Last updated - June 24, 2026

Privacy Policy

Stack Technology LLC (“Stack”, “we”, “us”, “our”) is a company registered in the Dubai International Financial Centre (“DIFC”), United Arab Emirates. We provide a point-of-sale and restaurant operations platform and related services (the “Services”).

This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and the rights you have. It applies to our website, our Services, and our dealings with clients, prospective clients, and visitors.

1. Who this policy is for

This policy covers personal data we handle about:

  • Website visitors - people who browse our website or contact us.
  • Clients and prospective clients - the restaurant businesses we serve, and their staff who administer the Services.
  • End users of our clients - where a client uses the Services to process data about their own customers (for example, a diner placing an order), the client is responsible for that data as the controller and Stack acts as a processor on their behalf. Our handling of that data is governed by our agreement with the client, not this policy.

2. Our role under data protection law

Stack is regulated by the DIFC Data Protection Law No. 5 of 2020 (“DIFC DPL”) and its regulations, supervised by the DIFC Commissioner of Data Protection. Where we collect and decide how to use personal data for our own purposes - for example, data about website visitors or our client contacts - we act as a Controller. Where we process data on behalf of a client in the course of providing the Services, we act as a Processor, and that processing is governed by our client agreement and, where applicable, a Data Processing Agreement.

Where we serve clients or handle personal data relating to individuals in the European Union, we also seek to align with the EU General Data Protection Regulation (GDPR). References below to “lawful basis” and individual rights should be read in that combined context.

3. Personal data we collect

Data you give us

  • Contact and account data - name, business name, email, phone number, role, and similar details when you enquire, sign up, or correspond with us.
  • Commercial data - information exchanged when negotiating, onboarding, billing, or supporting your account.
  • Communications - the content of emails, support requests, and other messages you send us.

Data we collect automatically

  • Usage and device data - when you visit our website, we collect information such as IP address, browser type, pages viewed, and referring source, using cookies and similar technologies.
  • Analytics - we use Google Analytics to understand how our website is used. This may set cookies and process usage data. See “Cookies” below.

Data within the Services

When you use the Services as a client, the platform processes operational data you enter or generate (such as menus, orders, transactions, and staff accounts). Personal data within that operational data is handled under our client agreement, where we generally act as your Processor.

4. How we use personal data and our lawful basis

We use personal data for the following purposes, relying on the lawful bases noted:

  • To provide and operate the Services and manage your account - performance of a contract.
  • To respond to enquiries and provide support - performance of a contract, or our legitimate interest in helping prospective clients.
  • To send service and administrative messages (billing, security, changes to terms) - performance of a contract or legal obligation.
  • To improve our website, products, and Services, including analytics - our legitimate interest in running and improving our business, or your consent where required for non-essential cookies.
  • For marketing - to send relevant updates about Stack, on the basis of consent or legitimate interest, and always with an option to opt out.
  • To meet legal, regulatory, and security obligations - compliance with a legal obligation and our legitimate interest in protecting our business.

Where we rely on consent, you may withdraw it at any time. Where we rely on legitimate interests, we balance those interests against your rights.

5. Cookies and similar technologies

Our website uses cookies and similar technologies to function, to remember preferences, and to measure usage through Google Analytics. Essential cookies are needed for the site to work; analytics and other non-essential cookies are used to understand and improve the site.

You can control cookies through your browser settings, and where required we will ask for your consent before setting non-essential cookies. Disabling some cookies may affect how the website works.

6. How we share personal data

We do not sell personal data. We share it only as needed:

  • Service providers (sub-processors) - we use trusted third parties to host our platform, process payments, send communications, and provide analytics and similar functions. They may process personal data only on our instructions and under appropriate confidentiality and data protection obligations. A current list of key sub-processors is available on request.
  • Professional advisers - such as lawyers, accountants, and auditors, where needed.
  • Legal and regulatory - where required by law, regulation, or valid legal process, or to protect our rights, users, or the public.
  • Business transfers - if Stack is involved in a merger, acquisition, or sale of assets, personal data may be transferred as part of that transaction, subject to this policy.

7. International transfers

Stack is established in the DIFC, and our service providers may be located in other jurisdictions. Where we transfer personal data outside the DIFC (or, for EU data, outside the European Economic Area), we do so only where a lawful transfer mechanism applies - for example, a finding of adequacy, appropriate contractual safeguards such as standard contractual clauses, or another basis permitted under the DIFC DPL or GDPR.

8. How long we keep personal data

We keep personal data only as long as needed for the purposes set out in this policy, including to provide the Services, meet legal and accounting obligations, resolve disputes, and enforce our agreements. When personal data is no longer needed, we delete or anonymize it. For client operational data, retention is governed by our client agreement, including a defined export window after the agreement ends.

9. How we protect personal data

We use commercially reasonable technical and organizational measures to protect personal data against loss, misuse, and unauthorized access - including access controls, encryption in transit, and ongoing security practices. No system is perfectly secure, but we work to protect your data and to meet our obligations under applicable law, including notifying the relevant authority and affected individuals of a personal data breach where required.

10. Your rights

Subject to applicable law, you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data deleted in certain circumstances;
  • restrict or object to certain processing;
  • receive your data in a portable format;
  • withdraw consent where we rely on it; and
  • complain to a supervisory authority - the DIFC Commissioner of Data Protection, or, for EU data, your local data protection authority.

To exercise any of these rights, contact us using the details below. We will respond within the timeframes required by applicable law. We may need to verify your identity first.

11. Children

Our website and Services are intended for businesses and are not directed to children. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us personal data, please contact us and we will take appropriate steps to delete it.

Our website may link to third-party sites or services we do not control. This policy does not apply to them, and we are not responsible for their privacy practices. Please review their policies separately.

13. Changes to this policy

We may update this policy from time to time. When we do, we will revise the “Last updated” date above, and where changes are material we will take reasonable steps to notify you. Continued use of our website or Services after an update means the updated policy applies going forward.

14. Contact us

If you have questions about this policy or how we handle personal data, or if you wish to exercise your rights, contact us at:

Stack Technology LLC
Dubai International Financial Centre, Dubai, United Arab Emirates
Email: privacy@stack-pos.com

You also have the right to lodge a complaint with the DIFC Commissioner of Data Protection (www.difc.ae).