Why Can't I Install Third-Party Apps on My POS Terminal?
Qashier POS terminals only allow apps that have been reviewed and approved by Qashier. You cannot install apps from the Google Play Store, sideload APK files, or add other third-party Android software to the device. This is a deliberate security control, not a limitation of the hardware.
Why POS Terminals Are Locked Down
A POS terminal is not a general-purpose Android tablet. It processes card numbers, transaction data, and other sensitive financial information, which puts it under a different set of rules than a personal phone or tablet.
PCI-DSS Requirements
Payment terminals that handle card data fall under the Payment Card Industry Data Security Standard (PCI-DSS). PCI-DSS requires that devices processing cardholder data run only approved, verified software, with all applications on the device tracked, tested, and controlled. Allowing unverified apps onto the terminal would break this chain of control and put the device out of compliance.
Local Regulatory Requirements
On top of PCI-DSS, payment infrastructure is also subject to oversight from local financial regulators. Each requires financial institutions and their payment systems to maintain strict, auditable control over the software running on devices that touch financial transactions:
Singapore: The Monetary Authority of Singapore (MAS) technology risk management guidelines expect financial institutions and their payment infrastructure to maintain strict controls over the software running on devices that touch financial transactions.
Thailand: The Bank of Thailand (BOT) IT Risk Management Guidelines, issued under the Payment Systems Act, require designated payment service providers to secure and control the systems handling transactions.
Malaysia: Bank Negara Malaysia's (BNM) Risk Management in Technology (RMiT) policy sets requirements for device security, authentication, and technology risk controls for payment system operators and regulatees.
Philippines: The Bangko Sentral ng Pilipinas (BSP) Information Technology Risk Management (ITRM) guidelines require financial institutions to maintain asset classification, access controls, and fraud management systems across devices used for payments.
An open, unrestricted app environment on a POS terminal would not meet the expectations set by any of these frameworks.
Cybersecurity Risk
Beyond compliance, unverified third-party apps are a direct security risk. An app installed outside Qashier's review process could contain malware, request excessive permissions, or create a pathway for attackers to intercept payment data. Locking down the terminal to approved software closes off this attack surface.
What This Means for You
You can only use apps that are pre-installed or explicitly approved and distributed by Qashier
Sideloading APKs or enabling unknown sources is disabled at the system level
This restriction applies across all Qashier POS terminal models in Singapore, Thailand, Malaysia, and the Philippines
This approach is standard across the payments industry. Other POS hardware manufacturers and payment providers apply the same restriction for the same reasons: protecting cardholder data and meeting regulatory obligations.
Common Questions
Q: Can I request an exception to install a specific app?
No. Because the restriction is tied to PCI-DSS compliance and local regulatory requirements (MAS in Singapore, BOT in Thailand, BNM in Malaysia, BSP in the Philippines), exceptions cannot be made on a per-merchant or per-device basis.
Q: Is this specific to Qashier, or do other POS providers do the same?
This is an industry-wide practice. Any POS terminal that processes card payments and needs to remain PCI-DSS compliant will lock down app installation in the same way.
Q: What if I need additional functionality on my terminal?
Reach out to Qashier support with the specific functionality you need. If it's broadly useful and can be reviewed for security, it may be added as an approved app in a future release.
