Privacy Policy
This Privacy Policy is issued by the operator of the RetailFlow POS web application (the “Service”) available at retailflowpos.com (“Provider”, “we”, “us”, or “our”). The Provider’s full legal identity is set out in the Master Subscription Agreement (MSA-2026-v1) which all subscribers accept at sign-up.
This Privacy Policy describes our data practices and your rights. It is supplementary to and governed by our Master Subscription Agreement (MSA-2026-v1) which all subscribers accept at sign-up. In the event of any conflict or inconsistency between this Privacy Policy and the Master Subscription Agreement, the Master Subscription Agreement shall prevail.
1. Information We Collect
We collect the following categories of information:
- Account information: When you register, we collect your name, email address, store name, and a password (stored as a one-way hash).
- Google sign-in: If you choose to sign in with Google, we receive your Google account email address, display name, and a unique identifier from Google. We do not receive your Google password.
- Business data: Inventory records, sales transactions, receivables, and other data you enter into the application ("Store Data"). This data belongs to you.
- Usage and security logs: Server-side logs may record IP addresses, browser user-agent strings, request timestamps, clickwrap acceptance logs, and account activity logs. These are used for security, billing reconciliation, chargeback defense, and dispute resolution as permitted under the Master Subscription Agreement (Section 4.3). Routine operational logs are purged after 30 days; security, audit, and billing records may be retained longer where required by law or a lawful preservation order.
- Error and diagnostic data: When unexpected application errors occur, we collect error messages, a last-3-action trail (the buttons or tabs you interacted with immediately before the error), your store ID, username, and a permanent device identifier (“terminal ID”) stored in your browser’s
localStorage. This data is sent to Sentry (see §4) and is used solely to diagnose and fix software defects. - Local browser storage: The application stores your Store Data locally in your browser’s IndexedDB (via Dexie) and caches error/diagnostic logs in
localStorageto support offline use and cross-device sync. This data is stored only on your device and is not shared with third parties, except when synced to the server as part of normal Service operation.
2. How We Use Your Information
- To provide and operate the Service, including authenticating your identity and syncing your Store Data across devices.
- To send transactional emails (invite codes, subscription receipts). We do not send marketing emails without your explicit consent.
- To detect and block automated attacks (brute-force login attempts, denial-of-service) against the Service itself.
- To diagnose and fix technical errors reported by users.
3. Data Storage and Security
Your Store Data is stored in a PostgreSQL database provisioned through Vercel Postgres (powered by Neon, a SOC 2 Type II certified provider). Data is encrypted in transit (TLS 1.2+) and at rest. Authentication tokens are stored in HttpOnly cookies that are inaccessible to JavaScript. A copy of your Store Data is also cached locally in your browser’s IndexedDB to support offline use; this local copy is not accessible to other websites.
4. Third-Party Services
We use the following third-party services that may process your data:
- Vercel — hosting and serverless functions (Privacy Policy)
- Vercel Postgres / Neon — database hosting (Privacy Policy). Your Store Data is stored in this database.
- Sentry — error monitoring (Privacy Policy). When an unexpected error occurs, Sentry receives the error message, a last-3-action trail, your store ID, username, and terminal ID. Sentry does not receive passwords, payment card numbers, or full inventory data. Only non-4xx (unexpected) errors are forwarded; user-input validation errors are suppressed. Sentry is initialised only after you log in — it does not run on the public landing page.
- Google — optional OAuth sign-in (Privacy Policy)
- Resend — transactional email delivery for subscription invites (Privacy Policy)
We do not sell your data to any third party.
5. Data Retention
We retain your account information and Store Data for as long as your account is active or as otherwise required under the Master Subscription Agreement (Sections 4.3 and 10.4). Specifically:
- OAuth state tokens: purged after 10 minutes.
- Routine operational logs: purged after 30 days.
- Security, audit, clickwrap acceptance, and billing logs: retained for a commercially reasonable period for security, billing reconciliation, chargeback defense, and dispute resolution, and longer where required by law or a lawful preservation order.
- Store Data: retained while your account is active. After account deletion or subscription lapse, Store Data is deleted within a commercially reasonable period, subject to any lawful litigation hold or preservation order.
To request deletion of your account, use the contact details in Section 12 below. Deletion requests are processed promptly, subject to any legal retention obligations under the Master Subscription Agreement.
6. Your Rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate personal data.
- Request deletion of your personal data.
- Export your Store Data in a machine-readable format.
To exercise any of these rights, use the contact details in Section 12 below.
7. Government and Law Enforcement Requests
As stated in the Master Subscription Agreement (Section 11.3), we may preserve and disclose data to comply with lawful orders and legal investigations consistent with Applicable Law, including the Cybercrime Prevention Act of 2012 (RA 10175) and the Data Privacy Act of 2012 (RA 10173). Our policy for handling such requests is:
- We require a valid, specific, and lawfully issued court order, subpoena, or warrant before voluntarily disclosing user data. Informal requests, verbal requests, or administrative letters without proper judicial authority will be referred to our legal process.
- Any disclosure will be limited to the data specified in the legal order — no broader voluntary disclosure will be made.
- We will notify the affected subscriber promptly of any such request where we are legally permitted to do so.
- We will assert available legal defenses against any legal process we reasonably believe to be overbroad, improperly issued, or lacking valid legal basis.
Nothing in this section shall be construed to limit our rights or obligations under the Master Subscription Agreement (Section 11.3) or under any lawful order issued by a Philippine court of competent jurisdiction.
8. Cookies
We use a single HttpOnly session cookie (pos_auth) strictly necessary for authentication. We do not use advertising cookies or third-party tracking cookies.
9. Children's Privacy
The Service is not directed at children under 13 years of age. We do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time by posting the revised version on this page. As stated in the Master Subscription Agreement (Section 13.1), continued use of the Service after the effective date of any amendment constitutes acceptance. The “Last updated” date at the top of this page reflects the most recent revision.
11. Governing Law and Supremacy of Master Subscription Agreement
This Privacy Policy is governed by the laws of the Republic of the Philippines, including Republic Act No. 10173 (Data Privacy Act of 2012) and its Implementing Rules and Regulations. Disputes regarding this Privacy Policy are subject to the exclusive venue provisions of the Master Subscription Agreement (Section 12.3).
In the event of any conflict between this Privacy Policy and the Master Subscription Agreement (MSA-2026-v1), the Master Subscription Agreement shall control. Nothing in this Privacy Policy shall be construed to limit rights expressly granted to Provider under the Master Subscription Agreement, including rights to retain security logs, defend against claims, and comply with lawful legal process.
12. Contact
If you have any questions about this Privacy Policy, please contact us via the email address displayed in the application or on the home page of retailflowpos.com.