Legal
Privacy Policy for SolBiz
Version 2026-09-28 · Effective September 28, 2026
1. Scope of This Policy
This Privacy Policy explains how [COMPANY LEGAL NAME] ("SolBiz," "we," "us") collects, uses, and protects information in connection with the SolBiz point-of-sale, inventory, HRIS, and related web and mobile applications (the "Service").
For business data you or your staff enter into the Service about your own customers or employees ("Your Data"), SolBiz acts as a data processor/service provider on your behalf -- you (the tenant business) remain the data controller responsible for the collection and lawful use of that data. This section applies to Your Data alongside the data-processing terms in our Terms of Service.
2. Information We Collect
Account & tenant admin information: name, email, phone, business name, and billing details provided when you register a tenant or admin-portal (billing/customer support) account.
Staff/employee data entered by a tenant: names, contact details, role, work schedule, attendance/time-clock records, and payroll-related data (pay rate, computed wages, overtime, statutory deduction estimates) entered by the tenant admin to operate the HRIS module. This data is entered and controlled by the tenant, not collected by SolBiz directly from the employee.
Customer data entered by a tenant: names, contact details, and purchase history a tenant chooses to record for their own customers (e.g. for receipts, loyalty, or reporting).
Transaction & business data: sales, discounts, taxes, inventory, supplier/purchase records, and credit-wallet/billing history associated with your tenant.
Device & PA data: device identifiers and approval status for registered POS terminals, used to authorize devices and target PA announcements. Announcement audio is relayed for playback and is not stored (see Terms of Service Section 10).
Payment metadata: transaction identifiers, amounts, and status from PayPal (SolBiz billing) and any payment gateway you connect (e.g. PayMaya, for your own customer payments). We do not receive or store full card numbers or gateway account credentials; those are held by the respective payment provider.
Usage & log data: standard technical logs (IP address, device/browser type, timestamps, error logs) generated by using the Service, used for security, debugging, and reliability.
3. How We Use Information
We use the information above to: provide and operate the Service (including processing sales, computing payroll figures, and delivering PA messages); authenticate accounts and secure the Service; process billing and send transactional communications (invites, receipts, renewal notices); provide customer support; and monitor, maintain, and improve the Service's performance and reliability.
We do not sell Your Data or use it to serve third-party advertising. [Confirm and, if applicable, disclose any use of aggregated/de-identified data for product analytics or benchmarking.]
4. Legal Bases for Processing
Where applicable data protection law requires a legal basis (for example, under the EU/UK GDPR), we process personal data to perform our contract with you (the Terms of Service), to comply with legal obligations, for our legitimate interests in operating and securing the Service, and, where required, with consent. [Counsel: confirm which frameworks actually apply given where SolBiz operates and where its tenants/their employees and customers are located, and tailor this section accordingly -- this is a significant gap if any tenant or their staff/customers are in a jurisdiction with a comprehensive privacy law such as GDPR, and needs express confirmation before publishing.]
5. Third-Party Service Providers
We share information with service providers who help us operate the Service, under confidentiality and data-protection obligations appropriate to the data involved, including: PayPal (SolBiz subscription/credit-wallet billing); payment gateways you configure, such as PayMaya (processing your customers' payments -- see Terms of Service Section 7); our cloud hosting/infrastructure provider [NAME TO BE ADDED]; and our transactional email delivery provider [NAME TO BE ADDED].
We disclose information where required by law, to protect the rights, safety, or property of SolBiz, our users, or the public, or in connection with a merger, acquisition, or sale of assets (subject to this Policy continuing to apply to previously collected data).
SolBiz separately operates its own company mailboxes (for sales/support correspondence) that authorized SolBiz staff can access through an internal admin tool. These mailboxes belong to SolBiz and are unrelated to Your Data -- they are not used to read or process tenant customer or employee data.
6. Cross-Tenant (Super Admin) Access
The Service is multi-tenant: each tenant's business data is kept in a logically or physically separate data store from other tenants. A limited number of authorized SolBiz personnel hold administrative access that can span tenants, used only for purposes such as billing support, technical troubleshooting, fraud/abuse investigation, or as required by law. [Confirm and disclose here whether this access is logged/audited, and any internal policy limiting who holds it and how it is reviewed -- a concrete access-control/audit commitment materially reduces breach-of-confidence exposure and should be added once product/security confirms the details.]
7. Data Security
We apply technical and organizational measures appropriate to the data involved, including per-tenant data isolation, encryption of sensitive stored credentials (for example, connected mailbox passwords are stored encrypted, never in plain text), and access controls on administrative tooling.
No system is completely secure, and we cannot guarantee absolute security of information transmitted to or stored by the Service. [Counsel/security: confirm whether a specific security-incident notification commitment/timeline should be added.]
8. Data Retention & Deletion
We retain Your Data for as long as your tenant account is active, to provide the Service. If your tenant is suspended (for example, for non-payment), your data is retained, unavailable to you, and restored on reactivation.
If a tenant account is deleted -- whether at your request or by us for cause under the Terms of Service -- deletion is immediate and irreversible: it permanently removes the tenant's dedicated database and associated records and cannot be recovered afterward. Before requesting deletion, you are responsible for exporting any records you wish to keep using the Service's available report exports (sales, inventory, purchases, payroll, etc.).
[Product/legal gap to resolve: the Service does not currently offer a single "export all my data" tool, and deletion has no grace period. Counsel and product should agree whether to (a) commit to a defined post-cancellation retention/export window before this Policy promises one, or (b) keep disclosing the current immediate-deletion behavior plainly, as drafted here, and rely on the export-first guidance above.]
9. Your Rights & Choices
Depending on your jurisdiction, you (or, for employee/customer data you entered as a tenant, the individuals whose data you control) may have rights to access, correct, export, or request deletion of personal data. Tenant admins can access and correct most business, staff, and customer data directly within the Service. For anything not self-service, contact us using the details in Section 13, and we will respond as required by applicable law.
Where a request concerns data a tenant entered about their own employee or customer (rather than SolBiz's own tenant-admin account data), we will generally direct the request to, or process it on behalf of, the relevant tenant, consistent with our processor role described in Section 1.
10. Device Permissions
The mobile and POS applications may request device permissions (for example, camera access for barcode scanning). Permissions are used solely to provide the corresponding feature and are not used to collect unrelated data. You can manage permissions through your device settings, though disabling a permission may disable the related feature.
11. Children's Privacy
The Service is intended for business use by adults and is not directed to children. We do not knowingly collect personal data from children. If you believe a child's data has been provided to us, contact us using the details in Section 13 and we will take appropriate action.
12. International Data Transfers
Depending on where our infrastructure and service providers are located, your data may be processed in a country other than your own. [Counsel: confirm hosting location(s) and add the applicable transfer-safeguard language (e.g. standard contractual clauses) if data is transferred out of a jurisdiction that restricts such transfers.]
13. Contact
Questions about this Privacy Policy, or requests regarding your data, can be sent to support@cloud-tech.biz. [Counsel/ops: confirm whether a distinct data-protection contact and registered postal address should be added here per applicable law.]
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced by email to the tenant admin and/or an in-product notice, with a new effective date shown at the top of this page.