Last updated: August 28, 2026
SBBPOS is a SaaS Point of Sale platform developed and operated by SBB Solutions AB, a company registered in Sweden under organisation number 559588-1433, with registered address at Östra Gränsgatan 2, 283 72 Lönsboda, Sweden ("we", "us", "our"). Our service is available at app.sbbpos.com and our main website is at www.sbbpos.com.
For privacy-related questions, contact us at: webmaster@sbbpos.com
SBBPOS is a business tool and is not directed at, or intended for use by, individuals under the age of 18. We do not knowingly collect personal data from children.
We collect only the data necessary to operate the service:
We do not collect or store end-customer (shopper) personal data. Receipts are issued per transaction without identifying the buyer unless you explicitly attach customer information.
We do not sell your data. We do not use your data for advertising or marketing profiling.
SBBPOS sends transactional emails only — these are emails triggered directly by your actions (e.g. signing up, requesting a password reset, or sending an email receipt). We do not send unsolicited marketing emails.
Transactional email is delivered via SendGrid (by Twilio), a third-party email delivery provider. SendGrid processes your email address solely to deliver messages on our behalf and is located in the USA. Transfers to the USA are covered by EU Standard Contractual Clauses (SCCs) and Twilio's Data Processing Agreement. No transaction data or payment information is shared with SendGrid. Their privacy policy is available at twilio.com/en-us/legal/privacy.
Card payment processing can be handled via Stripe (stripe.com). SBBPOS does not store card numbers or payment credentials. All card data is handled directly by Stripe in accordance with PCI DSS standards. Stripe's privacy policy is available at stripe.com/privacy.
Card, Swish, Klarna, and Vipps payments can also be handled via Westpay AB, a Swedish payment provider. SBBPOS never stores your full card number or CVV. For card payments made through a Westpay terminal, we do store limited, non-sensitive card metadata alongside the transaction record — a masked card number (e.g. ending in the last 4 digits), card type, expiry date, and a stable card reference used to match up refunds and reconciliation. For Swish payments, your phone number is processed directly by Westpay as part of completing the payment. Westpay's privacy policy is available at westpay.se/sv/privacy-policy.
If you shop at a business using our Skatteverket compliance module (Swedish accounts only), your transaction amount, timestamp, and a control code are sent to a certified control unit provider, Origum Distribution AB, as required by Swedish law (kassaregisterlagen, SFS 2007:592). No other personal data about you is shared with this provider. Origum's terms and privacy policy are available at origum.se/villkor.
Your data is stored in a cloud-hosted MongoDB database. Each account's data is isolated by a unique account identifier — no tenant can access another tenant's data. Access to the database is restricted to the SBBPOS application and authorised developers only.
Authentication uses short-lived JWT tokens stored in httpOnly cookies, which are not accessible from JavaScript. Passwords are hashed using bcrypt before storage.
We use the following third-party sub-processors to operate the service. All sub-processors are bound by data processing agreements that impose at least equivalent data protection obligations as this policy.
We will notify Account Holders by email at least 30 days before adding or replacing a sub-processor.
Third-party services you choose to connect: if a business enables an optional CRM integration (Salesforce) or accounting integration (Fortnox, Visma), we act on that business's instructions to send data to their own account with that provider — for the CRM integration, this includes member profile details (name, phone, email) and purchase history for any member linked to a sale; for accounting integrations, this includes daily aggregated sales totals. These providers are not selected or contracted by us — the business controls the connection, and that provider's own privacy policy and terms govern their processing of the data sent to them.
In the event of a personal data breach, we will notify affected Account Holders without undue delay and, where required by GDPR, within 72 hours of becoming aware of the incident. The notification will include a description of the nature of the breach, the categories of data affected, and the measures we have taken or propose to take in response.
If you are based in the European Economic Area (EEA), you have the following rights under the General Data Protection Regulation (GDPR):
To exercise any of these rights, email us at webmaster@sbbpos.com. We will respond within 30 days.
You also have the right to lodge a complaint with your local data protection supervisory authority. In Sweden, this is the Swedish Authority for Privacy Protection (IMY) — imy.se.
We do not make any decisions about you based solely on automated processing (including profiling) that produce legal or similarly significant effects.
SBBPOS uses a single authentication cookie (httpOnly, Secure) to maintain your login session. This cookie is strictly necessary for the service to function and does not track you across other websites.
We do not use advertising cookies, analytics tracking cookies, or third-party cookies on app.sbbpos.com.
We may update this policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of the service after changes constitutes acceptance of the updated policy. For significant changes, we will notify account holders by email.
For any privacy-related questions or requests (including GDPR requests — data access, correction, deletion, or export), email us with the subject line "GDPR Request". We will respond within 30 days.
SBB Solutions AB
Östra Gränsgatan 2, 283 72 Lönsboda, Sweden
Organisation number: 559588-1433
Email: webmaster@sbbpos.com
Website: www.sbbpos.com