Rmos POS Mobile App Privacy Policy
Last updated: 2026-09-18
This policy explains how personal data is processed in the Rmos POS mobile application (the "App"), developed by Reşat Mendi Otelcilik Sistemleri Bilgisayar Sanayi Turizm ve Ticaret Anonim Şirketi ("RMOS", the "Company"). The App is intended for staff of hotels and restaurants that use the RMOS POS system; it is not a public consumer app.
Data controller
The data controller is Reşat Mendi Otelcilik Sistemleri Bilgisayar Sanayi Turizm ve Ticaret Anonim Şirketi.
- Address: Akdeniz Üniversitesi Akdeniz Tekno Kenti K:2 No:3 Konyaaltı / Antalya, Türkiye
- Phone: +90 242 227 87 31
- E-mail: [email protected]
- Registered e-mail (KEP): [email protected]
- Mersis No: 0-7340-1010-1400012
Data we process
The App processes only what it needs to function:
- Authentication data: username and password (sent to the server at sign-in only, never stored on the device) and the session. The last username used is kept on the device to prefill the sign-in screen.
- User profile: your first name, last name, user code and permissions as defined in the POS system.
- App preferences: selected branch, language, appearance and card size.
- Business data: table, order, bill, payment and discount records.
- Guest and customer data: the guest's name, room number, reservation and folio details, and the name on a customer account, so that a payment can be posted to the right room or account.
- Card data: the number of a room card or prepaid card issued by the business (the card identifier read over NFC, or a number typed in), the cardholder's name and the card balance.
- Technical data: IP address, operating system, app version, and a random identifier specific to the installation, used to check for updates. This identifier is not linked to your identity.
Business, guest, customer and card data belong to the business you work for; RMOS hosts and processes it on that business's behalf.
The App does not read, process or store bank or credit card details (card number, expiry date, security code). Card payments are taken on the business's separate payment terminal; the App records only the type and amount of the payment.
Accounts are created by your employer; the App offers no public sign-up.
Use of NFC
The NFC reader is the only device capability the App uses. It runs only when you start a card read, reads the card's identifier, and stops after every read. The App writes nothing to the card and never reads in the background. On devices without NFC the card number is typed in.
Data we do not collect
The App collects no location, contacts, calendar, photos, camera, microphone, health data or advertising identifier (IDFA/AAID). It contains no advertising network, tracking or third-party analytics.
Purposes and legal basis
Data is processed to authenticate you, carry out table, order and payment operations, post a payment to the right room, customer account or card, debug faults and maintain security.
The legal basis is Article 5/2-c (necessary for the performance of a contract) and Article 5/2-f (legitimate interest) of Turkish Law No. 6698 (KVKK); for users in the EEA the equivalent grounds under GDPR Art. 6(1)(b) and 6(1)(f) apply.
Where data is stored
The session is kept on your device in the operating system's cookie store for the App; the App's own code cannot read it. Signing out closes the session, and every session is valid for 30 days at most.
Only your preferences, the selected branch, your user code and the last username used are kept on the device. Order drafts, guest lists, card numbers and balances are never written to the device; they exist in memory only while the App is open. Removing the App deletes everything on the device.
Server-side data is hosted on RMOS's servers and/or those of its cloud provider. All traffic is encrypted with HTTPS (TLS).
Disclosure
Your personal data is never sold or shared for marketing. It is disclosed only to the business you work for, to the infrastructure providers that host the service, and to public authorities where required by law, within the framework of KVKK Art. 8-9.
Two infrastructure providers are established outside Türkiye:
- Cloudflare, Inc. (USA): all traffic between the App and the servers passes through Cloudflare's network, for security and availability.
- Expo — 650 Industries, Inc. (USA): on every launch the App asks Expo's update server whether an update exists. Only the technical data listed above is sent; no business, guest or card data is.
Retention
Your user record is retained while your relationship with the business continues. When the record is closed your user details are deleted; records that legislation requires us to keep are retained for the statutory period. See the Account Deletion page for details.
Children's privacy
The App is a business tool, is not directed at anyone under 18, and does not knowingly collect data from children.
Your rights
Under KVKK Art. 11 you may learn whether your personal data is processed, request information and correction or erasure, object to processing, and claim compensation for damages.
Send requests, with information that verifies your identity, to [email protected] or to the registered e-mail address [email protected]. Requests are answered within 30 days at the latest.
If you are a guest or customer of a business, you may first address requests about your data to that business.
Changes
When this policy is updated, the effective date changes and the current text is published on this page. Material changes are announced in the App.
Contact
Privacy questions: [email protected]. Technical support: [email protected].