Loka Kasir
Privacy Policy
Last updated: 10 August 2026
Loka Kasir is developed by Kreativita Sinergi as a point-of-sale system for small businesses. This page explains the permissions the app asks for, why it needs them, and what data is collected.
This policy covers every version of Loka Kasir — Android (Google Play), iOS and iPadOS (App Store), macOS (Mac App Store), Windows (Microsoft Store), and Web Admin at app.lokakasir.id. They all use the same account and the same server. Because operating systems differ in what they allow, some permissions below apply only on certain platforms; each one says where it applies.
Permissions and What They're For
Notifications
RequiredPOST_NOTIFICATIONS (Android)
Applies on: Android, iOS, macOS, Windows
Why it's needed: To deliver alerts as they happen: incoming orders, low stock, payment confirmations, and other things that affect how the day runs.
What is collected: On Android and iOS, an FCM (Firebase Cloud Messaging) device token so notifications can be delivered. On macOS and Windows no token is sent — notifications there are produced locally by the app from data it has already fetched.
Bluetooth
OptionalBLUETOOTH_CONNECT, BLUETOOTH_SCAN (Android)
Applies on: Android, iOS
Why it's needed: To connect to wireless thermal receipt printers and print receipts directly from the register app.
What is collected: The names and addresses of nearby Bluetooth devices. Used only for pairing a printer, never stored on our servers. On macOS and Windows the permission isn't requested — receipts go to whichever printer the operating system already has installed.
Camera
OptionalCAMERA (Android)
Applies on: Android, iOS, macOS
Why it's needed: To scan product barcodes and QR codes when adding or looking up items, which is both faster and less error-prone than typing.
What is collected: No images are stored. The camera is active only during a scan. On Windows the app doesn't access the camera at all — a USB barcode scanner is read as an ordinary keyboard.
Photo library (no special permission)
OptionalAndroid Photo Picker — no permission required
Applies on: Android, iOS, macOS, Windows
Why it's needed: To upload product photos to your catalogue and the business logo that appears on receipts. The app uses the operating system's own file picker, so it never needs access to your whole photo library.
What is collected: Only the images you pick yourself are uploaded to our storage provider (Cloudinary) and attached to your business account. The app cannot see any other image on the device.
Notification access (automatic QR payment confirmation)
OptionalBIND_NOTIFICATION_LISTENER_SERVICE (Android)
Applies on: Android only
Why it's needed: Only for the optional automatic confirmation of static QR payments. Static QR payments land straight in the merchant's bank account without a gateway, so there is no official confirmation the app could receive. With this permission the app reads incoming-payment notifications from THE SHOP OWNER'S OWN banking or e-wallet apps on the same device and matches the amount against the bill waiting at the counter, so the sale can settle itself instead of the cashier confirming by hand.
What is collected: Only notifications from a defined list of banking and e-wallet apps are read. Notifications from anything else — private messages, social media, email — are never read, stored, or transmitted. The text of a matched payment notification is sent to our server to be reconciled and kept as proof of payment, visible to the owner in Web Admin. The feature is OFF by default and only works if the owner enables it and grants the permission by hand in Android settings. It does not exist on iOS, macOS, or Windows.
Other Data We Collect
Account data: name, phone number, email address, and password (hashed with bcrypt), needed to sign you in.
Business data: business name, business type, outlets, products, and stock — everything you enter yourself.
Transaction data: sales history, line items, prices, payment methods, and your financial reports.
Payment notifications (optional): if automatic QR payment confirmation is switched on, the text of incoming-payment notifications from the owner's own banking or e-wallet app is sent to our server to be matched against a sale. It is used only to verify payment, never shared with third parties, and can be removed by switching the feature off and contacting us.
Third Parties That Process Data
We do not sell user data. The following services process some data on our behalf, purely so the app can work:
Firebase Cloud Messaging (Google): receives device tokens in order to deliver notifications to the Android and iOS apps. Not used by the macOS or Windows versions.
Firebase Crashlytics (Google): receives crash reports containing diagnostics such as device model, OS version, and a stack trace. Enabled only in Android and iOS release builds, and it contains neither transaction data nor passwords.
Cloudinary: stores the images you upload yourself — product photos and your business logo.
App stores (Google Play, Apple App Store, Microsoft Store): handle installation and updates. We receive no personal data from them beyond purchase information where applicable.
Storage and Retention
Account, business, and transaction data are kept for as long as your account is active, because your own bookkeeping depends on that history staying available.
If you delete your account through the account deletion page, data is removed from active systems within 7 working days at the latest once the request is verified, and copies in system backups are gone within 30 days after that.
Notification device tokens are deleted when you log out of the app or uninstall it.
Some data may be kept longer where tax or other applicable legislation requires it.
How Your Data Is Protected
- ✅ All traffic between the apps and the server is encrypted with HTTPS/TLS.
- ✅ Passwords are stored as bcrypt hashes — they cannot be read back.
- ✅ Images are stored on Cloudinary under strict access control.
- ✅ Local session data on the device is held in Flutter Secure Storage.
- ✅ We do not sell user data to anyone.
Your Rights
You can revoke any permission at any time. Revoking one doesn't disable your account; it only means the feature that relies on it stops working. The steps differ per operating system:
Android: Settings › Apps › Loka Kasir › Permissions. For notification access specifically, Settings › Notifications › Special app access — or simply turn off automatic confirmation in the outlet settings in Web Admin.
iOS and iPadOS: Settings › Loka Kasir.
macOS: System Settings › Privacy & Security, then the relevant category (Camera or Notifications, for example).
Windows: the app requests neither camera nor Bluetooth permission, because neither feature exists there. Notifications can be turned off under Settings › System › Notifications.
To request access to your data, a correction, or deletion, write to us at help@lokakasir.id.
Contact Us
📧 Email: help@lokakasir.id
📞 Phone: +62 853-9373-7313
🏢 Developer: Kreativita Sinergi
📍 Jl. Air Camar No. 24, Padang Timur, Kota Padang, Sumatera Barat, Indonesia
© 2026 Loka Kasir — Kreativita Sinergi. All rights reserved.