PhsarOS
OverviewProductPricing
Log inSign up free

Legal / Security

Security

Last updated 7 August 2026Draft — publish only what is actually true in production

Draft. Every claim on this page must be verified against the real deployment before publishing — a security page that overstates is worse than none. Bracketed items are unverified.

Plain-English summary

  • Your shop's data is encrypted in transit, passwords are stored only as hashes, and staff see only what their role allows.
  • We never store your customers' or your card numbers — subscription billing lives with Stripe.
  • If a breach ever affects your data, we will tell you quickly and honestly — within 72 hours of confirming it.
  • Found a vulnerability? Tell us at security@ and we will not take legal action against good-faith research.

1.How your data is protected

  • Encryption in transit. All traffic between your browser and PhsarOS uses TLS. [Encryption at rest — confirm with hosting provider before claiming.]
  • Passwords are stored only as salted hashes, never in plain text. We cannot read your password and will never ask for it.
  • Role-based access. The ADMIN/STAFF split is enforced on the server, not just hidden in the interface — a STAFF session cannot call owner-only endpoints.
  • No card data. Subscription payments are processed by Stripe (PCI DSS Level 1). Card numbers never touch PhsarOS servers. The register records cash sales and does not capture your customers' payment credentials at all.
  • Backups. [Frequency and retention — confirm before claiming.] Deleted data leaves backups within 60 days, per the Privacy Policy.
  • Access control on our side. Production access is limited to the people who operate the service, with unique credentials.

2.What we honestly do not have yet

PhsarOS is a beta product from a small team. We do not yet hold SOC 2 or ISO 27001 certification, and we do not yet publish an uptime SLA. We would rather say so than imply otherwise. As the product matures this page will grow with it.

3.If something goes wrong

If we confirm a personal-data breach that affects you, we will notify affected workspace owners within 72 hours of confirming it, with what happened, what data was involved, and what we are doing — matching the GDPR Art. 33 standard even where the law does not require it. Where a supervisory authority must be notified, we will do that too.

4.Reporting a vulnerability

If you find a security problem, email security@[domain — placeholder] with enough detail to reproduce it. We commit to:

  • acknowledging your report within 3 business days;
  • keeping you informed while we fix it;
  • taking no legal action against good-faith research that avoids accessing other people's data, degrading the service, or extortion;
  • crediting you if you would like, once the issue is fixed.

Please do not test against real shops' workspaces — create a free workspace of your own.

5.Your part

Use a strong, unique password; remove staff accounts when people leave; and export your data regularly during the beta. Security of the account starts with the credentials only you hold.

PhsarOS

The operating system for shop, café and restaurant owners in Cambodia and Southeast Asia.

Product

Point of saleInventoryStaff & rolesReports

Company

OverviewPricingHelp

Account

Sign up freeLog in

Legal

TermsPrivacyRefundsCookiesSecurityAcceptable UseContact
© 2026 PhsarOSPhsarOS records cash sales.Free while every plan is in beta.