Privacy Policy
Effective date: July 22, 2026 · Last updated: September 1, 2026
This Privacy Policy describes how VoVi POS ("VoVi," "we," "us," or "our"), the operator of vovipos.com and the VoVi point-of-sale platform (together, the "Service"), collects, uses, discloses, and protects personal information. It applies to visitors of our website, people who join our waitlist or contact us, and merchants and their staff who use the VoVi platform.
We run our website deliberately light: no advertising trackers, no third-party analytics, no marketing pixels, and no sale of your personal information — ever.
1. Information we collect
Information you give us
- Waitlist and contact details. When you ask us to contact you, we collect your name, phone number, and — only if you choose to provide it — your email address, together with the number of locations you told us about.
- Merchant account information. When a business creates a VoVi workspace, we collect the business name, owner name, login credentials (passwords are stored only as salted one-way hashes), staff names and the register PINs an owner issues to them, and the business configuration the merchant enters (locations, products, prices, and similar operational data). A register PIN is held inside that merchant's own account record. Access to it is restricted: it is shown once when it is issued and after that it is never displayed to staff, to another business, or to us in ordinary use — only to an owner who re-authenticates in order to reveal one named employee's PIN, which we write to that merchant's audit log. Repeated wrong PIN entries at a till are throttled by a progressive lockout, so a PIN cannot be found by guessing.
- Support communications. The contents of emails or calls you exchange with us.
- Website chat. Our website carries a pre-sales chat assistant. It asks for no account and no identity, but whatever you type into it is sent to Anthropic, which runs the model that writes the reply as our processor, and both your messages and the assistant's replies are stored on our side, verbatim, so we can see what people ask us before they buy and improve our answers. Obvious card numbers, national identity numbers, phone numbers and pasted secrets are masked out of the text before it is stored. We do not store your IP address with these conversations, and we keep them for 365 days (see section 8). Please don't type anything into it you would not want kept — to reach a person, use the contact form or email us.
Information collected automatically
- Server logs. Like nearly every website, our servers record basic request data (requested URL, timestamp, browser type) to operate and secure the Service.
- Signed-in session records. While someone is signed in to the VoVi platform, we record the IP address the request came from and the browser's user-agent string, alongside the authorized device and the session identifier, so that we can investigate suspicious access and so a merchant can answer "who did this, from which device, and from where?". These records are kept for 90 days and then deleted. They are produced by activity inside the platform: simply browsing this marketing website does not create one, and the contact form on it stores only the one-way hash described below, never your IP address.
- Abuse-control identifiers. When you submit a form, we derive a salted, truncated one-way hash of your IP address for rate limiting and abuse prevention. We store the hash, not your IP address, and the hash cannot be reversed into your IP.
- Local storage. See our Cookie Policy. We use no advertising or analytics cookies. The marketing site uses browser local storage only as a temporary fallback to avoid losing a form you submitted while offline; the app uses one essential, httpOnly authentication cookie after sign-in.
Merchant customer data
Merchants using VoVi may record their own customers' information (for example a customer profile attached to a sale, loyalty balances, or purchase history). For that data, the merchant is the controller/business and VoVi acts as a service provider/processor: we process it solely to provide the platform to the merchant, under the merchant's instructions, and never for our own marketing.
2. How we use personal information
- To respond to your request to be contacted, and to onboard your business onto VoVi;
- To provide, maintain, secure, and improve the Service;
- To run the optional AI-assisted features inside the platform, when a merchant chooses to use one (see section 4);
- To communicate service and account information (for example password resets or important changes);
- To prevent fraud and abuse and to enforce our Terms of Service;
- To comply with legal obligations and to establish, exercise, or defend legal claims.
We do not use your personal information for third-party advertising, and we do not build advertising profiles about you.
3. Legal bases (EEA/UK visitors)
Where the GDPR or UK GDPR applies, we process personal information on these bases: consent (when you ask us to contact you — you may withdraw it at any time); performance of a contract (operating a merchant's workspace); legitimate interests (securing and improving the Service, preventing abuse); and legal obligation (where retention or disclosure is required by law).
4. When we share information
We share personal information only with:
- Infrastructure providers that host the Service and store its data on our behalf under contractual confidentiality obligations: Railway Corp., which runs the application, and Supabase, which hosts the PostgreSQL database holding the platform's records. Both are in the United States; the database is in the US East (Ohio) region;
- Our email delivery provider, Resend (Plus Five Five, Inc.), which transmits the transactional emails described in section 6 and receives only what is needed to deliver them;
- Our internal CRM (Growth OS), the system we use to manage sales leads, which receives what you submit through a form on this website — your name, phone number, email address if you gave one, the page you submitted from, the page that referred you, and any campaign parameters (utm) in the link you arrived by — so that a person can follow up with you about VoVi. It is used for sales lead management only; it feeds no advertising and is not shared onward;
- Telegram (Telegram Messenger Inc.), which carries the alert that tells us a form on this website has been submitted. This is our primary notification channel — the one that reaches a phone rather than an inbox — so the message contains your name, your phone number, your email address if you gave one, what you told us you were interested in, and the page you submitted from, in order that a person can call you back the same day. If Telegram is unavailable or unconfigured, the same notification is sent to our own support inbox by email instead. One other kind of message goes through the same channel: when a merchant's workspace reaches a limit of its plan, we are told the business name and the name of the person who asked for more, so we can raise it or call them. Nothing else is sent to Telegram — no shopper records, no sales data, no credentials — and the message is a nudge only; the record itself stays in our own database;
- Our AI provider, Anthropic, which runs the optional AI features inside the platform — report writing and written insights, campaign and loyalty copywriting, the store assistant, and the in-app help assistant. When a merchant uses one of those features, that request is sent to Anthropic's API so the answer can be generated and returned. Most of what crosses is business information rather than personal information: product names and prices, totals and counts, the question being asked, and the name and role of the staff member asking it. One feature can include a customer's personal information. If a merchant builds a report about their own customers and asks for a written summary of it, the rows of that report are sent so the summary can be written, and those rows can include a customer's name next to what they spent. No AI feature is sent passwords, PINs, or card numbers, and nothing is sent to Anthropic from inside the platform unless a merchant uses one of these features. Anthropic also runs the pre-sales chat assistant on this website, described in section 1, which receives the messages a visitor types into it;
- GitHub, which hosts the Service's source code and runs our automated nightly backup of the platform database; the resulting snapshot is stored there as a private file for a limited period (see section 8);
- Payment partners, if and when you ask us to set up integrated card processing for your business — at that point the partner's own terms and privacy notice will be presented to you;
- Professional advisers and authorities where required by law, subpoena, or to protect the rights, safety, or property of VoVi, our merchants, or the public;
- A successor entity in connection with a merger, acquisition, or sale of assets, in which case this Policy will continue to apply to your information until you are told otherwise.
We do not sell personal information and we do not share it for cross-context behavioral advertising. We have not done so in the preceding 12 months.
5. Communications and your choices
If you submit your phone number, you consent to VoVi contacting you by phone, text message, or email about VoVi. Consent is not a condition of purchasing anything. Message and data rates may apply to texts. You can opt out at any time: reply STOP to any text, use the unsubscribe link in any marketing email, or email us at support@vovipos.com — we will honor the request promptly. Service messages that are necessary to operate your account (for example a password reset you requested) are not marketing and are not affected by a marketing opt-out.
6. Transactional email we send
VoVi sends a small number of transactional emails — messages that exist because someone asked for them or needs them to use the Service. They are not marketing, and a marketing opt-out does not switch them off.
- Password reset and password-changed notices to a merchant user who requested a reset. The reset link is single-use and expires after 30 minutes. We never include your password in an email, because we cannot read it.
- Lead notifications to our own support inbox when someone submits a form on this website and the Telegram alert described in section 4 could not be delivered. Telegram is the primary channel for these; email is the fallback that makes sure no request to be contacted is lost.
- Emailed sales receipts to a shopper who asks a VoVi merchant to email their receipt at the till (see the next section).
Email is delivered on our behalf by Resend (Plus Five Five, Inc.), which processes the recipient address, subject and message content solely to deliver it. Where a merchant mailbox is used instead, delivery goes through that mail provider. We log each send — the recipient address, subject, the outcome, and whether it bounced — so a merchant can prove a receipt was sent and so we can stop mailing addresses that bounce or report spam. Those send logs are kept for up to 180 days and then deleted.
7. Emailed receipts, and shoppers at VoVi stores
If you shop at a business that uses VoVi and ask them to email your receipt, you give your email address to that business. VoVi processes it on their behalf: in data-protection terms the merchant is the controller of that information and VoVi is the processor. The merchant decides what happens to it; we act on their instructions.
What happens when you ask for an emailed receipt:
- Your address is stored in that merchant's customer records together with that purchase, the date and time, the store location and the employee who served you — so the merchant can look the sale up later, and so returns and warranty claims work.
- The receipt itself contains the merchant's business name, location, address, phone number, refund policy, the items purchased and the amounts.
- Asking for a receipt does not sign you up for marketing. Records created this way are marked as not consenting to marketing email, so the merchant cannot send you promotions without you separately opting in.
- If you do separately opt in to a store's marketing email, those campaign messages can carry a small tracking image and links that record whether the message was opened or clicked, so the merchant can see how their campaign performed. Those counts are kept for that merchant inside VoVi and are not shared with anyone else. Transactional email — receipts, password resets, order updates — carries no such tracking.
- We do not sell this information, and we do not use a merchant's customer records to market VoVi to their customers.
To stop receiving emailed receipts, ask at the counter or reply to the receipt. To see, correct, or delete what a merchant holds about you, contact the merchant — they can erase your personal details in VoVi while retaining the sales figures they are legally required to keep for tax and accounting. If you cannot reach them, email us at support@vovipos.com and we will help you reach the right business.
8. Retention
- Waitlist details: until we have onboarded you, you ask us to delete them, or 24 months after our last contact with you — whichever comes first;
- Merchant account and operational data: for the life of the merchant account and up to 7 years afterwards where required for tax, accounting, audit, or dispute purposes;
- Support conversations — the questions put to the website chat assistant and to the in-app help assistant, and the answers given, stored verbatim after masking: 365 days;
- Email send logs (recipient address, subject, delivery outcome): up to 180 days;
- Nightly database backup snapshots: up to 14 days. Each night's snapshot is held in two places — as a private file at GitHub, and as a copy on the storage volume of our own server — and both are held to that same 14-day window, after which the older files are deleted automatically. Fourteen days is a deliberate choice, not a technical limit: it is longer than our database provider's own recovery window, so these snapshots add real recovery range rather than repeating what the provider already holds, and it is comfortably shorter than the 30 days we have to answer a deletion request in, so information you asked us to erase cannot survive inside a backup for a month afterwards;
- Server logs, activity logs and abuse-control hashes: up to 90 days.
9. Security
We use administrative, technical, and physical safeguards appropriate to the nature of the data, including encryption in transit (TLS), salted one-way hashing of passwords, access-restricted and brute-force-protected handling of register PINs as described in section 1, role-based access controls inside the platform, owner-approved device authorization for registers, and audit logging of sensitive actions. No method of transmission or storage is completely secure; if we learn of a breach affecting your personal information we will notify you and the relevant authorities as required by applicable law.
10. Your privacy rights
United States (including California)
Depending on your state, you may have the right to know what personal information we have about you, to access it, to correct it, to delete it, and to opt out of its sale or sharing (we do not sell or share personal information, so there is nothing to opt out of). We will never discriminate against you — in price or service — for exercising a privacy right.
EEA / UK
You may have the rights of access, rectification, erasure, restriction, portability, and objection, the right to withdraw consent at any time, and the right to lodge a complaint with your supervisory authority.
How to exercise any right
Email support@vovipos.com with your request. We will verify your identity against the details we hold (for example by confirming the phone number or email on file) and respond within the time required by applicable law (generally 30–45 days). You may use an authorized agent; we will ask the agent for proof of your written permission.
11. Do Not Track and Global Privacy Control
Our website does not track visitors across other sites, so browser "Do Not Track" and Global Privacy Control signals are honored by design: there is no tracking to disable.
12. Children
The Service is intended for businesses and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, contact us and we will delete it.
13. International visitors
The Service is operated from, and personal information is processed in, the United States. If you access the Service from outside the United States, you understand your information will be transferred to and processed in the United States, where privacy laws may differ from those of your country. For EEA/UK data we rely on your consent and on contractual safeguards with our infrastructure providers.
14. Changes to this Policy
When we make material changes, we will update the effective date above and post the revised Policy here; for significant changes affecting data we have already collected from you, we will notify you directly using the contact details we hold. The current version always lives at vovipos.com/privacy.
15. Contact us
VoVi POS · vovipos.com
Email: support@vovipos.com