Last Updated: April 1, 2026 | Version 1.0
Invoco ("we," "us," "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard personal data in connection with our Restaurant POS service (the "Service").
This Policy applies to:
By using the Service, you consent to the practices described in this Policy.
Compliance: This Policy is compliant with Singapore's Personal Data Protection Act (PDPA) 2012.
Invoco
Email: [email protected]
Website: https://pos.invoco.org
For privacy-related inquiries, contact: [email protected]
When a Restaurant creates an Account, we collect:
When Staff are added to the Service, we collect:
When Customers place orders, we may collect:
We automatically collect:
We receive data from:
Under Singapore's PDPA, we process personal data based on:
| Purpose | Legal Basis |
|---|---|
| Account creation and management | Consent (when you create an Account) |
| Order processing | Consent (when Customer places order) |
| Payment processing | Contractual necessity |
| Service improvement | Legitimate interest |
| Legal compliance | Legal obligation (e.g., IRAS records retention) |
| Marketing communications | Consent (opt-in; opt-out available) |
We share personal data with trusted third parties to provide the Service:
| Provider | Purpose | Location | Safeguards |
|---|---|---|---|
| Supabase | Database hosting, authentication | United States | Data Processing Agreement, encryption |
| Stripe | Payment processing | United States | PCI-DSS compliant, Stripe DPA |
| Cloudflare | Hosting, CDN, analytics, DDoS protection | Global network | Data Processing Agreement, encryption |
Cross-Border Transfers: Data may be transferred to the United States. We rely on:
We may disclose personal data if required by law:
In the event of a merger, acquisition, or sale of assets, personal data may be transferred to the acquiring entity. We will notify you and ensure the new entity complies with this Policy.
We do not sell, rent, or share personal data for marketing purposes without explicit consent.
| Data Type | Retention Period | Reason |
|---|---|---|
| Restaurant Account | Duration of Subscription + 30 days | Service provision, data export opportunity |
| Staff Data | Duration of Staff employment + 30 days after removal | Service provision |
| Customer Order Data | Duration of Restaurant Subscription + 30 days | Service provision, dispute resolution |
| Financial Records | 7 years after transaction | IRAS compliance (Income Tax Act) |
| Analytics/Logs | 12 months | Service improvement, security |
After the retention period, data is permanently deleted using secure deletion methods.
You have the following rights:
Request a copy of your personal data we hold (data portability available via Account dashboard).
Request correction of inaccurate or incomplete personal data.
Withdraw consent for marketing communications or optional data collection (does not affect prior processing).
Export your data in a machine-readable format (CSV, JSON).
File a complaint with the Personal Data Protection Commission (PDPC) Singapore if you believe we have violated PDPA.
How to Exercise Your Rights:
We will respond within 30 days of your request.
We implement industry-standard security measures:
Your Responsibility: Keep your Account credentials and Staff PINs secure. Do not share them with unauthorized persons.
We use cookies and similar technologies to:
Types of Cookies:
For detailed information, see our Cookie Policy.
Cookie Consent: By using the Service, you consent to our use of strictly necessary cookies. For analytics cookies, you can opt-out via your browser settings or our cookie consent banner.
The Service may contain links to third-party websites (e.g., Stripe dashboard). We are not responsible for their privacy practices. Please review their privacy policies.
The Service is not intended for children under 13. We do not knowingly collect personal data from children under 13 without parental consent.
Staff Under 18: Restaurants are responsible for obtaining parental consent for Staff under 18 (if required under Singapore law).
Personal data may be transferred to and stored in countries outside Singapore (e.g., United States for Supabase and Stripe).
Safeguards:
In the event of a data breach involving personal data, we will:
We may update this Policy periodically. Material changes will be notified via:
The "Last Updated" date at the top will be revised. Continued use after changes constitutes acceptance.
For privacy-related questions or to exercise your rights, contact:
Invoco
Email: [email protected]
Website: https://pos.invoco.org
Personal Data Protection Commission (PDPC) Singapore:
Website: https://www.pdpc.gov.sg
Email: [email protected]