PandazPOS was built behind the counter of a real Tampa smoke shop. So we treat your store's data the way we'd want ours treated: card numbers we never touch, sales we wall off store-by-store, and infrastructure we rent from the same companies the big platforms use.
This page lays out exactly how that works — in plain language, with no certifications we don't actually hold. If something here matters to your call, email us and a human answers.
These certifications belong to our infrastructure partners — not to PandazPOS. We are not independently SOC 2 or HIPAA certified. Those certifications belong to our infrastructure partners, not us.
Card data never touches our servers. We're integrators of Stripe Terminal, not a payment processor.
One store can never see another store's data. Enforced by the database, not just the app.
We don't reinvent security — we build on companies audited for it. Each stamp below belongs to the vendor named on it, not to PandazPOS.
Built for regulated retail, by people who run regulated retail.
The vendors we rely on, what they do, and what data they touch. We update this when it changes.
"I keep your sales data walled off the same way I'd want mine. If you can't trust the register, you can't run the shop."
Good-faith reports get a real human reply — we're a small team and we mean it.
Send details and steps to reproduce. We aim to acknowledge within 2 business days. Please don't access data that isn't yours or run disruptive tests against live stores.