Scope
Retail OS processes account identity, tenant configuration, product and inventory records, sales and finance records, files, integration credentials and operational audit events.
Biometric data
Face templates and images require explicit organizational consent, a documented purpose, limited retention and a deletion process. CompreFace recognition is not certified liveness or anti-spoofing.
Security and access
Tenant and role boundaries restrict access. Provider secrets are encrypted. Organizations remain responsible for account policy, lawful data collection and device security.
Retention and deletion
Operational retention follows the organization’s legal and accounting requirements. Biometric and uploaded content should be removed when its purpose expires, subject to required records.
Processors and transfers
Connected providers process data under their own terms. A provider connection must be reviewed before production use and should receive only the minimum necessary data.