Privacy Policy
Last updated: September 12, 2026 · Effective: September 12, 2026
Introduction
InvenTally is committed to protecting user privacy. This Privacy Policy explains how personal data is collected, processed, and stored when you use the app.
This policy is based on Turkey's Personal Data Protection Law No. 6698 (KVKK); for users in the EU/EEA, the General Data Protection Regulation (GDPR) also applies.
- Data Controller
- InvenTally
- Contact
- privacy@inventally.app
Data We Collect
A. Identity & Contact
- Name, email address
- Username, profile photo
- Firebase Authentication UID
B. Inventory Data
- Product details (name, category, barcode)
- Stock quantities and locations
- Product images (Firebase Storage)
C. Usage Data
- App usage statistics
- Device information (model, OS version)
- Session information and activity logs
D. Data We Do Not Collect
- Sensitive personal data (health, religion, ethnicity)
- Financial information (credit cards)
- GPS location data
Purposes of Processing
Your data is processed for the following purposes:
- Service delivery: Inventory management, synchronization
- Security: Authentication, account protection
- Communication: Stock alerts, system notifications
- Analytics: App improvement (anonymous)
- Legal compliance: Regulatory requirements
Legal bases: Performance of a contract (KVKK Art. 5/2-c · GDPR Art. 6(1)(b)), legitimate interest (KVKK Art. 5/2-f · GDPR Art. 6(1)(f)), explicit consent (KVKK Art. 5/1 · GDPR Art. 6(1)(a)), legal obligation (KVKK Art. 5/2-a · GDPR Art. 6(1)(c))
Storage & Security
Storage Location
- Firebase Cloud Firestore (Google Cloud)
- EU and US servers
- SSL/TLS and AES-256 encryption
Retention Period
- For as long as the account is active
- When you delete your account, your sign-in (identity) record is deleted immediately
- Your inventory data and photos are permanently deleted within 30 days at the latest; you can confirm the deletion status at privacy@inventally.app
Security Measures
- Passwords are hashed by Firebase Authentication with an industry-standard algorithm (scrypt); we never see your password
- Two-factor authentication (2FA)
- Per-account access control with Firebase Security Rules
- Network and physical security of the Google Cloud infrastructure
Your Rights (KVKK & GDPR)
Your Rights
- Right to be informed
- Right of access (a copy of your data)
- Right to rectification
- Right to erasure (right to be forgotten)
- Right to object
- Right to data portability
- Right to withdraw consent
How to Make a Request
- Email: privacy@inventally.app
- Subject: "KVKK/GDPR Rights Request"
- Identity details and a description of the request
- Response time: 30 days
- Fee: free of charge
If your request is refused, you may lodge a complaint with the Turkish Data Protection Authority. Web: kvkk.gov.tr
Users in the EU/EEA: you may use the same address for your rights under the GDPR, and you also have the right to lodge a complaint with the data protection authority of the country you live in.
Website (inventally.app)
This website does not use analytics or advertising/tracking cookies.
- NEXT_LOCALE cookie: remembers the language you chose (functional, required)
- theme and preferredLocale in browser local storage: your theme and language preference; they stay on your device and are not sent to us
- Our hosting provider, Vercel, may keep short-term access logs (IP address, browser information) for security and debugging
This data is not used to identify you and is not shared with third parties.
Notifications
Notification Types
- Stock alerts (low stock, critical stock)
- System updates
- Account security notifications
- Inventory reminders
Control
- Permission is requested during initial setup
- Manageable from Settings › Notifications
- Customizable per notification type
- Can be turned off at any time
Email Communication
- Account verification
- Password reset
- Security alerts
- Service and policy change notices
- We do not send marketing emails
Children's Privacy
Age Limit
- Not designed for children under 13
- Parental consent is required for ages 13–18
Children's Data
- We do not knowingly collect data from children under 13
- If detected, it is deleted immediately
- Parents may request deletion
Contact: privacy@inventally.app
International Transfers
Transfer Locations
- Firebase (Google Cloud)
- EU servers (Belgium, Netherlands)
- US servers (Iowa, Oregon)
Safeguards
- EU–US Data Privacy Framework
- Standard Contractual Clauses
- Google's GDPR compliance commitments
- Encryption and security measures
Details: firebase.google.com/support/privacy
Data Breach Notification
In Case of a Breach
- Notification to the Turkish Data Protection Authority within 72 hours
- User notification in high-risk cases
- Email and in-app announcement
Measures Taken
- Closing the vulnerability
- Securing affected accounts
- Password reset (if necessary)
- External security review if needed
Suspected breach: privacy@inventally.app
Policy Changes
Updates
- Regular review
- Significant changes are announced 30 days in advance
- Email and in-app notification
User Consent
- Renewed consent for significant changes
- Service may be limited if consent is not given
- You may delete your account at any time
Last updated: September 12, 2026
Contact & Complaints
Contact
- Privacy: privacy@inventally.app
- Support: support@inventally.app
- Web: inventally.app/privacy
Complaints
- Contact us first
- Response within 30 days
- If unresolved, apply to the Turkish Data Protection Authority
Turkish Data Protection Authority (KVKK Board)
- Web: kvkk.gov.tr
- Email: kvkk@kvkk.gov.tr
- Phone: +90 312 216 50 50
Response Times
- General questions: 5 business days
- KVKK/GDPR requests: 30 days
- Urgent security: 24 hours
Summary
- Collected
- Name, email, inventory data
- Purpose
- Service delivery, security, improvement
- Sharing
- Firebase (Google) only
- Sale
- Never sold
- Rights
- Access, rectification, erasure, objection
- Security
- SSL/TLS, AES-256, 2FA
- Contact
- privacy@inventally.app
- Compliance
- KVKK & GDPR