Legal
VeriTech POS Privacy Policy
Effective Date: August 1, 2026
This Privacy Policy explains how PNW Creative Labs, LLC (“VeriTech,” “Company,” “we,” “us,” or “our”) collects, uses, discloses, and protects information in connection with VeriTech POS, including our website, hosted POS platform, back-office software, desktop and mobile applications, AI-assisted inventory tools, vendor tools, customer support, and related services (collectively, the “Service”).
By using the Service, you agree to the practices described in this Privacy Policy.
1. Scope
VeriTech POS is primarily a business-to-business retail software platform. We collect information about merchants, merchant users, staff users, vendor users, and website visitors.
Merchants may also use the Service to store information about their own customers, sales, receipts, inventory, vendors, loyalty accounts, invoices, and store operations. When a merchant enters customer data into VeriTech POS, the merchant is responsible for its own customer relationship and legal compliance. VeriTech processes that data to provide the Service.
2. Information We Collect
We may collect the following categories of information.
Account and business information
- name;
- email address;
- phone number;
- business name;
- store name;
- business address;
- tenant slug or workspace identifier;
- staff roles and permissions;
- login credentials or authentication records;
- account setup and onboarding information;
- subscription plan and billing status.
POS, inventory, and store operation information
- product names, SKUs, UPCs, barcodes, categories, brands, descriptions, costs, prices, and images;
- inventory counts, stock movements, receiving records, vendor sources, purchase records, and adjustments;
- sales, refunds, voids, receipts, tax lines, tenders, cashier attribution, till sessions, cash movements, and closeout information;
- customer names or customer identifiers if entered by the merchant;
- age-verification records, including birth date and derived age when a merchant chooses to key a customer birth date;
- loyalty or customer account records if enabled;
- vendor names, contact information, product listings, requests, notes, and communications.
Payment and billing information
For VeriTech subscription billing, we may collect plan, subscription, checkout, payment status, and billing metadata. Payment card details for VeriTech subscription payments are handled by our billing provider.
For merchant customer sales, VeriTech may record tender type, amount, change due, external terminal reference, processor reference, note, or reconciliation data. Unless we expressly provide a separate payment-processing service, VeriTech does not process merchant customer card payments and does not store full customer card numbers.
AI, document, and file information
When you use AI-assisted features, we may process:
- product photos;
- vendor invoices;
- packing slips;
- spreadsheets;
- PDFs;
- CSV files;
- text documents;
- screenshots;
- inventory documents;
- prompts, chat messages, assistant requests, and AI outputs.
AI features may extract product names, UPCs, barcodes, quantities, costs, categories, descriptions, vendor names, and other information from uploaded files or user prompts.
You should not upload files unless you have the right to upload them and doing so complies with your legal obligations.
Desktop app, mobile app, hardware, and diagnostics information
Our desktop and mobile apps may collect or process:
- app version;
- operating system;
- device type;
- connected URL or workspace;
- tenant identifier;
- update status;
- printer status;
- printer configuration;
- cash drawer configuration;
- hardware settings;
- local error logs;
- crash or diagnostic logs;
- update logs;
- support diagnostics.
Local logs or mock printer files may include receipt or transaction data depending on configuration. Merchants should control device access and avoid using test or mock modes with sensitive production data unless appropriate.
Website, usage, and technical information
We may automatically collect:
- IP address;
- browser type;
- device type;
- operating system;
- pages viewed;
- links clicked;
- referring pages;
- session activity;
- cookies or similar identifiers;
- error logs;
- security logs;
- approximate location derived from IP address.
3. Sources of Information
We collect information from:
- you;
- your business;
- your staff users;
- vendors or vendor users;
- customers when entered by you;
- uploaded files and documents;
- connected devices and apps;
- website and app usage;
- service providers;
- billing providers;
- support communications;
- security and diagnostic systems.
4. How We Use Information
We use information to:
- provide, operate, secure, and maintain the Service;
- create and manage accounts;
- authenticate users;
- process subscriptions and billing;
- provision tenants and workspaces;
- run POS, inventory, catalog, receipt, reporting, vendor, assistant, and app features;
- support printer, cash drawer, desktop app, and mobile app functions;
- provide AI-assisted document scanning, product drafting, inventory import, categorization, and business assistant features;
- detect, prevent, and investigate fraud, abuse, security incidents, unauthorized access, and platform misuse;
- provide support and diagnostics;
- improve the Service;
- communicate about updates, security, billing, support, and product changes;
- comply with law, legal process, contractual obligations, and regulatory requirements;
- enforce our Terms and other agreements.
5. AI Processing
When you use AI-assisted features, we may send relevant prompts, files, images, extracted text, or business data to AI service providers or model providers to process your request. AI providers process the data to return outputs such as product drafts, extracted invoice rows, descriptions, categories, summaries, or assistant responses.
Selecting a photo while creating a new product sends the selected photo and file metadata to OpenAI to draft product details automatically. Administrators can create a product without a photo to avoid this processing. Selecting or dropping an inventory document sends the selected document, its contents, and file metadata to Anthropic (Claude) to extract inventory rows, including during retry or recovery. Administrators who prefer not to upload a document may paste structured spreadsheet or CSV rows directly; those pasted rows are parsed inside VeriTech and are not sent to a third-party AI provider for document extraction.
Merchant Agent requires a versioned opt-in before its first provider request. When enabled, a requested response may send the user's message, bounded recent conversation context, authorized VeriTech business evidence, explicitly attached files or images, and bounded excerpts retrieved from that user's authorized document library to OpenAI. Merchant Agent requests do not ask OpenAI to store the response. OpenAI states that API data is not used to train its models by default unless the API customer explicitly opts in, and OpenAI may retain abuse-monitoring logs for up to 30 days unless approved retention controls apply.
Merchant Agent files remain in tenant-private VeriTech storage for the 7-, 30-, or 90-day period selected at upload. Authorized users can delete files and their derived searchable knowledge from the workspace, revoke future Merchant Agent provider requests, and delete their conversation history. Core POS functions remain available without Merchant Agent.
We use reasonable controls designed to limit AI processing to the request and related Service operation. However, you are responsible for reviewing AI outputs and for deciding what information is appropriate to upload.
Do not upload sensitive personal information, regulated information, employee information, customer information, or vendor information to AI features unless you are permitted to do so and the upload is necessary for your business use.
6. Apple and Google Account Sign-In
You may choose Continue with Apple or Continue with Google to create or access a merchant account. These sign-in features request only the provider account identifier, verified email address, and available name or basic profile information. Apple users may choose Hide My Email. VeriTech uses this information to authenticate you, prefill account setup, link the identity to your VeriTech user record, prevent fraud, and maintain account security.
Account sign-in does not give VeriTech access to iCloud, Gmail, Google Drive, contacts, calendars, or your Apple or Google password. VeriTech validates the provider's signed identity response and does not retain the temporary authorization token used during sign-in. We retain the linked provider account identifier and associated identity information while your VeriTech account remains active or as otherwise needed for security and legal obligations.
A provider identity with an email address cryptographically verified by Apple or Google may be linked to the active VeriTech account carrying that same normalized email address. When the addresses differ, VeriTech requires the account's email and password once before linking. You may continue using email-based account access if you do not choose a provider.
7. Google Mailbox Connections and Google User Data
An authorized merchant owner or administrator may optionally connect a tenant-owned Google Workspace or Gmail mailbox to Merchant Agent. Connecting a mailbox is separate from signing in to VeriTech. VeriTech never receives the user's Google password.
Depending on the permissions the user selects, VeriTech accesses the following Google user data:
- Google account identity information, including the connected account's email address and profile name, so VeriTech can identify the mailbox connection;
- permission to send email through the connected account. VeriTech sends only the exact single-recipient message that an authorized user has separately reviewed, approved, and chosen to execute through the governed Merchant Agent action flow; and
- if the owner or administrator separately enables inbox reading, message identifiers, sender, subject, date, read status, and a short Google-provided message snippet for up to 10 messages from a user-requested lookback of 1 to 30 days.
Inbox reading is off by default and occurs only when an authorized user asks Merchant Agent to perform that mailbox task. VeriTech does not use this connection to retrieve full message bodies or attachments, bulk-import the inbox, mark messages read, move or delete messages, or automatically reply. Mailbox text is treated as untrusted content, and payment-card and authentication patterns are redacted before model processing.
VeriTech uses Google user data only to provide the prominent, user-facing mailbox features described above. When an authorized user requests mailbox analysis, VeriTech may send the connected mailbox address and the selected bounded metadata and snippets to OpenAI solely to generate the requested Merchant Agent response. VeriTech does not use Google user data to train general-purpose AI or machine-learning models. When a user approves and executes an email, VeriTech transmits the approved recipient, subject, and body to Gmail and to the chosen recipient as necessary to send that message.
OAuth access and refresh tokens are encrypted at rest. VeriTech stores the connected account identity, granted scopes, permission settings, connection status, and operational timestamps while the connection is active. Retrieved mailbox previews are not retained as a separate mailbox archive; however, the requested Agent response and a bounded subject-based evidence label may remain in the authorized user's Merchant Agent conversation history until that user deletes the conversation or history. An executed outbound message is retained as a tenant-scoped delivery and audit record under the Service's applicable retention practices.
Authorized users can disconnect the mailbox in Merchant Agent. Disconnecting deletes usable OAuth credentials from the connection and disables future read and send access, while content-free security and audit records may be retained. To revoke access at Google as well, the user can remove VeriTech POS from the Google Account's third-party connections. Users can also delete their Merchant Agent conversation history through the workspace or contact info@veritechpos.com for a privacy request.
VeriTech personnel do not read Google mailbox data except with the user's affirmative permission for specific data, when necessary for security or abuse investigation, when required by law, or when data is aggregated for permitted internal operations. VeriTech does not sell Google user data or use it for advertising, retargeting, surveillance, creditworthiness, lending, or unrelated purposes.
VeriTech's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
8. How We Disclose Information
We may disclose information to:
- hosting, infrastructure, database, and storage providers;
- payment and subscription billing providers;
- email and communications providers;
- AI and document-processing providers;
- analytics, logging, update, diagnostics, and security providers;
- app distribution and operating system providers;
- support contractors or professional advisers;
- vendors or merchants when you use vendor request or marketplace features;
- law enforcement, courts, regulators, or other parties when required by law or to protect rights, safety, and security;
- a buyer, successor, or assignee in connection with a merger, acquisition, financing, reorganization, or sale of assets.
We do not sell merchant customer data. We do not use merchant customer data for third-party targeted advertising.
9. Merchant Customer Data
If you are a customer of a merchant that uses VeriTech POS, the merchant controls the customer relationship and decides what information to enter into the Service. Contact the merchant directly for questions about a sale, receipt, refund, loyalty account, or merchant customer record.
VeriTech processes merchant customer data to provide the Service to the merchant, including receipts, sales records, inventory updates, reporting, support, security, and related functions.
10. Cookies and Similar Technologies
We may use cookies, local storage, session cookies, and similar technologies to:
- keep users signed in;
- secure sessions;
- remember preferences;
- support onboarding;
- analyze usage;
- improve performance;
- prevent abuse.
You may control cookies through browser settings, but disabling cookies may prevent parts of the Service from working.
11. Data Retention
We retain information for as long as reasonably necessary to provide the Service, maintain business records, comply with legal obligations, resolve disputes, enforce agreements, maintain security, support backups, and operate the platform.
Retention periods may vary depending on the type of data, account status, legal requirements, backup cycles, security needs, and merchant configuration.
After account termination, some information may remain in backups, logs, tax records, audit logs, legal records, security records, or archived systems for a limited period or as required by law.
12. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information. These may include access controls, encryption in transit, authentication, tenant separation, logging, monitoring, backup procedures, and security review.
No method of transmission, storage, or processing is completely secure. You are responsible for securing your own accounts, passwords, devices, local networks, printers, cash drawers, card terminals, operating systems, and staff access.
13. Your Choices and Rights
Depending on where you live and how you use the Service, you may have rights to:
- access personal information;
- correct inaccurate personal information;
- delete personal information;
- request a copy of personal information;
- opt out of certain marketing communications;
- limit certain processing;
- object to certain processing;
- appeal a privacy request decision where required by law.
To submit a privacy request, contact us at info@veritechpos.com. We may need to verify your identity and authority before fulfilling a request.
For merchant customer data, we may direct you to the merchant that controls the data.
14. California Privacy Notice
This section applies to California residents where applicable.
We may collect the categories of personal information described above, including identifiers, commercial information, internet or network activity, professional or employment-related information, geolocation approximated from IP address, and inferences related to Service use.
We collect this information for the business and commercial purposes described in this Privacy Policy.
We disclose personal information to service providers and other parties described in this Privacy Policy.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising unless we separately disclose that practice and provide legally required opt-out rights.
California residents may have the right to know, access, correct, delete, and opt out of certain uses of personal information, and the right not to be discriminated against for exercising privacy rights.
Submit requests to info@veritechpos.com.
15. Children
The Service is intended for businesses and authorized business users. It is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact us at info@veritechpos.com.
Merchants are responsible for complying with laws that apply to their own customers, including any laws related to minors, age-restricted products, and customer records.
16. International Users
The Service is operated from the United States. If you access the Service from outside the United States, you understand that information may be processed in the United States or other jurisdictions where we or our service providers operate.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The updated version will be posted on our website or made available through the Service. The effective date will indicate the latest version.
18. Contact
PNW Creative Labs, LLC — VeriTech POS
info@veritechpos.com
