VendoPOS
Privacy Policy

Privacy Policy

Committed to protecting merchant datasets and customer information under RA 10173.

Effective June 14, 2026Data Privacy Act of 2012
  1. 1

    Our Role as a Data Processor

    VendoPOS operates as a Data Processor. Each merchant on the platform is the Data Controller of their own retail records — we process those records only on their documented instructions, never for our own ends.

    • Every tenant's dataset is fenced and processed in isolation — one merchant's records are never co-mingled with, or visible to, another's.
    • We act on the controlling merchant's instructions for the storage, access, and deletion of their data.
    • Sub-processors are limited to vetted infrastructure providers bound by equivalent data-protection terms.
  2. 2

    Consumer Transaction Histories

    Transaction histories captured at the register terminal — line items, tendered amounts, and any customer detail a cashier records — are held under strict non-disclosure.

    • Register-level transaction data is bound to the originating tenant and is never sold, rented, or shared across tenants.
    • We do not use consumer purchase histories for advertising, profiling, or model training.
    • Access is least-privilege — scoped to the merchant's own authenticated staff and a narrow, fully audited support path.
  3. 3

    What We Process

    We process only the operational data a POS + ERP needs to run a business, and nothing collected for its own sake.

    • Merchant and staff account details — names, roles, and authentication credentials.
    • Operational records — sales, inventory, suppliers, payroll, and finance entries.
    • Customer profiles a merchant chooses to keep — contact details and loyalty activity.
  4. 4

    Lawful Basis & RA 10173

    Processing is governed by the Data Privacy Act of 2012 (Republic Act No. 10173) and the issuances of the National Privacy Commission (NPC).

    • Processing rests on the merchant's contract and the legitimate operation of their business.
    • We uphold the data-subject rights guaranteed by the Act — access, correction, objection, and erasure.
    • A registered Data Protection Officer oversees compliance, audits, and breach-notification timelines.
  5. 5

    Retention & Deletion

    Records are retained for as long as the merchant's subscription is active, plus any statutory window the law requires us to keep them.

    • Financial and invoice records are retained to meet BIR record-keeping requirements.
    • On verified request or account closure, tenant data is purged from active systems on a defined schedule.
    • Backups age out on a rolling cycle and are never used to silently revive deleted records.

Reach our Data Protection Officer

To exercise a data-subject right or raise a privacy concern, contact our DPO. We acknowledge requests within one business day.

Email
privacy@vendopos.app
Headquarters
Cebu City, Philippines
Phone
0915 515 2314
Contact our team