Skip to main content
Logo

Privacy Policy

At Fuze Store, we are committed to safeguarding your personal information and ensuring transparency in how we collect, use, and protect your data. This Privacy Policy outlines our practices and your rights regarding your information when you interact with our application.

1. Introduction


This Privacy Policy explains how Fuze-Store IT Solutions (“Fuze Store,” “we,” “our,” or “us”) collects, uses, and protects personal information in connection with the Fuze Store POS and store management platform — including the Fuze Store mobile app for store operators, the Fuze Store customer app, the Fuze Store Hub desktop companion, and our website and account dashboard (collectively, the “Service”).
We comply with applicable data protection laws, including the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations, and — where they apply to international users — the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA).


2. Our Two Roles: Controller and Processor


Fuze Store is a business tool used by merchants. Depending on whose data is involved, we act in one of two roles:

  • As a data controller — for the personal data of account holders and staff (the merchants and their team members who sign up for and operate Fuze Store). We decide how and why this data is processed, and this Policy applies in full.
  • As a data processor — for customer records that merchants enter into their own store (see Section 3c). The merchant is the data controller of their customers' information; we host and process it only on the merchant's instructions. Customers of a store who have questions about their data should contact that store directly. We support merchants in honoring their customers' data-subject requests.

3. Information We Collect


a. Account Information (we are the controller)

  • Name, business name, username, email address, mobile number, country, avatar photo, and password (stored hashed, never in plain text).
  • Store address, business identification, and subscription details.
  • Two-factor authentication secrets and recovery codes (stored encrypted).
  • If you sign in with Google or Facebook, we receive your name and email address from the provider to create or link your account. We use these providers for sign-in only — the Facebook SDK's advertising and tracking features (advertiser-ID collection and automatic app-event logging) are disabled in our apps.
  • One-time verification codes (OTP): when you verify a mobile number we temporarily store the phone number and a hashed copy of the code; codes expire within minutes.

b. Transaction and Usage Data

  • Orders, products, inventory, and staff activity logs created through normal store operation.
  • Payment-related data for your Fuze Store subscription is handled securely by Maya (PayMaya Philippines, Inc.); we do not store full card or account details. Payments your customers make to your store are settled directly into your own accounts and do not pass through us.
  • Technical data such as IP address, browser type, operating system, and device identifiers.
  • Push-notification device tokens, when you enable notifications in our mobile apps.
  • Crash and error diagnostics via Sentry (see Section 5). Session replay is disabled in our mobile app.
  • Product analytics via PostHog (feature-usage events that help us improve the Service), where enabled.

c. Store Customer Records (the merchant is the controller)

  • Merchants may record their customers' details in their store's CRM: name, email address, mobile number, date of birth, gender, addresses (which may include map coordinates), and SMS opt-out status.
  • Order, booking, and loyalty history linked to those customer records.
  • Orders customers start online. Where a merchant switches on online ordering, their customers can build an order on the store's public page and submit it for staff to complete. We hold that draft order so the store's staff can pull it into their register — the items selected, any note, the contact details the customer enters (first name, and optionally last name, email address, and mobile number), a pickup or delivery address where the merchant offers those options, and any extra checkout details the merchant asks for (for example, a plate number or a claim tag). Draft orders are deleted automatically (see Section 6). No payment is taken on this page — the customer settles directly with the store.
  • We process this data solely to provide the Service to the merchant. Merchants are responsible for collecting it lawfully — including any data about minors — and for responding to their customers' privacy requests.

d. Local Data on Your Devices (Fuze Store Hub)

  • The Fuze Store Hub desktop app stores operational data locally on the merchant's own computer — including a local audit log of administrative actions (which records the acting user's email address), printer configuration, and kitchen-display tickets. This data stays on the merchant's premises; local audit entries are kept for up to 365 days.
  • Hub also stores a shop-local TLS certificate and private key on the merchant's computer so the browser app can talk to the Hub over HTTPS. Staff can optionally install that shop's certificate in their OS so Chrome shows a lock. The private key never leaves the computer.

e. Cookies and Analytics

  • Our landing and marketing website uses cookies and similar technologies. A cookie-consent banner lets you accept or reject non-essential cookies on your first visit, and you can change your choice anytime via Cookie settings in the site footer. See our Cookie Policy for full details.
  • Strictly necessary cookies (sign-in, security, and core site functions) are always active.
  • Analytics cookies run only with your consent — Vercel Speed Insights (aggregated performance data) and Sentry (error diagnostics).
  • Live chat is not cookie-gated because it is not loaded until you ask for it — the Tawk.to widget loads only when you click Chat with us, and stores nothing before that.
  • The Fuze Store POS app does not use tracking cookies or advertising identifiers.

f. NFC Tags (optional add-on)

  • Where a merchant enables the NFC add-on, their staff can read, write, and erase NFC tags from the app — using the device's own NFC hardware, or a USB reader connected to Fuze Store Hub. A tag holds only what the merchant writes to it: a link to their own store page, table, or product, or short text of their choosing. It is the same content a merchant can already print as a QR code.
  • We collect nothing through NFC. Reading and writing tags stays on the merchant's own device or Hub — nothing is sent to us. When a customer taps a tag with their own phone, their phone simply opens the link; the tag does not identify them, and nothing is read from their device.

4. How We Use Information


We process collected data to:

  • Provide, operate, and improve the Service.
  • Manage subscriptions, billing, and account authentication.
  • Send service updates, invoices, and important notifications (email, SMS, and push).
  • Deliver real-time updates between your devices (order status, kitchen display, and similar features).
  • Offer customer support.
  • Send marketing communications (you may opt out anytime).
  • Analyze usage to improve performance and user experience.
  • Detect, investigate, and prevent fraud, abuse, and security incidents.

5. Data Sharing and Service Providers


We do not sell or rent personal data.
We share limited data with the following service providers, under data processing agreements, only as needed to run the Service:

  • Payment Processing: Maya (PayMaya Philippines, Inc.) — subscription and add-on billing, and prepaid wallet top-ups.
  • Email Delivery: Amazon Web Services (Amazon SES) — transactional and account emails.
  • SMS Delivery: Movider — order, booking, and queue text notifications sent on a store's behalf. Message logs retain only the last 4 digits of the recipient's number.
  • Push Notifications: Expo push notification service — delivery of mobile push notifications via device push tokens.
  • Hosting & Storage: Amazon Web Services (application servers, and file/receipt storage in access-controlled private buckets) and Vercel (website hosting). Our domain is registered with GoDaddy, which does not process personal data.
  • Real-Time Messaging: Pusher-protocol websockets — real-time sync of orders and store events between your devices.
  • Error Diagnostics: Sentry — crash and error reporting across our apps, website, and servers. Internal error alerts may also be routed to our team's Slack workspace; these alerts contain technical error context, not customer records.
  • Product Analytics: PostHog — aggregated feature-usage analytics, where enabled.
  • Website Analytics & Diagnostics: Vercel Speed Insights and Sentry on our website — subject to your cookie choices.
  • Live Chat: Tawk.to (customer support chat widget) — loaded only when you open the chat.
  • Other trusted vendors assisting in secure operations under data processing agreements.

We may also disclose data when required by law, court order, or lawful government request, or to protect the rights, safety, and security of Fuze Store and its users.

Optional public features (merchant-controlled)

  • Store directory: merchants may choose to list their store profile and menu in our public store directory. This is on by default for new stores and can be turned off anytime in store preferences; a hidden store is not publicly discoverable.
  • Order-status pages: printed receipts and claim stubs may carry a QR code that opens a public order-status page. That page shows order progress and a masked first name only (e.g., “J***”) — never contact details or payment information. Merchants can disable these features in store preferences.
  • Store contact details and links: merchants may add their store's contact details (phone numbers, email) and links (website, social profiles) to their store record. These appear on the store's public page. Showing contact details and showing links are on by default and can each be turned off — either as a whole or per entry — anytime in store preferences. Only add details you are willing to publish: anything left switched on is visible to anyone who opens the store's public page.
  • Online ordering: merchants may switch on online ordering so their customers can submit an order from the store's public page. This is off by default and can be turned on or off anytime in store preferences. After checkout the customer receives a link or QR code for their draft order to show to staff; that page shows the order's progress with a masked name and phone number only (e.g., “M*** · **** 4567”) — never the customer's full contact details. Where the merchant has chosen to publish a payment method, that page shows the store's account details so the customer can pay; no customer payment information is collected.
  • Payment details on the store page: merchants may mark a payment method as shown on their store page, so a customer who has placed an online order can see the store's account name, account number and payment QR. This is off by default for every payment method and can be switched on or off per method anytime. Only mark an account public if you are willing to publish it: it is visible to anyone who holds a link to an order placed with your store.

6. Data Retention


  • Account and store data are retained as long as the account remains active.
  • When you delete your account, it is deactivated with a 30-day grace period during which you can restore it by logging back in; after that it is permanently deleted. Deleted stores and orders are likewise purged about 1 month after deletion. A store is deleted on its own schedule rather than with your account, and a store keeps the staff record it holds for you with your account link removed — see the Data Deletion page for the full breakdown of what is and is not removed.
  • Certain financial records (invoices, official receipts) may be retained longer where required by law (e.g., Philippine tax regulations).
  • Operational records are automatically pruned on a schedule:
DataRetention
Deleted user accounts30 days after deletion, then permanently removed
Deleted stores and orders~1 month after deletion, then permanently removed
SMS delivery logs (last 4 digits of number)90 days
Print job records90 days
Staff activity (audit) logs400 days
Terminal pairing codes30 days
Waiting-list entries2 weeks
Online order draftsClaimable for 24 hours, then removed about 7 days later
Fuze Store Hub local audit log365 days (stored locally on the merchant's computer)

7. Data Security


We implement industry-standard security measures, including:

  • Encrypted communication (HTTPS, SSL/TLS).
  • Token-based authentication using JWT, with optional two-factor authentication.
  • Hashed passwords and encrypted two-factor secrets.
  • Private, access-controlled file storage with short-lived signed download links.
  • Access controls and regular system audits.
    Despite these measures, no system is completely secure; users share data at their own risk.

8. International Data Transfers


Your data may be processed in Singapore or other regions where our servers and service providers operate.
We ensure appropriate safeguards consistent with international standards.


9. Your Rights


Under the Data Privacy Act of 2012 (RA 10173) — and, where applicable, GDPR/CCPA — you have the right to:

  • Be informed about how your personal data is collected and processed.
  • Access a copy of the personal data we hold about you.
  • Rectify (correct) inaccurate or outdated data.
  • Erasure or blocking — request that we delete your personal data, subject to any records we must keep by law (see Data Retention). You can delete your account directly in the app (Account → Details → Delete Account) or on the web dashboard — see our Data Deletion page.
  • Data portability — request a copy of your data in a portable format by emailing support@fuze-store.com; we fulfill export requests within 30 days.
  • Object to processing or withdraw consent at any time.
  • Damages — be indemnified for harm caused by inaccurate, unlawfully obtained, or unauthorized use of your data.

To exercise any of these rights, email support@fuze-store.com or our Data Protection Officer (see Contact Us). We respond within the period required by law. If you believe your rights have been violated, you may also file a complaint with the Philippine National Privacy Commission (NPC) at privacy.gov.ph.

If you are a customer of a store that uses Fuze Store, the store is the controller of your record — please direct requests to the store; we will assist them in fulfilling your request.


10. Children's Privacy


Fuze Store accounts may only be created by individuals 18 years or older, and we do not knowingly collect account data from anyone under 18. If we become aware of such an account, we will delete it promptly.
Merchant-entered customer records (Section 3c) may lawfully include data about minors (for example, a booking for a child); the merchant, as controller, is responsible for collecting and handling such data appropriately.


11. Changes to this Policy


We may update this Privacy Policy from time to time. The latest version will always be posted at www.fuze-store.com/privacy-policy.
Significant changes will be communicated via email or in-app notification.


12. Contact Us


Fuze-Store IT Solutions
Email: support@fuze-store.com
Talk to Us: Use the chat feature on our website
Address: 1076 A. Bonifacio, Balingasa, Quezon City, 1115, Philippines

Data Protection Officer (DPO) — for privacy questions, data-subject requests, or concerns under the Data Privacy Act of 2012, contact our DPO at support@fuze-store.com (subject line: "Attn: Data Protection Officer").


Last Updated: August 4, 2026
Effective Date: October 22, 2025

Start FreeSee Demo