Best Practices and Recommendations
Building applications for Getnet POS terminals requires more than just functional integration. Following best practices ensures your application is secure, efficient, and passes certification on the first attempt.
This guide covers recommended development practices and critical prohibitions that will result in immediate rejection. By following these guidelines, you’ll create applications that perform well on POS hardware while meeting Getnet’s security and operational standards.
Security best practices
As a developer, you are responsible for information security within your application. Follow these guidelines to protect sensitive data and maintain user trust:
1. Use Android programming best practices
Follow standard Android development guidelines and patterns to ensure code quality and maintainability.
2. Ensure information security
Implement proper security measures throughout your application. Protect data in transit and at rest.
3. Protect sensitive customer data
Never expose passwords, personal information, or payment details in logs, error messages, or insecure storage.
4. Maintain data integrity
Validate all inputs and ensure data consistency throughout your application’s lifecycle.
5. Optimize APK size
Review your project and delete unused images, resources, and dependencies to keep your APK lean.
Performance and resource management
POS terminals have constrained resources compared to typical smartphones. Efficient resource usage is critical:
6. Avoid infinite timeouts
Set appropriate timeouts for all operations. Never leave your application waiting indefinitely for events or responses that may never arrive.
7. Manage hardware responsibly
Only activate the Mifare antenna when needed. Turn it off immediately after use to conserve battery and prevent interference.
8. Minimize data consumption
Be conscious of network usage. Implement efficient data sync strategies and avoid unnecessary API calls.
9. Reduce printing waste
Optimize receipt layouts to minimize paper consumption:
- Avoid large images and excessive white space
- Remove unnecessary gaps between lines
- Eliminate blank spaces at the beginning and end of receipts
10. Optimize memory and CPU usage
Monitor and minimize resource consumption. Avoid memory leaks and CPU-intensive operations that could impact other applications running on the terminal.
Critical prohibitions
The following restrictions are strictly enforced and will cause immediate rejection during certification:
1. WebView and WebApps are prohibited
Applications using WebView-based technologies (e.g., Ionic, Cordova) are expressly forbidden due to security requirements. Our certification team uses specialized tools to detect WebView usage.
2. Google Play Services are unavailable
POS terminals do not have access to Google Play Services. Do not include dependencies that require them.
3. No communication with competitors
Your application cannot communicate with any direct or indirect competitor of Getnet or the Santander Group, including:
- Other banks
- Payment processors or acquirers
- Sub-acquirers
- Digital wallets
4. Full-screen mode is forbidden
Applications must not run in full-screen mode. The system status bar must remain visible at all times.
5. No system settings modifications
Your application cannot modify Android system settings such as date, time, location, or any other system-level configuration.
6. Restricted external resource access
Access to certain external resources is prohibited, including:
- USB devices
- Google Play Store
- Other unauthorized hardware or services
7. Brand and visual identification restrictions
Your application’s icon, logo, and name must not reference or resemble:
- Getnet and its products
- Banco Santander
- Direct or indirect competitors of Getnet or the Santander Group (banks, acquirers, sub-acquirers, wallets)
Next steps
Following these best practices and avoiding prohibited actions will help ensure your application passes certification and provides a reliable, secure experience on Getnet POS terminals. If you have questions about specific requirements, consult the complete certification guidelines or contact Getnet support.
- Quick Start - apply these practices while building the first integration.
- Architecture and flow - understand the Intent mechanism the rules protect.