
System Selection
POS customer records
Manage POS customer records through clear collection purposes, accurate profiles, staff access controls and an export plan.
Decide why each detail is needed. Find an existing profile before creating another. Keep marketing permission separate from service contact. Control who can view or export records.
Collect for a clear purpose
A delivery may need an address and contact number. A routine counter sale may need no named customer. Choose fields for the task rather than asking every shopper for the same details. Keep payment card numbers, health information and casual judgements out of customer notes.
Where the Australian Privacy Principles (APPs) apply, collection of ordinary personal information must be reasonably necessary for the organisation's functions or activities.
An email address collected for a digital receipt does not, by itself, establish permission for promotional messages. Keep evidence of the customer's choice separate from service contact details and consult the ACMA's guidance on avoiding spam.
In Square, manually entering an email address into a profile can automatically opt the customer into email marketing. Check the permission record against the customer's choice before sending a campaign.
Sensitive information has a stricter collection test for APP entities: collection must be reasonably necessary for the entity's functions or activities, and the individual must consent unless an exception applies.
Personal information must be collected by lawful and fair means and generally from the individual concerned, unless that is unreasonable or impracticable.
Square's directory can hold visit history, preferences, frequently purchased items, loyalty points and personalised notes alongside contact information.
Changes to a profile, including updates and deletions, appear in both Square Dashboard and the point of sale app, so staff can work from the same current record.
Pros and cons of collecting email addresses at checkout
- Pros
- Enables digital receipts and targeted promotions (with consent)
- Cons
- Automatic opt-in may breach APPs if consent not properly documented
Keep checkout moving
Give staff a short reason for asking, such as attaching a purchase to an existing profile for a warranty enquiry. Search first, confirm the match without disclosing another person's details, and collect only what the current task needs. If the request is optional and the customer declines, complete the sale through an available checkout path.
Square allows staff to add a customer during or after a sale. Check whether customer details are optional or required before making a routine profile request part of every sale.
Choose checkout fields deliberately
Shopify POS can be configured to request a first name, last name, phone number, email address, or combinations of contact details.
Its settings distinguish between details that are not required, recommended but skippable, and required. A required setting prevents checkout if a customer does not provide the information.
Required vs recommended vs optional checkout fields in Shopify POS
- Required
- Prevents checkout if not provided
- Recommended but skippable
- Displayed as suggestion, but not mandatory
- Not required
- No prompt during checkout
Maintain accurate profiles
Duplicate records can divide purchase history and leave conflicting contact or marketing details.
A shared name, phone number or email address is a reason to review two profiles, not proof that they belong to one person.
Square flags possible duplicates sharing an email address or phone number. Square warns that a completed profile merge cannot be reversed. Confirm identity and current preferences before an authorised person merges records.
Some Square records are created without a staff member entering a profile during checkout: customers are automatically added when they book through Square Appointments, enrol in Square Loyalty or are charged through Square Invoices. Account for these entry points when reviewing why a profile exists and whether its details remain current.
For Square customer email imports, the status column can be set to Subscribed, Unsubscribed or Unknown. Square describes Subscribed addresses as available for Square Marketing communications; an Unknown status is distinct from a recorded subscription and should not be treated as evidence of consent.
Key data points from Australian privacy and platform guidance
- APP collection requirement
- Must be reasonably necessary for functions or activities
- Email consent for marketing
- Not automatic — must be separately recorded
- Square merge warning
- Cannot be reversed after completion
- ACMA spam avoidance guidance
- Available at www.acma.gov.au/avoid-sending-spam
Control access and plan an exit
Check separately who may attach a customer to a sale, open details, edit a profile, merge records and download a list. Review admin and connected-app access as well as the till.
A customer CSV is another copy of personal information. Restrict its storage and decide when working copies can be removed.
Before changing providers, inspect a sample export for identifiers, contact details, notes, custom fields and marketing status. Ask separately how loyalty balances and stored payment arrangements would move. For transaction history, see the supporting article on transaction-history migration.
Keep a short operating record of collection purposes, identity checks, marketing choices, merge authority, access and export ownership. Revisit it when checkout settings, staff roles or providers change.
Explain access and correction
For an organisation covered by the Australian Privacy Principles, its privacy policy must explain how a person can access personal information held about them and seek its correction.
It must also describe the kinds of information collected, how it is collected and held, and the purposes for which it is used or disclosed.
The policy must also explain how a person can complain about an APP breach and how the organisation will handle the complaint.
If the organisation is likely to disclose personal information to overseas recipients, the policy must say so and, where practicable, identify the countries involved.
In this guide
- Collecting customer details without slowing a saleA short checkout process for asking for needed customer details, finding existing profiles and recording marketing choices separately.
- Finding duplicate customer profiles in a POSFind likely duplicate POS customers, verify identity and marketing preferences, and check irreversible merge limits before acting.
- Reviewing customer-data access at the tillCheck which till roles can view, edit, delete or export customer records against the actual plan, location and access routes.
- Exporting customer records when changing POS providersPrepare a POS customer export, map fields and consent status, check a small import and handle order history separately.


