Mobile Retail POS and Offline Trading
- Retail owners and cashiers
- Updated
In this guide
19.1 Availability and Preparation
Mobile offline selling is a controlled rollout, not a replacement for the web POS. It is unavailable until the platform, business, and register are enabled and a manager has configured positive per-sale and per-session limits. The business must have POS and Inventory enabled and you must have the required selling permissions. Offline activation remains blocked for fiscal-enabled businesses until their receipt and outage workflow is validated.
Prepare while connected: select the correct business, register, and location; authenticate the cashier; open or select the shift; synchronize products, prices, taxes, and receipt settings; then obtain the device's authorization and stock allocations. Confirm Offline Ready, the authorization expiry, and the remaining allocations before disconnecting. An authorization belongs to one account, device, cashier, register, and shift, for a maximum of 12 hours. Cashier switching and renewal require connectivity; the app does not download supervisor PIN hashes.
This release is Retail only. Restaurant tables and kitchen coordination, Pharmacy, and serialized or batch-controlled checkout require their supported online web workflows. Batch and serial products cannot be checked out in the native app, even while connected; use the web register. A product with an unsupported tax or pricing rule must be checked out online. Do not substitute another product to bypass an unavailable item.
19.2 Checkout and Receipts
Review the cart, fixed-combo contents, tax, and final amount. Discounts, promotions, and unsupported pricing rules require a fresh online quote. Offline payments are enabled cash and externally received payment evidence for Mobile Money in the prepared register configuration; a disabled method is not available at checkout. Confirm receipt of a Mobile Money transfer using the business's procedure and record its reference. This is not provider-verified collection, and the app does not charge a wallet. Cash tendered and change are recorded separately.
The app must save the receipt, lines, payments, allocation consumption, and pending synchronization operation together before showing sale completion or printing. Saved on device means the sale is preserved locally, not yet accepted by the server. Syncing means upload is in progress; Synced means there is a server acknowledgement. Needs attention requires review, not another payment. Reserved receipt numbers remain attached to the original sale and are never reused.
A network-printer failure does not undo a sale. Reprint the saved receipt rather than repeat checkout. Digital receipts use the prepared receipt configuration; cloud sharing requires connectivity. Local-network 58 mm and 80 mm printers need a supported, tested printer configuration. Do not assume that every Bluetooth or USB printer is compatible.
19.3 Stock and Authorization Limits
When negative stock is disabled, the device can sell only within its authorized allocations. Singles and every fixed-combo component consume those allocations, including components shared by other cart items. Other selling channels must respect the reserved quantities too. Allow negative stock applies to valid singles and combos but does not authorize an invalid recipe, serialized stock, or unsupported checkout.
Expiry stops new offline sales; it does not erase completed work. The server does not release uncertain stock automatically when authorization expires. Reconcile the device or ask a manager to follow the audited recovery procedure. Do not adjust stock to remove a legitimate device reservation.
Closing and reopening the app preserves the prepared workspace and paid receipts. Rebooting the phone or changing its clock requires connectivity and new preparation before additional offline selling; the existing paid evidence remains available for recovery. Prepare Inventory independently without replacing an active POS catalog or changing a paid sale's prices.
19.4 Synchronization, Recovery, and Closing
Open Sync Centre when connected and inspect pending operations. Retry the same operation; a lost acknowledgement is recovered using its original identifier, not a new sale. Changed permissions, fiscal locks, invalid prices or taxes, and incompatible stock policy can require review. A paid offline sale must not be silently repriced.
If activation is interrupted, reconnect and recover the saved activation before preparing another shift. The app retrieves the original authorization, allocations, receipt block, and expiry; recovery does not grant another 12 hours. Do not create a new authorization to replace one whose response was lost.
Choose Resolve unused preparation only when the server confirms the exact original setup was never issued and its issuance deadline has expired, or that it was already reconciled. Review the confirmation before continuing. A missing response or ordinary 404 is not proof. The app keeps the original setup in its encrypted archive and refuses this action while a local authorization or an associated offline paid sale exists. Recover and reconcile that work instead; pending online-sale acknowledgements remain preserved separately.
After five temporary server failures, automatic retries stop. Use the saved record's Retry saved operation action after the displayed cooldown, rather than repeat payment or create a replacement sale. Needs attention is different: restore the identified permission or policy and ask an authorized manager to use Recheck with supervisor with a supervisor PIN and a reason. The manager needs both POS settings and sale-history access. Review reruns the original safety checks; it does not override an invalid snapshot, receipt, price, or stock allocation.
For a cashier-to-manager handoff, choose Copy operation reference on the saved receipt. The manager signs into their own account, opens the Sync Centre menu, and chooses Review uploaded operation by reference. Enter that original UUID, a 4-8 digit supervisor PIN, and a review note of 10-500 characters, then confirm the displayed reference. A supervisor PIN alone does not grant access: current POS settings-management and sale-history permissions are required. Restore the original cashier's access and reported policy first. If the record has not been uploaded, the cashier must upload the preserved record before a manager can review it; do not create another sale.
The manager sees the review status, not a copy of the cashier's private receipt or local ledger. The original cashier selects Sync now to retrieve the acknowledgement for the same reference. Ownership, receipt number, payment evidence, and cashier attribution stay with the original transaction.
Do not discard a locally completed paid sale. Sign-out, account switching, or expired access must preserve pending work in its encrypted account-specific ledger. If access is revoked, request authenticated manager-assisted recovery. Keep the device available until reconciliation is confirmed. Uninstalling the app or losing the device can destroy work that has not been uploaded; do not uninstall or reset it as a synchronization fix.
Refunds, voids, credit sales, payment-provider collection, and final shift closure require connectivity. You may record a local cash count, but final shift closure requires online reconciliation of pending grants and sales. Review receipts, payment evidence, stock movements, register totals, and applicable Accounting entries; do not post a duplicate journal manually.
Permission revocation cannot reach a disconnected device instantly. The prepared authorization bounds that exposure to its expiry, at most 12 hours. Upload and recovery remain necessary even when new offline trading is disabled.