Privacy Policy
Effective date: 29/01/2026 · Contact: voraplex@voraplex.com · Entity: VoraPlex – Liliana Isabel Marques Dores · Tax ID: PT226400115 · Address: Av. São Lourenço da Barrosã, Apt. 201, 8500-510 Portimão, Portugal · Phone: +351 964 857 666
1. Scope
This Privacy Policy explains how VoraPlex (the “Platform”) processes personal data in the context of the website, the access areas (SuperAdmin, ProAdmin, Store Admins and Operators) and the loyalty services made available to participating merchants (“Stores”).
2. Roles and responsibilities (GDPR)
- Stores’ end-customer data (points/rewards programmes): as a rule, the Store is the Data Controller, and VoraPlex acts as a Data Processor, processing data on the Store’s behalf and under its instructions, pursuant to a data processing agreement.
- Platform user data (management accounts, billing, support and security): VoraPlex generally acts as the Data Controller.
If, in any scenario, the Store and VoraPlex jointly determine essential purposes and means, they may act as joint controllers. In such cases, the applicable terms will be defined and made available.
3. Categories of data that may be processed
Depending on how the service is used, the following types of data may be processed:
- Identification and contact: name, phone number, email, language, and other data provided voluntarily.
- Account and authentication: login identifiers, access role/profile, session history, tokens and audit logs.
- Loyalty programme transactional data: recorded purchases, points earned, redemptions, rewards, stamps, limits and campaign rules.
- Receipt scanning (optional): when the Customer scans a receipt's fiscal QR code to earn points, the camera is used only on the device to read the code; the receipt photo/image is not stored or uploaded. Only the QR fields (issuer tax ID, document number, date and total) are processed to award points and prevent duplicate use.
- Preferences and communications: contact preferences, messages sent/received via the Platform, support requests.
- Billing and compliance: billing details, VAT/Tax ID, billing address (where applicable), payment history and related documents.
- Technical and security data: IP address, device/browser identifiers, error logs, performance metrics, anti-fraud measures.
- Feedback and ratings: comments, ratings and replies submitted through feedback features.
The Platform is not intended to collect special categories of data (e.g., health, religion, biometric data). If a Store uploads such data on its own initiative, it remains responsible for ensuring a lawful basis and the safeguards required by law.
4. Data sources
- Data provided directly by the person (e.g., registration, contacting support, joining a loyalty programme).
- Data entered by the Store (e.g., customer enrolment, recording purchases and redemptions).
- Data generated through service use (e.g., logs, audit, metrics, anti-fraud).
5. Purposes and legal bases
Personal data may be processed for:
- Service delivery and contract performance (Art. 6(1)(b) GDPR): creating and managing accounts, running loyalty programmes, validating redemptions, sending operational communications.
- Legitimate interests (Art. 6(1)(f) GDPR): security, fraud prevention, auditing, service improvement, aggregated statistics, establishing or defending legal claims.
- Legal obligations (Art. 6(1)(c) GDPR): accounting/tax obligations and responding to lawful requests.
- Consent (Art. 6(1)(a) GDPR), where applicable: direct marketing, non-essential cookies, promotional communications beyond what is strictly necessary.
Where the Store is the Data Controller, the Store is responsible for defining and communicating the applicable legal basis for its customers’ data, including marketing communications and segmentation.
6. Sharing and recipients
Data may be shared, as necessary and with safeguards, with:
- Stores (to manage their programme and customer relationship).
- Infrastructure sub-processors (e.g., hosting, transactional email, backups, security monitoring), bound by confidentiality and data protection terms.
- SMSAPI — SMS delivery provider used for OTP verification at registration and for Store communication campaigns. Customers’ phone numbers are transmitted to SMSAPI solely for the delivery of messages authorised by the Store. SMSAPI is subject to a data processing agreement.
- Stripe — payment processor used to charge Stores' subscriptions by card. Card details are entered and processed directly by Stripe, in a secure environment, and are not stored by VoraPlex. Only the data necessary for the charge is transmitted to Stripe (e.g., store identifier, billing email and amount). Stripe acts as a payment service provider subject to its own terms and privacy policy.
- KeyInvoice — certified invoicing system used to issue the invoice-receipts for subscriptions. The Store's billing data is processed (name/legal name, VAT number, billing email and amounts) to comply with tax and accounting obligations.
- Providers selected by the Store (e.g., additional communication channels), when integrated at the Store’s initiative.
- Public authorities, where required by law or to protect rights.
VoraPlex does not sell personal data and does not allow third parties to use data for their own marketing purposes without an appropriate legal basis.
7. International transfers
Data is preferably processed and hosted within the European Economic Area. If operational needs require transfers outside the EEA, appropriate safeguards will be used (e.g., Standard Contractual Clauses and supplementary measures where required).
8. Retention
Data is kept only for as long as necessary for the purposes described and in accordance with legal retention periods. Examples:
- Account and security logs: for the duration of the account and for an additional reasonable period for auditing and fraud prevention.
- Loyalty programme data: while the programme is active and according to the Store’s instructions (where VoraPlex acts as processor).
- Billing and accounting records: for the period required by applicable tax/accounting law.
Where technically and legally possible, data will be deleted or anonymised at the end of the applicable period.
9. Security
VoraPlex implements technical and organisational measures appropriate to the risk, including, where applicable: role-based access control (need-to-know), audit logging, encryption in transit, backups, logical segregation per Store, monitoring, and vulnerability management processes. No measure fully eliminates risk; security is treated as a continuous process.
10. Personal data breaches
In the event of a security incident affecting personal data:
- Where VoraPlex acts as Controller, notification duties towards the competent authority and, where required, affected individuals will be assessed and fulfilled.
- Where VoraPlex acts as Processor, the relevant Store will be informed without undue delay, with available information to support incident management.
11. Automated decisions and profiling
The Platform may apply automated rules for technical operations (e.g., fraud pattern detection, rate limiting on login attempts, consistency checks). VoraPlex does not intend to carry out solely automated decisions that produce legal effects or similarly significantly affect an individual without an appropriate legal basis and safeguards.
12. Data subject rights
Under the GDPR, individuals may request access, rectification, erasure, restriction, portability, objection, and may withdraw consent (where applicable). To exercise rights:
- For a Store’s customer data: requests should be addressed first to the relevant Store (Controller). VoraPlex will support the Store, as processor, in handling the request.
- For Platform account/support/billing data: requests may be sent to VoraPlex at voraplex@voraplex.com.
Identity verification may be requested to prevent improper disclosures. There is also the right to lodge a complaint with the competent supervisory authority. In Portugal, the authority is the CNPD (Comissão Nacional de Proteção de Dados).
13. Cookies and similar technologies
The website and Platform may use essential cookies (e.g., session, authentication, language preferences) and, when enabled, analytics/measurement cookies. Cookie choices (where applicable) are managed via browser settings and/or a consent manager if provided.
14. Communications
Operational communications may be sent (e.g., security alerts, service notices, confirmations, OTP verification codes). Promotional communications are sent only where there is an appropriate legal basis (e.g., consent or a permitted prior relationship) and with an option to opt out.
SMS communications: Stores may send SMS messages to their Customers for marketing or informational purposes. Each Store includes up to 10 SMS per month in their subscription; unused quota does not carry over. Consent to receive marketing SMS is optional: the Customer may enable or disable it at any time from the customer area or by contacting the Store. OTP verification SMS are security communications and do not require marketing consent.
15. Children
The Platform is not intended for children under 16 without the authorisation and supervision of a parent or guardian. If improper processing is suspected, measures will be taken to remove data and mitigate risk.
16. Third-party links and integrations
The Platform may integrate with or link to third-party services (e.g., hosting, email, communications, analytics), enabled according to configuration. Each third party may apply its own policies. Where applicable, contractual safeguards and/or consent options will be put in place.
17. Changes to this Policy
VoraPlex may update this Policy to reflect legal, technical or operational changes. The version published on the website is the one currently in force.
18. Contact
For privacy questions or data-related requests: voraplex@voraplex.com.
Receipts, tax IDs and retention
The account is identified by phone number. VoraPlex does not request, store, compare or use customer tax IDs to validate receipts. It processes only the minimum document data and issuer tax ID. Images, where used, are deleted after the configured strictly necessary period; only minimum security, audit and history records remain.