Terms & Conditions
Last updated: 23/06/2026
These Terms & Conditions (“Terms”) govern access to and use of the VoraPlex platform (“Platform”), operated by VoraPlex (“Operator”). By creating an account, accessing or using the Platform, the User confirms they have read, understood and accepted these Terms.
Contents
- 1. Scope and acceptance
- 2. Definitions
- 3. Account, registration and credentials (PIN/Password)
- 4. Loyalty program: points, benefits and rewards
- 5. Merchant (Store) obligations and responsibilities
- 6. Plans, billing and payments (Merchants)
- 7. Fraud prevention, corrections and audit
- 8. Data protection, privacy and communications
- 9. SMS Communications
- 10. Intellectual property
- 11. Availability, changes and maintenance
- 12. Disclaimers and limitation of liability
- 13. Dispute resolution and governing law
- 14. Contact
1. Scope and acceptance
1.1. The Platform provides loyalty features (e.g., points, rewards, campaigns, analytics and operational tools) for participating Merchants (Stores) and registered Customers.
1.2. The Operator provides a technology service. The sale of goods/services, issuance of invoices/receipts and compliance with consumer and tax laws are the sole responsibility of the Merchant.
1.3. The User must have legal capacity to accept these Terms. Where applicable, use by minors requires consent from a legal guardian.
2. Definitions
- Customer: a person who registers to participate in loyalty programs offered by Merchants.
- Merchant/Store: a business that configures loyalty rules (points/rewards) and uses the Platform for operations.
- Operator: the entity operating the Platform and providing the technology service.
- Points: promotional units granted under Merchant-defined rules; they are not money.
- Reward: a benefit defined by the Merchant (e.g., discount, product, experience), redeemable under applicable rules.
3. Account, registration and credentials (PIN/Password)
3.1. To create an account, Customers provide minimum data (e.g., name and phone). Merchants may request additional data for operational needs and legal obligations.
3.2. Authentication may use:
- PIN: typically 4 digits (0-9); or
- Password: an alphanumeric string subject to Platform/Merchant requirements.
3.3. Users must keep credentials confidential and are responsible for all activity under their account. Any unauthorized use must be reported immediately.
3.4. For security reasons, the Operator and/or Merchant may require resets, additional verification or temporarily suspend access where there is a reasonable suspicion.
3.5. Phone number change: if the Customer changes their phone number, they must immediately update it at a participating VoraPlex Store or contact VoraPlex directly by email at voraplex@voraplex.com. VoraPlex and participating Stores accept no responsibility for misuse of the account, unauthorised access, loss of points, rewards or any other damages resulting from failure to update the phone number in a timely manner. Responsibility for the update lies entirely with the Customer.
4. Loyalty program: points, benefits and rewards
4.1. Accrual and redemption rules are defined by each Merchant (e.g., accrual rate, limits, exclusions, campaigns, expiry, quotas and time windows).
4.2. Points:
- are not money, have no legal tender status, do not accrue interest and are not a deposit, e-money or financial instrument;
- are non-transferable unless expressly allowed by the Merchant;
- may be reversed/adjusted in cases of refunds, chargebacks, logging errors or fraud.
4.3. Reward redemption may require in-person validation (e.g., POS/operator) and/or security mechanisms (e.g., dynamic code/QR, identity check, phone verification).
4.4. Merchants may change program rules. Where applicable, material changes should be communicated with reasonable notice. Changes may apply to future Points unless otherwise required by law or fraud prevention.
4.5. In addition to counter registration, the Merchant may allow the Customer to earn points by scanning the receipt's fiscal QR code. Each receipt may only be used once and within a limited time window; daily limits and other anti-fraud rules may apply. Issuing the receipt and tax compliance are the Merchant's responsibility; the award of Points is merely promotional.
4.5. Reward availability is the Merchant’s responsibility. If unavailable, the Merchant may offer an equivalent alternative, reschedule or cancel redemption in line with its policies and applicable law.
5. Merchant (Store) obligations and responsibilities
5.1. Merchants represent they are entitled to operate loyalty programs and will comply with all applicable laws (consumer, advertising, tax, GDPR, electronic communications, etc.).
5.2. Merchants are responsible for: clear rules; proper staff training; correct logs and validations; truthful customer communications; and billing/support in compliance with law.
5.3. Prohibited: bypassing counters/limits; entering false data; accessing Customer accounts without legal basis; and using the Platform for spam, phishing or deceptive practices.
6. Plans, billing and payments (Merchants)
6.1. Merchant access to the Platform requires a subscription plan, billed monthly or annually. Available plans are as follows (prices in euros, excluding VAT; VAT at the applicable legal rate — 23% in Portugal — is added to the stated amounts):
| Plan | Customers | Excl. VAT | Incl. VAT 23% |
|---|---|---|---|
| Google Business | 0–501+ | 77.00 € | 94.71 € |
| Start | 0–250 | 77.00 € | 94.71 € |
| Growth | 251–1000 | 99.00 € | 121.77 € |
| Pro | 1001–5000 | 149.00 € | 183.27 € |
| Enterprise | 5001–501+ | On request | |
Current prices are always those shown in the Store Guide and in the registration confirmation email. The confirmation email is proof of the price accepted at the time of sign-up. On the annual plan, the amount corresponds to ten monthly payments (equivalent to two months free), unless stated otherwise in the Store Guide.
6.2. Activation upon payment: Commercial plans do not include a free period. The Merchant selects a plan and makes the first Stripe payment during signup; the account, access and services are only created and activated after payment is confirmed. Without an active subscription, only the area required to start or regularize the subscription remains available. Internal free plans and VIP Offers expressly granted by the Operator do not require payment while that condition remains in effect. When a VIP Offer ends, the Merchant must start a paid subscription to retain or regain access.
6.2.1. 30-day satisfaction guarantee: Each Merchant’s first paid subscription benefits from a 30-calendar-day money-back guarantee, counted from the first payment. Within that period, the Merchant may cancel and request a full refund of that first payment by emailing voraplex@voraplex.com; the refund is made to the original payment method. The guarantee does not apply to renewals, plan changes, SMS or other extras and may not be used more than once by the same Merchant, account holder, tax number or business. Cancellation immediately blocks access under clause 6.4, and billing will be adjusted by a corrective document where applicable.
6.3. Payment and invoicing: The subscription is paid by card, through the payment processor Stripe. Card details are entered and processed directly by Stripe in a secure environment and are not stored by the Operator. For each charge, the Operator issues an invoice-receipt through a certified invoicing system, sent to the billing email provided by the Merchant. The Merchant is responsible for keeping the VAT number and billing email up to date.
6.4. Renewal and cancellation: The subscription renews automatically at the end of each period (monthly or annual). The Merchant may cancel at any time through the subscription management portal. Voluntary cancellation takes effect immediately: future charges stop and Merchant access is blocked at once. Operational data is retained for 90 days and may only be accessed by the Operator/super administrator for support or export after the administration credentials have been rotated. Outside the guarantee provided in clause 6.2.1, no refunds are given for partial periods unless otherwise required by law.
6.5. Automatic plan upgrade: The Merchant's subscription plan is automatically adjusted based on the number of active registered customers, in accordance with the limits defined in the table above. When the number of enrolled customers exceeds the maximum of the current plan, the Merchant automatically moves to the next higher plan, and the new price (incl. VAT) applies at the next renewal. This transition requires no prior notice from the Operator. The Merchant may also, at any time, upgrade manually on the subscription page, in which case the prorated difference is charged immediately. By accepting these Terms, the Merchant expressly accepts automatic plan upgrades and the corresponding prices shown in the table above.
6.6. Non-payment: If a renewal charge fails (for example, a declined card or insufficient funds), a 45-day regularisation period begins. During this period, the Merchant keeps full functionality, no data is deleted, and repeated notices are sent to update the payment method and settle in full every amount outstanding since the last successful payment. If the debt remains after 45 days, access is immediately suspended, the Stripe subscription is terminated to prevent new monthly charges, and the administration credentials are changed, with the new credential reserved for the Operator/super administrator. Operational data is then retained for a further 90 days, during which the Merchant may settle the full debt and recover access. If payment is not regularised by the end of that second period, operational data is securely deleted, without affecting records that must be retained by law, including tax, accounting or security records.
7. Fraud prevention, corrections and audit
7.1. Anti-fraud measures may be applied to protect Customers, Merchants and the Operator (e.g., period limits, additional verification, logs, temporary blocks and manual reviews).
7.2. The Operator may correct obvious logging errors (duplicates, incompatible values, technical incidents) and maintain an audit trail where possible.
7.3. If fraud is suspected, the Operator and/or Merchant may suspend accounts, reverse Points/Rewards, require verification and, where appropriate, report to competent authorities.
8. Data protection, privacy and communications
8.1. Personal data processing is governed by applicable law (including GDPR) and the Platform’s Privacy Policy and Cookie Policy.
8.2. As a rule, the Merchant acts as Data Controller for its loyalty program; the Operator acts as Processor when processing data on the Merchant’s behalf, under a DPA where applicable.
8.3. The Operator may use sub-processors (e.g., hosting, communications, technical analytics) with appropriate contractual safeguards. International transfers may occur under legally required mechanisms.
8.4. The Platform may send transactional/operational messages (e.g., confirmations and security alerts). Marketing communications require a lawful basis/consent where applicable.
8.5. The Operator implements appropriate security measures; however, no system is 100% secure. Incident handling follows applicable legal requirements.
8-A. Data Processing Agreement (DPA — Article 28 GDPR)
This section constitutes the Data Processing Agreement required by Article 28 of Regulation (EU) 2016/679 (GDPR), entered into between the Merchant (Data Controller) and the Operator VoraPlex (Data Processor). By completing registration on the Platform, the Merchant expressly accepts the terms of this Agreement; the date, time and IP address of acceptance are recorded.
8-A.1. Subject matter and duration
The Processor processes personal data on behalf of the Controller solely for the purpose of providing the loyalty services described in these Terms, for the duration of the contractual relationship and, after termination, for the minimum period required by law.
8-A.2. Nature, purpose and categories of data
Purposes: operating the loyalty programme (points accrual and redemption, authentication, transactional communications); aggregate usage analysis; fraud prevention. Data categories: name, phone number (E.164), transaction history, consents and preferences, registration IP and timestamp, authentication credentials (hash). Data subjects: end customers registered in the Merchant's loyalty programme.
8-A.3. Controller instructions
The Processor processes data only on the documented instructions of the Controller — including configuration of Platform features — and informs the Controller without undue delay if it considers that an instruction infringes the GDPR or other applicable law.
8-A.4. Confidentiality
The Processor ensures that persons authorised to process personal data are bound by a confidentiality commitment or are subject to an equivalent statutory duty.
8-A.5. Security
The Processor applies technical and organisational measures appropriate to the risk, including: credential encryption (bcrypt), role-based access control, audit logging and regular backups. Any personal data breach is notified to the Controller without undue delay, with the information necessary to comply with Articles 33 and 34 GDPR.
8-A.6. Sub-processors
The Processor may engage sub-processors, including: hosting/infrastructure provider (EU or with an adequate transfer mechanism), SMSAPI (SMS delivery) and a transactional email service. The Merchant grants general authorisation to use these sub-processors, to whom the Processor imposes equivalent data protection obligations. Material changes are communicated to the Merchant, who may object on reasonable grounds.
8-A.7. Data subject rights
The Processor assists the Controller in fulfilling data subject rights under Articles 15–22 GDPR (access, rectification, erasure, portability, restriction and objection) through the features available on the Platform.
8-A.8. DPIA and prior consultation
The Processor provides reasonable assistance with data protection impact assessments (DPIAs) and, where applicable, prior consultation with the supervisory authority, taking into account the nature of the processing and the information available.
8-A.9. Return and deletion of data
Upon termination of services, the Processor, at the Controller's request and subject to any legal retention obligation, provides data in a common structured format (CSV/JSON) and proceeds to its secure deletion within 90 days.
8-A.10. Audit
The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations of Article 28 GDPR and contributes to audits conducted by the Controller or an auditor mandated by the Controller, subject to reasonable prior notice and a confidentiality agreement.
9. SMS Communications
9.1. The Platform provides Merchants with the ability to send SMS messages to their registered Customers. Sending is handled through the provider SMSAPI (a sub-processor), subject to a data processing agreement.
9.2. Each monthly subscription includes 10 SMS for customer communications. The quota does not accumulate from month to month — it resets on the 1st of each month. Merchants may purchase additional SMS as needed.
9.3. The Customer's phone number is used solely for: (a) identity verification by OTP at registration; and (b) receiving communications from the Store where they enrolled.
9.4. Verification SMS (OTP) are operational and security communications — they do not require marketing consent. Campaign and promotional SMS sent by the Merchant require an appropriate legal basis (e.g., consent or prior relationship).
9.5. Consent to receive marketing SMS is optional. The Customer may enable or disable it at any time from the customer area or by contacting the Store where they enrolled. Requests sent to the Store must be processed without undue delay.
10. Intellectual property
10.1. The Platform (software, design, trademarks and content) is owned by the Operator and/or licensors and is protected by intellectual property laws.
10.2. Reverse engineering, copying, reproduction, distribution or exploitation of the Platform without authorization is prohibited, except where permitted by law or written consent.
11. Availability, changes and maintenance
10.1. The Operator aims for appropriate availability and performance and may perform maintenance, updates and fixes. Interruptions may occur due to technical reasons, security, force majeure or third-party dependencies (hosting, networks, etc.).
10.2. The Operator may modify or discontinue features for technical, legal, security or product reasons, seeking to minimize impact and provide reasonable notice when possible.
10.3. The Operator may update these Terms for legal, technical, security or commercial reasons. The current version is the one published on this page. Where changes are material, reasonable efforts will be made to notify via suitable channels (e.g., in-app notice, email).
10.4. Users may stop using the Platform at any time. The Operator may suspend or terminate access for breach of these Terms, security risk, legal obligation or non-payment (Merchants), without prejudice to record retention required by law.
10.5. Upon Merchant request and where technically feasible, data exports in common formats may be provided, subject to security, privacy and legal constraints.
12. Disclaimers and limitation of liability
11.1. The Platform is provided “as is” and “as available”. The Operator does not guarantee uninterrupted or error-free service or fitness for a particular purpose, without prejudice to mandatory legal warranties.
11.2. The Operator is not responsible for: Merchant business decisions; Merchant product/service quality; Merchant legal/tax compliance; or third-party failures (networks, devices, gateways).
11.3. To the maximum extent permitted by law, the Operator’s liability for direct damages is limited to the amounts paid by the Merchant in the 3 months prior to the event giving rise to liability. Indirect damages (lost profits, loss of opportunity, data loss, reputational damage) are excluded unless prohibited by law.
11.4. Nothing in these Terms excludes liability for willful misconduct, gross negligence or non-waivable rights under applicable law (including consumer rights where applicable).
13. Dispute resolution and governing law
12.1. These Terms are governed by Portuguese law, without prejudice to mandatory consumer protection rules where applicable.
12.2. For consumer disputes in Portugal, consumers may use Alternative Dispute Resolution (ADR/RAL) entities. Info: meiosral.justica.gov.pt and consumidor.gov.pt.
12.3. The electronic complaints book is available at www.livroreclamacoes.pt.
12.4. For disputes not settled out of court, the courts of the Operator’s registered office shall have jurisdiction, unless mandatory rules provide otherwise.
14. Contact
For questions about these Terms, security or privacy:
- Email: voraplex@voraplex.com
- Entity: VoraPlex – Liliana Isabel Marques Dores
- Tax ID (NIF): PT226400115
- Address: Av. São Lourenço da Barrosã, Apartamento 201, 8500-510 Portimão, Portugal
- Phone: +351 964 857 666
Automatic Mode and security
In the event of unusual use, abuse or suspected fraud, the store or VoraPlex may immediately suspend earning and redemption without prior notice while checks take place. A store suspension applies only to that store programme. In Manual Mode, redemption is validated with the customer PIN provided by the customer.