Legal / Privacy Policy
Privacy Policy
Draft. This page can publish before incorporation — you are a data controller the moment you collect an email address — but the controller identity and contact inbox below are placeholders until the entity and domain are final.
Plain-English summary
- We collect what we need to run PhsarOS: your account details, your shop's records, and basic usage and billing information.
- Your shop's data — sales, stock, expenses — is processed only to provide the service. We don't sell it and we don't use it for advertising.
- Subscription payments go through Stripe; we never see your full card number.
- You can export your data any time, and ask us to access, correct or delete what we hold about you.
- Close your workspace and we delete your data: 30 days from live systems, 60 more from backups.
1.Who is responsible
The data controller for your account and for this website is [PhsarOS legal entity — to be registered]. Contact for anything in this policy: privacy@[domain — placeholder]. We aim to answer within 30 days.
2.What we collect
- Account data — name, email, password (stored only as a hash), workspace name, plan, and the staff accounts the owner creates.
- Shop records — the sales, products, stock, expenses and reports your workspace enters. See §3.
- Billing data — plan, invoices and payment status. Card details are collected and held by Stripe, not by us.
- Usage and device data — logs (IP address, browser, pages, errors) kept for security and debugging.
- Waitlist and support messages — the email you give us and what you write to us.
We do not ask for, and please do not send us, sensitive personal data (health, religion, biometrics). PhsarOS does not need it.
3.Your shop's records — a special case
The records your shop enters may contain personal data about other people — your staff's names on shift records, for example. For that data, you (the workspace owner) decide what goes in and why; we process it only on your instructions, to provide the service. In GDPR terms: you are the controller of your shop's records, and we act as your processor. We process them to store, display, back up and export them — nothing else. If someone asks us directly about data inside your workspace, we will refer them to you unless the law requires otherwise.
4.Why we process, and the legal bases
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Providing the service | Account data, shop records | Contract (Art. 6(1)(b)) |
| Billing paid plans | Billing data | Contract; legal obligation (tax records) |
| Security, debugging, abuse prevention | Usage and device data | Legitimate interests (Art. 6(1)(f)) |
| Product emails about your account | Contract | |
| News and marketing emails | Consent — every email has an unsubscribe link | |
| Analytics cookies | Usage data | Consent — see the Cookie Policy |
We do not use your data to train machine-learning models, we do not sell it, and we do not share it with advertisers.
5.Who we share data with
Only service providers who help us run PhsarOS, under contracts that limit what they can do with it:
| Provider | Purpose | Location |
|---|---|---|
| [Hosting provider — to be confirmed] | Application hosting and database | [Region] |
| Stripe | Subscription billing | USA |
| [Email provider — to be confirmed] | Transactional email | [Region] |
| [Analytics provider, if any] | Consent-based analytics | [Region] |
We may also disclose data where the law genuinely requires it, or in a merger or acquisition — in which case this policy continues to apply to data collected under it.
6.International transfers
PhsarOS is operated from Cambodia with infrastructure that may be located elsewhere. Where data moves out of the EU/UK, we rely on Standard Contractual Clauses or an adequacy decision. The subprocessor table above shows where each provider processes data.
7.How long we keep data
- Open workspace: as long as your account exists.
- Closed workspace: deleted from live systems within 30 days, and from backups within a further 60 days. Export before you close.
- Invoices and tax records: kept as long as tax law requires, even after closure.
- Security logs: up to 12 months.
- Waitlist emails: until launch plus 6 months, or until you unsubscribe.
8.Your rights
You can ask us to access, correct, delete or export your personal data, to restrict or object to processing based on legitimate interests, and to withdraw consent at any time (this doesn't undo processing that already happened). Write to privacy@[domain]; we will verify it's you and respond within 30 days. If you are in the EU/UK you may also complain to your data protection authority. These rights are honoured for all users, wherever you are — including Cambodia.
9.Cookies
The short version: essential cookies only, unless you consent to analytics. The full list, lifetimes and how to withdraw consent are in the Cookie Policy.
10.Children
PhsarOS is a business tool for people 18 and over. We do not knowingly collect data from children; if you believe a child has created an account, tell us and we will delete it.
11.California residents
We do not sell or share personal information as defined by the CCPA/CPRA. California residents may exercise the access, deletion and correction rights in §8 without discrimination.
12.Changes and contact
If we change this policy materially we will notify you by email or in the product before the change takes effect. Questions: privacy@[domain — placeholder].