This Privacy Policy explains how Frogrest Co. ("we", "us", "our"), the operator of the FrogPOS point-of-sale platform, collects, uses, stores, shares, and protects personal data in connection with the Service. We process personal data in accordance with the Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations, together with other applicable Philippine laws. Please read this Policy together with our Terms of Service.
1. Information We Collect
We collect only the information needed to operate the Service and keep it secure:
- Account & identity information. Your email address (used for OTP sign-in and notifications), the display name you choose, your role in the business (owner, manager, cashier), and a hash of any PIN you set for staff idle-lock (PINs are never stored in plain text).
- Business data you enter. Products, categories, prices, inventory counts, orders, sales, discounts, add-on configurations, store settings, and similar business records you deliberately enter into the Service.
- Government ID verification. When a paid plan is subscribed, the account owner submits a self-attestation of a Philippine government-issued ID: ID type, ID number, full name as shown on the ID, and (optionally) its expiry date. This is used solely to verify that a real business operator is subscribing.
- Communications data. Email receipts sent to your customers are processed in order to deliver them.
- Audit logs. Records of security-relevant actions (sign-ins, checkouts, cancellations, staff changes, verification reviews) including the actor, action, and timestamp.
- Technical data. IP address, browser and device type, and basic server logs, used for security, rate limiting, and troubleshooting. We also use Vercel Web Analytics, built into our hosting platform, which reports aggregate, anonymized visit statistics (top pages, referrers, and countries). It does not use cookies and does not collect personal data. We do not use third-party advertising or other analytics trackers.
2. How We Use Your Information
- To provide, operate, and maintain the Service — including processing orders and syncing data across devices.
- To authenticate you securely (email OTP codes and PIN unlocks).
- To verify ID submissions before paid-plan subscriptions, and to manage your plan and trial.
- To deliver transactional messages: OTPs and receipts.
- To protect the Service and its users — detecting fraud, abuse, and unauthorized access.
- To comply with legal obligations and to respond to lawful requests.
3. Legal Bases for Processing
We process personal data on the following bases under the Data Privacy Act:
- Contract: processing is necessary to provide the Service you subscribed to.
- Consent: where you voluntarily submit data (e.g., ID verification).
- Legal obligation: where processing is required by applicable law or regulation.
- Legitimate interest: securing our platform, preventing abuse, and improving the Service, balanced against your rights.
4. Sharing & Disclosure
We do not sell, rent, or trade your personal data. We share it only as necessary to operate the Service:
- Service providers (processors). Hosting (Vercel), database storage (Neon Postgres), and transactional email (Resend). These providers process data solely on our instructions and are bound by appropriate confidentiality and security commitments.
- Law enforcement & regulators. When required by law, court order, or a lawful request from a competent authority.
- Business transfers. In connection with a merger, acquisition, or sale of assets, with notice to you.
Some of our providers are located outside the Philippines. Where personal data is transferred internationally, we rely on appropriate safeguards required by applicable data protection law to ensure your data receives an adequate level of protection.
5. Cookies, Local Storage & Offline Data
- Session cookie. We use a secure session cookie to keep you signed in. It expires automatically after 30 days of inactivity.
- Vercel Web Analytics. Our page-view analytics does not set cookies; visitors are identified by a single-day anonymized hash derived from their request.
- Local storage. Your theme (light/dark) and language preferences, plus a guest-demo flag, are kept in your browser's local storage.
- Offline mode. To keep your store selling without internet, the Service stores copies of your menu, recent data, and a queue of pending transactions in your browser's IndexedDB, and caches app files through a service worker. These local copies sync to our servers when you reconnect. Because browsers retain site data, local copies may remain on the device after you sign out unless the site's stored data is cleared — on shared devices, we recommend signing out and clearing browser data for the FrogPOS site after each shift.
6. Data Security
- All traffic is encrypted in transit using HTTPS.
- Passwords are not used; sign-in uses one-time codes. Staff PINs are stored only as salted hashes, never in plain text.
- Government ID numbers are masked to their last four digits in administrative views and are accessible only to authorized personnel for verification purposes.
- Access to business data is scoped by role (owner, manager, cashier), and security-sensitive actions are recorded in audit logs.
- We apply organizational, physical, and technical safeguards appropriate to the sensitivity of the data, and we review our security measures as part of ongoing development. Should we deploy additional safeguards such as encryption at rest, we will reflect them in updates to this Policy.
- In the unlikely event of a personal data breach, we will notify the National Privacy Commission and affected individuals as required by the Data Privacy Act and its Implementing Rules and Regulations.
7. Data Retention
- Account and business data are kept while your account is active and for a reasonable period afterward to allow for reactivation, export, and legal compliance.
- One-time sign-in codes expire within minutes; session cookies after 30 days of inactivity.
- Audit logs are retained for accountability and security purposes.
- You may export or request deletion of your business data at any time (see Section 8).
8. Your Rights Under the Data Privacy Act
As a data subject, you have the right to:
- Be informed of how your personal data is collected, used, and processed;
- Object to processing, including for direct marketing;
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete personal data;
- Suspend or withdraw your consent to processing;
- Request erasure or blocking of personal data that is no longer needed or was processed unlawfully;
- Data portability — receive your data in a structured, commonly used format;
- Claim damages for violation of your data privacy rights; and
- File a complaint with the National Privacy Commission (NPC) at www.privacy.gov.ph.
To exercise any of these rights, contact us using the details in Section 10. We will respond within fifteen (15) working days from receipt of your request, as required by the DPA.
9. Children's Privacy
The Service is intended for business use by adults aged 18 and above. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
10. Contact Us
For questions, requests, or concerns about this Privacy Policy or your personal data, contact frogrest.pos@gmail.com. You may also reach our Data Protection Officer through the same address. We are committed to resolving your concerns within fifteen (15) working days.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or within the Service. The updated Policy takes effect on the date posted at the top of this page, and your continued use of the Service constitutes acceptance of the updated Policy.