Legal

Privacy Policy

This policy explains what personal data Umati Health Store collects, why we collect it, and what you can do about it. It covers both our online store at www.umatihealthstore.com and the Umati POS Android application (com.umati.pos).

Last updated 6 August 2026

Who we are

Umati Health Store is a retail health, wellness, and beauty business operating from Sifa Plaza, Kenyatta Avenue, Nakuru, Kenya. We are the data controller for the personal data described in this policy. You can reach us at info@umatihealthstore.com.

The Umati POS app

Umati POS is a point-of-sale application used by our own shop staff to ring up in-store sales, print receipts, and review daily takings. It is a staff tool, not a shopping app. It has no advertising, no analytics or tracking SDKs, and no third-party trackers of any kind.

The app does not collect customer names, phone numbers, addresses, payment card details, contacts, photos, location, or any device identifier used for advertising. A counter sale is recorded as a list of products, quantities, prices, a payment method, and a timestamp — it is not linked to the shopper.

What the app handlesWhy
Cashier name and account IDTo sign the cashier in and attribute each sale to the staff member who rang it up.
Cashier PINEntered on the device to sign in and verified on our server. The PIN is never stored on the phone and is held only in hashed form on the server.
Session tokenStored on the device so the cashier does not have to sign in again on every shift. Cleared on sign-out.
Sale recordsProducts, quantities, unit prices, discount, payment method (cash or M-Pesa), total, and time. Required for stock control, accounting, and tax records.
Product catalogue cacheA copy of product names, prices, images, and stock levels kept on the device so the till keeps working when the internet drops.
Queued offline salesSales made while offline are stored on the device only, then uploaded and deleted from the device once the connection returns.

The app requests three Android permissions, all of them network related, and none of which shows a permission prompt: INTERNET to reach our server, and ACCESS_NETWORK_STATE and CHANGE_NETWORK_STATE so it can open a connection to the receipt printer on the shop's local network. It asks for no access to your location, camera, microphone, contacts, photos, or files.

Receipt printing

Receipts are sent directly from the phone to a thermal printer on the shop's own local network using a standard raw printing connection. That traffic stays inside the shop network and never leaves it. Because raw network printing has no encryption of its own, we run it only on a private shop network and print only sale contents — never personal data.

The online store

If you shop with us at www.umatihealthstore.com, we collect what we need to fulfil your order:

  • Your name and email address when you create an account.
  • Your delivery details — name, town, area or landmark, and phone number — when you place an order.
  • Your order and cart contents.
  • Transactional SMS and email notifications about orders you have placed. We do not send marketing messages without your consent.

We do not process card payments on our website and we never store card numbers.

Where your data is stored

Data is stored in our Appwrite backend on infrastructure we control, and is transmitted over encrypted HTTPS connections. Access is limited to store administrators who need it to run the business. Cashiers can see only the sales data their role requires.

We use a small number of service providers strictly to deliver our service: an email delivery provider for order emails and an SMS gateway for order notifications. They receive only what is needed to deliver the message and may not use it for anything else. We do not sell or rent personal data to anyone.

How long we keep it

  • Sales and order records: retained for at least five years, as Kenyan tax law requires businesses to keep records supporting their returns.
  • Cashier accounts: kept while the person works with us, then deactivated and removed on request.
  • Customer accounts: kept until you ask us to delete them.
  • On-device caches in the POS app: cleared when the cashier signs out or the app is uninstalled.

Your rights

Under the Kenya Data Protection Act, 2019 you have the right to be informed about how your data is used, to access it, to have inaccurate data corrected, to object to processing, and to ask for deletion. To exercise any of these, email info@umatihealthstore.com and we will respond within 30 days.

See our data deletion page for how to request that an account and its data be removed.

Children

Neither our online store nor the Umati POS app is directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, contact us and we will delete it.

Security

Connections to our servers use HTTPS. Cashier PINs are stored hashed, never in plain text. Administrative access is restricted and password-protected. No system is perfectly secure, but we take reasonable technical and organisational measures to protect the data we hold, and we will notify affected people and the Office of the Data Protection Commissioner of any breach that puts personal data at risk.

Changes to this policy

If we change this policy we will update the date at the top of this page. Material changes affecting the Umati POS app will also appear in the app's release notes on Google Play.

Contact us

Questions about this policy, or about any data we hold — email info@umatihealthstore.com, or write to us at Sifa Plaza, Kenyatta Avenue, Nakuru, Kenya.