Skip to main content
Bibeno

Bibeno product

Everything your team needs to run each sale.

Explore Bibeno’s point-of-sale, product, stock and reporting tools.

Software overviewSee what Bibeno includes.Point of saleTake orders and complete sales at the counter.Products & menusManage products, prices and selling options.Inventory managementTrack stock movement and complete stock takes.Backoffice & reportingManage access and review business performance.Download for WindowsInstall Bibeno on a supported device.
Bibeno product catalog interface.Inside BibenoSee the full Bibeno product.Explore

Made for independent businesses

Software that fits the way your business works.

See how Bibeno supports food-service and specialty retail teams.

Industries overviewSee which businesses Bibeno is built for.CafésManage orders, products, stock and daily reporting.Takeaways and quick-serviceKeep service fast and every order organised.Boutiques and specialty retailManage checkout, products and stock together.
A café team serving a customer at the counter.Find the right fitTell us how your business operates.Explore
Pricing

About Bibeno

A South African team focused on independent business.

Learn about Bibeno, how we help businesses get started and how to contact us.

About BibenoOur story, purpose and product principles.How we workSee what to expect from setup and rollout.Contact usSpeak to sales, support or our general team.Get startedTell us about your business and what you need.
A team of independent bakery operators working together.Meet BibenoBuilt locally. Supported by real people.Explore
Sign inBook a demo
Legal/Privacy Notice

Privacy Notice

How Bibeno processes account, billing, support, security, device, POS, customer-controlled, workforce, loyalty, marketing, and service-operations information under POPIA and related lawful obligations.

Status: Effective 14 August 2026Version: 1.0.0Content hash: 89294002806f46a02b21bfca1acd2d89f79a7383ed1226358bfa98c5d91d61c2
1. Scope and responsible roles0% read

On this page

Privacy Notice

  1. 1. Scope and responsible roles
  2. 2. People covered by this policy
  3. 3. Information we collect
  4. 4. Sensitive and special personal information
  5. 5. Sources of information
  6. 6. How we use information
  7. 7. Legal bases, required information, and consequences
  8. 8. Customer business data ownership
  9. 9. Sharing information
  10. 10. Operators, providers, and sub-processors
  11. 11. International transfers
  12. 12. Retention
  13. 13. Security
  14. 14. Security compromises
  15. 15. Cookies and local storage
  16. 16. Your privacy rights
  17. 17. South African launch and other territories
  18. 18. Children
  19. 19. Marketing, loyalty, and communications
  20. 20. Third-party links and customer content
  21. 21. Changes to this policy
  22. 22. Contact and complaints

1. Scope and responsible roles

This Privacy Notice explains how Bibeno collects, uses, shares, stores, and protects personal information when people use Bibeno POS, Bibeno Backoffice, Bibeno-powered merchant storefronts, public support pages, account recovery, device pairing, billing, notifications, and related services.

BIBENO (PTY) LTD

2026/355321/07

Plot 17 Second Street, Mooilande AH, Meyerton, Gauteng, 1963, South Africa

Where POPIA uses the terms responsible party and operator, Bibeno may be the responsible party for its own account, billing, support, security, website, and platform administration records, and may be an operator when processing business content on behalf of a customer business.

For business content uploaded into Bibeno, the customer business usually decides why and how that information is processed. Bibeno processes that business content to provide the service, support the account, secure the platform, maintain records, and meet legal obligations.

If you place an order with a business through a Bibeno-powered storefront, that business is normally the responsible party for your order and customer information. Bibeno normally processes that information as the business's operator. Contact the business first about the order or its use of your information; Bibeno will assist the business and will handle any processing for which Bibeno is independently responsible.

The published Data Processing Agreement governs Bibeno's operator processing, including documented instructions, confidentiality, security, sub-operators, cross-border processing, rights assistance, compromise notification, audit evidence, return, deletion, retention, and legal holds. Where Bibeno independently decides a purpose, such as its own billing, account security, fraud prevention, legal compliance, product administration, or direct relationship with a user, Bibeno is responsible for that separate processing.

2. People covered by this policy

This policy may cover business owners, administrators, employees, invited users, support requesters, billing contacts, website and merchant-storefront visitors, online-order customers and recipients, device users, loyalty members, customers, suppliers, and other people whose information is entered into or generated by the service.

If you are a customer, employee, supplier, or loyalty member of a business that uses Bibeno, that business may be responsible for giving you its own privacy notice and handling certain privacy requests. Bibeno will assist where legally required or practically able to do so.

3. Information we collect

We collect information directly from account holders, invited employees, business administrators, support requesters, billing contacts, and users of connected devices. We also collect information automatically when the service is used.

  • Account information: name, email, phone number, date of birth where needed for employee setup, role, permissions, login status, security settings, and account identifiers.
  • Business information: business name, locations, products, menus, inventory records, device names, sales records, tax settings, billing details, support tickets, and operational preferences.
  • Operational records: order summaries, product sales summaries, import and export records, storage usage, uploaded image metadata, notification state, device sync activity, and account lifecycle events.
  • Online-order information: customer and recipient names, phone numbers, email addresses, collection or delivery details, addresses where enabled, ordered items and options, order notes, requested time, fulfilment and acceptance status, payment choice and provider reference, cancellation, refund, and customer communications.
  • Customer and staff records: customer names or contact details entered by the business, employee access data, PIN settings, audit activity, and support communications.
  • Technical information: IP address, browser, device, operating system, active session records, security logs, crash data, event logs, diagnostic data, and cookie or local storage identifiers.
  • Payment and billing information: plan details, invoices, payment status, transaction references, and limited payment metadata from payment providers. We do not store full card numbers where a payment provider is used.
  • Communications information: emails, SMS messages, notification preferences, support messages, account recovery requests, loyalty communication settings, unsubscribe records, and proof that operational notices were sent.
  • Legal acceptance records: document versions, checkbox acceptance, timestamps, source of acceptance, IP address, user agent, user ID, business ID, and related checkout metadata.
  • Storage and cleanup information: uploaded file keys, file sizes, file types, uploader details, temporary export download records, import session records, deleted notification state, and cleanup recommendations.

Information identified as required during registration, security verification, checkout, billing, support, or a statutory request is mandatory for that purpose. If it is not provided, Bibeno may be unable to create or secure the account, conclude or perform the requested transaction, process payment, provide the requested support, or verify and answer the request. Optional profile, communication, loyalty, marketing, and other fields are voluntary unless the customer business separately requires them for a lawful business purpose; the relevant screen or notice identifies the practical consequence of leaving them blank.

4. Sensitive and special personal information

Some information entered into the service may be sensitive or special personal information depending on context, such as employee dates of birth, security credentials, support attachments, allergy or health information included in an order note, customer loyalty notes, payment metadata, or information included in uploaded documents.

Businesses must not enter unnecessary sensitive information into Bibeno. If a business uses Bibeno to process special personal information, children's information, employee information, direct marketing records, or other regulated data, that business is responsible for having a lawful basis and any required consent, notice, authorisation, or workplace policy.

Bibeno does not intentionally collect full payment card numbers where a payment provider is used, and customers must not upload full card numbers, identity documents, health details, or other high-risk information unless the feature specifically requires it and the business has authority to process it.

A merchant must not use a general order-notes field to invite broad medical histories or other unnecessary special personal information. If limited allergy or safety information is genuinely needed to fulfil an order, the merchant must explain the purpose, collect only what is necessary, restrict access, set an appropriate retention rule, and obtain any consent, authorisation, or other legal basis required for that processing. That processing may be enabled only after the current legal requirements for health information have been reviewed and satisfied.

5. Sources of information

We may receive information from users, customer businesses, connected devices, imports, uploaded files, support requests, payment providers, email or SMS providers, app platforms, hosting providers, analytics or monitoring tools, and integration partners.

We may also create information through the operation of the service, including order summaries, product sales summaries, device sync records, audit logs, storage records, invoices, support history, legal acceptance records, and account lifecycle records.

When Bibeno receives personal information from a customer business or another source rather than directly from the person, the customer is generally responsible for the collection notice for its own business purposes. Bibeno provides this notice and the Data Processing Agreement so the customer can explain Bibeno's operator role, provider categories, processing locations, retention, safeguards, and rights-assistance channel.

6. How we use information

We use personal information to operate, secure, support, improve, and communicate about the service. We also use it to meet legal obligations, investigate misuse, and protect customers and the platform.

  • Create and authenticate accounts, manage invitations, verify email addresses, and support two-factor authentication.
  • Provide backoffice workflows, POS sync, device management, merchant storefront catalogues, online quoting, ordering, collection, delivery, shipping, payment and refund evidence, reporting, billing, support tickets, notifications, exports, and account recovery.
  • Send service messages, support replies, security alerts, billing notices, product updates, and legal notices.
  • Detect, prevent, and investigate fraud, unauthorised access, abuse, errors, security incidents, and platform reliability issues.
  • Manage storage limits, retention, cleanup, backups, data exports, account lifecycle processes, and subscription entitlements.
  • Generate and maintain invoices, checkout records, subscription history, legal acceptance evidence, support records, and audit records.
  • Analyse usage at an account, business, aggregated, or de-identified level to improve performance, product design, support quality, security, billing, and feature planning.
  • Send or display storage, billing, trial, security, and account-status notices where action is needed to keep the service working.

Bibeno does not make a decision that produces legal or similarly significant effects about a person solely through automated processing unless the responsible party has approved a lawful use, meaningful information about the logic and consequences is provided where required, and a route for human review and objection is available. Product rankings, risk indicators, audience suggestions, and operational recommendations remain subject to authorised human decisions.

7. Legal bases, required information, and consequences

Depending on the location and context, we process personal information because it is necessary to perform a contract, comply with legal obligations, protect legitimate interests, protect security, respond to consent-based choices, or process information as instructed by a customer business.

Where POPIA applies, we process personal information under lawful processing conditions such as accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards, and data subject participation.

Customer businesses are responsible for choosing a lawful basis or condition for the personal information they enter into Bibeno about their customers, employees, suppliers, loyalty members, and business contacts.

Where consent is used, consent may usually be withdrawn, but withdrawal does not affect processing already performed lawfully or processing needed for legal, contractual, security, billing, dispute, or recordkeeping purposes.

Information marked as required in an account, checkout, billing, security, support, employment, device, or legal process is mandatory for that specific process. Other requested information is voluntary. The collection screen or related notice identifies the applicable position before collection where Bibeno collects the information directly.

If required information is not supplied, Bibeno may be unable to create or secure the account, conclude or perform the requested contract, process payment, issue the correct record, pair a device, provide support, verify authority, investigate misuse, or comply with a legal duty. Declining optional information does not prevent use of unrelated core functions, although the optional feature or communication may be unavailable.

Depending on the record and transaction, collection or retention may be authorised or required by POPIA, PAIA, the Companies Act, the Consumer Protection Act, the Electronic Communications and Transactions Act, tax and accounting legislation, employment legislation, payment and anti-fraud obligations, court process, or another law that applies to Bibeno or the customer business. A collection-specific notice identifies a more particular legal requirement where one applies.

8. Customer business data ownership

Customer businesses retain ownership of the business data, customer records, employee records, loyalty records, inventory records, sales records, and other content entered into Bibeno.

Bibeno does not claim ownership of customer business data. Customer businesses grant Bibeno a limited right to host, process, store, back up, transmit, display, and otherwise use that data only as needed to provide, secure, maintain, support, improve, and operate the service.

Upon lawful account closure, customer businesses may request export of their data where export tools are available, subject to retention, legal, billing, security, backup, dispute, and technical requirements.

9. Sharing information

We share personal information only where needed to provide the service, comply with law, protect rights, or support business operations. We do not sell personal information.

  • Service providers: hosting, email delivery, analytics, payment processing, security, support tooling, backups, and infrastructure providers.
  • Customer administrators: business owners or administrators may see employee, device, sales, customer, billing, support, and activity information for their tenant.
  • Connected service providers: payment providers, email or SMS providers, storage providers, domain providers, app platforms, integration partners, and other tools configured by Bibeno or the customer business.
  • Legal and safety recipients: regulators, courts, law enforcement, professional advisers, or affected parties where required or appropriate.
  • Business transfers: information may be transferred if we are involved in a merger, acquisition, financing, restructuring, or sale of assets, subject to appropriate protections.

10. Operators, providers, and sub-processors

Bibeno may use operators, service providers, and sub-processors to host, store, secure, transmit, back up, and support the service. These providers may process information only for agreed service, security, support, legal, or operational purposes, and are bound by appropriate confidentiality and data-protection obligations.

We use providers in categories such as cloud application hosting, database hosting, object and file storage, payment processing, email delivery, SMS delivery, domain and DNS services, app distribution platforms, monitoring, logging, backups, and support tooling. We select providers that offer appropriate security and data-protection safeguards.

The exact legal entity, purpose, personal-information categories, data subjects, processing and support regions, onward providers, retention, security evidence, contract, and transfer safeguard for every enabled provider must be verified in Bibeno's controlled vendor register before that provider is approved for production processing.

The current approved Subprocessor List and Data Processing Agreement are published at their canonical legal routes. A customer should review them and disclose any customer-selected provider before entering regulated, high-risk, or contractually restricted information into the service.

11. International transfers

Bibeno does not approve an international processing location merely because a cloud service is technically available there. Before personal information is transferred from South Africa, Bibeno verifies the recipient, country and support-access locations, purpose, onward transfers, security, retention, and a safeguard permitted by section 72 of POPIA, and records that evidence in the provider register.

Customer businesses must not select, configure, or instruct an unsupported foreign destination without first establishing their own lawful transfer basis and required notices. The international-customer and analytics-benchmarking gates remain disabled until the relevant territories, contracts, notices, and safeguards are approved.

12. Retention

We keep personal information for as long as needed to provide the service, maintain records, support the account, comply with tax and legal obligations, resolve disputes, enforce agreements, prevent fraud, and maintain secure backups.

Retention periods vary by record type. Account, billing, legal acceptance, invoice, tax, and audit records may be kept for legal and evidentiary reasons after closure, while support and security logs may be kept for a shorter operational period unless needed for an investigation.

Bibeno uses a documented retention schedule by record class, purpose, responsible party, minimum or maximum period, trigger, legal basis, deletion or anonymisation action, legal-hold rule, backup treatment, and accountable owner. Automated cleanup runs only through the policy-driven dry-run, approval, application, and immutable outcome process.

  • Short-lived download artefacts, temporary uploads, import work files, delivery payloads, and cache records are removed after the approved operational window while the minimum audit record may remain.
  • Account, user, device, support, consent, suppression, acceptance, invoice, payment, tax, security, and transaction-integrity records follow separate retention classes rather than one account-wide deletion date.
  • Trial or closed accounts pass through notice, export, suspension, legal-hold, deletion or anonymisation, backup expiry, and completion-evidence stages; they are not hard-deleted solely because a timer elapsed.
  • A valid legal hold pauses destruction only for the records and purpose identified and is reviewed and released through an authorised event.
  • Backups expire through the controlled backup lifecycle and are not silently restored into ordinary use after a valid live-system deletion.
  • Aggregated or de-identified information may be retained only where it cannot reasonably be linked back to a person and re-identification is prohibited.

13. Security

We use administrative, technical, and organisational safeguards designed to protect personal information against unauthorised access, loss, misuse, alteration, and disclosure. These safeguards include access controls, authentication, secure transport, role-based permissions, monitoring, backups, and staff access limitations.

We may keep security, session, audit, and device activity records to help customers review access, detect suspicious activity, investigate incidents, and protect the service.

No online service can guarantee absolute security. Customers must also protect passwords, PINs, two-factor codes, devices, exports, and administrator access.

Administrators should use strong passwords, review user access, remove former staff, secure exported files, protect connected devices, and report suspected unauthorised access promptly.

14. Security compromises

If Bibeno has reasonable grounds to believe that personal information for which it is the responsible party has been accessed or acquired by an unauthorised person, Bibeno activates its security-compromise workflow, preserves evidence, contains the issue, records the assessment, and notifies the Information Regulator and identifiable affected data subjects as soon as reasonably possible as required by section 22 of POPIA, subject only to a lawful delay directed by the relevant authority.

Where Bibeno acts as an operator for a customer business, Bibeno notifies that responsible party immediately after discovering a relevant compromise and supplies the available facts and assistance needed for containment, investigation, regulator and data-subject notification, remediation, and evidence preservation. Bibeno does not notify on the customer's behalf unless authorised and lawful.

A data-subject notice describes the possible consequences, measures taken or planned, recommendations to reduce harm, and the identity of the unauthorised person if known and lawful to disclose. Notices use the channel required or permitted by law and are recorded without exposing additional personal information.

15. Cookies and local storage

Bibeno uses cookies, local storage, and session storage to keep users signed in, protect and validate sessions, remember interface choices, and support core product functionality. These are strictly necessary or functional technologies used to operate the service.

The production cookie and tracking inventory is verified before a technology is enabled and whenever its provider or purpose changes. Advertising, retargeting, cross-site behavioural tracking, or optional analytics technologies are not enabled unless the vendor, purpose, data, retention, transfer, notice, and any required consent controls have been approved.

You can use browser controls to limit or clear these technologies, but some service features may stop working correctly. If we later add analytics, marketing, or retargeting tools, we will update this notice and provide any cookie controls or consent mechanisms required by applicable law before those tools are used.

16. Your privacy rights

Depending on where you live and how your information is processed, you may have rights to access, correct, delete, restrict, object to, port, or receive details about personal information. You may also have rights to withdraw consent, opt out of certain marketing, or lodge a complaint with a regulator.

If your information is controlled by a Bibeno customer business, we may refer your request to that business or ask you to contact them directly. We will still help where we are legally required or practically able to do so.

Where export tools are available, account administrators can export certain business records before deleting data, closing an account, or allowing a trial to expire.

We may need to verify your identity, authority, business relationship, or administrator role before responding to a request. Some requests may be limited where information is needed for legal, billing, tax, security, fraud prevention, dispute, backup, or transaction integrity reasons.

We will respond to privacy requests within the time required by applicable law. If a request is complex, involves a customer business as the responsible party, or requires identity or authority checks, we may need more information before we can complete it.

Bibeno keeps a durable request record with the request type, responsible party, identity and authority checks, scope, searches, decisions, exemptions or refusal grounds, exports, correction or deletion outcomes, communications, deadlines, legal holds, and appeal or complaint route. The prescribed POPIA objection and correction or deletion forms and the PAIA access process remain available through the published PAIA Manual.

17. South African launch and other territories

This notice is written for Bibeno's approved South African service and POPIA, PAIA, ECTA, consumer, labour, tax, and related obligations. South African data subjects may use the access, correction, deletion, objection, marketing, and complaint routes described here and in the PAIA Manual.

Bibeno does not activate a customer in another territory or claim compliance with GDPR, UK GDPR, US state privacy law, or another foreign regime until the territory, representative requirements, contracts, transfer mechanisms, rights workflows, notices, providers, and product behaviour have been assessed and approved through the international-customer gate.

A person outside South Africa may still contact Bibeno about their information. Bibeno will identify the responsible party and applicable law and will not use this section to reduce a right that validly applies.

18. Children

Bibeno is a business service and is not intended for children. A customer must not create an account for a child or intentionally process children's personal information through Bibeno unless the feature and processing have been expressly approved, the responsible party has a lawful justification and competent-person authorisation where required, appropriate notices and safeguards are in place, and any required Information Regulator prior authorisation has been obtained before processing begins.

19. Marketing, loyalty, and communications

You may opt out of Bibeno marketing emails by using the unsubscribe link or contacting support. We may still send transactional, security, billing, legal, and service messages that are necessary for the service.

A public waitlist or early-access form results in marketing follow-up only where the form clearly identifies Bibeno, the purpose, offerings and channels, captures a valid affirmative choice where required, and provides a simple withdrawal route. Submitting an operational support or account request is not treated as consent to unrelated marketing.

Customer businesses that use Bibeno loyalty or marketing tools are responsible for obtaining and managing any consent, opt-out, unsubscribe, direct marketing, or customer notice requirements that apply to their own customers.

Bibeno may keep unsubscribe, consent, delivery, bounce, complaint, and suppression records to respect communication choices and protect the service.

Unsolicited electronic direct marketing is sent only where section 69 of POPIA permits it, including valid consent obtained through the prescribed approach or the limited existing-customer route for Bibeno's own similar services with a clear opt-out at collection and in every message. Consent is specific by sender, purpose, offering, and channel; silence, bundled service acceptance, or a pre-ticked box is not treated as consent.

Before any direct-marketing send, the authoritative eligibility check applies internal objections and suppressions, unsubscribe and STOP records, delivery complaints, consent or existing-customer evidence, channel rules, permitted contact times, and current National Consumer Commission Opt-Out Registry cleansing evidence. The direct-marketing feature remains disabled until those controls and registrations are current.

20. Third-party links and customer content

The service may contain links to third-party websites, payment pages, app stores, provider portals, or customer-managed content. Those third parties are responsible for their own privacy practices and terms.

Customer businesses are responsible for the content they upload, import, send, publish, or make available through Bibeno, including product images, email templates, SMS templates, customer notices, loyalty content, and exported files.

21. Changes to this policy

We may update this Privacy Notice as the service, law, or business changes. If we make material changes, we will provide reasonable notice through email, in-product notice, or another suitable method.

The version acknowledged during registration or checkout is recorded for evidentiary purposes. A material change to purpose, role, information category, recipient, transfer, retention, automated decision, marketing practice, or data-subject right is classified and notified through the legal change process and triggers fresh acknowledgement or acceptance where the contract or law requires it.

22. Contact and complaints

Privacy requests about a merchant order should normally be sent first to the merchant identified on the storefront or receipt. Requests about a Bibeno account or Bibeno's own processing may be sent to support@bibeno.co.za or to the verified Information Officer contact published below. Include your name, business name if relevant, account or order reference, country, relationship to the relevant account, and the right you want to exercise.

Jean Posthumus

support@bibeno.co.za

The verified registered and service addresses are published below. We may need to verify your identity, authority, business relationship, or administrator role before acting on a request.

Plot 17 Second Street, Mooilande AH, Meyerton, Gauteng, 1963, South Africa

Plot 17 Second Street, Mooilande AH, Meyerton, Gauteng, 1963, South Africa

If you are in South Africa and believe your privacy rights have not been handled correctly, you may lodge a complaint with the Information Regulator (South Africa) using its current Form 5, eServices portal, or other official complaint channel published at inforegulator.org.za. Check the Regulator's official site for the current form, address, and submission method before filing.

Book a demo
Bibeno

Point of sale and business management software for South African food-service and independent retail businesses.

Book a demo

Product

Software overviewIndustriesPricingDownload for WindowsBook a demoGet started

Company

AboutContact usSign in

Legal

Legal centreTermsPrivacyData processing agreementRefunds and cancellation
BIBENO (PTY) LTD · Reg. 2026/355321/07© 2026 Bibeno POSsupport@bibeno.co.za+27 60 659 1848

Choose your cookie preferences

Essential storage is always active. Optional analytics and marketing tools remain off unless you allow them. Read more.

Cookie preferences

Control optional website technologies

Necessary technology is always active. Optional categories remain off until you enable them. You can change these choices from the website footer.

Strictly necessary

Remembers your consent choice and supports essential website security and forms. This category cannot be switched off.

Currently used: Bibeno consent storage; Cloudflare Turnstile on protected demo forms.

Functional

Would remember optional site preferences that are not needed for core features.

Not currently used.

Analytics

Would help us understand website use and improve performance through approved measurement tools.

Not currently used.

Marketing

Would support approved advertising, campaign measurement or personalised marketing.

Not currently used.

Your browser is sending a Global Privacy Control signal. Optional categories remain off unless you actively change them here.