Security & control
The boring features you only need once
Permissions, an audit trail and a system that refuses to charge a card twice. Unglamorous until the first time somebody asks who gave that discount — and then the most important thing in the product.
- Role-based permissions
- Audit trail with names
- Card data stays on the terminal
Recorded on every sale
- Who performed the service
- Who took the payment
- Which tender settled it
- Any discount or override, and by whom
- Which register and drawer it closed against
Control, in six pieces
Roles and permissions
Permissions attach to a role, and the roles cover the actions that move money — discounts, price overrides, voids, refunds and access to reporting. A front-desk coordinator and an owner are not the same user with different intentions.
An audit trail with names on it
Audit events record who changed what and when. Voids, refunds, discounts and overrides are the entries you want to have before anyone asks for them, not after.
PIN app lock
A tablet on a counter is a shared device in a public room. The PIN lock closes it between users without logging the location out of the shift.
OTP on login
Email and password with a one-time code, so a leaked password on its own is not a working login.
Access scoped per location
Per-user location access means a manager at one site does not silently gain the numbers for another. Registers and drawers belong to a location, so an end-of-day means one specific till.
Card data stays on the terminal
Payments run on your Dejavoo or PAX terminal against your merchant account. The card is read by the terminal, not typed into the tablet.
Safeguards around the money
The failures that cost real money are rarely dramatic. They are a retried card, a lost message and a history that was overwritten.
-
Double-charge guards
When a terminal payment has resolved but the backend save is unknown, the app says so explicitly and tells staff not to retry the card. A hopeful retry is how a client gets charged twice.
-
Offline continuity
Sales continue through an outage and upload when the connection returns, so the fallback is not a paper slip and a promise.
-
Reliable event delivery
Outbox events and scheduled jobs mean a message that matters is retried rather than lost the first time a network hiccups.
-
Archive rather than delete
Inventory transactions, invoices and archive logs keep history instead of overwriting it, which is what makes a dispute answerable months later.
Questions worth asking any vendor
Are you PCI compliant?
Card data is captured by the payment terminal, not by the tablet, which is the architecture that keeps the app out of the card data path. We are not publishing a certification claim on this page until there is a certificate to point at — treat any vendor that does otherwise with suspicion.
Can I stop staff refunding without approval?
Yes. Refunds, voids, discounts and price overrides are permissions on a role, and every use is written to the audit trail with the user and the time.
What stops someone using a logged-in tablet?
The PIN app lock. It closes the app between users without ending the shift or the drawer session.
Who can see the numbers?
Reporting access is a permission, and location access is per user. Somebody who works two days a week at one site does not get the tenant’s figures by default.
Can I export my data?
Yes, on request, and there is no contract holding it. Data you cannot leave with is leverage, not a feature.
Keep your terminal. Keep your rate. Keep every feature.
Groww POS runs on the Dejavoo or PAX terminal you already own — no features held back, no marketplace commission.