[ RESTAURANT PAYMENTS ]

Card data never touches our software

Payment processing is usually the largest line item in a POS relationship and the least examined part of the contract. Here is exactly how it works in ThaliPOS, including what has not been certified yet.

How restaurant payment processing works

A restaurant POS can handle card payments in two ways. In an integrated setup the POS software captures the card details and passes them on, which drags the whole system into PCI scope. In a semi-integrated setup the POS only tells a certified reader how much to charge; the card data goes from the reader straight to the processor and never enters the POS at all. ThaliPOS is semi-integrated.

The practical difference is what happens if the POS vendor is ever breached. If card data never entered their software, there is nothing in it to take.

How we enforce it, rather than promise it

Every vendor says they take card security seriously. The version of that claim worth anything is architectural, and checkable.

That is a design constraint enforced by tooling, not a policy someone could quietly relax under deadline pressure.

Where the money goes

Where cards are taken

The counter

Card-present

A tap-and-chip reader assigned to the counter station. The POS drives it directly — no one retypes an amount into a separate terminal, which is where the mismatches come from.

The kiosk

Card-present

Each station has its own assigned reader, so the kiosk charges its own guest without borrowing the counter's hardware.

QR and online orders

Card-not-present

Checkout runs in the processor's own hosted payment form. Card details are entered into their form, on their infrastructure, never into ours.

Cash

Not an afterthought

Business-day close with drawer counts and a Z-report that reconciles cash tenders, not just card settlements. Money is held in integer cents throughout, so the day ties out exactly rather than approximately.

What happens to payments when the internet drops

Card payments need connectivity. Authorising a card means reaching the issuing bank, and no POS can do that offline — anyone claiming otherwise is describing deferred capture, where the authorisation happens later and somebody carries the risk of a decline after the guest has gone.

ThaliPOS does not do that. What it does instead is make sure the outage costs you the card lane and nothing else: the counter, kiosk and kitchen display keep running on the in-store hub, cash keeps flowing and reconciles normally at close, and card payments resume when the connection does. How the offline-first architecture works →

Current status — honestly

We would rather tell you this on a page you can read at your own pace than let you find out on a call after you had already planned around it.

What to ask any POS vendor about payments

  1. Am I locked to one processor? This single answer decides whether you can ever renegotiate your rates. Some major platforms require their own processing and do not permit alternatives.
  2. What is my effective rate on my own card mix? Not the headline rate. Ask for a blended figure based on the cards your guests actually present.
  3. Does card data pass through the POS software? If yes, ask what that means for your PCI scope.
  4. Do payouts go to my account or through the vendor's?
  5. What happens to card payments during an outage? If the answer is "they keep working", ask who absorbs a decline that arrives after the guest has left.

These are worth asking us as well. The full buyer's guide →

[ FAQ ]

Questions, answered straight

Does ThaliPOS store or process my customers' card numbers?

No. Payments use semi-integrated readers, so card data goes from the reader to the processor directly and never enters ThaliPOS. There are no card-number fields anywhere in the codebase, and an automated check fails the build if anyone adds one.

Can I take card payments with ThaliPOS today?

Not yet. The payment integration is built and tested but is in partner certification and is not switched on for restaurants. Cash handling and cent-exact end-of-day close are available to pilot restaurants now.

Where do my payouts go?

To a connected account in your restaurant's name. You complete the processor's identity and banking checks directly, and payments cannot be taken until that account is cleared.

Can I take card payments when the internet is down?

No, and no POS can — authorising a card requires reaching the issuing bank. Cash sales continue and reconcile normally, the counter and kitchen keep running on the in-store hub, and card payments resume when connectivity returns.

Who issues refunds?

A manager, from the POS, server-side against the original payment. Refunds are not available from customer-facing surfaces.

Tell us about your restaurant.

We're onboarding pilot restaurants now. Email us and we'll tell you honestly whether ThaliPOS is a fit for how you run service.

Email hello@thalipos.com