RETAILOS

DATA HAS AN OWNER.

This policy explains what Retail OS processes, why it is needed and the controls organizations must keep over operational and biometric data.

01

Scope

Retail OS processes account identity, tenant configuration, product and inventory records, sales and finance records, files, integration credentials and operational audit events.

02

Biometric data

Face templates and images require explicit organizational consent, a documented purpose, limited retention and a deletion process. CompreFace recognition is not certified liveness or anti-spoofing.

03

Security and access

Tenant and role boundaries restrict access. Provider secrets are encrypted. Organizations remain responsible for account policy, lawful data collection and device security.

04

Retention and deletion

Operational retention follows the organization’s legal and accounting requirements. Biometric and uploaded content should be removed when its purpose expires, subject to required records.

05

Processors and transfers

Connected providers process data under their own terms. A provider connection must be reviewed before production use and should receive only the minimum necessary data.