Last updated: March 2026
1. Introduction
InvSpot ("we", "us", "our") operates the InvSpot platform, a cloud-based software-as-a-service (SaaS) solution for cost management and data analytics in the food and beverage industry. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our website (invspot.com), use our platform, or interact with us in any way.
We are committed to complying with the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong and other applicable data protection laws. By using our services, you acknowledge that you have read and understood this Privacy Policy.
2. Information We Collect
We collect different types of information depending on how you interact with us:
2.1 Information You Provide Directly
- Account registration details: company name, contact person name, email address, phone number, business address
- Enquiry and demo request forms: name, email, phone, company, message content
- Payment and billing information processed through our secure payment providers
- Communication records: emails, support tickets, and chat messages exchanged with our team
2.2 Information Collected Automatically
- Device information: IP address, browser type and version, operating system, device type
- Usage data: pages visited, features used, click patterns, session duration, referring URLs
- Log data: access times, error logs, and server performance data
2.3 Business Data You Upload
When using the InvSpot platform, you may upload or connect business data including invoices, inventory records, purchase orders, supplier information, and POS data. This data is processed solely for providing our services to you and remains your property.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Providing and maintaining the InvSpot platform and services
- Processing your account registration and managing your subscription
- Responding to your enquiries, support requests, and demo bookings
- Sending transactional communications (e.g. account confirmations, invoices, security alerts)
- Sending product updates, newsletters, and marketing communications (only with your consent)
- Analysing usage patterns to improve our platform, features, and user experience
- Generating aggregated, anonymised analytics and benchmarking reports
- Detecting, preventing, and addressing fraud, abuse, or technical issues
- Complying with legal obligations and enforcing our terms
4. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience:
- Essential cookies: required for the platform to function properly (e.g. session management, authentication)
- Analytics cookies: help us understand how visitors use our website and platform (e.g. Google Analytics)
- Preference cookies: remember your settings and preferences (e.g. language selection)
You can control cookie preferences through your browser settings. Disabling certain cookies may affect the functionality of our services.
5. Data Sharing and Disclosure
We do not sell, rent, or trade your personal data to third parties. We may share your information in the following circumstances:
- Service providers: trusted third-party vendors who assist us in operating our platform (e.g. cloud hosting, payment processing, email delivery, analytics). These providers are contractually obligated to protect your data and may only use it for the services they provide to us.
- Legal compliance: when required by law, regulation, legal process, or enforceable governmental request
- Business transfers: in connection with a merger, acquisition, reorganisation, or sale of assets, your data may be transferred as part of the transaction
- Protection of rights: to protect the rights, property, or safety of InvSpot, our users, or the public
6. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including:
- Active account data: retained for the duration of your subscription and for 90 days after account closure
- Business data you upload: deleted within 30 days of account termination upon your request, or retained for up to 90 days for recovery purposes
- Enquiry and contact form data: retained for up to 24 months
- Billing and transaction records: retained as required by applicable tax and accounting laws
7. Data Security
We implement robust security measures to protect your data, including:
- Encryption of data in transit (TLS/SSL) and at rest (AES-256)
- Regular security audits and vulnerability assessments
- Role-based access controls and multi-factor authentication
- Secure cloud infrastructure with reputable hosting providers
- Employee training on data protection and security best practices
While we strive to protect your personal data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to promptly addressing any data breaches in accordance with applicable laws.
8. International Data Transfers
Your data may be transferred to and processed in jurisdictions outside of Hong Kong where our service providers operate. When such transfers occur, we ensure appropriate safeguards are in place, including contractual data protection clauses, to maintain an equivalent level of data protection.
9. Your Rights
Under the Personal Data (Privacy) Ordinance and applicable data protection laws, you have the right to:
- Access: request a copy of the personal data we hold about you
- Correction: request correction of inaccurate or incomplete personal data
- Deletion: request deletion of your personal data (subject to legal retention requirements)
- Data portability: request your data in a structured, machine-readable format
- Opt-out: unsubscribe from marketing communications at any time
- Withdraw consent: withdraw previously given consent for data processing
To exercise any of these rights, please contact us at info@invspot.com. We will respond to your request within 40 days as required by Hong Kong law.
10. Third-Party Links
Our website or platform may contain links to third-party websites or services. We are not responsible for the privacy practices of these external sites. We encourage you to read their privacy policies before providing any personal data.
11. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes by posting the updated policy on our website and updating the "Last updated" date. For significant changes, we may also notify you via email. Your continued use of our services after the changes take effect constitutes your acceptance of the updated policy.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Privacy Commissioner for Personal Data in Hong Kong.