurement, product analytics, and diagnostics, including Railway, Expo/EAS, PostHog, and Sentry. They receive only the data needed to perform their role and are subject to confidentiality and security obligations. Where data is processed outside the European Economic Area, EATNOW applies the safeguards required by applicable law, such as Standard Contractual Clauses or an adequacy decision.

Retention

  • Account and configuration data is retained for the duration of the contractual relationship and then for the periods needed to handle requests and legal obligations.
  • Sales, invoice, and compliance data is retained for the fiscal, accounting, and evidentiary periods applicable to the merchant.
  • Product analytics events, diagnostics, errors, and problem reports are retained for no more than 90 days during the pilot, unless a specific incident must be kept longer to resolve it or establish or defend legal rights.
  • Local register data remains on the device until it is synchronized, removed through an available deletion function, or the device is reset, subject to data that must be retained by law.
At the end of the service, data is deleted or returned as provided by the agreement, except where separate retention is required by law.

Security

NowOS combines protected local storage, encrypted communications, limited technical identifiers, access controls, and cryptographic signatures. No measure removes all risk; EATNOW maintains procedures designed to prevent, detect, and handle unauthorized access, loss, or alteration.

Your rights

Depending on your circumstances, you may request access, correction, deletion, restriction, or portability of your personal data and object to certain processing. You may also lodge a complaint with the French Data Protection Authority, the CNIL. For data managed by your employer or by a merchant with which you made a reservation or purchase, contact that merchant first. You may also email privacy@eat-now.app. EATNOW may request only the information necessary to verify your identity and locate the relevant data.

Changes

This policy may change as NowOS features or legal requirements evolve. The date at the top of the page identifies the current version.