PDPA
Singapore Personal Data Protection Act.
Seven straight answers to "what do you do with my data?" — sourced from our internal data-use policy, not marketing copy.
Receipts (line items, totals, taxes, timestamps), items and variants, categories, shifts, stores, and employees (id + display name only). Strictly read-only via Loyverse's public REST API. By design, we process sales data for only the single outlet you select at signup — no other outlet's receipts are ingested.
Customer records and contact PII (names, phones, emails) — we never ingest them; only an opaque customer id may appear on a receipt. Payment-card data (Stripe handles that — we never see it), Loyverse account settings, and anything outside the documented receipts/items/employees scope.
Supabase Postgres in Singapore (ap-southeast-1). Every row is tagged with your tenant ID and protected by Postgres Row-Level Security — isolation is enforced at the database layer, not just the application layer. Even our internal queries are tenant-scoped.
Only authenticated users on your account see your data in the product. For support and debugging, our internal admin tooling can query data across accounts (the only role that bypasses Row-Level Security); these privileged actions are written to an audit log. We do not sell or share your data, and we never mix it with another business's.
TLS 1.3 in transit (HSTS enabled, HTTP redirects to HTTPS). AES-256 at rest (Supabase default). Your Loyverse connection credential — an OAuth refresh token, or a Personal Access Token if you paste one — is encrypted with a separate key before being stored.
Delete your account from your Profile page ('Delete account'). After a 30-day recovery grace period, all your data — raw receipts, derived insights, audit logs — is purged. After deletion we keep only a hashed, non-identifying record that a given Loyverse account used its free trial, retained for fraud prevention (it contains no sales data and cannot be reversed to identify you). Export anytime via 'Export my data' on your Profile page. Business customers can request a Data Processing Agreement by emailing [email protected].
VentaLens is operated by SKANDAN PTE. LTD. (UEN 202621966R), a Singapore-incorporated company. For privacy or data-handling questions, email [email protected].
Singapore Personal Data Protection Act.
EU General Data Protection Regulation.
Top-10 web application security risks.
Strict transport security on every page.
Email us — we handle DPA requests from business customers.
Connect Loyverse in 60 seconds. No credit card, cancel any time.