Privacy Notice - DIGO CONNECT

Effective date: October 7, 2026  •  Version: 4.0

Privacy scope. This Notice explains DIGO CONNECT’s public privacy practices for a business POS/SaaS service. It distinguishes information processed on a business customer’s instructions from information DIGO CONNECT handles for its own account, security, support, and legal purposes. It intentionally avoids promising security or retention controls that have not been fully implemented and verified.

Contents

  1. 1. Who DIGO CONNECT Is
  2. 2. Scope of this Notice
  3. 3. Our Privacy Roles
  4. 4. Categories of Information We May Process
  5. 5. Data Minimization and Sensitive Information
  6. 6. Sources of Information
  7. 7. Purposes for Processing
  8. 8. Business and Legal Purposes
  9. 9. Account and User Information
  10. 10. Employee and Business-User Information
  11. 11. Customer Contact and Account Information
  12. 12. Transaction, Inventory, and Audit Information
  13. 13. Shipping, Rentals, Layaways, Credits, and Special Orders
  14. 14. Photos and Operational Evidence
  15. 15. Device, Session, Security, and Log Data
  16. 16. Support Communications
  17. 17. Payment Information and Square
  18. 18. Cookies, Sessions, and Similar Technologies
  19. 19. Service Providers and Subprocessors
  20. 20. Hosting, Cloud, and Storage
  21. 21. Communications and Notifications
  22. 22. When We Disclose Information
  23. 23. No Sale of Customer Personal Data; No Unrelated Targeted Advertising
  24. 24. Cross-Border Processing
  25. 25. Retention
  26. 26. Backups
  27. 27. Deletion, De-Identification, and Legal Holds
  28. 28. Customer Termination and Data Return
  29. 29. Privacy Rights
  30. 30. Texas Privacy Rights Where Applicable
  31. 31. How to Submit a Privacy Request
  32. 32. Appeals and Applicable Request Procedures
  33. 33. Security
  34. 34. Security Incidents and Data Breaches
  35. 35. Children
  36. 36. Third-Party Links and Services
  37. 37. Changes to this Privacy Notice
  38. 38. Contact

1. Who DIGO CONNECT Is

DIGO CONNECT is point-of-sale and business-management software operated by a Mexico-based independent software provider under the DIGO CONNECT name. The service is provided to business customers that use DIGO CONNECT to manage retail and operational workflows.

This Privacy Notice explains how DIGO CONNECT handles personal information in connection with the service. It does not describe the independent privacy practices of a business customer, Square, or another third party.

2. Scope of this Notice

This Notice applies to personal information processed by DIGO CONNECT when operating, securing, supporting, administering, or improving the DIGO CONNECT service and when handling support or account communications.

It does not apply to third-party websites, payment processors, or services that publish their own privacy notices, except to explain how DIGO CONNECT may interact with them.

3. Our Privacy Roles

DIGO CONNECT may act in different privacy roles depending on the information and purpose:

The business customer generally determines the business purpose for Customer Data it enters into the POS.

4. Categories of Information We May Process

Depending on configuration and use, DIGO CONNECT may process:

5. Data Minimization and Sensitive Information

DIGO CONNECT is designed to support business operations, not unrestricted collection of personal information. Business customers and users should collect only information that is adequate, relevant, and reasonably necessary for the intended business purpose.

DIGO CONNECT does not require government-issued identification by default merely because a database or future workflow could technically support additional fields. Users should not upload or enter Social Security numbers, full payment-card data, medical information, government IDs, biometric identifiers, or other highly sensitive information unless a specific lawful and approved business workflow expressly requires it.

6. Sources of Information

Information may be received from the business customer, its authorized users, customers of the business customer, connected devices, payment processors, integrations, uploaded files or photos, support communications, and records generated through use of the service.

7. Purposes for Processing

DIGO CONNECT may process information to:

8. Business and Legal Purposes

DIGO CONNECT processes information only for legitimate service, business, security, support, contractual, or legal purposes connected to operating DIGO CONNECT or fulfilling documented customer instructions. We do not repurpose Customer Data for unrelated consumer profiling or advertising.

9. Account and User Information

User accounts may include a name or identifier, username, role, branch/location assignment, account status, and authentication-related information. DIGO CONNECT may record login, session, administrative, and audit events for security and accountability.

10. Employee and Business-User Information

When employees or other personnel use the POS, DIGO CONNECT may process role, shift, activity, transaction responsibility, timesheet-related information where enabled, and audit records. The business customer is responsible for its own employment notices, workplace policies, and lawful use of employee information.

Employment-related information may be subject to legal rules different from consumer privacy rights.

11. Customer Contact and Account Information

When enabled by the business customer, DIGO CONNECT may process customer names, telephone numbers, email addresses, addresses, date of birth for membership/birthday functions, account balances, credit information, purchase history, notes, and related account records.

The business customer determines whether these fields are necessary for its operations and is responsible for using them lawfully.

12. Transaction, Inventory, and Audit Information

The service may process sales, line items, prices, discounts, taxes, payment-method classifications, returns, cancellations, credits, inventory movements, products, supplier/purchase information, transfers, and audit history. These records may be associated with employees, customers, branches, or transaction references when needed for business operation and accountability.

13. Shipping, Rentals, Layaways, Credits, and Special Orders

Operational workflows may require additional information such as recipient name, telephone number, shipping address, carrier/tracking information, rental details, return status, layaway balances, credit payments, special-order information, or related notes. DIGO CONNECT processes these records to provide the customer-requested workflow and maintain appropriate business history.

14. Photos and Operational Evidence

Authorized users may upload product images, shipment evidence, or other operational photos. Users should avoid capturing unnecessary people, government documents, payment cards, precise location information, or other sensitive content that is not necessary for the business purpose.

Uploaded images may contain metadata created by the originating device. DIGO CONNECT does not promise that all metadata is automatically removed unless and until that control is specifically implemented and documented.

15. Device, Session, Security, and Log Data

DIGO CONNECT may process browser/session identifiers, timestamps, authentication events, user/activity records, application errors, audit logs, security events, and technical request information that is reasonably necessary to operate, troubleshoot, defend, and audit the service.

We do not publicly disclose detailed defensive configurations, credentials, network architecture, or security procedures that could increase security risk.

16. Support Communications

If a customer or user requests support, DIGO CONNECT may process the contact information, screenshots, descriptions, files, logs, transaction references, or other information reasonably necessary to investigate and resolve the request. Users should redact unrelated sensitive information before sending support materials when practical.

17. Payment Information and Square

Card payments may be processed by Square or another separately contracted payment processor. DIGO CONNECT may receive limited payment metadata such as amount, status, payment method, date/time, processor identifier, terminal/checkout reference, or information necessary for reconciliation, support, audit, and permitted refund workflows.

DIGO CONNECT is not designed to store full payment-card numbers, CVV/CVC values, PIN data, magnetic-stripe/track data, or equivalent sensitive authentication data. Payment processors independently control their own collection, security, retention, and legal obligations under their published terms and privacy notices.

18. Cookies, Sessions, and Similar Technologies

DIGO CONNECT may use technically necessary cookies, session identifiers, local browser state, or similar mechanisms to maintain authentication, preferences, security, CSRF protection, and application state. These technologies are used for service operation and security and are not used by DIGO CONNECT for unrelated behavioral advertising based on POS Customer Data.

19. Service Providers and Subprocessors

DIGO CONNECT may use service providers or subprocessors for functions such as hosting, infrastructure, cloud/storage, communications, security, backup, monitoring, support, or payment integrations. They receive information only as reasonably necessary for the function they perform and are subject to their own legal and contractual obligations.

A current contractual subprocessor register may be maintained for business customers where required by agreement or applicable law. Internal infrastructure details that would create security risk are not necessarily published in this Notice.

20. Hosting, Cloud, and Storage

Customer Data may be hosted or stored using third-party infrastructure providers selected to operate the service. Hosting architecture may change over time as DIGO CONNECT migrates or improves infrastructure. We use reasonable measures to restrict unauthorized access to production data, but we do not represent that every category of data is encrypted at rest unless specifically verified and documented.

21. Communications and Notifications

If messaging, email, SMS, WhatsApp, Telegram, or another notification service is used for an enabled business workflow, only information reasonably necessary for that notification should be transmitted. A business customer is responsible for obtaining any consent required for marketing or customer communications it initiates.

DIGO CONNECT does not treat a customer’s communication opt-in as permission for unrelated advertising by DIGO CONNECT.

22. When We Disclose Information

DIGO CONNECT may disclose information:

23. No Sale of Customer Personal Data; No Unrelated Targeted Advertising

DIGO CONNECT does not sell Customer Data for monetary or other valuable consideration and does not use POS Customer Data for unrelated targeted advertising. If these practices materially change, this Notice will be updated and legally required disclosures or choices will be provided before the new practice is used where required.

24. Cross-Border Processing

DIGO CONNECT is operated from Mexico, while business customers and service providers may be located in the United States or other countries. Information may therefore be processed across national borders as needed to provide, host, support, secure, or administer the service.

Where applicable law requires specific safeguards for an international transfer, DIGO CONNECT and the relevant business customer or provider will address those requirements through appropriate contractual or operational measures.

25. Retention

DIGO CONNECT retains information only for as long as reasonably necessary for the purpose for which it is processed, including service operation, accounting, tax, audit, security, support, contractual, dispute, legal-hold, or other legitimate requirements.

Retention periods vary by record type and legal or contractual need. This Notice intentionally does not promise a universal fixed deletion period that the current system cannot operationally guarantee.

26. Backups

Data may exist in backups used for continuity and recovery. Deleting an item from the active service may not immediately remove every backup copy. Backup copies may remain until they are overwritten, expire, or are removed under the applicable backup lifecycle.

DIGO CONNECT does not publicly claim that every backup copy is encrypted or stored off-site unless that control has been implemented and verified.

27. Deletion, De-Identification, and Legal Holds

When information is no longer reasonably required, it may be deleted, de-identified, archived where lawfully necessary, or allowed to expire under applicable procedures. Deletion may be delayed by legal holds, tax/accounting obligations, fraud/security investigations, unresolved disputes, backup lifecycle, or other lawful requirements.

28. Customer Termination and Data Return

When a business customer’s service ends, data return, export, retention, and deletion are governed by the signed customer agreement, technical feasibility, applicable law, and documented retention procedures. A reasonable export opportunity may be provided where required by contract or law.

29. Privacy Rights

Depending on applicable law and DIGO CONNECT’s role for the specific information, individuals may have rights to confirm processing, access information, correct inaccuracies, request deletion, obtain a portable copy, or opt out of certain processing such as a sale of personal data, targeted advertising, or qualifying profiling.

These rights are not identical in every jurisdiction and may be subject to exceptions. Describing a possible right in this Notice does not expand a law that otherwise does not apply.

30. Texas Privacy Rights Where Applicable

Where the Texas Data Privacy and Security Act (“TDPSA”) applies to DIGO CONNECT in a controller role, eligible Texas consumers may have rights including confirmation/access, correction, deletion, portability, and opt-out rights for qualifying targeted advertising, sale, or profiling.

DIGO CONNECT currently does not sell Customer Data or use POS Customer Data for unrelated targeted advertising. The TDPSA contains exemptions and role-specific rules, including a general small-business exemption subject to specific restrictions. DIGO CONNECT will evaluate requests and obligations based on the facts and law applicable at the time.

31. How to Submit a Privacy Request

When a business customer collected the information and determines its business purpose, a person should ordinarily direct the request to that business customer. DIGO CONNECT will reasonably assist the customer when required by law or contract.

For information for which DIGO CONNECT acts independently as a controller, requests may be submitted through the published DIGO CONNECT support channel. We may request information reasonably necessary to verify identity, authority, account relationship, and the scope of the request before taking action.

32. Appeals and Applicable Request Procedures

If applicable law requires an appeal process for a denied privacy request, DIGO CONNECT will provide the applicable instructions when responding to the request. Response timing, free-request limits, appeal procedures, and regulator complaint rights depend on the law that applies to the particular request.

33. Security

DIGO CONNECT uses reasonable administrative, technical, and organizational safeguards appropriate to the nature of the service and information involved. Current controls may include authenticated access, role restrictions, session controls, CSRF protections, password hashing, validation of certain uploads, audit/logging mechanisms, and encrypted network transport where configured.

No method of transmission, storage, or security can guarantee absolute protection. DIGO CONNECT does not claim certifications, universal encryption at rest, MFA, continuous 24/7 monitoring, or other controls unless they have been specifically implemented and verified.

34. Security Incidents and Data Breaches

DIGO CONNECT maintains an incident-response process for suspected or confirmed security events. Actions may include investigation, containment, preservation of relevant evidence, credential or token changes where appropriate, recovery, and customer/legal assessment.

If a security incident triggers a legal or contractual notification obligation, DIGO CONNECT and the affected business customer will evaluate and perform applicable notification duties based on the facts, roles, affected individuals, and governing law. Nothing in this Notice shortens or extends a statutory deadline.

35. Children

DIGO CONNECT is business software and is not directed to children for independent consumer use. Business customers should not knowingly use DIGO CONNECT to collect personal information from children in a manner that violates applicable law.

A birthday or date-of-birth field used for an ordinary retail membership does not by itself make DIGO CONNECT a child-directed service.

DIGO CONNECT may link to or interoperate with third-party services. Those services are responsible for their own terms, privacy notices, security practices, and data handling. Users should review third-party notices before providing information directly to those services.

37. Changes to this Privacy Notice

We may update this Notice to reflect changes in law, service functionality, business practices, providers, or data processing. The current version will identify its effective date and version number. Material changes may be communicated through reasonable service or customer channels where appropriate or legally required.

38. Contact

DIGO CONNECT
POS & business management software
Website: digoconnect.com
Privacy / Customer Support via WhatsApp: +1 682-210-7165

DIGO CONNECT is operated from Mexico. The U.S. support telephone number is a customer-support number and does not represent a U.S. office, headquarters, or physical establishment.


DIGO CONNECT - Public Privacy Notice - Version 4.0.