The short version: we collect what we need to run your account and the platform. We do not sell your personal information and we do not use your business records for advertising. Business data you enter about your customers, suppliers, and employees belongs to you — we process it on your instructions. You can access, export, correct, or delete your information; see Your rights.
1. Scope and who we are
Pomanager, Metro Manila, Philippines, operates Pomanager (pomanager.net) — a business operations platform for purchasing, sales, inventory, payroll, and related workflows, used by businesses worldwide.
This policy explains how we handle personal information across our websites, web and mobile applications, and related services. It applies to visitors to our site, people who register accounts, users invited into a customer's workspace, and people whose details appear in data our customers process through the platform.
Our use of cookies and similar technologies is described in the Cookie Policy.
2. Controller or processor — which one we are
Our role differs depending on the data, and this determines who you should contact.
| Data | Our role | What that means |
|---|---|---|
| Account, billing, support, marketing and website data — the information you give us to have an account with us | Controller | We decide why and how it is processed. Exercise your rights with us directly. |
| Customer Data — the records our customers enter into their workspace, including details of their own customers, suppliers, contacts, and employees | Processor | We process it only on the customer's instructions. The customer is the controller. If your details are in a business's Pomanager workspace, contact that business; we will refer your request to them. |
Where we act as processor, our Data Processing Addendum governs the processing and forms part of our contract with the customer.
3. Information we collect
3.1 You give us
- Account and profile: name, work email, phone, password, company name, role, country, time zone, profile photo.
- Company and tax details: business name, addresses, registration and tax identifiers, branch structure.
- Billing: plan, billing contact, billing address, transaction history, and the last four digits and type of your payment card. Full card numbers are handled by our payment providers and never reach our systems.
- Support and communications: messages you send us, chat content, attachments, and inbound email to our platform addresses.
- Customer Data: everything you enter or upload into your workspace — purchase orders, quotations, invoices, delivery receipts, item catalogues, price lists, inventory, marketplace listings and orders, production records, employee and payroll records, documents, and images.
3.2 Collected automatically
- Device and connection: IP address, browser type and version, operating system, device identifiers, language, referring page.
- Usage: pages viewed, features used, actions taken, timestamps, login times and last-seen status, error and performance logs.
- Security: authentication events, session and remember-me tokens, and, where your employer has enabled office-network restriction, the network address you connect from — used to allow or deny access.
- Approximate location derived from IP address, for security, fraud prevention, tax determination, and localisation. We do not collect precise GPS location.
- Cookies and similar technologies as described in the Cookie Policy.
3.3 From others
- From your employer or the account owner, if you were invited as a user: your name, work contact details, role, and permissions.
- From connected businesses on the platform, when they send you documents naming you or your colleagues.
- From payment providers: transaction status, fraud signals, and limited billing details.
- From service providers for security, spam filtering, and email delivery status.
3.4 Sensitive information
We do not seek sensitive or special-category personal data for our own purposes. Where a customer uses the payroll and employee modules, the records they enter may include government identifiers and statutory contribution numbers. We process that data only as a processor, on the customer's instructions. Customers are responsible for having a lawful basis and for meeting any additional local requirements before entering such data.
4. How we use information
- Create and administer accounts, authenticate users, and enforce permissions.
- Provide the features you use, including the B2B network, marketplace, chat, and AI-assisted functions.
- Process subscriptions, payments, invoices, taxes, refunds, and dunning.
- Provide support and respond to your requests.
- Send service communications — confirmations, security alerts, billing notices, and changes to terms. These are not marketing and you cannot opt out of them while you hold an account.
- Send product news, onboarding sequences, and offers, where you have opted in or where permitted by law. Unsubscribe at any time.
- Monitor, debug, secure, and improve the platform, including analysing usage in aggregate.
- Detect, investigate, and prevent fraud, abuse, and security incidents, and enforce our terms.
- Comply with legal obligations and establish, exercise, or defend legal claims.
What we do not do: we do not sell personal information, we do not share it for cross-context behavioural advertising, we do not use Customer Data to build advertising profiles, and we do not permit our AI providers to train their general models on your content.
5. Legal bases (EEA and UK)
Where the GDPR or UK GDPR applies and we act as controller, we rely on:
| Purpose | Legal basis |
|---|---|
| Providing the Service and administering your account | Performance of a contract (Art. 6(1)(b)) |
| Billing, collections, and tax records | Contract; legal obligation (Art. 6(1)(b), (c)) |
| Security, fraud prevention, service improvement, aggregate analytics, direct marketing to business contacts | Legitimate interests (Art. 6(1)(f)) — balanced against your rights |
| Non-essential cookies and analytics, and marketing where consent is required | Consent (Art. 6(1)(a)) — withdrawable at any time |
| Retaining records and responding to lawful requests | Legal obligation (Art. 6(1)(c)) |
6. AI processing
Some features send content you submit to third-party AI providers so they can generate a result — for example, parsing an emailed purchase order into a draft, transcribing and interpreting a spoken order, counting items in a photo, or matching item names.
- What is sent: only the content needed for that request — the document, message text, image, or transcript, plus limited context such as your item names for matching.
- Who processes it: Anthropic, OpenAI, and Google (see Sub-processors). Processing happens on their infrastructure, which may be outside your country.
- Training: our agreements with these providers prohibit using your content to train their general models.
- Retention: providers may retain content briefly for abuse monitoring under their own terms, then delete it. We retain the input and the result in your workspace as part of your records.
- No automated decisions with legal effect: AI output is a draft for a human to review. We do not use it to make decisions producing legal or similarly significant effects about anyone.
7. Sharing through the B2B network
Pomanager's core feature is that connected businesses exchange documents directly. When you send a purchase order, quotation, invoice, delivery receipt, or marketplace order to a connected company, the contents — including the names, email addresses, phone numbers, and delivery addresses that appear on the document — are delivered into that company's workspace, where they control their copy.
This is a disclosure between two independent controllers. Deleting a document in your workspace does not delete the counterparty's copy, and we cannot recall it. Before transmitting, make sure you have a lawful basis to disclose the personal data on the document to that counterparty.
8. Who else we share with
- Users in your workspace: your name, contact details, and activity are visible to others in your company according to the permissions the account owner sets.
- Service providers (sub-processors): under contract, only to provide the Service. Listed below.
- Payment providers: to take payment and meet financial and tax obligations.
- Professional advisers: lawyers, auditors, accountants and insurers, under confidentiality.
- Authorities: where required by valid legal process or to protect rights, safety, or property. We assess requests, push back on overbroad ones, and, where lawful, notify the affected customer.
- Corporate transactions: in a merger, acquisition, financing, or sale of assets, subject to this policy continuing to apply. We will notify you of any change of controller.
We do not disclose personal information to third parties for their own marketing.
9. Sub-processors
We use the following categories of provider. Each is bound by contract to appropriate confidentiality and security obligations.
| Provider | Purpose | Primary location |
|---|---|---|
| Hostinger | Application and database hosting | EU / global |
| Cloudflare | CDN, DNS, DDoS protection, bot and abuse mitigation | Global edge network |
| Mailgun (Sinch) | Transactional and inbound email | EU / US |
| Paddle | Merchant of record, payments, tax, invoicing | UK / EU |
| PayPal | Payments | Global |
| PayMongo | Payments (Philippines) | Philippines |
| Anthropic | AI processing — document parsing, extraction, vision, assistance | United States |
| OpenAI | AI processing — document and email parsing | United States |
| Google Cloud | Vision / OCR processing | United States / global |
The current list is maintained here. To be notified of additions before they take effect, email privacy@pomanager.net and ask to join the sub-processor notification list.
10. International transfers
Pomanager is operated from the Philippines and serves customers worldwide, so personal information may be transferred to and processed in countries other than your own — including the Philippines, the United States, and the European Union — which may not provide the same level of protection as your home country.
Where we transfer personal data out of the EEA, the UK, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards, principally the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where relevant, plus supplementary technical and organisational measures. Request a copy of the safeguards for a specific transfer at privacy@pomanager.net.
11. How long we keep it
| Category | Retention |
|---|---|
| Account and profile data | For the life of the account, then deleted or anonymised within 90 days of closure |
| Customer Data in your workspace | For the life of the account; retrievable for 30 days after termination, then deleted |
| Billing, invoices, and tax records | As required by tax and accounting law, typically up to 10 years |
| Security, access, and audit logs | Typically 12 months |
| Support correspondence | Up to 3 years after the matter closes |
| Marketing contact records | Until you unsubscribe, plus a suppression record so we do not contact you again |
| Backups | Deleted data persists in encrypted backups until they expire on the ordinary rotation cycle |
We may keep information longer where needed to resolve disputes, enforce agreements, or comply with law.
12. Security
We take technical and organisational measures appropriate to the risk, including:
- encryption in transit using TLS for traffic to and from the platform;
- logical isolation of each company's data, enforced at the query layer on every request;
- role-based access controls, per-page permission gating, and optional restriction of employee access to your office network or working hours;
- protection against common web attacks, including parameterised database queries and cross-site request forgery tokens on state-changing actions;
- a CDN and security layer that mitigates denial-of-service and automated abuse;
- validation and scanning of uploaded files, with private storage and authenticated download;
- access to production systems limited to personnel who need it, with logging;
- routine backups.
No system is perfectly secure. You are responsible for using a strong, unique password, protecting your credentials, managing your users' permissions, and removing access promptly when someone leaves. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities as required by applicable law and within the deadlines it sets.
Report a vulnerability or a suspected incident to security@pomanager.net. We do not pursue legal action against good-faith researchers who report responsibly and do not access other people's data.
13. Your rights
Subject to your local law, you may have the right to:
- Access the personal information we hold about you and get a copy;
- Correct inaccurate or incomplete information;
- Delete your information, where no overriding obligation or legitimate ground applies;
- Port your data in a structured, machine-readable format, or have it transmitted to another provider where technically feasible;
- Restrict or object to processing, including profiling and processing based on legitimate interests;
- Withdraw consent at any time, without affecting processing already carried out;
- Opt out of marketing at any time;
- Not be discriminated against for exercising these rights;
- Complain to your data protection authority.
How to exercise them
Much of this is self-service: update your profile, export your data, and manage notification settings inside the app. Otherwise email privacy@pomanager.net with the request and enough detail to identify your records. We will verify your identity — usually by confirming control of the email on the account — and respond within 30 days, extending once by a further 60 days for complex requests with notice to you. There is no charge unless a request is manifestly unfounded or excessive.
An authorised agent may submit a request on your behalf with written proof of authority. If your information sits in a customer's workspace, we will forward your request to that customer, who is the controller.
14. EEA, UK and Swiss notice
If you are in the EEA, the UK, or Switzerland, the GDPR or UK GDPR gives you the rights in section 13. You may lodge a complaint with your national supervisory authority — in the UK, the Information Commissioner's Office; in Switzerland, the Federal Data Protection and Information Commissioner — though we ask that you contact us first so we can try to resolve the matter.
We do not currently have an establishment in the EEA or UK. If we are required to appoint an Article 27 representative, their details will be published here.
15. US state privacy notice
This section applies to residents of California, Virginia, Colorado, Connecticut, Utah, Texas, and other states with comparable laws.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding 12 months, including with respect to minors under 16.
Categories collected in the last 12 months, using CCPA terminology: identifiers; customer records; commercial information; internet and network activity; approximate geolocation; professional or employment information; and inferences drawn for product improvement. Sources, purposes, and disclosure recipients are described in sections 3, 4, 8, and 9. Retention is in section 11.
California residents may request access, correction, deletion, and details of the categories collected, used, and disclosed, and may limit the use of sensitive personal information — although we do not use sensitive personal information for any purpose that triggers that right. Residents of states with an appeal right may appeal a refused request by replying to our decision; if the appeal is denied we will tell you how to contact your Attorney General.
Submit requests to privacy@pomanager.net. Where we handle personal information on behalf of a business customer, we act as a service provider or processor and will direct your request to that customer.
16. Philippines notice
As a company operating from the Philippines we comply with the Data Privacy Act of 2012 (RA 10173), its implementing rules, and issuances of the National Privacy Commission. You have the rights to be informed, to object, to access, to rectification, to erasure or blocking, to damages, and to data portability, and the right to lodge a complaint with the National Privacy Commission.
Our Data Protection Officer can be reached at dpo@pomanager.net or at the address in section 20.
17. Other regions
We honour equivalent rights for users covered by other data protection laws, including Brazil's LGPD, Canada's PIPEDA, Australia's Privacy Act, Singapore's PDPA, India's DPDP Act, and comparable regimes. Contact us and we will apply the rights available to you under your local law.
18. Cookies and tracking
We use strictly necessary cookies to keep you logged in and to protect against cross-site request forgery, plus optional functional and analytics cookies where you consent. Full detail, including how to manage your choices, is in the Cookie Policy. We do not currently respond to browser Do Not Track signals; we do honour Global Privacy Control signals where legally required.
19. Children's data
Pomanager is a business tool intended for people aged 18 and over. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact privacy@pomanager.net and we will delete it.
20. Changes to this policy
We may update this policy. The revised version will be posted here with a new "Last updated" date. For material changes we will give notice by email or in-app before they take effect, and where the law requires it we will seek your consent.
21. Contact and complaints
Pomanager
Metro Manila, Philippines
- Privacy requests: privacy@pomanager.net
- Data Protection Officer: dpo@pomanager.net
- Security: security@pomanager.net
- General support: support@pomanager.net
If you are not satisfied with our response, you may complain to your local data protection authority. We would appreciate the chance to address it first.