On this page
- 1. Scope and our roles
- 2. Information we collect
- 3. Sources of information
- 4. How we use information
- 5. Legal grounds where required
- 6. How we disclose information
- 7. Billing, App Store purchases, connected accounts, and memberships
- 8. Analytics, cookies, and mobile diagnostics
- 9. Optional client profile and precise location data
- 10. Data retention
- 11. Security
- 12. Privacy choices and rights
- 13. U.S. state privacy notice
- 14. International processing and transfers
- 15. Children and restricted information
- 16. Changes and contact
1. Scope and our roles
This Policy applies when you visit FacturaOS sites, create or use an account, join a workspace, use the mobile application, contact support, subscribe, or interact with a FacturaOS-operated payment page or communication.
J.R.SOSA & CO. LLC controls personal information used for accounts, billing, product operations, security, analytics, support, and our business. For client, invoice-recipient, supplier, employee, contractor, and similar personal information submitted by a business customer, that customer generally determines the purpose and FacturaOS generally acts as its processor or service provider under the Data Processing Addendum.
2. Information we collect
Depending on how you use FacturaOS, we may collect the following categories:
- Account and identity: name, email address, authentication provider, user identifier, language, role, profile settings, saved-account and active-workspace selections, and login or invitation records.
- Business and workspace: business name, merchant registration number, contact details, logo, external links, operating market, tax and invoice settings, locations and images, addresses, service model, service and delivery areas, working hours, professional-license records, members, invitations, and permissions.
- Operational Customer Data: client first and last name, email, phone, photograph, optional birth date or year and gender, address, precise location captured with device permission, internal notes, estimates, invoices, line items, service and product categories, catalog images, appointment dates and status, assigned staff, blocked time, working hours and exceptions, cart and sale records, membership plan and sold-term snapshots, included benefits, redemption and status history, evidence files, templates, inventory consumption, suppliers, purchase orders, routes, reports, exports, support tickets, and related records.
- Billing and payments: plan, seats, billing interval, billing contact, product and transaction identifiers, purchase and expiration dates, trial and renewal status, entitlement status, storefront and environment, cancellation, billing-issue, refund or revocation events, limited saved-payment-method metadata such as provider identifier, brand, type, last four digits, expiration, and status, connected-account and customer-membership status, renewal dates, payment method category, owner confirmations of externally collected payments, disputes, and risk signals. Stripe receives and stores full credentials for direct and customer-saved payment methods and eligible Online Checkout transactions through its components; FacturaOS does not receive or store the full card number or security code. Apple receives Apple Account and payment information for App Store purchases; FacturaOS and RevenueCat do not receive the full App Store payment credentials. If a workspace activates ATH Móvil Business, FacturaOS processes the merchant integration credentials and transaction information needed to connect to Evertec and initiate and verify supported invoice payments. For a manually recorded sale or membership payment, FacturaOS stores the business user's entry but does not receive independent proof of payment unless a supported provider event is also available.
- Device and usage: IP address, browser, device, operating system, application version, approximate region, pages or features used, timestamps, referral or campaign data, diagnostic logs, crash information, and privacy preferences.
- Mobile permissions you choose: contacts selected for import, photographs or files selected for upload, camera access, and precise location captured for a client address, route, business location, or other location feature.
- Communications: support messages, email-delivery status, survey or feedback responses, legal requests, and records of notices or consent.
3. Sources of information
We receive information directly from you; workspace owners and members; your device or browser; clients, invoice recipients, or membership purchasers interacting with a payment or checkout link; authentication, hosting, analytics, email, subscription-management, application-store, and payment providers; public sources; and integrations you choose.
If someone adds you to FacturaOS, sends you an invoice, or provides your information through a workspace, that business user is responsible for giving required notices and ensuring lawful collection.
4. How we use information
We use information to:
- Create accounts, authenticate users, operate workspaces, and provide requested features.
- Store, organize, generate, export, send, and display business records; operate client profiles, locations, service areas, catalogs, working hours, reports, and routing under customer instructions.
- Process FacturaOS subscriptions, validate App Store transactions, synchronize entitlements, manage seats and plan changes, process invoices and connected payments, support customer-membership checkout and renewal status, record owner-confirmed external collections and benefit redemptions, handle refunds where FacturaOS is authorized to do so, and provide billing support.
- Secure the service, prevent fraud and abuse, troubleshoot, monitor reliability, and enforce agreements.
- Provide support, send service communications, respond to privacy requests, and maintain audit records.
- Measure privacy-safe usage, attribution, performance, and product quality where optional analytics are enabled.
- Comply with law, legal process, tax and accounting duties, and protect rights, safety, and property.
- Develop and improve features using aggregated, de-identified, or appropriately minimized information.
5. Legal grounds where required
Where applicable law requires a legal basis, we process information to perform our contract; follow your instructions; comply with legal obligations; pursue legitimate interests such as security, support, fraud prevention, service improvement, and business administration; protect vital interests; or based on consent. You may withdraw consent for future processing where consent is the basis, without affecting earlier lawful processing.
6. How we disclose information
We may disclose information in these circumstances:
- Within a workspace according to roles, permissions, invitations, and actions chosen by workspace administrators.
- To service providers and subprocessors that support hosting, databases, storage, authentication, analytics, diagnostics, email, support, billing, subscription-entitlement management, and security, subject to appropriate obligations.
- To RevenueCat for App Store transaction validation, subscription-entitlement synchronization, purchase restoration, lifecycle events, and related support.
- To Stripe, Evertec and ATH Móvil, banks, card networks, payment methods, and financial partners for direct subscription billing, connected accounts, customer-membership Online Checkout, merchant authentication, identity verification, fraud prevention, payment initiation and verification, recurring billing, settlement, refunds, disputes, and compliance.
- To Apple for App Store purchases, subscription management, refund processing, application distribution, and Sign in with Apple when you choose that service; or to Google or another authentication provider when you choose that login method.
- To professional advisers, auditors, insurers, financing sources, and transaction parties under confidentiality safeguards.
- To authorities or other parties when reasonably necessary to comply with law, legal process, protect rights or safety, investigate abuse, or enforce our agreements.
- In connection with a merger, financing, reorganization, sale, bankruptcy, or transfer of all or part of the business, subject to applicable law.
7. Billing, App Store purchases, connected accounts, and memberships
When you start an iOS in-app subscription, Apple collects the Apple Account, payment, device, storefront, tax, and transaction information needed to complete and manage the purchase under Apple's terms and privacy notices. FacturaOS receives limited product, transaction, subscription, renewal, cancellation, billing-issue, refund, revocation, environment, and entitlement information from Apple through RevenueCat. RevenueCat uses an app user identifier and that store information to validate purchases, restore access, and synchronize entitlement status on behalf of FacturaOS. Neither FacturaOS nor RevenueCat receives full App Store payment credentials or independently controls Apple Account charges, renewals, plan changes, cancellations, refund decisions, or refund timing; Apple handles those matters under its terms and privacy notices.
Stripe independently collects payment credentials, identity documents, tax identifiers, bank details, device information, and transaction information needed for its services. For an eligible customer membership sold through Online Checkout powered by Stripe, Stripe also receives the customer, price, recurring authorization, payment-method, invoice, renewal, cancellation, refund, and dispute information needed to manage that connected-business payment. Stripe may act as an independent controller for regulated payment, verification, fraud, and compliance purposes. Its privacy policy, connected-account terms, and checkout disclosures apply in addition to this Policy.
If a workspace activates ATH Móvil Business, FacturaOS sends Evertec or ATH Móvil the merchant credentials, business and invoice identifiers, amount, description, and transaction data needed to initiate, verify, reconcile, secure, and support the payment. Evertec's payment component may separately collect payer or phone, device, network, authentication, and risk information directly under its terms. Evertec and participating financial institutions handle the payment service under their terms and privacy notices and may act independently for those purposes.
Evertec webhook payloads may include payer name, email, phone number, item descriptions or metadata, device or network information, and transaction details. FacturaOS may receive those fields transiently but is designed to retain only the limited identifiers, status, amount, reference, and audit data needed to correlate and verify the payment.
FacturaOS receives payment and connected-account identifiers, readiness or restriction status, limited account and transaction details, callbacks, webhooks, and provider-lookup results needed to provide billing and payment features. We do not intentionally store full card numbers or card security codes. See https://terms.facturaos.com/en/payment-services, the ATH Business Terms and Conditions at https://ath.business/en/terminos, and the Evertec privacy notice at https://ath.business/en/politica_privacidad.
8. Analytics, cookies, and mobile diagnostics
FacturaOS may use Google Analytics for optional website and product measurement and Firebase Analytics and Crashlytics for optional mobile analytics and diagnostics. Our implementation is designed to avoid sending client names, invoice contents, contact details, addresses, search text, document contents, or full URLs containing record identifiers as analytics event values.
RevenueCat's iOS software development kit is a necessary subscription technology, not optional advertising or product analytics. It processes the app user identifier and limited App Store subscription information described above when the Apple purchase feature is configured or used.
Signed-in users may turn optional product analytics off in Account settings. Mobile users may use the corresponding privacy setting. Browser or device privacy controls may also apply. Necessary authentication, security, fraud-prevention, billing, entitlement, support, and service logs continue because they are required to operate and protect the service. See the Cookie Statement.
9. Optional client profile and precise location data
A business user may choose to store optional client birth information, gender, a profile photo, address, precise coordinates, and internal notes. FacturaOS provides fields and device controls for those records but the workspace owner determines why they are collected, who may access them, and how they are used. The business must provide any required notice, obtain consent or another lawful basis, respect device permissions, and avoid collecting information that is excessive for its purpose.
Precise location may be captured only after a user invokes a location feature and the device or browser grants permission. It may then be stored in the applicable workspace record and visible to authorized workspace members. FacturaOS does not use client birth information, gender, or precise location to infer characteristics for advertising. Individuals seeking access, correction, or deletion of workspace-controlled profile information should ordinarily contact the business that collected it.
10. Data retention
We retain information only as long as reasonably necessary for the purposes described, including the life of the account or workspace and any additional period needed for legal, tax, accounting, payment, security, backup, fraud-prevention, support, and dispute obligations.
Retention varies by category. Active Customer Data generally remains until deleted by an authorized user or the workspace is deleted. Sold-membership term snapshots, redemption history, account, consent, billing, payment, abuse, and legal records may remain longer when needed for customer, accounting, tax, fraud, or dispute obligations. Backups and provider systems may take additional time to cycle out. We may retain aggregated or de-identified information that cannot reasonably identify a person.
11. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information, including access controls, encrypted transmission, private storage controls, environment separation, logging, and provider security measures. No method is completely secure, and we cannot guarantee absolute security.
Workspace owners are responsible for user access, device security, exports, recipient addresses, and lawful handling after information leaves FacturaOS. Report suspected incidents promptly to privacy@facturaos.com.
12. Privacy choices and rights
Depending on your location and our legal role, you may request access, correction, deletion, portability, restriction, objection, or withdrawal of consent, and may appeal a denied request where law provides. You may also update many account and workspace fields directly and turn off optional analytics.
Send requests to privacy@facturaos.com. We may verify identity, authority, workspace role, and jurisdiction. If FacturaOS processes information for a business customer, we may direct you to that business or assist it in responding. Authorized agents must provide legally sufficient authority. We will not discriminate for exercising applicable privacy rights.
13. U.S. state privacy notice
The categories collected, sources, purposes, and recipients during the preceding 12 months are described in Sections 2 through 9. FacturaOS does not sell personal information for money. We do not knowingly sell or share personal information for cross-context behavioral advertising as those terms are defined by applicable U.S. state privacy laws.
If our practices change in a way that creates a right to opt out of sale, sharing, or targeted advertising, we will provide the legally required control before using information that way. We use and disclose sensitive personal information only for permitted business purposes or as directed by a business customer, and not to infer characteristics for advertising.
14. International processing and transfers
FacturaOS and its providers may process information in the United States and other countries where they operate. Those countries may have different privacy laws. Where required, we rely on contractual protections, provider transfer mechanisms, consent, or another lawful transfer basis.
The Subprocessors and Other Providers page identifies current direct subprocessors and separately describes role-dependent or independently controlled services. Business customers needing additional transfer documentation may contact privacy@facturaos.com.
15. Children and restricted information
FacturaOS is not directed to children under 13 and is not intended for anyone under 18 to open an account. An optional birthday field for a business's client record does not make FacturaOS a service directed to children. We do not knowingly collect personal information directly from a child under 13. A business that records information about a minor is responsible for appropriate authority, notices, consent, minimization, and lawful service. Contact us if you believe a child submitted information directly to FacturaOS without appropriate authorization.
FacturaOS is not designed to store HIPAA-regulated protected health information, full payment-card credentials, or other specially regulated data unless we expressly agree in writing. Business users must avoid submitting restricted information and are responsible for their own legal obligations.
16. Changes and contact
We may update this Policy as services, providers, or laws change. The date above shows the latest revision. We will provide additional notice or consent for material changes where required.
Privacy questions and requests may be sent to privacy@facturaos.com or by mail to J.R.SOSA & CO. LLC, 2125 Biscayne Blvd, Ste 204 #24427, Miami, Florida 33137 US. General support is available at contact@facturaos.com.