Privacy Policy

Last updated: September 12, 2026 · Effective: September 12, 2026

Introduction

InvenTally is committed to protecting user privacy. This Privacy Policy explains how personal data is collected, processed, and stored when you use the app.

This policy is based on Turkey's Personal Data Protection Law No. 6698 (KVKK); for users in the EU/EEA, the General Data Protection Regulation (GDPR) also applies.

Data Controller
InvenTally

Data We Collect

A. Identity & Contact

  • Name, email address
  • Username, profile photo
  • Firebase Authentication UID

B. Inventory Data

  • Product details (name, category, barcode)
  • Stock quantities and locations
  • Product images (Firebase Storage)

C. Usage Data

  • App usage statistics
  • Device information (model, OS version)
  • Session information and activity logs

D. Data We Do Not Collect

  • Sensitive personal data (health, religion, ethnicity)
  • Financial information (credit cards)
  • GPS location data

Purposes of Processing

Your data is processed for the following purposes:

  • Service delivery: Inventory management, synchronization
  • Security: Authentication, account protection
  • Communication: Stock alerts, system notifications
  • Analytics: App improvement (anonymous)
  • Legal compliance: Regulatory requirements

Legal bases: Performance of a contract (KVKK Art. 5/2-c · GDPR Art. 6(1)(b)), legitimate interest (KVKK Art. 5/2-f · GDPR Art. 6(1)(f)), explicit consent (KVKK Art. 5/1 · GDPR Art. 6(1)(a)), legal obligation (KVKK Art. 5/2-a · GDPR Art. 6(1)(c))

Storage & Security

Storage Location

  • Firebase Cloud Firestore (Google Cloud)
  • EU and US servers
  • SSL/TLS and AES-256 encryption

Retention Period

  • For as long as the account is active
  • When you delete your account, your sign-in (identity) record is deleted immediately
  • Your inventory data and photos are permanently deleted within 30 days at the latest; you can confirm the deletion status at privacy@inventally.app

Security Measures

  • Passwords are hashed by Firebase Authentication with an industry-standard algorithm (scrypt); we never see your password
  • Two-factor authentication (2FA)
  • Per-account access control with Firebase Security Rules
  • Network and physical security of the Google Cloud infrastructure

Data Sharing

Third-Party Services

  • Firebase (Google): Infrastructure services
  • Apple Sign-In: Authentication
  • Google Sign-In: Authentication

Sharing Principles

  • Your data is never sold
  • No sharing for marketing purposes
  • Only the sharing required to deliver the service

Legal Requirements

  • Court orders
  • Prosecutor requests
  • Requests from the Turkish Data Protection Authority (KVKK Board)

Your Rights (KVKK & GDPR)

Your Rights

  • Right to be informed
  • Right of access (a copy of your data)
  • Right to rectification
  • Right to erasure (right to be forgotten)
  • Right to object
  • Right to data portability
  • Right to withdraw consent

How to Make a Request

  1. Email: privacy@inventally.app
  2. Subject: "KVKK/GDPR Rights Request"
  3. Identity details and a description of the request
  4. Response time: 30 days
  5. Fee: free of charge

If your request is refused, you may lodge a complaint with the Turkish Data Protection Authority. Web: kvkk.gov.tr

Users in the EU/EEA: you may use the same address for your rights under the GDPR, and you also have the right to lodge a complaint with the data protection authority of the country you live in.

Cookies & Tracking

Technologies Used

  • Session management (Firebase tokens)
  • Firebase Analytics (optional)
  • Firebase Crashlytics (crash reporting)
  • UserDefaults (local preferences)

Control

  • Settings › Privacy › Analytics Data
  • Can be disabled at any time
  • Disabling does not affect functionality

Website (inventally.app)

This website does not use analytics or advertising/tracking cookies.

  • NEXT_LOCALE cookie: remembers the language you chose (functional, required)
  • theme and preferredLocale in browser local storage: your theme and language preference; they stay on your device and are not sent to us
  • Our hosting provider, Vercel, may keep short-term access logs (IP address, browser information) for security and debugging

This data is not used to identify you and is not shared with third parties.

Notifications

Notification Types

  • Stock alerts (low stock, critical stock)
  • System updates
  • Account security notifications
  • Inventory reminders

Control

  • Permission is requested during initial setup
  • Manageable from Settings › Notifications
  • Customizable per notification type
  • Can be turned off at any time

Email Communication

  • Account verification
  • Password reset
  • Security alerts
  • Service and policy change notices
  • We do not send marketing emails

Children's Privacy

Age Limit

  • Not designed for children under 13
  • Parental consent is required for ages 13–18

Children's Data

  • We do not knowingly collect data from children under 13
  • If detected, it is deleted immediately
  • Parents may request deletion

Contact: privacy@inventally.app

International Transfers

Transfer Locations

  • Firebase (Google Cloud)
  • EU servers (Belgium, Netherlands)
  • US servers (Iowa, Oregon)

Safeguards

  • EU–US Data Privacy Framework
  • Standard Contractual Clauses
  • Google's GDPR compliance commitments
  • Encryption and security measures

Details: firebase.google.com/support/privacy

Data Breach Notification

In Case of a Breach

  • Notification to the Turkish Data Protection Authority within 72 hours
  • User notification in high-risk cases
  • Email and in-app announcement

Measures Taken

  • Closing the vulnerability
  • Securing affected accounts
  • Password reset (if necessary)
  • External security review if needed

Suspected breach: privacy@inventally.app

Policy Changes

Updates

  • Regular review
  • Significant changes are announced 30 days in advance
  • Email and in-app notification

User Consent

  • Renewed consent for significant changes
  • Service may be limited if consent is not given
  • You may delete your account at any time

Last updated: September 12, 2026

Contact & Complaints

Contact

Complaints

  1. Contact us first
  2. Response within 30 days
  3. If unresolved, apply to the Turkish Data Protection Authority

Turkish Data Protection Authority (KVKK Board)

Response Times

  • General questions: 5 business days
  • KVKK/GDPR requests: 30 days
  • Urgent security: 24 hours

Summary

Collected
Name, email, inventory data
Purpose
Service delivery, security, improvement
Sharing
Firebase (Google) only
Sale
Never sold
Rights
Access, rectification, erasure, objection
Security
SSL/TLS, AES-256, 2FA
Compliance
KVKK & GDPR