Privacy Policy

Last updated: June 26, 2025

Applies to: the VendorOrbis Android app (package: com.vendororbis), iOS app, and the website at vendororbis.com.

This privacy notice for VendorOrbis (“we,” “us,” or “our”) explains how and why we collect, store, use, and share (“process”) your data when you visit our website, download/use our web or mobile POS app, engage with our AI features, payment QR system, subscription services, or communications. If you disagree with our policy, please do not use our Services. Questions? Contact us at support@vendororbis.com.

Summary of Key Points

Table of Contents

  1. What Information Do We Collect?
  2. How Do We Use and Process It?
  3. Legal Bases for Processing
  4. Sharing with Third Parties
  5. Cookies & Tracking
  6. Biometric Authentication
  7. AI & OpenAI
  8. Subscriptions & Payments
  9. Security and Storage
  10. Data Retention
  11. Children Under 18
  12. Your Privacy Rights
  13. Do Not Track
  14. US State & International Rights
  15. Changes to This Policy
  16. Contact & Updates
  17. Review, Update, or Delete Your Data

1. What Information Do We Collect?

Personal Information You Provide

Automatically Collected Information

Biometric

Optional device-native biometrics (Face ID/Fingerprint) used for authentication—the actual biometric data remains on device and is not sent to our servers.

2. How Do We Use and Process Your Data?

3. Legal Bases for Processing

If you are in the EU/UK/GDPR region:

Similar grounds apply under CCPA, CPRA, UK Data Protection, etc.

4. Sharing with Third Parties

5. Cookies & Tracking Technologies

We use cookies/local storage/web beacons to maintain sessions, track feature usage and app performance, and remember notification preferences. You can disable cookies in your browser; functionality may be affected.

6. Biometric Authentication

We only store a flag that biometrics is enabled. The actual biometric template never leaves your device.

7. AI & OpenAI

VendorOrbis uses OpenAI models to provide item restock and sales suggestions. Only hashed or partial sales data is sent. OpenAI’s policies apply to their processing.

8. Subscriptions & Payments

Subscriptions are processed by Google Play Billing (Android), Apple In‑App Purchases (iOS), and Stripe (web). We receive subscription metadata (plan, expiry, status) and never access your card/payment credentials.

9. Security and Storage

Data is encrypted in transit (HTTPS) and at rest (MongoDB). Hosted on AWS Amplify with JWT‑based access control, rate limiting, and monitoring/backups.

10. Data Retention

We retain your data while your account is active and for required backup/legal periods. Upon verified request, we anonymize or delete data per legal requirements.

11. Children Under 18

We do not knowingly collect data from individuals under 18. If discovered, we will delete it upon verification.

12. Your Privacy Rights

Contact support@vendororbis.com. We respond within legal timeframes (typically 30–45 days).

13. Do Not Track

We currently don’t process DNT signals. If standards evolve, we will update this policy.

14. US State & International Rights

We honor rights under CCPA/CPRA and other US state laws (access, delete, correct, opt‑out of sale/sharing; we do not sell data). EU/UK/EEA GDPR rights include access, correction, erasure, restriction, objection, and portability.

15. Changes to This Policy

We may update this policy. We will notify users via email, in‑app notice, or login reminder.

16. Contact & Updates

VendorOrbis
Email: support@vendororbis.com
Discord: Link available in‑app
Mail: VendorOrbis, 123 Business Address, City, State, USA

17. Review, Update, or Delete Your Data

You can review or request updates/deletion by emailing us or using in‑app profile controls. Requests are handled within 30–45 days where applicable.