Last updated August 2026
3-Asfar is operated by Bengologic Ltd, a company registered in England and Wales under company number 16797011, with its registered office at 254-256 Hertford Road, Enfield, London, EN3 5BL, United Kingdom. We follow the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
There are two kinds of data here, and they are not treated the same way. For your own account — your name, your email address, how you use the app — we are the data controller. For the business records you enter, including details of your own customers and suppliers, you are the controller and we are only your processor: we hold and process them on your instructions, to run the service for you.
This distinction matters throughout what follows, so it is worth keeping in mind as you read.
The business records you enter — products, prices, sales, purchases, ledgers, and the customers and suppliers you deal with — are yours. We process them only to provide the service to you.
We do not sell your data or your customers’ data, we do not share it with anyone for their marketing, and we do not use your business records to train anything.
We use it to run your account and your company, to provide the features you are using, to keep the service secure and prevent abuse, to answer you when you contact support, to take payment for a subscription, and for our own internal analytics about how 3-Asfar is used so that we can improve it.
We rely on the performance of our contract with you (providing the service you signed up for), our legitimate interests (running, securing and improving 3-Asfar and preventing abuse), our legal obligations (keeping accounting records, for example), and your consent where a particular use depends on it.
We use a small number of providers to run the service, and they act only on our instructions, never for their own purposes:
Our servers are in the United Kingdom and the European Union. If data is ever transferred outside the UK or the European Economic Area, we make sure a lawful safeguard is in place, such as the approved standard contractual clauses.
3-Asfar keeps selling when the internet does not, and that only works because some data is held in your browser’s storage on the device itself.
What is held there: your product catalogue and prices, so the till can ring up a sale; recent sales; any sales made offline that have not yet reached us; and a copy of the last signed-in profile — who you are, which company you are in, and what you are allowed to do — so the app can start up with no connection.
What is not held there: your password and your session token. Those live in cookies the page itself cannot read. Your PIN is not stored either. What is stored is a verifier derived from it, which can check a PIN you type but cannot reveal the PIN.
We would rather be straightforward about the limit of this: a browser has no secure hardware to lock the verifier away in. It protects the way a phone left on the counter protects — enough to stop someone idly poking at the till, not enough to stop a determined attacker who takes the device away. The alternative was a till that stops selling the moment the line drops.
The device is in your hands, so keeping it physically safe is your responsibility. Signing out clears the stored copy, which is worth doing on a till that is shared between shifts. Clearing your browser’s data for the site removes it as well — but do not do that while offline sales are still waiting to sync, because they will be lost.
We keep your data while your account is active. After an account is closed we keep it for 90 days so that it can be restored or exported, and then delete it — except for records we must keep by law, such as accounting and audit records, and anything we need to resolve a dispute.
You have the right to see the personal data we hold about you, to have it corrected, to have it deleted, to receive a copy in a portable form, to object to or restrict how we use it, and to withdraw consent where our use of it rests on consent. Write to us at support@3-asfar.com and we will act on any request we can verify, subject to the exceptions above.
If you are a customer of a shop that uses 3-Asfar and you want to know what that shop holds about you, please ask the shop. Those records belong to them and we act on their instructions; if you come to us, we will pass your request on and help them answer it.
We use cookies and browser storage only to make the service work: to keep you signed in, to protect against cross-site request forgery, to remember your language and theme, and for the offline data described above. We do not use advertising cookies and we do not track you across other websites.
Passwords and PINs are stored hashed, never in a form we could read. Traffic between your device and our servers is encrypted. Each company’s data is separated from every other company’s, and access on our side is limited to the people who need it to run the service. No system is perfectly secure, but these are the measures we take.
3-Asfar is a tool for running a business and is not intended for children. We do not knowingly collect data from anyone under 18.
We may update this policy. Each version carries the date it was last updated, and where a change is significant we will tell you.
If something concerns you, please tell us first — we would rather put it right. You also have the right to complain to the UK Information Commissioner’s Office at ico.org.uk.
For any question about privacy or to make a request, write to us at support@3-asfar.com.