Self-Service Kiosks

It is 12:15 on a Saturday. The lunch line is twelve people deep. Somewhere upstream, a fiber cut takes out your internet provider for the entire retail block. Your point of sale terminals fall back to local mode and keep ringing. Your kiosks, all six of them, display a spinner and then an error screen.
For the next forty minutes, the most expensive ordering hardware in your restaurant is a set of digital paperweights, and every guest who walked toward a kiosk has to be absorbed by a counter you deliberately staffed down.
The question is not whether your connectivity will fail. It is what your kiosks do while it is failing.
Connectivity Fails More Often Than Vendors Admit
Restaurant networks are not data center networks. They are commodity broadband circuits terminating in a back office closet, frequently sharing bandwidth with security cameras, digital menu boards, guest Wi-Fi, and back office reporting.
The realistic failure modes are mundane and constant:
- Upstream provider outages, which take out every location on that circuit at once.
- Failed or rebooting network hardware that nobody has power cycled in three years.
- Bandwidth saturation at peak, when the network is technically up but too slow to be usable.
- Venue networks you do not control. Airports, stadiums, casinos, and travel plazas often place concessions behind a landlord managed network with firewall rules and maintenance windows you hear about after the fact.
- Genuinely remote sites. National park lodges, mountain resorts, and highway plazas frequently run on cellular or satellite backhaul, where an outage is a weather event rather than an incident ticket.
None of this is exotic. It is Tuesday.
The Cost Is Not Just the Missed Orders
Operators tend to model an outage as lost transactions during the outage window. That understates it considerably.
When kiosks stop selling, the guests in front of them do not evaporate. They redirect to a counter that was intentionally staffed for a lower share of orders, which creates a queue that does not clear when the network comes back. Throughput stays degraded for the rest of the daypart. Some guests leave. Staff spend the recovery period apologizing rather than serving.
If your self-ordering channel is carrying a meaningful share of transactions, and for many of our customers it carries most of them at peak, then a kiosk platform that cannot operate through an outage is not a self-ordering strategy. It is a fair weather one. We have covered the financial modeling in more detail in the hidden cost of kiosk downtime.
What "Offline Capable" Should Actually Mean
Nearly every kiosk vendor will tell you they support offline mode. The claim is worth very little on its own, because it is often satisfied by displaying a cached menu and a polite error message at the payment screen.
A kiosk platform that genuinely operates through an outage should be able to do four things while the internet is unavailable:
- Keep taking orders. The guest browses the full menu, configures modifiers, and completes a check without knowing anything is wrong.
- Keep feeding the kitchen. Tickets still reach the printers and the kitchen display, because the path between the kiosk and the kitchen does not depend on a connection to the outside world.
- Keep taking payment. Card transactions continue within limits agreed with your processor, rather than failing outright.
- Reconcile cleanly on recovery. When connectivity returns, orders land in the point of sale accurately and without duplicates, with a clear record of what was captured while offline.
Anything less than all four leaves a hole somewhere in the operation. Taking an order you cannot cook, or cooking an order you cannot charge for, is not meaningfully better than refusing it.
Where This Matters Most
Offline capability is valuable everywhere, but in some environments it is a requirement rather than a nice to have:
- Airports and travel concessions, where the network is landlord managed and the guest has a boarding time.
- National parks and remote resorts, where backhaul is cellular or satellite and seasonal infrastructure is the norm. The kiosks pictured above run at Lodgepole in Sequoia National Park, which is exactly the kind of site where assuming a reliable internet connection is not a defensible design decision.
- Stadiums and arenas, where tens of thousands of phones saturate the same airspace inside a compressed selling window.
- Highway travel plazas, geographically isolated, high volume, and with no technical staff on site.
- High volume QSR, where even a fifteen minute outage at peak is a material revenue event.
XPR Is Built for This
XPR was designed for operators running real venues, in exactly the environments above, which means the platform treats loss of connectivity as an expected condition rather than an exception.
XPR kiosks continue taking orders during an internet outage, tickets keep reaching the kitchen, card payments continue within the limits configured for your business, and orders reconcile into your point of sale once the connection is restored.
This includes deployments running Oracle Simphony. XPR integrates directly with Simphony, and the offline behavior is designed around that integration rather than bolted on beside it, so the checks that land in Simphony after an outage reflect what the guest actually ordered. The same applies across the other POS platforms XPR supports, including PAR Brink POS and Heartland Genius POS.
The exact configuration depends on your environment, including how your POS is deployed, which payment processor you use, and how you want to handle cash and reconciliation. Those are decisions we work through with your team during design, because the right answer for an airport concession is not the right answer for a national park lodge.
Keep Selling When the Network Does Not
Self-ordering only pays for itself if it works during the hours that matter, and those hours are exactly when networks are under the most strain.
If your team is evaluating kiosks for airports, parks, stadiums, travel plazas, or high volume restaurants, we are happy to walk through how XPR behaves during an outage against your own POS and payment environment, including Oracle Simphony.
Talk to the XPR team and ask us to pull the network cable during the demo. We expect the question.
Ready when you are
See your menu, your brand, your POS — running on XPR.
Book a 30-minute demo. We’ll set it up with your menu, your brand colors, and the full ordering-to-kitchen flow on your POS — not a generic walkthrough.