Files
wms-app/landing/privacy.php
T
Thanakorn f11af6e949 Self-host front-end libraries, minimal sign-in header and CSP
- sign-in pages load only what they use (include_login_header.php, ajax_core.js)
- every library, font and data file served from assets/vendor with pinned
  versions (VERSIONS.json); no CDN at runtime
- Content-Security-Policy on app, sign-in and landing pages
- remove httpbin Dropzone target and source-map references
2026-09-24 14:53:41 +07:00

73 lines
3.6 KiB
PHP

<?php
require __DIR__ . '/../app/config.php';
require __DIR__ . '/includes/security_headers.php';
$base = rtrim($base_url, '/') . '/landing';
$app_url = rtrim($base_url, '/') . '/app';
$page_title = 'Privacy Policy — BRN WMS';
$page_description = 'Privacy Policy for BRN WMS.';
$active_nav = '';
?>
<!DOCTYPE html>
<html lang="en">
<head>
<?php require __DIR__ . '/includes/head.php'; ?>
<style>
.legal-section { padding: 5rem 0 3rem; }
.legal-section h1 { margin-bottom: 0.5rem; }
.legal-section .updated { color: #888; font-size: 0.875rem; margin-bottom: 2.5rem; }
.legal-section h2 { font-size: 1.25rem; margin-top: 2rem; margin-bottom: 0.5rem; color: #272556; }
</style>
</head>
<body>
<?php require __DIR__ . '/includes/nav.php'; ?>
<div class="legal-section">
<div class="container">
<div class="row justify-content-center">
<div class="col-lg-8">
<h1>Privacy Policy</h1>
<p class="updated">Last updated: May 2026</p>
<p>This Privacy Policy describes how BRN WMS collects, uses, and protects your information when you use our service.</p>
<h2>1. Information We Collect</h2>
<p>We collect information you provide directly — such as your name, email address, and company details when you register — and operational data you enter into the system (products, stock, orders).</p>
<h2>2. How We Use Your Information</h2>
<p>We use your information solely to provide and improve the BRN WMS service, authenticate your identity, and communicate with you about your account. We do not sell or share your data with third parties for marketing purposes.</p>
<h2>3. Session and Authentication Data</h2>
<p>Login sessions are protected by OTP-based two-factor authentication. Session tokens are stored securely and expire after inactivity. We log login events for security auditing.</p>
<h2>4. Data Isolation</h2>
<p>Each company's data is logically isolated. Users can only access data belonging to their own company. We implement access controls at both the application and database levels.</p>
<h2>5. Data Retention</h2>
<p>Your data is retained for as long as your account is active. Upon account termination, data may be retained for a limited period for legal or audit purposes before deletion.</p>
<h2>6. Security</h2>
<p>We use industry-standard security practices including CSRF protection, parameterised queries, and encrypted connections. No system is completely secure — you are also responsible for protecting your credentials.</p>
<h2>7. Cookies</h2>
<p>BRN WMS uses session cookies for authentication. We do not use third-party tracking or advertising cookies.</p>
<h2>8. Your Rights</h2>
<p>You may request access to, correction of, or deletion of your personal data by contacting us. We will respond within a reasonable timeframe.</p>
<h2>9. Changes to This Policy</h2>
<p>We may update this policy periodically. We will notify users of significant changes via email or an in-app notice.</p>
<h2>10. Contact</h2>
<p>Privacy questions? Email <a href="mailto:contact@brnwms.com">contact@brnwms.com</a>.</p>
</div>
</div>
</div>
</div>
<?php require __DIR__ . '/includes/footer.php'; ?>
<?php require __DIR__ . '/includes/scripts.php'; ?>
</body>
</html>