1. Scope and privacy principles
This policy applies to POSONLY websites, merchant accounts, point-of-sale and inventory services, documentation, billing, and customer inquiry forms. We aim to process personal information transparently, for legitimate and declared purposes, and only to a proportionate extent.
POSONLY is designed with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and its implementing rules in mind. Product design alone does not guarantee a merchant’s legal compliance.
2. Information we collect
- Account information: names, email addresses, mobile numbers, passwords stored as secure hashes, roles, branch assignments, and account status.
- Business information: merchant and branch details, registered name, TIN, address, subscription plan, payment references, and configured receipt details.
- Operational records: products, inventory movements, suppliers, purchase orders, sales, receipt data, cashier shifts, reports, and audit-related timestamps.
- Inquiry information: contact name, work email, optional mobile number and business name, message, and follow-up status.
- Technical and security information: session, request, error, and security logs reasonably needed to operate and protect the service.
Do not enter payment card numbers, account passwords, medical information, government identification documents, or unrelated sensitive information into inquiry, notes, or free-text fields.
3. How we use information
Information is processed to create and administer accounts; provide POS, inventory, purchasing, branch, reporting, billing, and support functions; authenticate users; prevent misuse; maintain audit records; communicate about inquiries and service changes; collect and verify subscription payments; and meet lawful obligations.
The applicable legal basis may include performance of a service agreement, compliance with law, legitimate interests that do not override data-subject rights, or consent where consent is required.
4. Merchant and platform responsibilities
For merchant staff, supplier contacts, and customer transaction information entered by a merchant, the merchant generally decides why and how the information is used. The merchant is responsible for providing appropriate notices, limiting access, configuring retention, responding to data-subject requests, and ensuring that its collection is lawful.
The POSONLY operator processes that information to deliver and secure the service, subject to the service agreement and applicable law. For platform accounts, subscriptions, security, and website inquiries, the operator may act as the personal information controller.
6. Retention and deletion
Records are retained only for as long as needed for the purposes described, the merchant service agreement, security and dispute handling, backup cycles, and applicable accounting, tax, or legal requirements. Different record types may require different periods. When retention is no longer justified, information should be securely deleted, anonymized, or blocked as appropriate.
7. Security
POSONLY uses tenant separation, branch scoping, role-based permissions, password hashing, session controls, validation, audit records, and encrypted HTTPS deployment when properly configured. No internet service can promise absolute security. Merchants must protect credentials, remove former users promptly, use secure devices and networks, and report suspected unauthorized access.
8. Data-subject rights
Subject to applicable conditions and exceptions, Philippine data subjects may have rights to be informed, object, access, correct or rectify, erase or block, obtain data portability, claim damages, and file a complaint with the National Privacy Commission.
Requests concerning information controlled by a merchant should first be directed to that merchant. Requests concerning the platform account, website, or operator may be submitted through the POSONLY contact form. Identity verification may be required before fulfilling a request.
10. Contact, complaints, and changes
Privacy questions or requests can be submitted through the contact form. The platform operator must publish its registered business address and dedicated privacy or Data Protection Officer contact before production launch.
This policy may be updated when the service, subprocessors, or legal requirements change. Material changes should be communicated through the service or account email, with a new effective date shown here.
Official resources: Data Privacy Act of 2012, Implementing Rules and Regulations, and NPC data-subject rights.