Training formats: live webinars, recorded tutorials, interactive sandboxes, and knowledge bases.
Training materials: quick-start guides, step-by-step SOPs, video tutorials, and in-system help.
Train-the-trainer approach for multi-store deployments.
Implementation-phase training
Pre go-live training to minimize disruption.
Pilot store training and hands-on practice with live configurations.
Post-go-live support
Hypercare window (first days/weeks) with elevated support SLAs.
Ongoing access to a dedicated account manager or customer success representative (varies by plan).
Support channels and SLAs
24/7 phone and chat support, email, and a web portal for tickets.
Tiered SLAs: critical/urgent issues (e.g., POS down) vs standard support (functional questions).
Security Measures
Data encryption
In transit: TLS 1.2+ for all data exchanged between POS terminals, back-office, and cloud services.
At rest: encryption (e.g., AES-256) for databases and backups.
Access control and authentication
Role-based access control (RBAC) with least-privilege permissions.
Multi-factor authentication (MFA) options for admin and privileged accounts.
Strong password policies and periodic credential rotation.
Compliance standards
PCI DSS alignment for cardholder data handling; scope reduction practices (e.g., tokenization, PCI SAQ scope).
Data residency and localization options (where data is stored geographically)
Privacy compliance (e.g., GDPR, CCPA) where applicable; data minimization and retention policies.
Data protection and backups
Regular automated backups with defined RPO/RTO targets.
Backup encryption and secure restore procedures.
Disaster recovery planning and tested failover processes.
Security monitoring and incident response
Continuous monitoring, anomaly detection, and access logs.
Known vulnerability management and timely patching.
Incident response plan, notification timelines, and post-incident reviews.
Updates
Release cadence
Planned frequencies: monthly, quarterly, or as-needed with emergency patches.
Major vs minor updates vs hotfixes: how distinctions are made and communicated.
Update scope and impact
Are updates automatic or optional? Do you require downtime, or can updates be applied in a rolling fashion.
Backward compatibility: will updates require changes to customizations, integrations, or scripts,
Change management
Release notes detailing new features, bug fixes, security patches, and any breaking changes.
A staging/test environment or sandbox to validate updates before production.
Guidance and support for migrating customizations or APIs after updates.
Rollback and fallback
Ability to roll back a problematic update with minimal disruption.
Backup before update and documented rollback procedures.
Communication
Advance notice (timelines, window) for planned maintenance or updates.
Customer-facing documentation and internal IT readiness resources.
Data Ownership and Portability
Data ownership
Confirm that your organization retains full ownership of all data you generate (sales transactions, customer data, product catalogs, inventory, etc.).
Clarify rights to access, export, and use data for analytics, reporting, or migration.
Data formats and export
Available export formats (CSV, XML, JSON, SQL dumps) and the scope of export (raw data vs processed reports).
Frequency of data exports (on-demand, scheduled, or real-time replication).
Data portability
Availability of data migration tools or APIs to move data to another system.
Any required data transformation or mapping when exporting to a new platform.
Timeline and process for a customer-initiated data export upon termination.
Data retention and deletion
Retention policies for historical data after contract termination.
Procedures for secure deletion/destruction of data and backups.
Data localization and cross-border transfer
Where data is stored (data center regions) and whether data can be stored in a region of your choice.
Scaling Up / Down
Flexible licensing and billing
Whether you can scale by location/register, with prorated pricing, and how upgrades/downgrades are billed.
Minimums, notice periods, and any lock-in requirements for scaling.
Containerized or modular feature enablement
Ability to add or remove modules (e.g., advanced analytics, loyalty, eCommerce) without full redeployment.
Impact on data model, integrations, and SLAs when features are added/removed.
Performance and capacity guarantees
Accepted maximum throughput, concurrent users, and transaction volumes per plan.
SLA commitments around uptime and performance during scale changes.
Data and process continuity
How scaling affects data migration, synchronization, and offline capabilities.
Change management requirements (retraining, reconfiguration) when increasing or decreasing scope.
Termination or pause options
Ability to pause capabilities (e.g., temporarily reduce active locations) without penalties.
The terms & conditions for contract renewal and cancellation
Renewal structure
Auto-renewal terms, renewal notice requirements, and any price escalation policies.
Whether pricing changes at renewal are capped or subject to market adjustments.
Term lengths and termination rights
Contract term length (1 year, multi-year) and termination windows without penalties.
Termination for convenience vs. termination for cause (with cure periods) and related notice requirements.
Fees on termination
Early termination fees (if any), data export costs, or decommissioning charges.
Responsibility for unamortized hardware leases, if applicable.
Data handover at end of term
Timelines and formats for data export after termination.
Assistance or professional services offered for migration out, and any related fees.
SLAs and support during/after renewal
Continuity of support levels during transition periods.
Any changes to support tiers upon renewal (e.g., upgrade to higher-tier support).
Pricing guarantees
Any price-lock options for a fixed period, or concessions for multi-year commitments.
Auditability and compliance
Right to audit contract terms, service levels, and data handling commitments if required by your governance.
Compliance
PCI DSS scope and certification
Whether PCI DSS certification covers all cardholder data processing or only certain components (e.g., cloud processing, KMS, payment terminals).
PCI SAQ types applicable to your deployment (e.g., SAQ A, A-EP, or D) and any scope reduction measures (tokenization, end-to-end encryption, point-to-point encryption).
Data protection regulations
GDPR/CCPA compliance, data subject rights handling, and data processing addenda.
Data residency options and cross-border data transfer mechanisms (SCCs, BCRs).
Security controls aligned to standards
ISO 27001/27018, SOC 2 Type II reports, or other third-party attestations.
Regular third-party security assessments, vulnerability scanning, and penetration testing cadence.
Industry-specific requirements
If applicable, compliance with industry norms (e.g., healthcare, alcohol sales, gaming) and corresponding data handling rules.
Incident response and breach notification
RPO/RTO targets, incident notification timelines, and post-incident reporting.
Privacy and data minimization
Data retention schedules, anonymization/pseudonymization options, and data deletion procedures.