Vibepay POS — Privacy Policy
Effective date: July 27, 2026
Last updated: July 27, 2026
Who this applies to
Vibepay POS is a point-of-sale terminal app used by merchant staff(cashiers and store admins) who process meal-benefit card payments for Vibepay-affiliated merchants in Mongolia. It is not intended for use by the general public and is not directed at children. This policy describes what the app itself collects and does with data — it does not cover Vibepay's employer or employee-facing surfaces, which are described separately.
Data we collect
Camera access
The app uses your device's camera to scan a cardholder's rotating payment QR code during a charge. Camera frames are processed on-device only, in real time, to detect and decode the QR code — no photo, video, or camera frame is ever stored, saved to your device's photo library, or transmitted anywhere. Once a QR code is decoded, only the decoded token string (a short-lived, single-use payment token, not an image) is sent to Vibepay's backend to process the charge.
Terminal credential
When a terminal is first paired, it is issued a device credential by a merchant admin (via the separate merchant dashboard). This credential is stored using your device's secure, OS-level credential storage (iOS Keychain / Android Keystore) and is used solely to authenticate the terminal's API requests to Vibepay. It identifies the terminal device, not an individual cashier or cardholder.
Transaction data
To process a charge or refund, the app sends the following to Vibepay's backend over an encrypted (HTTPS) connection:
- The charge amount you enter
- The decoded payment token (for QR-scan charges) or wallet/card charge amount (for a manually keyed charge, if applicable)
- The resulting transaction record (amount, status, timestamp), which the app also displays back to you in the Transactions tab
This data is Vibepay's transaction record of the payment and is retained according to Vibepay's standard transaction-record retention practices (including as required for Mongolian tax/VAT receipt compliance).
App preferences
Your selected display language (English/Mongolian) is stored locally on the device (not sent to our servers) so it persists between app launches.
Data we do NOT collect
- No location data
- No contacts, photos, or media library access beyond the transient camera use described above
- No advertising identifiers, and the app contains no advertising or third-party analytics SDKs
- No data is sold or shared with third parties for marketing purposes
Who can see this data
Transaction and terminal data is visible to:
- Vibepay (to operate the payment platform, issue VAT receipts, and provide support)
- The merchant that owns the paired terminal (via the merchant dashboard)
It is not shared with any other third party except as required to process the payment itself (e.g. Vibepay's banking/payment-rail partners) or as required by Mongolian law (e.g. tax authority reporting via the VAT receipt system).
Data security
All network communication uses HTTPS/TLS encryption. The terminal credential is stored using platform-native secure storage (Keychain on iOS, Keystore on Android), not in plain text.
Your rights
You may request access to, correction of, or deletion of data associated with your merchant account, subject to Vibepay's transaction-record retention obligations under Mongolian tax and financial-services law. To make a request, contact us using the details below.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
Contact
Questions about this policy: info@vibepay.mn