Privacy Policy
Last Updated: April 3, 2026
Welcome to Cora! Your privacy and the security of your business data are our highest priorities. This Privacy Policy explain how we collect, protect, and use your data across the Cora platform.
1. Data We Collect
- Merchant Information: Business name, email, and billing details provided during registration.
- Transactional Data: Details of sales processed through the POS (excluding full credit card numbers—these are handled by integrated payment terminals).
- Inventory Data: Product catalog, stock levels, and supplier information.
- Staff Logs: Names, emails, role assignments, and timeclock entries of your employees.
2. Tenant Data Isolation
Cora is built on a multi-tenant architecture. Your merchant data is logically isolated from the data of other merchants. We use dedicated organizational IDs and secure API endpoints to ensure that no business can ever access, view, or modify the data of another business.
3. How We Use Data
We use your data solely to provide the Service, including:
- Generating your dashboard analytics and reports.
- Processing your subscription payments.
- Providing support and troubleshooting system issues.
- Syncing inventory across your multiple locations.
We do not sell your data to third parties.
4. Data Security
Cora uses industry-standard security protocols to protect your data, including:
- SSL/TLS encryption for all data in transit.
- AES-256 encryption for data at rest.
- Secure API authentication and regular infrastructure health audits.
5. Your Rights
You have the right to access, edit, or request the deletion of your account and merchant data at any time. To request a full data export or account closure, please contact us at support@cora-pos.co.za.
6. Cookies and Tracking
We use essential cookies to maintain your login session and improve platform performance. We do not use intrusive tracking or third-party advertising cookies within the POS environment.