Legal
Privacy Policy
Effective 28 August 2026
THE SHORT VERSION
Inventovia is a point-of-sale service for businesses. We store the data a shop needs to run — its products, sales, staff, and the customer records it chooses to keep. We don't run ads, we don't sell data, and we never handle your customers' card or mobile-money credentials: payments go to the merchant's own accounts, and Inventovia only records that they happened. The full detail is below.
1. Who we are
Inventovia ("we", "us") is operated by INVENTOVIA LIMITED, No. 129, Jikwoyi Phase 2, Abuja, Nigeria. For anything in this policy, write to support@inventovia.com.
Two roles matter throughout this policy:
- For merchant accounts (the business owner's email, password, plan and billing records), we are the data controller — we decide how that data is used.
- For a shop's business data (its products, sales, staff records, and any customer details the shop enters), the merchant is the controller and we are their processor: we store and process it only to provide the service, on the merchant's instructions. Our Data Processing Addendum governs this.
2. What we collect, and why
Account data (we are controller)
- Owner account — email address, password (stored only as a bcrypt hash, never readable by us), country of business, store name. Used to sign you in, recover your account, and send the service emails described in section 5.
- Billing — your plan, subscription status, and references issued by our payment providers. Card and mobile-money details for your subscription are collected by Paystack or Stripe on their own hosted pages; we never see or store them.
Shop data (the merchant is controller)
- Catalog and trading records — products, prices, stock, sales, refunds, shifts, purchase orders, and reports derived from them.
- Staff records — employee names and till PINs (stored only as bcrypt hashes), and the permissions the merchant assigns.
- Customer records the merchant chooses to keep — for loyalty points and credit sales: typically a name and phone number, purchase history, points and balances. Merchants are responsible for telling their customers about this and for having a lawful basis to record it.
- Payment provider credentials — if a merchant connects their own account (for example MTN MoMo API credentials), we store those encrypted (AES-256-GCM) and use them only to act on that merchant's instructions.
Technical data
- Device records — each paired till has an identifier and a name so it can sync and be revoked if lost.
- Logs — server request logs (IP address, timestamps, request identifiers) kept for security and troubleshooting.
- Crash and error reports — sent to Sentry when something breaks, so we can fix it. These contain technical context (device model, OS version, the error itself), not your sales data.
3. What we do NOT collect
- No location. The app never reads or derives your location. On Android 11 and older, the operating system requires a location permission for the Bluetooth scan that finds your receipt printer — that is the permission's only purpose, and on Android 12+ we declare the scan as "never for location".
- No camera, no microphone, no contacts. Barcode scanning uses a hardware scanner, not the camera.
- No advertising or tracking SDKs. There is no ad network, no analytics profile, and no sale or sharing of personal data for advertising — ever.
- No customer payment credentials. Your customers pay you on your own accounts and terminals. Their card numbers and wallet credentials never touch Inventovia.
4. Data on the till itself
Inventovia is offline-first: the till app keeps a local copy of the shop's catalog and its own sales in an encrypted database (SQLCipher) on the device, so selling never depends on the network. Protect the device as you would a cash drawer. A lost or stolen till can be revoked from the dashboard at once, after which it can no longer sync; its local database remains encrypted.
5. Emails we send
Service email only: email verification, password resets, and billing notices. We do not send marketing email. Transactional email is delivered through our email provider (see subprocessors).
6. Who else touches the data (subprocessors)
- Hosting — our servers and database run with our cloud hosting provider, in Germany (European Union).
- Paystack and Stripe — collect subscription payments from merchants on our behalf; they receive your email and payment details you give them directly.
- Sentry — receives crash and error reports.
- Resend — delivers our service email.
- Google Fonts — our web pages load fonts from Google, which sees the requesting IP address as a consequence.
We share data with no one else, except where the law requires it of us.
7. Security
- TLS for every connection; HTTPS everywhere.
- Passwords and PINs stored only as bcrypt hashes.
- Sensitive credentials encrypted at rest with AES-256-GCM.
- The till's on-device database is encrypted with SQLCipher.
- Every merchant's data is isolated by database-enforced row-level security.
- Our staff accounts require two-factor authentication, and every access by our support staff to a merchant's data is logged and auditable.
- Encrypted nightly backups, integrity-verified, pruned on a rolling schedule (currently 14 days).
8. Retention and deletion
- Your data stays for as long as your account exists — including on the Free plan. Plan limits never delete anything: they shape the analysis we compute, not your records.
- You can export your sales history (CSV) at any time, on every plan.
- Account deletion works as described on the account deletion page: request it, we verify you control the account, and we delete or irreversibly anonymize the account and its shop data within 30 days, after which backup copies expire on the rolling schedule above. We keep only what the law requires us to keep (for example records of our own invoices to you).
9. Your rights
Depending on where you live — including under Nigeria's Data Protection Act, 2023, Ghana's Data Protection Act, 2012 (Act 843), and the EU/UK GDPR — you may have rights to access, correct, export, restrict, or delete personal data about you, and to complain to a supervisory authority. Write to support@inventovia.com and we will respond within 30 days. If you are a customer of a shop that uses Inventovia, your relationship is with that shop: contact the merchant, and we will help them honour your request.
10. International transfers
Merchants use Inventovia from many countries; the data is stored in Germany (European Union). Where the law of your country restricts transfers, we rely on appropriate safeguards such as standard contractual clauses.
11. Children
Inventovia is a business tool. It is not directed at children, and account holders must be old enough to form a binding contract in their country.
12. Changes
If this policy changes in a way that matters, we will note it here with a new effective date and, for significant changes, tell account owners by email.