We stand with Palestine🍉

InventXInventX
Legal

Privacy Policy

Plain-English detail on what personal data InventX collects, why, who we share it with, and the rights you have over it — for the POS platform and for this website.
Effective date
19 August 2026
Applies to
pos.inventx.app · pos.inventx.app
Questions
legal@pos.inventx.app

01Who we are and what this policy covers

This Privacy Policy explains how InventX, a software business operated from Sri Lanka (“InventX”, “we”, “us”) collects, uses, shares and protects personal data in connection with:

  • the InventX POS & inventory platform — the web application at pos.inventx.app, its API and the emails it sends (together, the “Service”); and
  • this marketing website at pos.inventx.app (the “Site”).

Our digital studio website at inventx.apphas its own privacy policy. Where you use the Service through an employer or business that holds the account, that business is the “Customer” and you are a “User”. People whose details a Customer records in the Service — shoppers, suppliers, drivers — are “End Customers”.

We process personal data in accordance with the Sri Lanka Personal Data Protection Act No. 9 of 2022 (the “PDPA”) and, where it applies to people in the European Economic Area or United Kingdom, the GDPR and UK GDPR.

02Controller or processor: our two roles

The Service is multi-tenant software. We wear two hats, and it matters which one applies to a given piece of data:

DataOur roleWhat that means
Account and User data — staff names, usernames, emails, phone numbers, login activity, permissions; Customer business details; billing and support correspondence; Site analytics.ControllerWe decide why and how this data is processed, as described in this policy.
Customer Data — everything a Customer and its Users enter into the Service about End Customers and the business: customer and supplier records, invoices, payments (including cheque details), delivery orders, notes, expenses, stock.ProcessorThe Customer is the controller. We process Customer Data only to provide the Service on the Customer’s instructions, as set out in our Terms & Conditions. If you are an End Customer with a question about your data, please contact the business you dealt with first; we will help them respond.

03Personal data we collect

Data you or your business give us

  • Account registration. Accounts are created from an invitation (registration token) issued to a Customer. We collect your first and last name, email address, mobile number, a username and a password. Passwords are stored only as a salted bcrypt hash — we cannot read them.
  • Business profile. Business name, address, business email, contact number, trading currency, receipt footer text, and notification, printer and security settings (including whether the business-wide lockdown switch is enabled).
  • Locations and staff.Store names, addresses and contact numbers; which Users may access which locations; the permissions each User holds and which actions require a manager’s one-time code.
  • Customer Data (as processor). End Customer and supplier names, email addresses, phone numbers and postal addresses; invoices and line items; recorded payments including, for cheques, the bank, branch, account-holder name and cheque number; delivery orders including driver name and vehicle; free-text notes; expenses (which may include salary entries).
  • Billing and support. Invoices we issue for paid plans, bank-transfer references, and anything you send us by email or through a demo request on the Site.

Data collected automatically

  • Activity log.For accountability, the Service records who performed which action on which record and when (for example “created invoice INV-2041”). The activity log does not store IP addresses or device identifiers.
  • Session and security data. Session identifiers, last-login time, one-time codes and password-reset tokens (all short-lived), and whether an account is locked.
  • Connection data. Our hosting and security provider (Cloudflare) processes your IP address, browser user agent, requested URLs and timestamps to deliver the Service and Site and to block abuse. Our API servers keep short-term request logs for operations and security.
  • Error and performance monitoring. The web application sends error reports and performance traces to Sentry, hosted in the European Union. Reports include your user ID, username and email (so we can follow up on a failure), your IP address, browser details, and the sequence of screens that led to the error. A sample of sessions (currently one in ten, and every session in which an error occurs) is also captured as a session replay — a reconstruction of what was on screen — which may include Customer Data you were viewing or typing at the time. Replays are used solely to diagnose defects and are accessible only to our engineering team.
  • Site analytics (Site only, with your consent). The Site currently loads no analytics service. If you enable analytics in the cookie banner, your choice is remembered so that a privacy-respecting analytics service (page-view counts and page performance) may later be loaded for consenting visitors only; this policy and the cookie details will be updated before any such service is introduced.

Data we do not collect

The Service never asks for or stores payment-card numbers, CVV codes or bank-account credentials. “Card” in the Service is a bookkeeping label for a payment taken on your own terminal. We do not collect national identity numbers, dates of birth, precise location or biometric data, and we do not buy data about you from third parties.

04How we use personal data and our lawful bases

PurposeLawful basis
Providing the Service: authenticating Users, enforcing permissions and location scoping, recording sales, stock, transfers and deliveries, generating invoices and reports.Performance of our contract with the Customer; for Customer Data, the Customer’s instructions.
Sending transactional email: one-time codes for password resets and manager approvals, password-change confirmations, account invitations, and — when the Customer has switched it on and the End Customer has an email address on file — invoice receipts to End Customers.Contract; legitimate interest in securing accounts; for End Customer receipts, the Customer’s instructions.
Keeping an activity log of who did what, and offering a business-wide lockdown that signs every User out.Legitimate interests of the Customer and of InventX in security, fraud prevention and accountability.
Detecting, investigating and fixing defects and outages (including Sentry error reports and sampled session replays).Legitimate interest in running a reliable service. You may ask us to exclude your account from replay sampling — see Your rights.
Billing paid plans, collecting payment, and keeping accounting records.Contract; legal obligation (tax and accounting law).
Responding to support, demo and sales enquiries, and telling existing Customers about material changes to the Service or these terms.Contract or steps before a contract; legitimate interest in communicating with Customers.
Measuring how the Site is used.Consent, given through the cookie banner.
Protecting our rights, complying with the law, and responding to lawful requests from authorities.Legal obligation; legitimate interests.

We do not sell personal data, use it for advertising, or make decisions about you by automated means that have legal or similarly significant effects.

05Cookies and on-device storage

We keep cookies to the minimum the Service needs. There are no advertising or cross-site tracking cookies on the Site or in the Service.

On the Site (pos.inventx.app)

NameTypePurposeLifetime
inventx_cookie_consentStrictly necessaryRemembers whether you accepted or declined optional analytics, so we do not ask again.180 days
Analytics (none at present)Analytics (optional)No analytics service is currently loaded. Your opt-in is stored so a privacy-respecting service may later run for consenting visitors only.No cookie set

You can change your choice at any time via the Cookies link in the footer, which reopens the preferences dialog.

In the Service (pos.inventx.app)

NameTypePurposeLifetime
authTokenStrictly necessary cookie (HttpOnly)Keeps you signed in. Contains a signed session token; it is not readable by scripts.45 minutes, extended while you are active; 15 minutes for platform administrators
sidebar_statePreference cookieRemembers whether the sidebar is expanded.7 days
inventx-theme, table page sizes, column visibility, last-selected location, “what’s new” dismissalsLocal storage (preferences)Interface preferences kept on your device.Until cleared
invoice-holds*, InventXDrafts (IndexedDB)Local storage (functional)Keeps held and draft invoices — including the selected customer’s name and line items — on the device so they survive a refresh or crash.Until the hold is completed or cleared

Because held invoices live on the device, Customers should sign out and clear the browser’s site data before handing a shared terminal to someone who should not see them.

06Who we share data with

We share personal data only with the service providers below, each bound by contract to process it solely for us, and with others only where this policy says so or the law requires.

ProviderPurposeLocation
Cloudflare, Inc.Hosting and content delivery for the Site and web application, DDoS protection, TLS, edge request logs.Global edge network
Our infrastructure providerVirtual servers on which we run the API and MongoDB databases that hold account data and Customer Data. Each Customer’s data is held in its own database.Provider data centre; may be outside Sri Lanka
Microsoft Ireland Operations Ltd (Microsoft 365)Sending transactional email from support@pos.inventx.app, billing@pos.inventx.app and hello@pos.inventx.app, and hosting the mailboxes that receive your enquiries.EU / global
Armitage Labs OÜ (Creem)Merchant of record for paid plans: hosted checkout, card storage, subscription billing, invoices and refunds. We receive the subscription status, plan and the billing email; we never receive card numbers.European Union (Estonia)
Our SMS gateway providers (SMSGo, Text.lk)Delivering the Service’s text messages: invoice and payment notifications to End Customers, and approval codes to administrators. They receive the mobile number, the message text and our sender ID. Text messages are only available to Customers in Sri Lanka.Sri Lanka
Functional Software, Inc. (Sentry)Error monitoring, performance tracing and session replay.European Union (Germany)

We may also disclose personal data:

  • to the Customer that holds your account (for example, the activity log shows administrators what each User did);
  • to anyone holding a public invoice link — see the next section;
  • to professional advisers, auditors, insurers and payment providers where necessary;
  • to courts, regulators and law-enforcement bodies where we are legally required to, or to protect the rights, safety or property of InventX, our Customers or others;
  • to a successor if InventX is reorganised, merged or acquired — we will tell you before your data becomes subject to a different privacy policy.

07Public invoice links and receipts

Users can share an invoice as a public web page at pos.inventx.app/i/… and, where enabled, the Service emails a receipt to the End Customer. You should know that:

  • the link is long and unguessable, but anyone who has it can open the page without signing in;
  • the page shows the business name and contact details, the End Customer’s name and contact details, the items, amounts and payment status, and the name of the staff member who issued the invoice;
  • links do not currently expire or get revoked when an invoice is cancelled (a cancelled invoice is shown with a cancellation notice).

Customers are responsible for sharing links only with the people entitled to see them and for obtaining any consent needed to email receipts or text End Customers.

Where a Customer is in Sri Lanka and has the relevant switches on, the Service also sends End Customers a text message when an invoice is raised, a payment is recorded, items are returned or an invoice is cancelled. The text is sent to the mobile number the Customer holds for that End Customer and carries the business name, the invoice number, the amounts and the public invoice link. Users and End Customers can be excluded from these messages in the Service, and the same gateways deliver the one-time approval codes we send to administrators’ mobile numbers.

08International transfers

We operate from Sri Lanka, and some of our providers store or access data in other countries, including the European Union and the United States. Where personal data leaves the country in which it was collected, we rely on the provider’s standard contractual data-protection terms, on adequacy arrangements where available, and on technical measures such as encryption in transit. You can ask us for more detail about the safeguards that apply to a particular transfer.

09How long we keep data

  • Account data and Customer Dataare kept for as long as the Customer’s account exists. When an account is closed or a subscription ends, we keep the data — so that the Customer can return to it or request an export — until the Customer asks us to delete it. On a verified deletion request we delete or irreversibly anonymise the data within 30 days, except for invoices and accounting records we must retain under tax and company law, which are kept for the statutory period and then deleted.
  • Held and draft invoices stay only on the device that created them.
  • One-time codes and reset tokens expire after 10 minutes (codes) or one hour (reset links) and are cleared once used.
  • Error reports and session replays are retained by Sentry for 90 days.
  • Edge and API request logs are kept for short, rolling periods for security and troubleshooting.
  • Enquiry and support email is kept while the matter is open and for a reasonable period afterwards, typically no more than 24 months after our last exchange unless you become a Customer.

10How we protect data

We apply technical and organisational measures proportionate to the risk, including:

  • passwords hashed with bcrypt; we never store them in clear;
  • HttpOnly session cookies with short sliding expiry and a single active session per User — a new sign-in signs the previous device out;
  • granular, location-scoped permissions, one-time-code approval for sensitive actions, and an activity log;
  • a business-wide lockdown switch that instantly signs out every User of a Customer;
  • TLS for all traffic, HSTS and related hardening headers on the API, and per-Customer database isolation;
  • access to production systems limited to named InventX staff.

No system is perfectly secure. If we learn of a personal-data breach that is likely to harm you, we will notify the affected Customer and, where required, the Data Protection Authority of Sri Lanka or another competent regulator, without undue delay. See also our security overview.

11Your rights

Subject to the conditions in the PDPA and, where applicable, the GDPR or UK GDPR, you have the right to:

  • access the personal data we hold about you and receive a copy;
  • rectify inaccurate or incomplete data — Users can edit their own profile in the Service;
  • erase your data, or have it anonymised, where we no longer need it;
  • restrict or object to processing based on legitimate interests, including asking us to exclude your account from session-replay sampling;
  • withdraw consent at any time where consent is the basis (for example, Site analytics — use the Cookies link in the footer);
  • data portability — receive the data you provided in a structured, machine-readable format. Customers may request an export of their Customer Data at any time;
  • complain to the Data Protection Authority of Sri Lanka or, if you are in the EEA or UK, to your local supervisory authority. We would appreciate the chance to address your concern first.

To exercise a right, email legal@pos.inventx.appfrom the address linked to your account, or have your Customer’s administrator contact us. We may need to verify your identity. We respond within one month, or within any shorter period the law requires, and will tell you if we need longer for a complex request. There is no fee unless a request is manifestly unfounded or excessive.

If you are an End Customer, the business you dealt with controls your data; please contact them directly. We will assist them in responding to you.

12Children

The Service and Site are intended for businesses and their adult staff. We do not knowingly collect personal data from anyone under 18 as a User. Customers may, of course, record a minor as an End Customer where their own law permits, in which case they are the controller of that data.

13Changes to this policy

We will update this policy as the Service evolves — for example when we add new integrations or providers. Material changes will be announced to Customers by email or an in-app notice before they take effect, and the effective date at the top of this page will change. Continued use after that date means the revised policy applies.

14Contact us

InventX
Privacy and legal: legal@pos.inventx.app
General and support: hello@pos.inventx.app
Postal address: Sri Lanka — available on request by email.