Privacy policy
Version 2026-08-21
International operating framework pending country-specific legal review before public launch.
This policy explains how Vertice Digital processes personal data when providing Vértice POS, Vértice Retail, and Vértice Services and Beauty and handling accounts, payments, security, support, and rights requests.
1. Scope and roles
- Vértice as controller: determines the purposes related to accounts, prospects, subscriptions, its own billing, fraud prevention, security, support, compliance, and SaaS improvement.
- Vértice as processor: processes, on the restaurant's or business's instructions, the data it manages about buyers, guests, employees, suppliers, or other third parties.
- The customer as controller: determines the purposes of its operation and must inform data subjects, have an appropriate legal basis, and answer the requests for which it is responsible.
2. Data processed
We may process identity and contact details; account, role, and authentication data; country and language; company and location information; subscription, currency, payment, and billing data; support requests; security events; device, IP, and technical logs; cookie preferences; and usage metrics. We do not intentionally store complete card details when payment is handled by an external provider.
Customer operational data may include orders, reservations, contacts, deliveries, purchases, inventory, staff, or documents that the customer chooses to manage.
3. Purposes and legal bases
We process data to perform the contract, create and protect accounts, provide support, process charges, meet legal obligations, prevent fraud, respond to rights requests, and maintain continuity. We rely on consent when required by law, such as for analytics or marketing cookies, and on legitimate interests only after assessing that the data subject's rights do not override them.
4. Providers, transfers, and sale of data
We may use infrastructure, database, hosting, email, analytics, payment, and support providers—including Supabase, Render, Google, and Hotmart when configured—under contractual and access controls. If an international transfer occurs, we will apply the mechanism required by applicable law. We do not sell personal data or share it for behavioral advertising without notice and a legally valid choice.
5. Retention and security
We retain information during the contractual relationship and afterward for as long as necessary for accounting, tax, security, claims defense, or deletion-request obligations. We apply company-level segregation, access control, audit logs, encryption in transit, secret management, backups, and monitoring. No system eliminates all risk; incidents will be assessed and reported as required by applicable law.
6. Rights and requests
Depending on the country, a data subject may request information, access, updating, correction, deletion, objection, restriction, portability, withdrawal of consent, or review of automated decisions, and may complain to the competent authority. Colombia recognizes consultation, complaint, correction, and deletion rights; the EEA and United Kingdom add GDPR rights; and several United States jurisdictions recognize access, correction, deletion, and choices regarding sale or targeted advertising.
Requests are received through the authenticated support channel and logged so the owner or authorized team can respond, verify identity, and manage deadlines. If Vértice acts as processor, it will forward the request to or assist the responsible company. No person will be discriminated against for exercising a recognized right.
See the public account and data deletion process.
7. Cookies and Google Analytics
Non-essential cookies and Google Analytics remain subject to the applicable preference. The panel lets you accept, reject, or customize categories and withdraw consent. See the Cookie policy.
8. Children
The business SaaS is not directed to children who cannot provide valid consent. Customers must not use it to collect children's data without the authorization and safeguards required in their jurisdiction.
9. International scope
This framework covers Colombia, the European Economic Area, the United Kingdom, the United States, Venezuela, and other Latin American countries. Applicable law depends on the facts, location, each party's role, and mandatory rules; a contractual reference to Colombia does not displace non-waivable territorial rights.
10. Changes and contact
We will publish the current version and date. Material changes will be communicated, and renewed acceptance or consent will be requested when appropriate. For privacy matters, use your account's support center; before production launch, the external channel and contact identity required in each market will also be published.