Privacy Policy

Last updated: June 2026 · Select your region below for the applicable policy.

Your region:
🔒 KVKK Uyumlu · 6698 Sayılı Kanun
1

Veri Sorumlusu

6698 sayılı KVKK kapsamında veri sorumlusu: Pruva Business uygulamasının geliştiricisi.
İletişim: privacy@pruvabusiness.app

2

İşlenen Kişisel Veriler

  • Kimlik / İletişim: E-posta (Firebase Auth)
  • Mağaza bilgileri: İşletme adı, mağaza kimliği
  • Personel: Ad, rol, PIN (yerel cihazda şifreli)
  • Satış / stok: Ürün adı, barkod, fiyat, tarih, ödeme yöntemi, KDV
  • Veresiye: Müşteri adı, telefon, borç (yalnızca yerel cihazda)
  • Ürün fotoğrafları: Cihazda şifreli; sunucuya gönderilmez
  • Topluluk katkıları: Barkod + ürün adı (anonim)
  • Konum (isteğe bağlı): Yalnızca kurye rolü aktifse
3

İşleme Amaçları ve Hukuki Dayanak

  • POS hizmeti sunmak — Sözleşme ifası (Madde 5/2-c)
  • Bulut yedekleme, personel yönetimi, raporlama — Meşru menfaat (Madde 5/2-f)
  • Konum — Açık rıza (Madde 5/1)
4

Yurt Dışı Aktarım

Google Firebase (ABD): Bulut depolama, kimlik doğrulama. KVKK kapsamında gerekli tedbirleri almış veri işleyendir.
Apple StoreKit: Abonelik doğrulama.

5

Veri Saklama

  • Hesap verileri: Hesap aktif olduğu sürece saklanır. Silme talebi iletildiğinde hesap anlık olarak devre dışı bırakılır, tüm veriler 90 gün içinde kalıcı olarak silinir.
  • Satış kayıtları: TTK gereği 5 yıl (yasal zorunluluk).
  • Konum: Anlık işlenir, hiçbir sunucuda saklanmaz.
6

Haklarınız (KVKK Madde 11)

  • Verilerinizin işlenip işlenmediğini öğrenme
  • Düzeltme, silme veya yok etme talep etme — hesabınız 90 gün içinde kalıcı olarak silinir
  • Aktarılan üçüncü kişileri bilme
  • Otomatik karar alma süreçlerine itiraz
  • Zararın giderilmesini talep etme

KVKK talepleriniz için

privacy@pruvabusiness.app
🇪🇺 GDPR Compliant · EU 2016/679
1

Data Controller

The data controller for Pruva Business is the app developer.
Contact: privacy@pruvabusiness.app

2

Data We Collect

  • Identity / contact: Email address (Firebase Authentication)
  • Business data: Store name, store ID
  • Staff data: Name, role, PIN (stored encrypted on device only)
  • Transaction data: Product name, barcode, price, date, payment method, VAT
  • Customer credit records: Name, phone, balance (local device only, never uploaded)
  • Product photos: Encrypted on device; not sent to servers
  • Community contributions: Barcode + product name (anonymous)
  • Location (optional): Only when courier feature is active
3

Legal Basis (GDPR Article 6)

  • Contract performance (Art. 6(1)(b)) — POS service delivery
  • Legitimate interest (Art. 6(1)(f)) — security, analytics, bug fixing
  • Consent (Art. 6(1)(a)) — location data, only when explicitly granted
4

International Transfers

Google Firebase (USA): Cloud storage and authentication. Transfers are protected by Standard Contractual Clauses (SCCs) per GDPR Chapter V.
Apple StoreKit: Subscription verification under Apple's privacy framework.

5

Retention Periods

  • Account data: Retained while the account is active. Upon deletion request, the account is immediately deactivated and all data is permanently deleted within 90 days.
  • Sales records: 5 years (legal obligation under applicable commercial law).
  • Location: Processed in real-time only; never stored on any server.
6

Your Rights (GDPR Articles 15–22)

  • Access — obtain a copy of your data
  • Rectification — correct inaccurate data
  • Erasure — request account deletion; data permanently removed within 90 days
  • Restriction — limit processing
  • Portability — receive data in machine-readable format
  • Objection — object to processing based on legitimate interest
  • Lodge a complaint — with your national supervisory authority (DPA)

For GDPR requests

privacy@pruvabusiness.app
🇬🇧 UK GDPR · Data Protection Act 2018
1

Data Controller

Pruva Business app developer.
Contact: privacy@pruvabusiness.app

2

Data We Collect

  • Email address, store name, staff name and role
  • Sales and stock records, payment methods, VAT
  • Customer credit records (local device only)
  • Product photos (local device only)
  • Location (optional, courier feature only)
3

Legal Basis (UK GDPR Article 6)

  • Contract performance — POS service
  • Legitimate interest — security and analytics
  • Consent — location data
4

International Transfers

Data transferred to Google Firebase (USA) under the UK International Data Transfer Agreement (IDTA). Apple StoreKit used for subscription verification.

5

Your Rights

Access, rectification, erasure (account deleted within 90 days of request), restriction, portability, objection. You may lodge a complaint with the ICO (ico.org.uk).

For UK GDPR requests

privacy@pruvabusiness.app
🇺🇸 United States · CCPA / State Laws
1

About This Policy

This policy applies to US residents. California residents have additional rights under the California Consumer Privacy Act (CCPA).

2

Information We Collect

  • Email address for account authentication
  • Business name, store ID
  • Sales, inventory, and staff data
  • Product photos (stored locally on device)
  • Location (optional, only for courier feature)
3

How We Use Your Information

  • To provide the POS service
  • Cloud backup and sync across devices
  • Analytics and service improvement
  • Subscription management via Apple
4

We Do Not Sell Your Data

Pruva Business does not sell personal information to third parties. We do not share data for cross-context behavioral advertising.

5

California Residents (CCPA)

  • Right to know what personal information is collected
  • Right to delete personal information — account deactivated immediately, all data permanently deleted within 90 days
  • Right to opt-out of sale (we don't sell)
  • Right to non-discrimination

For privacy requests (including CCPA)

privacy@pruvabusiness.app
🇧🇷 LGPD Compliant · Lei 13.709/2018
1

Controlador de Dados

Pruva Business é o controlador dos seus dados pessoais nos termos da Lei Geral de Proteção de Dados (LGPD — Lei 13.709/2018).
Contato do Encarregado (DPO): privacy@pruvabusiness.app

2

Dados Coletados

  • Endereço de e-mail (autenticação)
  • Nome da loja e identificador do negócio
  • Registros de vendas, estoque e funcionários
  • Fotos de produtos (somente no dispositivo, criptografia AES-256)
  • Localização (opcional, somente função de entregador)
3

Finalidades do Tratamento (Art. 7 LGPD)

  • Execução de contrato — operar o serviço POS
  • Légítimo interesse — backup em nuvem e sincronização
  • Cumprimento de obrigação legal — gestão de assinatura
  • Consentimento — contribuições anônimas de produtos
4

Compartilhamento de Dados

Google Firebase (EUA): Armazenamento em nuvem e autenticação. Transferência internacional com garantias adequadas (cláusulas contratuais padrão).
Apple StoreKit: Processamento de assinatura.
Não vendemos nem compartilhamos seus dados para fins publicitários.

5

Retenção de Dados

  • Dados da conta: Retidos enquanto a conta estiver ativa. Após solicitação de exclusão, a conta é desativada imediatamente e todos os dados são excluídos permanentemente em até 90 dias.
  • Registros de vendas: 5 anos (obrigação legal).
  • Localização: Processada em tempo real, nunca armazenada.
6

Seus Direitos (Art. 18 LGPD)

  • Confirmação e acesso aos dados
  • Correção de dados incompletos ou desatualizados
  • Anonimização, bloqueio ou eliminação
  • Portabilidade dos dados
  • Revogação do consentimento a qualquer momento
  • Exclusão da conta — dados removidos permanentemente em até 90 dias após solicitação
  • Petição à ANPD (Autoridade Nacional de Proteção de Dados)

Solicitações de privacidade (LGPD)

privacy@pruvabusiness.app
🌍 International Privacy Policy
1

Who We Are

Pruva Business is a mobile POS application. Contact: privacy@pruvabusiness.app

2

What We Collect

  • Email address for account sign-in
  • Store name and business identifier
  • Sales, inventory and staff records
  • Product photos (device-only, AES-256 encrypted)
  • Location (optional, courier feature only)
  • Anonymous product name contributions
3

Why We Collect It

  • To operate the POS service
  • Cloud backup and multi-device sync
  • Subscription management
  • Service improvement and bug fixing
4

Third Parties

  • Google Firebase (USA) — cloud storage and authentication
  • Apple StoreKit — subscription processing
  • We do not sell or share your data for advertising
5

Data Retention

  • Account data: Retained while your account is active. Upon deletion request, your account is immediately deactivated and all data is permanently deleted within 90 days.
  • Sales records: May be retained for up to 5 years for legal compliance.
  • Location: Processed in real-time only, never stored.
6

Your Rights

  • Access — request a copy of your data
  • Correction — fix inaccurate information
  • Deletion — account deactivated immediately, all data permanently deleted within 90 days
  • Export — download your data via the Excel export feature in the app
7

Children

Pruva Business is not directed at children under 18. We do not knowingly collect data from minors.

Privacy requests

privacy@pruvabusiness.app