Privacy Policy
Committed to protecting merchant datasets and customer information under RA 10173.
- 1
Our Role as a Data Processor
VendoPOS operates as a Data Processor. Each merchant on the platform is the Data Controller of their own retail records — we process those records only on their documented instructions, never for our own ends.
- Every tenant's dataset is fenced and processed in isolation — one merchant's records are never co-mingled with, or visible to, another's.
- We act on the controlling merchant's instructions for the storage, access, and deletion of their data.
- Sub-processors are limited to vetted infrastructure providers bound by equivalent data-protection terms.
- 2
Consumer Transaction Histories
Transaction histories captured at the register terminal — line items, tendered amounts, and any customer detail a cashier records — are held under strict non-disclosure.
- Register-level transaction data is bound to the originating tenant and is never sold, rented, or shared across tenants.
- We do not use consumer purchase histories for advertising, profiling, or model training.
- Access is least-privilege — scoped to the merchant's own authenticated staff and a narrow, fully audited support path.
- 3
What We Process
We process only the operational data a POS + ERP needs to run a business, and nothing collected for its own sake.
- Merchant and staff account details — names, roles, and authentication credentials.
- Operational records — sales, inventory, suppliers, payroll, and finance entries.
- Customer profiles a merchant chooses to keep — contact details and loyalty activity.
- 4
Lawful Basis & RA 10173
Processing is governed by the Data Privacy Act of 2012 (Republic Act No. 10173) and the issuances of the National Privacy Commission (NPC).
- Processing rests on the merchant's contract and the legitimate operation of their business.
- We uphold the data-subject rights guaranteed by the Act — access, correction, objection, and erasure.
- A registered Data Protection Officer oversees compliance, audits, and breach-notification timelines.
- 5
Retention & Deletion
Records are retained for as long as the merchant's subscription is active, plus any statutory window the law requires us to keep them.
- Financial and invoice records are retained to meet BIR record-keeping requirements.
- On verified request or account closure, tenant data is purged from active systems on a defined schedule.
- Backups age out on a rolling cycle and are never used to silently revive deleted records.
Reach our Data Protection Officer
To exercise a data-subject right or raise a privacy concern, contact our DPO. We acknowledge requests within one business day.
- privacy@vendopos.app
- Headquarters
- Cebu City, Philippines
- Phone
- 0915 515 2314
