Tiếng Việt · Русский · English
Privacy Policy — Efix POS
App: Efix POS (checkout, inventory, restaurants) — developed by EfixPro
Data controller: the merchant/business that deployed Efix POS for its own store or
chain (the organization account owner) is responsible for its staff's and customers' data. EfixPro provides the
software and server infrastructure, acting as a data processor on that business's behalf.
Last updated: 2026-09-17
This policy explains what data Efix POS collects and how it is used and protected when you use the app on a
phone, tablet, or in a web browser.
1. Data we collect
- staff accounts: organization code, login, password (stored only as a hash), full name, role/permissions;
- sales data: orders, receipts, products, inventory, tables/zones (for restaurants), promotions;
- loyalty program data (optional, if enabled by the merchant): name, phone number, loyalty points;
- payment data: bank-transfer/VietQR transaction references — the app does not store card numbers;
- device data: camera (only when scanning barcodes/QR codes), local network address (to print receipts on a
Wi-Fi/LAN receipt printer), push-notification tokens;
- technical logs: IP address, device/browser type, sign-in times, security events.
2. Purposes of processing
- staff authentication and access control scoped to their own organization;
- checkout, inventory management, receipt printing and reporting;
- customer loyalty program (if enabled);
- automatic payment confirmation via the payment gateway (VietQR/Casso);
- system security and troubleshooting.
3. Device permissions
- Camera — used only to scan product barcodes/QR codes at checkout, no background recording;
- Local network — used to connect to and print receipts on a Wi-Fi thermal printer at the
point of sale;
- Push notifications — new-order and kitchen-status alerts.
4. Sharing with third parties
EfixPro does not sell data. Data may be shared only with:
- server hosting/infrastructure providers (under confidentiality agreements);
- Casso/the partner bank — solely to confirm VietQR bank-transfer payments;
- Firebase Cloud Messaging — device token, for push notifications;
- government authorities — where required by law.
5. Storage and security
Data is stored on servers chosen by the deploying business, transmitted over encrypted HTTPS/WSS connections,
passwords are stored as hashes (scrypt), access is role-restricted, and significant actions are logged. Data is
kept until the account is deleted or the operating business requests deletion, unless a longer retention period is
required by law (e.g. accounting/tax rules).
6. Your rights
You may request access to, correction of, or deletion of your personal data by contacting your organization's
administrator, or EfixPro directly using the contact details below.
7. Children
Efix POS is a business (B2B) tool, not directed at children, and does not knowingly collect data from anyone
under 16.
8. Changes to this policy
This policy may be updated from time to time; the current version is always available at this address.
9. Contact
EfixPro — info@efix.vn · efix.vn