This privacy notice for VendorOrbis (“we,” “us,” or “our”) explains how and why we collect, store, use, and share (“process”) your data when you visit our website, download/use our web or mobile POS app, engage with our AI features, payment QR system, subscription services, or communications. If you disagree with our policy, please do not use our Services. Questions? Contact us at support@vendororbis.com.
Summary of Key Points
- We collect: name, email, company, inventory/events info, AI data inputs, device info, location descriptors, biometric (locally), notification choices.
- Subscriptions: handled via Google Play, Apple App Store, or Stripe—no card data stored by us; subscription metadata (status, expiry) is processed.
- AI features: OpenAI is used to generate suggestions based only on sales entries—no raw financial data transmitted.
- Biometrics: Device-level authentication (Face ID/fingerprint) is permitted on user’s device only, and not stored or accessed by us.
- Security: Data stored in MongoDB on AWS Amplify, secured with JWT, encryption in transit/at rest, and access controls.
- Rights: Subject to GDPR, CCPA, etc.—you can request access, correction, deletion or object to processing.
- Updates to policy: You will be notified via email, in-app messaging, or login prompt.
Table of Contents
- What Information Do We Collect?
- How Do We Use and Process It?
- Legal Bases for Processing
- Sharing with Third Parties
- Cookies & Tracking
- Biometric Authentication
- AI & OpenAI
- Subscriptions & Payments
- Security and Storage
- Data Retention
- Children Under 18
- Your Privacy Rights
- Do Not Track
- US State & International Rights
- Changes to This Policy
- Contact & Updates
- Review, Update, or Delete Your Data
1. What Information Do We Collect?
Personal Information You Provide
- Name, email, company/vendor name
- Inventory records: item names, stock counts, pricing
- Event entries: titles, dates, location descriptions
- QR payment info: URLs/images pointing to user’s own payment methods (e.g., Cash App, Venmo)
- Push notification preferences and history
- Sales entered for AI suggestions
- Account credentials and JWT for login/authentication
Automatically Collected Information
- Device & Usage: IP, OS, browser/user agent, device model, app version
- Logs and diagnostic data: timestamps, crash dumps, performance data
- Application metadata: feature usage, timestamps, session data
- Location descriptions as text—no GPS unless user includes manually
Biometric
Optional device-native biometrics (Face ID/Fingerprint) used for authentication—the actual biometric data remains on device and is not sent to our servers.
2. How Do We Use and Process Your Data?
- To register/login users and manage accounts
- To enable inventory/event data entry and retention
- To generate AI suggestions using your entered data
- To deliver reminders, event tips, subscription notices
- To manage subscription status and enable/disable premium features
- To analyze usage and improve performance/security
- To communicate updates, policy changes, or support information
3. Legal Bases for Processing
If you are in the EU/UK/GDPR region:
- Consent: You consent to storing your input data and using AI suggestions.
- Contract: Needed to provide the Services you signed up for.
- Legitimate interests: To maintain app security, prevent fraud, enhance features.
- Legal obligations: To comply with laws or respond to lawful requests.
Similar grounds apply under CCPA, CPRA, UK Data Protection, etc.
4. Sharing with Third Parties
- OpenAI: to generate AI suggestions from your sales data
- Stripe/Apple/Google: to validate and manage subscriptions
- AWS/MongoDB: as our hosting/datastore providers
- Analytics: anonymized or aggregated usage stats
- Legal: to comply with law enforcement or legal obligations
- Business changes: if VendorOrbis is involved in mergers/sales, your data may transfer
5. Cookies & Tracking Technologies
We use cookies/local storage/web beacons to maintain sessions, track feature usage and app performance, and remember notification preferences. You can disable cookies in your browser; functionality may be affected.
6. Biometric Authentication
We only store a flag that biometrics is enabled. The actual biometric template never leaves your device.
7. AI & OpenAI
VendorOrbis uses OpenAI models to provide item restock and sales suggestions. Only hashed or partial sales data is sent. OpenAI’s policies apply to their processing.
8. Subscriptions & Payments
Subscriptions are processed by Google Play Billing (Android), Apple In‑App Purchases (iOS), and Stripe (web). We receive subscription metadata (plan, expiry, status) and never access your card/payment credentials.
9. Security and Storage
Data is encrypted in transit (HTTPS) and at rest (MongoDB). Hosted on AWS Amplify with JWT‑based access control, rate limiting, and monitoring/backups.
10. Data Retention
We retain your data while your account is active and for required backup/legal periods. Upon verified request, we anonymize or delete data per legal requirements.
11. Children Under 18
We do not knowingly collect data from individuals under 18. If discovered, we will delete it upon verification.
12. Your Privacy Rights
- Access, update, or correct personal data
- Request restriction or object to processing
- Request deletion (subject to legal exceptions)
- Withdraw consent at any time
Contact support@vendororbis.com. We respond within legal timeframes (typically 30–45 days).
13. Do Not Track
We currently don’t process DNT signals. If standards evolve, we will update this policy.
14. US State & International Rights
We honor rights under CCPA/CPRA and other US state laws (access, delete, correct, opt‑out of sale/sharing; we do not sell data). EU/UK/EEA GDPR rights include access, correction, erasure, restriction, objection, and portability.
15. Changes to This Policy
We may update this policy. We will notify users via email, in‑app notice, or login reminder.
16. Contact & Updates
VendorOrbis
Email: support@vendororbis.com
Discord: Link available in‑app
Mail: VendorOrbis, 123 Business Address, City, State, USA
17. Review, Update, or Delete Your Data
You can review or request updates/deletion by emailing us or using in‑app profile controls. Requests are handled within 30–45 days where applicable.