Skip to content

Security questions to ask a POS vendor (and the answers that should worry you)

Your POS holds your customers, your prices, your margins and your invoices. Here are twelve questions worth asking, what a good answer sounds like, and what a bad one means.

By Wameed product teamProduct and engineering

4 min read

A point of sale holds more sensitive information than most merchants realise: your full customer list with phone numbers, your cost prices and therefore your margins, your supplier terms, your staff records, and every invoice you have ever issued.

Here are twelve questions worth asking a vendor, with what a reassuring answer sounds like.

Access and accounts

1. Can every staff member have their own login?

Good: yes, unlimited users, each with their own permissions.
Worrying: a per-user charge that pushes shops towards shared logins. A shared login means no accountability, forever.

2. How granular are permissions?

Good: separate permissions for discounting, refunds, credit notes, price changes, viewing reports, viewing cost prices, and closing shifts.
Worrying: "cashier" and "manager" as the only two roles.

3. Can a manager approve an override without typing their password in front of a cashier?

Good: a PIN, a badge, or an approval on the manager's own device.
Worrying: the manager's password gets typed at the till, which means every cashier eventually knows it.

4. Can I see who did what?

Good: an audit log covering logins, price changes, permission changes, refunds, voids and exports — with the user and timestamp.
Worrying: "you can see sales by cashier." That is a report, not an audit trail.

The data itself

5. Where is my data stored, and who can access it?

Good: a clear answer about region, plus a statement of which of their staff can access customer data and under what controls.
Worrying: vagueness, or "our engineers can access anything they need to."

6. Is data encrypted in transit and at rest?

Good: yes, with specifics.
Worrying: "it's secure" without detail.

7. What happens to card data?

Good: card data does not touch the POS; it is handled by the payment terminal and the processor. This is the right architecture.
Worrying: any suggestion that the POS stores card numbers.

8. How are backups handled, and have you tested a restore?

Good: automated, encrypted, with a stated retention, and a restore tested on a schedule.
Worrying: backups mentioned but restores never tested. A backup nobody has restored is a hope, not a backup.

When things go wrong

9. What is your breach notification process?

Good: a defined process with a timeline, and a commitment to notify affected customers.
Worrying: no process, or "that has never happened to us."

10. What is your uptime history, and where can I see it?

Good: a status page with history.
Worrying: a number in a contract with no way to verify it.

Saudi specifics

11. How do you handle personal data under the Personal Data Protection Law?

Your customer list is personal data. You are the controller; the vendor is likely a processor. You need to know:

  • What they do with it
  • Whether they use it for anything other than providing you the service
  • How a customer's deletion request is handled
  • What happens to it when you leave

Good: clear answers and a data processing agreement.
Worrying: having to explain what PDPL is.

12. Can I export everything, and delete everything?

Good: export is self-service and included; deletion on termination is defined with a timeline.
Worrying: export is a paid service, or deletion is undefined.

The answers that should end the conversation

  • "We don't do individual logins, everyone uses the shop account."
  • "The POS stores the card number for refunds."
  • "You can't export the data, but you can view it any time."
  • "We've never had to think about that."

What we do

Per-user accounts with granular permissions and an admin activity log; card data handled by the payment provider and never stored in the POS; data export self-service and included; a defined deletion path — there is adata deletion request page for exactly that; and aprivacy policy that says what we hold and why.

Ask us these twelve. Ask everyone these twelve.

  • #security
  • #أمان
  • #PDPL
  • #data

Share this article

Ask about your own shop

Thirty minutes on your products, your tax setup and your hardware — not a slide deck.

Keep reading

Buying guides

4 min read

What is a POS system, really? Beyond the cash drawer

A point of sale is four systems wearing one screen: a sales engine, an inventory ledger, a compliance device and a reporting layer. Understanding that is why some shops buy well and others buy a till.