Privacy Policy

Effective 7 August 2026

Who we are

Nice Work POS is a restaurant point-of-sale platform operated by Nice Work, based in Singapore (“we”, “us”). It powers order-taking, kitchen displays, billing, and QR ordering for restaurants (“venues”) that subscribe to the platform.

This policy covers the Nice Work POS web application (including venue sites on *.nicework.sg subdomains), the customer QR ordering pages, and the Nice Work POS iOS app.

Two roles: the venue's data and ours

When you dine at a venue that uses Nice Work POS, the venue is the organisation collecting your data — your order, your table session, and any receipt email you choose to provide. We process that data on the venue’s behalf as a data intermediary under Singapore’s Personal Data Protection Act (PDPA). Questions about how a specific restaurant uses your data should go to that restaurant first.

For venue staff accounts, platform sign-ups, and subscription billing, we collect and control the data directly.

What we collect

Venue staff. Name, email address, role, and a short PIN used to attribute actions on shared devices. Staff actions in the POS (orders, voids, bill changes, settings changes) are recorded in audit logs so venue owners can see who did what.

Diners using QR ordering. No account is required and none is created. We record the order itself and the table or counter session it belongs to. If you choose to enter an email address to receive a receipt, we use it to send that receipt. If you pay online, payment is handled by HitPay — your card details go directly to the payment provider and never touch our servers.

Venue owners signing up. Business name, contact details, and country. Subscription billing is handled by Stripe; we do not store your card number.

Cookies. We use only functional cookies: staff sign-in sessions, the selected outlet, and your language preference. We do not use advertising cookies or cross-site tracking.

The iOS app

The Nice Work POS iOS app is used by venue staff on iPads and iPhones. Beyond what the web application collects, it uses two device capabilities:

Camera — to scan loyalty and table QR codes. Images are processed on the device for scanning and are not stored or uploaded.

Local network — to find and print to receipt and kitchen printers on the venue’s own network. This traffic stays on the venue’s local network; nothing about your network is sent to us beyond the printer addresses the venue configures.

The app contains no advertising, no third-party analytics SDKs, and does not track you across other companies’ apps or websites.

How we use information

To run the service: taking and preparing orders, producing bills and receipts, printing, reporting to venue owners, preventing fraud and abuse, and meeting bookkeeping and tax obligations (including GST/SST reporting). We send transactional email only — receipts, account invitations, and service notices. No marketing email is sent to diners.

Service providers

We rely on a small set of infrastructure providers to run the platform: Supabase (database and authentication), Vercel (hosting), Resend (transactional email), Stripe (subscription billing), and HitPay (diner payments). If a venue connects optional integrations — accounting (QuickBooks or Xero), loyalty programmes, or e-invoicing — relevant transaction data is shared with that provider at the venue’s instruction.

Some providers process data outside Singapore. Where they do, we rely on their contractual data-protection commitments consistent with the PDPA’s transfer requirements.

What we don't do

We do not sell personal data. We do not share it with advertisers. We do not profile diners or build marketing audiences from order data.

Security

All traffic is encrypted in transit. Each venue’s data is isolated at the database layer, and sensitive credentials are encrypted at rest. Access to production systems is restricted and audited.

Retention

Order and billing records are business and tax records; they are retained for as long as the venue uses the platform and for the statutory record-keeping period that applies to the venue (currently five years in Singapore and seven in Malaysia). Diner receipt emails are kept only as part of the transaction record they belong to.

Your rights

Under the Singapore PDPA (and the Malaysian PDPA for venues in Malaysia) you may request access to or correction of your personal data. Diners should contact the venue first, since the venue controls that data; we will support the venue in responding. Staff and venue owners can contact us directly.

Children

Nice Work POS is a business tool and is not directed at children. We do not knowingly collect personal data from children.

Changes and contact

If this policy changes materially, we will update this page and the effective date above. Questions, requests, or complaints: hello@nicework.sg.

Privacy Policy — Nice Work POS