Legal
Privacy Policy
Last updated: 2026-05-10
This Privacy Policy describes how ZeoFex ("we," "us," or "our") processes personal information when you use our websites, applications (including VentraPOS.com), and related services.
We respect your privacy and process data in accordance with this Policy and applicable laws, including where relevant the data protection framework in the Republic of Ghana and internationally recognized principles such as transparency, purpose limitation, data minimization, and accountability.
Last updated: 2026-05-10.
1. Scope and roles
This Policy applies to visitors, registered users, customers, and business contacts who interact with our services. If you are in the European Economic Area, United Kingdom, or similar jurisdictions, additional rights may apply as described in Section 9.
Where we process personal data on behalf of an organization (for example, as a processor for your employer's account), that organization's instructions and agreement govern business contact data, and you should also review their privacy notice.
2. Information we collect
2.1 Account and contact details
We collect identifiers such as name, email address, telephone number, organization name, job title, and billing address when you register, request a demo, subscribe, sign contracts, or communicate with us.
2.2 Authentication and security
We store passwords using strong one-way hashing and salting. We may process session tokens, refresh tokens, device identifiers, IP addresses, and audit logs to authenticate users, prevent fraud, and protect accounts.
2.3 Location and device data
With your consent where required, our applications may access precise or coarse location (including GPS-derived signals on mobile) to support features such as store routing, fraud checks, or regional compliance. You may disable location permissions in your device settings; some features may not function without them.
We also collect technical telemetry such as browser type, operating system, approximate location derived from IP address, and crash diagnostics.
2.4 Payment information
Payments are handled by certified payment processors. We typically receive limited payment metadata (such as last four digits, brand, expiry, billing country) rather than full card numbers, which are tokenized by our processor.
2.5 Marketplace and collaboration content
If you submit job proposals, project descriptions, attachments, messages, or support tickets, we process that content to operate the service, facilitate transactions, and maintain records.
2.6 Cookies and similar technologies
We use cookies, local storage, and pixels as described in our Cookie Policy. Marketing cookies are used only where you opt in where required by law.
3. How we use information
We use personal information to provide, secure, and improve our services; authenticate users; process payments; communicate service and billing notices; provide support; comply with law; enforce our terms; and, where permitted, send product updates or marketing (subject to your preferences).
We may create aggregated or de-identified data that cannot reasonably identify you, which we may use without restriction subject to applicable law.
4. Legal bases (where applicable)
Depending on context, we rely on performance of a contract, legitimate interests (such as securing our network, analytics in aggregate form, and product improvement balanced against your rights), consent (for optional marketing or non-essential cookies), and legal obligation.
5. Sharing with service providers
We share personal information with vendors who assist our operations, including:
5.1 Infrastructure and application hosting
Vercel for web application hosting, edge delivery, and related platform services.
5.2 Payments
Paystack (or other processors we designate) for payment authorization, settlement, and fraud screening.
5.3 Authentication and data platform
Supabase for authentication, real-time features, and managed data services where configured for your workspace.
5.4 Databases and ORM
Neon for managed PostgreSQL infrastructure; Prisma as database tooling and schema management; Drizzle ORM where used for typed database access and migrations.
6. International transfers
Our service providers may process data in Ghana, the European Union, the United States, and other regions. Where required, we implement appropriate safeguards such as standard contractual clauses or equivalent mechanisms and conduct transfer assessments.
7. Security
We implement administrative, technical, and organizational measures designed to protect personal information, including encryption in transit (TLS), encryption at rest where supported by our stack, access controls, least-privilege policies, logging, and vendor due diligence.
No method of transmission or storage is completely secure; we encourage strong passwords, multi-factor authentication where available, and prompt reporting of suspected incidents.
8. Retention
We retain personal information for as long as necessary to fulfill the purposes described in this Policy, including providing services, satisfying legal, tax, and accounting obligations, resolving disputes, and enforcing agreements.
Backup copies may persist for a limited period after deletion from production systems. Marketing preferences are retained to honor opt-outs.
9. Your rights and choices
9.1 Access and correction
You may request access to or correction of inaccurate personal information through account settings or by contacting us.
9.2 Deletion
You may request deletion of your personal information, subject to legal exceptions (for example, invoicing records we must retain).
9.3 Portability
Where applicable, you may request a machine-readable copy of personal information you provided, limited to information we process based on contract or consent.
9.4 Objection and restriction
You may object to certain processing based on legitimate interests or request restriction of processing where applicable law provides these rights.
9.5 Marketing opt-in and cookies
Marketing communications are sent only with consent where required. You may withdraw consent at any time via unsubscribe links or by contacting us. Non-essential cookies and similar technologies are controlled as described in our Cookie Policy.
10. Breach notification
If we become aware of a personal data breach likely to result in risk to your rights, we will investigate, mitigate, and notify competent supervisory authorities and affected individuals as required by applicable law and without undue delay.
11. Children
Our services are not directed to children under sixteen (16), and we do not knowingly collect personal information from children. If you believe we have collected such information, contact us and we will take appropriate steps to delete it.
12. Ghana and international framing
ZeoFex is committed to compliance with the Data Protection Act, 2012 (Act 843) of Ghana, including principles of lawful processing, data security, and data subject rights, where applicable to our activities.
If you reside outside Ghana, local privacy laws may also apply. Nothing in this Policy limits rights you may have under those laws.
13. Changes to this Policy
We may update this Policy to reflect operational, legal, or regulatory changes. We will post the revised version with an updated date and, where appropriate, provide additional notice.
14. Contact
To exercise privacy rights or ask questions, contact us via the contact page. You may also contact a supervisory authority where you have the right to lodge a complaint.