Privacy Policy
Effective date: 6 August 2026
Reference: Ghana Data Protection Act 2012 (Act 843)
Your privacy is important to us. This policy explains what data we collect, how we use it, and your rights as a data subject under Ghanaian law.
At a glance
Contents
1. About This Policy
This Privacy Policy explains how Brelto (“Brelto,” “we,” “us”) collects, uses, stores, and protects the personal and business data of Customers and their staff who use the Aro POS platform.
This policy is prepared in accordance with the Ghana Data Protection Act 2012 (Act 843). By using Aro POS, you acknowledge the practices described in this policy. We are committed to handling data with care, transparency, and respect for your rights.
2. Who We Are
Brelto is a Ghana-based software company building point-of-sale and inventory management tools for Ghanaian retail businesses. We are the data controller for personal data processed through the Aro POS platform.
Brelto, Ghana
WhatsApp: +233 20 626 1743
Email: hello@aropos.net
3. Data We Collect
We collect the following categories of data when you use Aro POS:
Business registration data
- Business name, type, and physical address
- Owner name and contact details
- Ghana Revenue Authority (GRA) TIN (where applicable)
Transaction and operational data
- Sales transactions, payment records, and receipts
- Product catalogue, pricing, and stock levels
- Stock transfers, adjustments, and waybill records
- Customer credit account information
- Daily session and cash reconciliation records
User account data
- Staff names, roles, and login credentials (passwords are hashed, never stored in plaintext)
- Phone numbers (for WhatsApp notifications, where enabled)
Technical and security data
- Device type, browser, and operating system (for compatibility support)
- IP addresses (logged for security and fraud detection purposes)
- Action audit logs (who did what and when within your account)
4. How We Use Your Data
We use the data we collect for the following purposes:
- Delivering and operating the Aro POS platform and all its features
- Processing subscription billing and generating invoices
- Providing technical support and responding to your queries
- Diagnosing and resolving platform errors or performance issues
- Detecting and preventing fraud, unauthorised access, and security breaches
- Maintaining audit trails for accountability and compliance
- Complying with obligations under Ghanaian law, including tax reporting
- Improving the platform through anonymised, aggregated usage analytics
We do not use your business transaction data for advertising, profiling, or any commercial purpose beyond operating the Service for you.
5. Data Sharing
We do not sell your data to third parties. We do not share your data with advertisers, data brokers, or marketing platforms.
We share data only in the following limited circumstances:
- Cloud infrastructure providers: Our application and database are hosted on Hostman, with our frontend served via Vercel. These providers process data solely to deliver the Service and are contractually bound to appropriate data protection standards.
- Payment processors: Card payments are processed by Paystack in accordance with their privacy policy. We will never store raw card details.
- Legal authorities: We may disclose data when required by Ghanaian law, a valid court order, or a lawful request from a government authority. We will notify you where legally permitted to do so.
- Brelto staff: Access is strictly limited. Staff access your account only for support purposes, only when you have requested help, and all access is logged.
6. Data Security
We take the security of your data seriously. Our security measures include:
- Encrypted storage for all data at rest
- HTTPS/TLS encryption for all data in transit
- Automatic daily backups to secure offsite storage
- Role-based access controls — staff only see what their role permits
- All staff access to customer data is logged and audited
- Passwords are hashed using industry-standard algorithms (never stored in plaintext)
- Offline transaction data is hash-chained on-device for tamper detection
No system is perfectly secure. In the unlikely event of a data breach that affects your personal data, we will notify you promptly in accordance with the Ghana Data Protection Act and take immediate remedial action.
7. Data Retention
We retain your data for as long as your account is active and for a defined period after closure, in accordance with our data retention policy:
We recommend requesting an export of your data before cancelling your account. Full data exports are available on request, at no charge, for active accounts.
8. Your Rights (Ghana Data Protection Act 2012)
Under the Ghana Data Protection Act 2012 (Act 843), you have the following rights regarding your personal data:
- Right of access: You have the right to request a copy of the personal data we hold about you.
- Right to correction: You have the right to have inaccurate or incomplete personal data corrected.
- Right to deletion: You have the right to request deletion of your personal data, subject to legal retention requirements.
- Right to data portability: You have the right to receive a complete export of your business data in a portable format, on request, at any time.
- Right to object: You have the right to object to how we process your data in certain circumstances.
To exercise any of these rights, contact us via WhatsApp at +233 20 626 1743 or email hello@aropos.net. We will respond within 30 days.
9. Cookies
Aro POS uses only essential session cookies — small pieces of data stored in your browser that are strictly necessary for you to stay logged in and for the platform to function correctly.
We do not use:
- Advertising or retargeting cookies
- Third-party analytics cookies (e.g., Google Analytics)
- Social media tracking pixels
- Behavioural profiling technologies
You can clear session cookies by logging out of Aro POS or clearing your browser's cookies. This will require you to log in again.
10. Children's Privacy
Aro POS is a business management platform designed for and intended to be used by adults operating retail businesses. We do not knowingly collect personal data from individuals under the age of 18.
If you believe that a minor has provided personal data through our platform, please contact us immediately and we will take steps to delete the information.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal obligations. We will notify you of material changes at least 30 days before they take effect, via:
- WhatsApp message to the business owner's registered number
- Email to the registered account email address
- An in-app banner visible when you next log in
Minor changes (such as clarifications that do not alter how we handle data) will be reflected on this page with an updated “Last updated” date. We encourage you to review this policy periodically.
12. Contact & Complaints
If you have questions about this policy or how we handle your data, please contact us:
If you are not satisfied with our response, you have the right to lodge a complaint with the Data Protection Commission of Ghana:
Data Protection Commission
P.O. Box CT 2133, Cantonments, Accra, Ghana
Website: www.dataprotection.org.gh
You may also review our Terms of Service for information about how the platform operates and your contractual rights.