Legal

Privacy Policy

How Sphereventory collects, uses, shares, and protects personal data across our website and multi-location operations platform.

Effective: 16 August 2026

Last updated: 16 August 2026

1. Introduction

This Privacy Policy explains how Sphereventory (“Sphereventory”, “we”, “us”, or “our”) collects, uses, discloses, and protects personal data when you visit our websites, create an account, or use our multi-location inventory, warehouse, POS, purchasing, credit, and finance software (the “Service”).

We designed Sphereventory for business customers. Depending on the context, we may act as a data controller (for our own marketing site, billing, and account administration) or as a data processor / service provider processing Customer Data on behalf of the tenant organisation that owns a workspace.

By using the Service, you acknowledge this Policy. If you do not agree, please discontinue use and contact us with any concerns.

2. Who this Policy covers

  • Website visitors and prospective customers who request demos, trials, or information.
  • Customer account owners, admins, and Users invited into a Sphereventory workspace.
  • Individuals whose information appears in Customer Data (for example end customers, suppliers, or staff records) — processed primarily under the Customer’s instructions and policies.

If you are an end customer of a Sphereventory merchant (for example a walk-in retail buyer), please contact that merchant for privacy requests about sales or credit records they hold. We will assist the merchant as required.

3. Personal data we collect

We may collect the following categories of personal data:

  • Identity and contact data: name, email, phone number, company name, job role, and messaging preferences.
  • Account and authentication data: login identifiers, password hashes, role assignments, location access, and security settings (such as MFA status).
  • Billing data: subscription plan, invoices, payment status, and limited payment-method metadata processed via payment providers (we do not store full card PAN data on our servers when using tokenised gateways).
  • Customer Data you upload or generate: products, inventory movements, sales/POS transactions, purchase orders, supplier and customer records, credit balances, journals, and related operational documents.
  • Usage and device data: IP address, browser/device type, approximate location derived from IP, pages viewed, feature usage, and diagnostic logs needed for security and reliability.
  • Support communications: messages, tickets, call notes, and attachments you send to support.
  • Cookies and similar technologies: essential cookies for session security; optional analytics cookies where enabled.

4. How we collect data

  • Directly from you when you sign up, configure settings, import data, or contact us.
  • Automatically through the Service (application logs, security monitoring, and product analytics).
  • From your organisation’s administrators when they invite Users or assign roles.
  • From payment, messaging, or hosting providers that support delivery of the Service.

5. Why we use personal data

We use personal data to:

  • Provide, operate, maintain, and secure the Service (including multi-tenant isolation and access control).
  • Create and administer workspaces, subscriptions, trials, demos, and billing.
  • Deliver transactional messages (receipts, password resets, security alerts, and service notices).
  • Provide customer support and investigate incidents or abuse.
  • Improve product performance, usability, and reliability using aggregated or de-identified insights where appropriate.
  • Comply with legal obligations and enforce our Terms of Service.
  • Send product or marketing communications where permitted (you may opt out of non-essential marketing).

7. Receipts, SMS, and transactional messaging

If you enable SMS, email, or similar messaging for receipts, credit reminders, password resets, or operational alerts, we (and our messaging providers) process the phone numbers, email addresses, and message content you instruct us to send.

You are responsible for obtaining any consents required from your end customers or staff before sending marketing or promotional messages. Transactional messages necessary to complete a purchase or secure an account may be sent as part of operating the Service.

8. How we share data

We do not sell personal data. We may share personal data with:

  • Infrastructure and subprocessors that host, store, email/SMS, monitor, or process payments for the Service under contractual confidentiality and security obligations.
  • Professional advisers (legal, accounting) under confidentiality where needed.
  • Authorities when required by law, court order, or to protect rights, safety, and security.
  • A successor entity in connection with a merger, acquisition, or asset transfer, subject to appropriate safeguards.

Customer workspaces are logically isolated. We do not use one tenant’s operational Customer Data to serve another tenant’s business.

9. International transfers

Sphereventory is operated from Ghana and may use cloud infrastructure or subprocessors in other countries. Where personal data is transferred internationally, we take steps designed to provide appropriate safeguards consistent with applicable law (such as contractual protections with providers).

10. Retention

We retain personal data only as long as needed for the purposes described in this Policy, including to provide the Service, resolve disputes, enforce agreements, and meet legal/accounting requirements.

Account and billing records are typically retained for the life of the Subscription plus a reasonable period thereafter. Operational Customer Data is retained while the workspace is active and for a limited post-termination export/wind-down window, unless a longer period is required by law or requested under a written agreement.

Security logs may be retained for a shorter period appropriate to threat detection and incident response.

11. Security measures

We implement technical and organisational measures appropriate to the risk, including authentication controls, role-based access, tenant scoping in application queries, encrypted transport (HTTPS), hashed passwords for portal logins, and operational monitoring.

No method of transmission or storage is perfectly secure. You are responsible for configuring User roles carefully, protecting devices used for POS/warehouse access, and promptly reporting suspected incidents to support.

12. Your rights

Depending on applicable law (including, where relevant, Ghana’s Data Protection Act, 2012), individuals may have rights to be informed, access, correct, delete, restrict, or object to certain processing, and to withdraw consent where processing is consent-based. You may also have the right to lodge a complaint with a supervisory authority such as the Data Protection Commission of Ghana.

Workspace Users should typically contact their organisation’s admin first for access or correction of workplace records. End customers of merchants should contact the merchant. You may also email us and we will route requests appropriately.

  • Email: support@sphereventory.com
  • Phone: +233 249397960
  • Location: Accra, Ghana

13. Children

The Service is intended for business use and is not directed to children under 16 (or the minimum age required in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided data, contact us and we will take appropriate steps.

14. Cookies and similar technologies

We use essential cookies to keep you signed in and protect sessions. We may use analytics technologies to understand product and website usage. Where required, we will request consent for non-essential cookies. You can control cookies through browser settings; disabling essential cookies may break login or core features.

Some browsers offer “Do Not Track” signals; because there is no uniform industry standard for responding to those signals, our Service may not respond to them in a particular way. You can still manage cookies as described above.

15. Marketing communications

We may send service-related messages without opt-in because they are necessary to operate your account. For promotional emails, you can unsubscribe using the link in the message or by contacting support. Opting out of marketing does not affect transactional or security notices.

16. Controller / processor roles

For Sphereventory marketing sites, billing identity, and our own CRM: Sphereventory acts as controller.

For Customer Data inside a tenant workspace (inventory, sales, customers, finance ledgers, etc.): the Customer is the controller and Sphereventory processes that data to provide the Service. Customers are responsible for their own privacy notices to end users and for lawful collection of that data.

17. Changes to this Policy

We may update this Privacy Policy periodically. We will post the revised version with a new “Last updated” date and, for material changes, provide additional notice where appropriate. Continued use of the Service after changes take effect constitutes acceptance where permitted by law.

18. Contact us

Privacy requests and questions: support@sphereventory.com · +233 249397960 · Accra, Ghana.

Please include enough detail for us to verify your identity and locate the relevant workspace or record.

Sphereventory

Accra, Ghana

Email: support@sphereventory.com · Phone: +233 249397960