Skip to main content

Privacy policy

This policy explains the information processed when you visit the website, submit an enquiry and use Cameo PoS, and how to submit requests about personal data.

Content updated:

This content is being finalized. The operator’s legal details, refund policy and data retention periods need confirmation before an official version is issued. The update date is not a contractual effective date.

1. Scope and processing parties

This policy covers the Cameo PoS website, enquiries and data needed to operate the application. For customer or staff data entered by stores, responsibilities of the store and provider need to reflect the processing purpose and applicable agreement. The operator’s legal name, address and responsible data contact await confirmation; the current request channel appears below.

2. Information categories

The contact form requires a name, email and enquiry message; store name and phone number are optional. Submissions are sent to the system and stored for handling. Application data may include account, store, product, order, staff and customer information, plus usage metrics for billing, depending on the functions used and data supplied. Do not include passwords, verification codes, payment card details or unnecessary sensitive data in enquiries.

3. Processing purposes

Contact information is used to receive, discuss and handle your sales or support enquiry. Account and store data support sign-in, access permissions and the workflows you use. Usage metrics support billing and reconciliation. Submitting an enquiry is not treated as signing up for advertising; advertising or new purposes need an appropriate processing basis and notice.

4. Processing basis and your choices

Each processing activity needs an appropriate basis under applicable law and service agreements. Where consent is required, you need information about the purpose, data types, processing parties and how to exercise related rights. Visiting the website does not replace consent where required by law. Omitting required form fields may prevent submission; optional fields can be left blank.

5. Browser storage and technical information

The website may store appearance preferences in your browser; the application stores session information and preferences for continuity. Protect sign-in details on shared devices. Information about cookies, technical logs and tracking tools needs confirmation for the operating environment. Tracking integrations need disclosure of purposes, recipients and your choices.

6. Data recipients and external services

The system sends necessary data to APIs and operational infrastructure to provide the functions you use. The current deployment configuration uses AWS infrastructure services. Sales or support staff should access only information needed for the enquiry. The subprocessor list, access scope and actual sharing arrangements need confirmation before the official version is issued. Disclosures to authorities need a valid request under applicable law.

7. Storage locations and transfers

Storage locations depend on operational infrastructure. Storage countries or regions, recipients and any international transfers await confirmation for disclosure in the official version. Contact us before uploading data if your store has location requirements.

8. Retention and deletion

Retention needs to reflect processing purposes, recordkeeping obligations and lawful requests. Specific periods for enquiries, accounts, store data, logs and backups await confirmation. Closing an account or stopping use does not mean every copy is immediately deleted. Deletion requests need to identify removable data, records subject to applicable retention duties and backup handling; this page does not promise automatic deletion within a fixed number of days.

9. Personal data requests and rights

Subject to applicable legal conditions, you may request information about processing, access, correction, provision or deletion; withdraw consent, restrict or object to processing; and complain or seek protection of your interests. Email the contact below with the data type and scope. Requester authority needs verification without collecting more information than necessary. If another store manages the data, contact that store; support can help identify the appropriate contact. Legal conditions and exceptions may apply.

10. Data protection and incident reports

Protect sign-in details and review staff access. No system eliminates all risks of data loss or unauthorized access. Report unusual activity with its time, description and the minimum necessary information; do not include other people’s data. The Data & security page provides practical guidance. Specific encryption, security assessment, backup and recovery commitments need evidence and an applicable agreement; this page does not verify unsupported certifications or recovery times.

11. Store customer and staff information

Store owners need appropriate authority and grounds to collect, enter or share customer and staff data. Provide only necessary information and give notices or obtain consent where required. Do not upload children’s data, sensitive data or data outside your authority without establishing appropriate processing conditions. Requests from data subjects need coordination between the store and provider according to their actual roles.

12. Policy updates and contact

The update date identifies the content version. Changes to purposes, data categories, recipients or user choices need corresponding information and appropriate notice or consent processes. Use the contact below for questions, corrections or complaints; avoid including unnecessary personal data.

Contact us about terms and data

Use your registered email for requests involving an account or store data. Describe the issue and scope; do not send passwords, verification codes or unnecessary data.

contact@cameostack.com