Legal

Privacy Policy

This policy outlines how Tinker Pro collects, protects, processes, and handles your data, business metrics, and device permissions when you use the TinkerPro POS application and web terminal.

Last Updated: June 30, 2026

Tinker Pro ("we," "our," or "us") operates the TinkerPro POS - Point of Sale mobile application and web-based terminal platforms (the "Service"). This privacy policy outlines how we collect, protect, process, and handle sensitive user data, business metrics, and device permissions when you utilize our application ecosystem.

Data Transparency Commitment: In strict compliance with Google Play Developer Policies, we disclose that all user data collected is explicitly utilized to provide core B2B operational functions. We do not sell or lease your commercial or personal data to third-party advertising networks.

Information We Collect

To deliver real-time cloud-synchronized point-of-sale features, enterprise resource planning, and secure transaction handling, we process several categories of information:

A. Personal and Account Data

  • Account Profiles: When users register an account via our mobile application or web browser, we collect credentials including email addresses, full names, business names, and passwords to authenticate terminal sessions safely.
  • Customer & CRM Profiles: Customer details captured during sales operations (names, contact points) are collected to build your retail relationship profiles.

B. Operational and Business Data

  • Sales & Transaction Histories: Records of items sold, payment methodologies, and operational logs are instantly captured to process client checkouts.
  • Inventory Logs & Activity Logs: Real-time changes to inventory counts, item modifications, and explicit user actions within the admin workspace are documented to maintain clean ledger transparency.

C. Technical and Device Data

  • Device & Usage Information: We may automatically collect technical data such as device model, operating system, app version, IP address, and general usage activity to keep the Service secure and functioning correctly.
  • Diagnostic & Crash Logs: Error reports and performance logs are collected to diagnose issues, prevent fraud, and improve the reliability of the Service.

How We Use Your Information

We use the information we collect strictly to operate, maintain, secure, and improve the Service. In particular, we process your data to:

  • Create and authenticate your Account and manage your access to the Service;
  • Process in-store sales, checkouts, receipts, and cloud synchronization across your devices and branches;
  • Provide inventory management, reporting, and other point-of-sale and back-office features;
  • Facilitate subscription payments and recurring billing through our payment processor;
  • Provide customer support and respond to your requests and inquiries;
  • Monitor, secure, and troubleshoot the Service, and detect and prevent fraud or abuse; and
  • Comply with our legal, tax, and regulatory obligations.

We do not sell or lease your commercial or personal data to third-party advertising networks, and we do not use your business or customer data for advertising purposes.

Device Hardware Permissions

The App requests access to specific hardware subsystems strictly necessary to execute system actions. These permissions include:

  • Camera Access: Utilized exclusively for optical barcode and QR code scanning to fetch inventory items or process transactions instantly.
  • Bluetooth & Location Services: Required to scan, connect, and transmit printing queues directly to physical local network receipt printers. Location tracking parameters are queried solely to establish peripheral hardware connections.
  • Local Storage Access: Utilized to securely download, store, and temporarily cache invoice drafts, operational logs, and localized business reports.

Third-Party Payment Processing

To securely process electronic payments within the POS workspace, our application integrates the PayMongo payment gateway API. Tinker Pro does not directly store your complete credit card numbers or raw banking credentials on our infrastructure. All financial transmissions are handled securely via PayMongo under their respective security certifications.

Data Sharing and Disclosure

We do not sell your personal or business data. We share information only in the limited circumstances described below:

  • Service Providers: With trusted third parties who process data on our behalf to operate the Service — such as cloud hosting, payment processing (PayMongo), and analytics or diagnostic providers — under contractual obligations of confidentiality and security.
  • Legal and Regulatory: Where required to comply with applicable law, a court order, or a lawful request by a government or regulatory authority, or to establish, exercise, or defend legal claims.
  • Business Transfers: In connection with a merger, acquisition, financing, or sale of assets, in which case data may be transferred to the successor entity, subject to this Privacy Policy.
  • With Your Direction: Where you instruct or authorize us to share information, or where you input data into features that involve third parties.

As the Merchant, you remain the personal information controller for the customer data you collect through the Service and are responsible for the lawful handling of that data.

Data Storage and Security

All gathered information is securely transmitted across encrypted protocols (HTTPS/TLS) and stored securely within our protected corporate cloud database environments to ensure live synchronization across web browsers and mobile terminals.

We implement reasonable and appropriate organizational, physical, and technical security measures to protect your data against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Our cloud infrastructure and certain service providers may store or process data on servers located outside the Philippines. Where data is transferred internationally, we take reasonable steps to ensure it remains protected in accordance with this Privacy Policy and applicable law.

Data Retention

We retain your personal and business data for as long as your Account remains active and for as long as necessary to provide the Service, comply with our legal, tax, and regulatory obligations, resolve disputes, and enforce our agreements.

When data is no longer required for these purposes, we will securely delete or anonymize it. Following an account deletion request, we will erase your personal records within standard regulatory limits, except where retention is required by law.

Your Privacy Rights

Under the Data Privacy Act of 2012, you have the following rights as a data subject, which you may exercise by contacting us using the details in the Contact & Compliance section:

  • Right to be informed about how your personal data is collected and processed;
  • Right to access the personal data we hold about you;
  • Right to rectification of inaccurate or incomplete data;
  • Right to erasure or blocking of your data, subject to legal limits;
  • Right to object to certain processing of your data;
  • Right to data portability for data processed by electronic means; and
  • Right to file a complaint with the National Privacy Commission, and to be indemnified for damages arising from unlawful processing.

We will respond to legitimate requests within a reasonable period and may need to verify your identity before acting on a request.

Account & Data Deletion

We respect your ultimate governance over your information. In compliance with international digital data provisions and Google Play's user protection standards, any registered user can request the permanent erasure of their account and associated data.

Data That Will Be Deleted

When we process an approved deletion request, we permanently remove the personal and business data associated with your Account, including:

  • Account credentials — your email address, password, full name, and business name;
  • Contact & profile details — phone number and any other profile information linked to your Account;
  • Customer & supplier records — customer and supplier profiles (names, contact points, and purchase history) you stored in the Service;
  • Sales & transaction history — your recorded sales, receipts, and payment records;
  • Inventory & operational data — product lists, inventory logs, and activity logs; and
  • Technical & device data — usage and diagnostic identifiers tied to your Account.

Data That May Be Retained

We may retain limited information after deletion only where necessary to:

  • Comply with legal, tax, accounting, or regulatory obligations (for example, invoicing and financial records required by law);
  • Resolve disputes, prevent fraud or abuse, and enforce our agreements; and
  • Keep records in backup archives until they are cycled out on our regular backup schedule.

Any retained data is kept only for as long as required for these purposes, after which it is securely deleted or anonymized. Data handled by our payment processor (PayMongo) is subject to their own retention policies.

How to Request Account & Data Deletion

  • Send an email to our data compliance team at accounts@tinkerpro.io, using the email address registered to your Account.
  • Set the subject line exactly as: ACCOUNT DELETION REQUEST.
  • Include the account email (and business name) you want deleted so we can locate your records.

Upon receiving your request, our team will verify your identity, then permanently delete your personal records — including your email and password — from our active systems, typically within thirty (30) days, except for the limited data noted above that we are required to retain by law.

Cookies and Tracking Technologies

Our web-based terminal may use cookies and similar technologies (such as local storage and session tokens) to keep you signed in, remember your preferences, maintain the security of your session, and understand how the Service is used.

You can control or disable cookies through your browser settings; however, disabling certain cookies may limit your ability to use parts of the Service, such as staying logged in.

Children's Privacy

The Service is a business tool intended for use by merchants and their authorized staff and is not directed to children. We do not knowingly collect personal data from children under the age of eighteen (18). If we become aware that we have inadvertently collected such data, we will take steps to delete it promptly.

Policy Modifications

We may intermittently adjust this privacy framework to keep pace with functional updates or security protocols. We will notify stakeholders of any modifications by posting the updated text to this link and adjusting the "Last Updated" timestamp. Where changes are material, we will take reasonable steps to notify you, and your continued use of the Service after the updated policy takes effect constitutes your acknowledgment of the changes.

Contact & Compliance

For any queries surrounding this document, our data handling practices, or to exercise your privacy rights, please contact us:

If you believe your data privacy rights have been violated, you also have the right to lodge a complaint with the National Privacy Commission (NPC) of the Philippines at privacy.gov.ph.