Effective date: September 3, 2026
OrderPOS (the "App") is a business tool for cafe and store owners and staff to receive, prepare, and hand over customer orders and to manage store operations data. It is not a consumer app; its users are owners or staff belonging to a store.
SangLimSoft (the "Company") complies with the Personal Information Protection Act of Korea and related laws.
1. Personal information processed
The App handles two different kinds of information, and the Company's role differs for each.
a. Information about App users (owners and staff) — processed by the Company as the processor
- Account information: email address, authentication session token
- Store membership: store identifier, role (owner / manager / staff), active status
- Device information: push notification token (FCM), platform (iOS), app version
- Operational records: POS connectivity check records, the operator identifier on order status change history
b. Information about the store's customers — held by the store and processed by the Company on the store's behalf
The App displays the information below in order to process orders the store has received. The data subject is the store's customer and the collecting party is the store. The Company only stores and delivers this information on the store's behalf.
- Information the customer entered when ordering: name (or nickname), phone number, request note
- Order details: order number, ordered items and options, amount, order status and timestamps
c. Information the App does not collect
The App does not collect location data, contacts, photos, advertising identifiers (IDFA), cookies, or behavioral data, and it does not embed advertising SDKs or user behavior analytics SDKs.
2. Purpose of processing
- Identifying staff and maintaining login state
- Providing store operations features such as accepting, preparing, handing over, cancelling, and refunding orders
- Sending a push notification when a new order arrives
- Managing store operations data such as inventory, partners, and sales
- Checking POS device connectivity and reporting outages
3. Retention and use period
- Account information: until the staff member's use at the store ends
- Push notification token: deactivated immediately on logout; tokens that are no longer valid (for example after the app is deleted) are deactivated automatically at send time
- Information stored on the device (notification sound setting, order commands queued for sending): deleted when the app is deleted. A queued command contains only the order identifier and the target status, and includes no customer personal information
- Store customers' order information: follows the store's retention policy and the periods required by law (under the Act on Consumer Protection in Electronic Commerce: records of contracts and withdrawal of subscription 5 years, records of payment and supply of goods 5 years, records of consumer complaints and dispute handling 3 years)
4. Outsourcing of personal information processing
The Company outsources processing as follows in order to operate the service. Processors may not process personal information for any purpose beyond the outsourced purpose under their contracts.
- Supabase, Inc. (United States): database and authentication infrastructure
- Google LLC (United States): push notification delivery (Firebase Cloud Messaging)
- Apple Inc. (United States): push notification delivery to iOS devices (APNs)
5. Transfer of personal information overseas
All processors above operate servers in the United States.
- Supabase, Inc. (United States): user account information, store operations data, order information — for database and authentication purposes — retained per Section 3
- Google LLC (United States): push notification token, notification title and body (order number, customer name, item count, amount) — for push delivery — not retained after delivery
- Apple Inc. (United States): push notification token, notification title and body — for delivery to iOS devices — not retained after delivery
6. Provision to third parties
The Company does not provide or sell personal information to third parties without the user's consent, except where required by law.
7. Destruction
When the retention period expires or the purpose of processing is achieved, information is destroyed without delay; electronic files are deleted by means that make recovery impossible.
8. Rights of users and how to exercise them
Users may at any time request access to, correction of, deletion of, or suspension of processing of their personal information. Requests sent to the contact below are answered within 10 business days.
If a store's customer wishes to exercise rights over their order information, the controller of that information is the store that received the order, so please contact that store first. The Company supports any measures the store requests.
9. App permissions
- Notifications (optional): used to alert staff when a new order arrives. If denied, every other feature of the App remains usable and the order list still refreshes in real time while the App is open.
10. Security measures
- All communication is encrypted with HTTPS/TLS
- Row Level Security is applied in the database so each user can access only the data of the store they belong to
- Processing that crosses a trust boundary — order status transitions, refunds, inventory changes — is re-verified on the server rather than trusting client-supplied values
- Server-only credentials are never bundled into the App
- A push notification token can be registered or removed only by its own account
11. Children under 14
The App is a business tool for store operators and is not directed at children under the age of 14.
12. Personal information protection officer
- Officer: SangLimSoft Personal Information Protection Officer
- Email: service.help@outlook.kr
- Hours: weekdays 09:00 – 18:00 (excluding public holidays)
Reports and consultations regarding personal information infringement may be directed to the following Korean agencies.
- Personal Information Infringement Report Center: privacy.kisa.or.kr / 118
- Personal Information Dispute Mediation Committee: kopico.go.kr / 1833-6972
- Supreme Prosecutors' Office Cyber Investigation Division: spo.go.kr / 1301
- National Police Agency Cyber Bureau: ecrm.cyber.go.kr / 182
13. Changes to this policy
This policy may be revised in line with changes to laws or the service. Any change will be announced on the App's settings screen and on this page.
This policy takes effect on September 3, 2026.