Privacy Policy
At Fuze Store, we are committed to safeguarding your personal information and ensuring transparency in how we collect, use, and protect your data. This Privacy Policy outlines our practices and your rights regarding your information when you interact with our application.
1. Introduction
This Privacy Policy explains how Fuze-Store IT Solutions (“Fuze Store,” “we,” “our,” or “us”) collects, uses, and protects personal information in connection with the Fuze Store POS and store management platform — including the Fuze Store mobile app for store operators, the Fuze Store customer app, the Fuze Store Hub desktop companion, and our website and account dashboard (collectively, the “Service”).
We comply with applicable data protection laws, including the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations, and — where they apply to international users — the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA).
2. Our Two Roles: Controller and Processor
Fuze Store is a business tool used by merchants. Depending on whose data is involved, we act in one of two roles:
- As a data controller — for the personal data of account holders and staff (the merchants and their team members who sign up for and operate Fuze Store). We decide how and why this data is processed, and this Policy applies in full.
- As a data processor — for customer records that merchants enter into their own store (see Section 3c). The merchant is the data controller of their customers' information; we host and process it only on the merchant's instructions. Customers of a store who have questions about their data should contact that store directly. We support merchants in honoring their customers' data-subject requests.
3. Information We Collect
a. Account Information (we are the controller)
- Name, business name, username, email address, mobile number, country, avatar photo, and password (stored hashed, never in plain text).
- Store address, business identification, and subscription details.
- Two-factor authentication secrets and recovery codes (stored encrypted).
- If you sign in with Google or Facebook, we receive your name and email address from the provider to create or link your account. We use these providers for sign-in only — the Facebook SDK's advertising and tracking features (advertiser-ID collection and automatic app-event logging) are disabled in our apps.
- One-time verification codes (OTP): when you verify a mobile number we temporarily store the phone number and a hashed copy of the code; codes expire within minutes.
b. Transaction and Usage Data
- Orders, products, inventory, and staff activity logs created through normal store operation.
- Payment-related data for your Fuze Store subscription is handled securely by Xendit; we do not store full card or account details. Payments your customers make to your store are settled directly into your own accounts and do not pass through us.
- Technical data such as IP address, browser type, operating system, and device identifiers.
- Push-notification device tokens, when you enable notifications in our mobile apps.
- Crash and error diagnostics via Sentry (see Section 5). Session replay is disabled in our mobile app.
- Product analytics via PostHog (feature-usage events that help us improve the Service), where enabled.
c. Store Customer Records (the merchant is the controller)
- Merchants may record their customers' details in their store's CRM: name, email address, mobile number, date of birth, gender, addresses (which may include map coordinates), and SMS opt-out status.
- Order, booking, and loyalty history linked to those customer records.
- We process this data solely to provide the Service to the merchant. Merchants are responsible for collecting it lawfully — including any data about minors — and for responding to their customers' privacy requests.
d. Local Data on Your Devices (Fuze Store Hub)
- The Fuze Store Hub desktop app stores operational data locally on the merchant's own computer — including a local audit log of administrative actions (which records the acting user's email address), printer configuration, and kitchen-display tickets. This data stays on the merchant's premises; local audit entries are kept for up to 365 days.
e. Cookies and Analytics
- Our landing and marketing website uses cookies and similar technologies. A cookie-consent banner lets you accept or reject non-essential cookies on your first visit, and you can change your choice anytime via Cookie settings in the site footer. See our Cookie Policy for full details.
- Strictly necessary cookies (sign-in, security, and core site functions) are always active.
- Analytics cookies run only with your consent — Vercel Speed Insights (aggregated performance data) and Sentry (error diagnostics).
- Functional cookies run only with your consent — the Tawk.to live-chat widget.
- The Fuze Store POS app does not use tracking cookies or advertising identifiers.
4. How We Use Information
We process collected data to:
- Provide, operate, and improve the Service.
- Manage subscriptions, billing, and account authentication.
- Send service updates, invoices, and important notifications (email, SMS, and push).
- Deliver real-time updates between your devices (order status, kitchen display, and similar features).
- Offer customer support.
- Send marketing communications (you may opt out anytime).
- Analyze usage to improve performance and user experience.
- Detect, investigate, and prevent fraud, abuse, and security incidents.
5. Data Sharing and Service Providers
We do not sell or rent personal data.
We share limited data with the following service providers, under data processing agreements, only as needed to run the Service:
- Payment Processing: Xendit — subscription and add-on billing, and prepaid wallet top-ups.
- Email Delivery: Amazon Web Services (Amazon SES) — transactional and account emails.
- SMS Delivery: Movider — order, booking, and queue text notifications sent on a store's behalf. Message logs retain only the last 4 digits of the recipient's number.
- Push Notifications: Expo push notification service — delivery of mobile push notifications via device push tokens.
- Hosting & Storage: Amazon Web Services (application servers, and file/receipt storage in access-controlled private buckets) and Vercel (website hosting). Our domain is registered with GoDaddy, which does not process personal data.
- Real-Time Messaging: Pusher-protocol websockets — real-time sync of orders and store events between your devices.
- Error Diagnostics: Sentry — crash and error reporting across our apps, website, and servers. Internal error alerts may also be routed to our team's Slack workspace; these alerts contain technical error context, not customer records.
- Product Analytics: PostHog — aggregated feature-usage analytics, where enabled.
- Website Analytics & Diagnostics: Vercel Speed Insights and Sentry on our website — subject to your cookie choices.
- Live Chat: Tawk.to (customer support chat widget) — loaded only with your consent.
- Other trusted vendors assisting in secure operations under data processing agreements.
We may also disclose data when required by law, court order, or lawful government request, or to protect the rights, safety, and security of Fuze Store and its users.
Optional public features (merchant-controlled)
- Store directory: merchants may choose to list their store profile and menu in our public store directory. This is on by default for new stores and can be turned off anytime in store preferences; a hidden store is not publicly discoverable.
- Order-status pages: printed receipts and claim stubs may carry a QR code that opens a public order-status page. That page shows order progress and a masked first name only (e.g., “J***”) — never contact details or payment information. Merchants can disable these features in store preferences.
6. Data Retention
- Account and store data are retained as long as the account remains active.
- When you delete your account, it is deactivated with a 30-day grace period during which you can restore it by logging back in; after that it is permanently deleted. Deleted stores and orders are likewise purged about 1 month after deletion.
- Certain financial records (invoices, official receipts) may be retained longer where required by law (e.g., Philippine tax regulations).
- Operational records are automatically pruned on a schedule:
| Data | Retention |
|---|---|
| Deleted user accounts | 30 days after deletion, then permanently removed |
| Deleted stores and orders | ~1 month after deletion, then permanently removed |
| SMS delivery logs (last 4 digits of number) | 90 days |
| Print job records | 90 days |
| Staff activity (audit) logs | 400 days |
| Terminal pairing codes | 30 days |
| Waiting-list entries | 2 weeks |
| Fuze Store Hub local audit log | 365 days (stored locally on the merchant's computer) |
7. Data Security
We implement industry-standard security measures, including:
- Encrypted communication (HTTPS, SSL/TLS).
- Token-based authentication using JWT, with optional two-factor authentication.
- Hashed passwords and encrypted two-factor secrets.
- Private, access-controlled file storage with short-lived signed download links.
- Access controls and regular system audits.
Despite these measures, no system is completely secure; users share data at their own risk.
8. International Data Transfers
Your data may be processed in Singapore or other regions where our servers and service providers operate.
We ensure appropriate safeguards consistent with international standards.
9. Your Rights
Under the Data Privacy Act of 2012 (RA 10173) — and, where applicable, GDPR/CCPA — you have the right to:
- Be informed about how your personal data is collected and processed.
- Access a copy of the personal data we hold about you.
- Rectify (correct) inaccurate or outdated data.
- Erasure or blocking — request that we delete your personal data, subject to any records we must keep by law (see Data Retention). You can delete your account directly in the app (Account → Details → Delete Account) or on the web dashboard — see our Data Deletion page.
- Data portability — request a copy of your data in a portable format by emailing support@fuze-store.com; we fulfill export requests within 30 days.
- Object to processing or withdraw consent at any time.
- Damages — be indemnified for harm caused by inaccurate, unlawfully obtained, or unauthorized use of your data.
To exercise any of these rights, email support@fuze-store.com or our Data Protection Officer (see Contact Us). We respond within the period required by law. If you believe your rights have been violated, you may also file a complaint with the Philippine National Privacy Commission (NPC) at privacy.gov.ph.
If you are a customer of a store that uses Fuze Store, the store is the controller of your record — please direct requests to the store; we will assist them in fulfilling your request.
10. Children's Privacy
Fuze Store accounts may only be created by individuals 18 years or older, and we do not knowingly collect account data from anyone under 18. If we become aware of such an account, we will delete it promptly.
Merchant-entered customer records (Section 3c) may lawfully include data about minors (for example, a booking for a child); the merchant, as controller, is responsible for collecting and handling such data appropriately.
11. Changes to this Policy
We may update this Privacy Policy from time to time. The latest version will always be posted at www.fuze-store.com/privacy-policy.
Significant changes will be communicated via email or in-app notification.
12. Contact Us
Fuze-Store IT Solutions
Email: support@fuze-store.com
Talk to Us: Use the chat feature on our website
Address: 1076 A. Bonifacio, Balingasa, Quezon City, 1115, Philippines
Data Protection Officer (DPO) — for privacy questions, data-subject requests, or concerns under the Data Privacy Act of 2012, contact our DPO at support@fuze-store.com (subject line: "Attn: Data Protection Officer").
Last Updated: July 17, 2026
Effective Date: October 22, 2025