Privacy Policy
Last updated 12 August 2026
This policy explains what information CashIn collects, why we collect it and what we do with it. It covers the CashIn web platform, the Cash In Mobile apps for iOS and Android, and this website.
1. Information we collect
CashIn is a business tool, and most of what it holds is operational data about machines rather than information about people. We collect:
- Account information — name, work email address, organisation, role and permissions, and the record of your invitation and sign-ins.
- Fleet and operational data — terminal records, transaction and end-of-day balance data, cassette and cash figures, routes, work orders and photos taken at a machine. This comes from you and from the processor accounts you connect.
- Processor credentials — the sign-in details you provide so that CashIn can collect data from your processor networks on your behalf. These are stored encrypted and used only for that purpose.
- Mobile app data — where you enable it, location is used to support routing and stop verification in Cash In Mobile. The app also keeps a local cache so it works offline, and can use your device’s biometric unlock to protect sign-in.
- Usage and technical data — log records of requests to the service, device and browser type, IP address, and error diagnostics.
This website is a marketing site and needs no account to read. It uses Google Analytics to measure traffic, which sets cookies in your browser and shares usage data — pages viewed, approximate location, device and browser type — with Google. We run no advertising cookies, and the CashIn platform and mobile apps carry no analytics of this kind.
2. How we use information
We use the information we hold for these purposes:
- To provide the service — collecting your processor data, producing dashboards, forecasts, routes and reports, and keeping the mobile app in sync.
- To secure the service — authenticating users, detecting suspicious activity and investigating incidents.
- To support you — answering questions, diagnosing faults and communicating about your account or changes to the service.
- To improve the service — understanding which features are used and where the product is falling short, using aggregated and de-identified data wherever that is sufficient.
- To meet our legal, tax and regulatory obligations.
We do not sell personal information, and we do not use your operational data to build products for your competitors.
3. Legal bases
Where the GDPR or a similar law applies, we process personal information on these bases: performance of our contract with you (providing the service and supporting it); our legitimate interests in securing and improving the service and administering our business, balanced against your rights; and compliance with legal obligations.
Where we handle data about your own staff and customers on your instruction, you are the controller of that data and we act as your processor.
5. How long we keep information
We keep operational and account data for as long as your account is active, and afterwards only for as long as the purposes described here require — typically to close out billing, resolve disputes and meet legal obligations.
Log and diagnostic data is kept on a shorter cycle. When data is no longer needed we delete it or de-identify it. You can ask us to delete your data sooner, subject to any legal retention requirement.
6. Security
We use encryption in transit, encrypted storage for credentials, role-based access control and per-organisation data separation. Access to production data by our staff is limited to those who need it to operate and support the service.
No system is completely secure. If a breach affects your data we will notify you without undue delay, and within whatever timeframe applicable law requires.
Your own controls matter too: keep credentials private, give each person their own account, and remove access for people who leave.
7. Your rights
Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, restrict or object to how we process it, receive a portable copy, or withdraw consent where we rely on it. You also have the right to complain to your data protection authority.
If you are a member of a customer organisation’s staff, ask your administrator first — many of these actions can be handled directly in CashIn. Otherwise contact us using the details below and we will respond within the period the law allows.
We will not treat you differently for exercising any of these rights.
8. Children
CashIn is a business product and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, contact us and we will delete it.
9. International transfers
CashIn is operated from the United States, and the information you provide is processed there. If you are outside the United States, using the service means transferring your information to a country whose data protection laws may differ from those where you live.
Where required, we put appropriate safeguards in place for those transfers, such as the European Commission’s standard contractual clauses.
10. Changes to this policy
We may update this policy as the product and our practices change. We will change the date at the top of this page, and give notice by email or in the product where a change materially affects how we handle your information.
11. Contact
CashIn is built and operated by Route 15 Software. To ask about this policy, or to exercise any of the rights described above, contact us at:
Enable JavaScript to see our address, or use the button.