Legal
Privacy Policy
Effective September 10, 2026. This policy explains what Tricera collects through the IcosaPOS website, the IcosaPOS platform, and the Pulse by IcosaPOS mobile app, and how we use and protect it.
Last updated: September 10, 2026
IcosaPOS is a point-of-sale platform built and operated by Tricera ("Tricera", "we", "us"). This Privacy Policy covers:
- The website at icosapos.com, including the contact and demo request forms.
- The IcosaPOS platform: the web admin at app.icosapos.com, the register, kiosk and kitchen display apps, online ordering pages, digital menu boards and event ticketing.
- Pulse by IcosaPOS, the mobile companion app for owners and managers, available for iPhone and Android.
If you are a customer of a business that uses IcosaPOS (for example, you placed an order, bought a ticket, or received a receipt), that business decides why and how your information is used. We process it on their behalf. Questions about a specific business's practices should go to that business.
1. Information we collect
Account and business information. When a business signs up for IcosaPOS, we collect the business name, location addresses, time zone, tax settings, the owner's name, email address and phone number, and billing details needed to invoice the subscription.
Employee information. Business owners and managers add their staff to IcosaPOS. For each employee we store name, role, email address and phone number (if provided), hourly rate (if provided), a register PIN (stored hashed, never in plain text), a login password (also hashed), and time clock records such as clock-in, clock-out and break times. Employees should contact their employer with questions about this data.
Order and transaction data. The platform records orders, line items, modifiers, discounts, taxes, tips, refunds, voids, gift card activity and which employee and device handled each transaction. This is the core business record of the merchant using IcosaPOS.
Payment information. Card payments are handled by our payment processing partners on certified payment terminals and secure hosted pages. Full card numbers, expiration dates and security codes are never stored on IcosaPOS servers. We keep only what is needed for receipts and reconciliation: the card brand, the last four digits, an authorization reference and the amount.
Customer information provided to a merchant. When a customer gives a business their name, email address or phone number, for example to receive an email receipt, place an online order, join a tab, buy an event ticket or register a gift card, that information is stored in that business's IcosaPOS account. Event tickets include the ticket holder's name and email so the ticket can be delivered and validated at the door.
Website inquiries. If you submit the contact or demo form on icosapos.com, we collect the name, business name, email address, phone number and message you provide, and we use it to respond to you.
Device and usage information. Our servers automatically log the IP address, browser or app version, device type, operating system, pages or screens requested, and timestamps. Registered devices such as terminals, kiosks, printers and menu boards are identified by a device name and a device key so they can be paired to a business.
2. Pulse by IcosaPOS mobile app
Pulse is for owners, managers and event staff. It uses the same account you already have with your business's IcosaPOS system; there is no separate sign-up.
- Camera. Used only when you open a scanning screen, to read ticket QR codes, product barcodes and SKU labels, and when you choose to take a photo for a menu item or event. Camera frames are processed on the device to find a code; they are not recorded or uploaded.
- Photo library. Used only when you choose to attach an existing photo to a menu item or event. We access only the photo you pick.
- Face ID, Touch ID and device biometrics. Optional quick unlock. Biometric matching is performed entirely by your phone's operating system. Pulse never receives, stores or transmits biometric data; it only learns whether the unlock succeeded.
- Location. Pulse does not collect or track your location.
- Advertising and tracking. Pulse contains no advertising, no third-party analytics or tracking SDKs, and does not track you across other apps or websites.
- Data stored on the device. Sign-in tokens are kept in the phone's secure keychain and a small cache of recently viewed screens is kept for speed. Signing out removes them.
3. How we use information
- To provide, operate and support the IcosaPOS platform and Pulse, including processing orders, printing receipts, running reports and validating tickets.
- To send transactional messages such as email receipts, ticket deliveries, order confirmations and account notices. These are sent because a customer or merchant requested them, not for marketing.
- To secure the service: authenticating users and devices, enforcing role permissions, detecting fraud or misuse, and keeping audit logs of sensitive actions such as refunds, voids, price changes and manager overrides.
- To bill merchants for their subscription and hardware.
- To respond to inquiries and provide customer support.
- To improve reliability and performance using aggregated, de-identified usage information.
- To comply with law, enforce our agreements and protect our rights and the rights of others.
4. How we share information
We do not sell personal information, and we do not share it with third parties for their own marketing. We share information only:
- With the merchant. Everything collected through a business's IcosaPOS account is available to that business's authorized owners and managers.
- With service providers who act on our behalf and under contract: cloud hosting and database providers, payment processing partners, email delivery services for receipts and tickets, and hardware and support tooling. They may use the information only to provide those services to us.
- For legal reasons, when required by law, subpoena or court order, or when necessary to protect the safety, rights or property of Tricera, our merchants or the public.
- In a business transfer, if Tricera is involved in a merger, acquisition or sale of assets, in which case this policy continues to apply to the transferred information.
5. Cookies and similar technologies
icosapos.com and app.icosapos.com use cookies and local storage that are strictly necessary to keep you signed in and remember your preferences. We do not use advertising cookies. Our website does not respond differently to browser "Do Not Track" signals because we do not track visitors across third-party sites.
6. Data retention
Order, transaction and time clock records are business records of the merchant and are retained for as long as the merchant's account is active, plus the period required by tax and accounting law. When a merchant closes their account, we delete or de-identify their data within 90 days, except where we must keep it to comply with legal obligations, resolve disputes or enforce our agreements. Website inquiries are kept for up to two years. Server logs are kept for up to 12 months.
7. Security
Data is encrypted in transit using TLS and at rest on our hosting provider's infrastructure. Passwords and register PINs are stored as salted hashes. Access to production systems is limited to authorized Tricera personnel and is logged. Each merchant's data is isolated from other merchants. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your information using industry-standard measures.
8. Your choices and rights
- Merchants and employees can view and update most account and staff information directly in the IcosaPOS admin or in Pulse. Owners can remove employees at any time.
- Customers of a merchant should direct requests to access, correct or delete their information to that business. We will assist the merchant in responding.
- Email receipts and tickets are one-time transactional messages; you can decline to provide an email address at the point of sale.
- Pulse permissions for camera, photos and biometrics can be changed at any time in your phone's Settings.
Depending on where you live, you may have the right to request access to, correction of, deletion of, or a copy of the personal information we hold about you, and to object to or restrict certain processing. To make a request, contact us using the details below. We will verify your identity before acting and respond within the time required by applicable law. We will not discriminate against you for exercising these rights.
9. Children
IcosaPOS and Pulse are business tools intended for adults. We do not knowingly collect personal information from children under 13, and merchants are not permitted to use the platform to do so. If you believe a child has provided us information, contact us and we will delete it.
10. International visitors
Tricera is based in the United States and our services are hosted in the United States. If you use the services from outside the U.S., your information will be transferred to and processed in the U.S., where privacy laws may differ from those in your country.
11. Changes to this policy
We may update this policy from time to time. When we do, we will change the date at the top of this page, and for significant changes we will notify merchants by email or through the admin dashboard before the change takes effect.
12. Contact us
Questions or requests about this policy can be sent to:
Tricera
Email: support@tricera.io
Web: icosapos.com/contact
