Every POS works when the internet does.
What matters is 14:32 on a Saturday, when the line drops and nine people are holding baskets. This page is about that hour and fifteen minutes, and what your books look like afterwards.
One Saturday
Scroll through a trading day. The line drops at 14:32.
Side by side
The same outage, two tills.
A cloud till is a web page that needs a server to do anything. Nostra is an application that happens to sync with one.
How it works
Exactly once is a design decision, not a hope.
Storing a sale offline is easy. The hard part is making sure that a sale which was sent, timed out and sent again does not become two sales. Here is the mechanism.
The device names the sale
Every offline transaction gets a unique identifier created on the device at the moment of sale, not assigned by the server later. It is part of the sale from the first second.
The queue survives everything
Queued sales live in the browser's own database on the device. Closing the tab does not lose them, restarting the machine does not lose them, and they are still there tomorrow morning.
The server deduplicates
When a sale arrives, the server checks whether it has accepted that identifier before. If it has, it returns the original result. Sending the same sale ten times produces one sale.
Stock moves in the same transaction
When the sale is accepted, its stock movement is written in the same database transaction. Either both happen or neither does. There is never a sale whose stock did not move.
Anything odd is shown, not buried
A sale that cannot be applied goes to a conflict log with the reason, never silently dropped and never silently forced through. You retry it one at a time or all at once.
When the line comes back
The printer tells you what it just did.
Restoring the connection prints a sync report: how many sales were queued on this device, how many the server accepted, and the one number that proves the mechanism worked, duplicates.
- Every queued sale listed with its total
- Accepted count matches queued count
- Stock and drawer reconciled before the report prints
The honest limits
What offline mode cannot do.
Anyone who says their offline mode has no limits is describing a demo, not a system. These are ours.
Card terminals still need the bank
We record that a card payment was taken, but only the bank can authorise it. Cash and transfer keep working normally, which in practice is most of what happens during an outage.
Other branches are a snapshot
An offline till knows its own stock exactly and other branches as of the last sync. Sell your own shelf with confidence; do not promise a customer something sitting across town.
Offers are priced online
Live promotions and loyalty redemptions are worked out while online. A sale made offline is recorded at the price the customer actually paid, rather than quietly repriced later.
Two tills can sell the last unit
If two offline tills each sell the final box, both sales are real and both sync. Nostra flags the negative stock on reconnect so you can fix it, instead of hiding it inside a figure.
A dead device with a queue is painful
Unsynced sales live on that device. That is why the queue count is always on screen, and why we recommend a second till per branch and a sync as soon as the line returns.
Full reports wait for the line
The till shows the day's local figures. Cross-branch and historical analytics run on the server. Selling is what cannot wait, so selling is what we made work.
Questions
Asked on every walkthrough.
How long can a till stay offline?
Do I need to install anything?
Can staff tell when the till is offline?
What if the sync fails halfway?
What about power, not just data?
Test it the hard way
Pull the cable mid-sale.
On a walkthrough we put a basket through the till, cut the network, finish the sale, reconnect and show you the ledger. It takes about four minutes.