Privacy Policy
Last updated: April 14, 2026
Inventory 01 ("we", "our", or "the Service") respects your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use the Inventory 01 inventory app and related websites (collectively, the "Service").
By using the Service, you agree to this policy. If you do not agree, please stop using the Service.
1. Data We Collect
1.1 Data You Provide
- Account data: Email address, password (stored as a bcrypt hash), display name.
- Google / Apple Sign-In: If you use third-party sign-in, we only receive a unique identifier (UID) and email address. We never store third-party passwords.
- Business data: Products, SKUs, inventory transactions, barcodes, and other inventory content you create.
- Images: Product photos you upload, compressed to WebP format and stored on our server (MinIO).
1.2 Data Collected Automatically
- Device information: Device model, OS version, app version.
- Log data: Error logs and operation timestamps (no JWT or PII included).
- Push token: FCM Token used to send low-stock alerts and subscription notifications.
1.3 Data From Third-Party Services
- Subscription data: Events from the Apple App Store based on your subscription status (purchase, renewal, expiration).
2. How We Use Your Data
- Provide, maintain, and improve the core features of the Service (inventory management, reports, notifications).
- Verify your identity and manage account security (JWT dual-token system, sign-out, account deletion).
- Process subscription payments and manage trial periods.
- Send notifications directly related to your account or the Service (low-stock alerts, subscription expiry).
- Detect and prevent fraud, abuse, and security incidents.
- Comply with applicable legal obligations.
We do not sell or rent your personal data to third parties, nor do we use your data for advertising purposes.
3. Data Storage and Security
- Encryption in transit: All data transmissions use TLS 1.3.
- Encryption at rest: The database (PostgreSQL) resides on host-level encrypted storage. Images (MinIO) use AES-256 SSE-S3 server-side encryption.
- Password security: Passwords are hashed with bcrypt (cost 12). We cannot recover your original password.
- Least-privilege access: All inter-service access is validated via JWT, with tenant data isolated by organization ID (orgId).
- Error tracking: Sentry error reports are filtered to remove JWT tokens and personally identifiable information (PII) before transmission.
4. Data Retention
Your account data is retained while your account is active. After account deletion, we will delete your personal and business data within 30 days. Data required by law (e.g., transaction records) will be retained for the required period and then deleted.
5. Your Rights
Under applicable privacy laws (including GDPR and other regional regulations), you have the following rights:
- Right of access: Request a copy of your personal data we hold.
- Right to rectification: Request correction of inaccurate or incomplete personal data.
- Right to erasure: Delete your account directly in the app settings; deletion requests trigger a full data purge across all services.
- Right to data portability: Export your products and inventory records in CSV / Excel format.
- Right to withdraw consent: Disable push notifications at any time in your device notification settings.
To exercise these rights or for any privacy-related questions, contact us at: [email protected]
6. Cookies and Local Storage
This website (Landing Page) uses localStorage to store your language preference (ms-lang), which contains no personal data. The app itself uses iOS Keychain to store tokens and does not use cookies.
7. Children's Privacy
The Service is not directed to children under the age of 13. We do not knowingly collect personal data from minors. If you believe a child has provided us with data without consent, please contact us and we will promptly delete it.
8. Third-Party Services
The Service integrates with the following third-party services, each with its own privacy policy:
- Apple App Store: Subscription management and receipt validation (StoreKit 2).
- Firebase (Google): Push notifications (FCM).
- Sentry: Self-hosted error tracking (data does not leave our servers).
- Resend: Transactional email (subscription notifications).
9. Policy Changes
We may update this policy in response to regulatory changes or new features. Material changes will be communicated via in-app notification or email. Continued use of the Service constitutes acceptance of the updated policy.
10. Contact Us
If you have any questions about this Privacy Policy, please contact:
๐ง [email protected]