Home / Privacy Policy

Privacy Policy

Effective date: April 17, 2026

1. Introduction

Budy ("we", "our", or "us") operates the Budy POS mobile application, the Budy Admin web dashboard, and the Budy web shop platform (collectively, the "Services"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Services.

2. Information We Collect

Account Information

When you create an account, we collect your name, email address, and authentication credentials. If you sign in via Google, we receive your Google profile information (name, email, profile photo) as authorized by you.

Business Data

When using Budy POS, you may enter business-related data including products, categories, pricing, inventory, customer (member) information, and order history. This data is stored locally on your device and synchronized to our cloud servers.

Device Information

We collect device identifiers, operating system version, app version, and device type for diagnostics, push notification delivery, and service improvement.

Bluetooth & Peripheral Data

The POS app connects to Bluetooth peripherals such as scales (Acaia), label printers (Niimbot), and barcode scanners (SUNMI) for point-of-sale operations. All Bluetooth data is processed locally on your device and is not transmitted to our servers.

Camera & Image Data

The app uses your device camera for barcode scanning and product photography. Product images may be uploaded to our servers for AI-powered product information extraction. Barcode scans are processed locally.

Location Data

We may collect approximate location data when you use delivery or store-related features. Location data is only collected during active use of these features and is not tracked in the background.

Usage Analytics

We collect anonymous usage analytics including screen views, feature usage patterns, and performance metrics to improve our services. This analytics data is not linked to your identity and is not used to track you across other apps or websites owned by other companies.

App Tracking Transparency (iOS)

Budy does not track you across apps or websites owned by other companies. We do not use the iOS Advertising Identifier (IDFA) and do not share any data with third parties for advertising or cross-app tracking purposes. As a result, the App Tracking Transparency prompt is not shown in the Budy POS app.

3. How We Use Your Information

  • To provide, operate, and maintain our point-of-sale services
  • To synchronize your business data across devices in real time
  • To send push notifications about orders, system updates, and relevant alerts
  • To process and fulfill online orders placed through the web shop
  • To provide AI-powered product data extraction and categorization
  • To improve, personalize, and optimize our services
  • To provide customer support and respond to inquiries
  • To detect, prevent, and address technical issues or security threats
  • To comply with legal obligations

4. Data Storage & Synchronization

Budy uses an offline-first architecture. Your business data is stored locally on your device using ObjectBox and synchronized to our cloud servers (MongoDB hosted on AWS) when connectivity is available. This ensures your POS system works without interruption even when offline.

Data is strictly isolated per tenant — your business data is never accessible to other businesses or users outside your organization.

5. Third-Party Services

We use the following third-party services to operate our platform:

  • Firebase Cloud Messaging (Google) — push notification delivery
  • Google Sign-In — authentication
  • Google Gemini AI — product data extraction from images (images are processed and not permanently stored by Google)
  • Amazon Web Services (S3) — image and file storage
  • ObjectBox Sync — real-time data synchronization
  • GO-UPC — barcode product database lookups

Each third-party service has its own privacy policy governing data handling.

6. Data Sharing

We do not sell, rent, or trade your personal information. We may share data only in the following circumstances:

  • With your consent — when you explicitly authorize sharing
  • Service providers — with trusted third parties who assist in operating our services (as listed above), under strict data protection agreements
  • Legal requirements — when required by law, regulation, or legal process
  • Business transfers — in connection with a merger, acquisition, or sale of assets

7. Data Retention & Account Deletion

We retain your data for as long as your account is active or as needed to provide our services. Local data on your device remains under your control and can be deleted by uninstalling the application.

How to delete your account

You can initiate account deletion at any time through either of the following methods:

  • Within the app: Go to Settings → Account → Delete Account and confirm the deletion. Your account and all associated personal data will be scheduled for removal.
  • By email: Send a deletion request to privacy@budy.app from the email address associated with your account.

Once requested, we will permanently delete your personal data and business data from our servers within 30 days, except where retention is required by law (e.g., tax records, anti-fraud obligations). You will receive email confirmation when deletion is complete.

For multi-user business accounts, only account owners or designated administrators can delete the business tenant. Individual staff members can remove their personal profile without affecting the business data.

8. Data Security

We implement industry-standard security measures to protect your information:

  • Encrypted data transmission (TLS/HTTPS)
  • JWT-based authentication with token expiration
  • Multi-tenant data isolation at the database level
  • Secure cloud infrastructure on Amazon Web Services
  • Regular security assessments and updates

While we strive to protect your data, no method of electronic transmission or storage is 100% secure.

9. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to or restrict processing of your data
  • Data portability — receive your data in a structured format
  • Withdraw consent at any time

To exercise any of these rights, contact us at privacy@budy.app.

California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to know what personal information we collect, use, disclose, and sell
  • Right to delete personal information we have collected about you
  • Right to correct inaccurate personal information
  • Right to opt out of the sale or sharing of personal information
  • Right to limit use of sensitive personal information
  • Right to non-discrimination for exercising these rights

Budy does not sell personal information and does not share personal information for cross-context behavioral advertising. To exercise any California privacy right, email privacy@budy.app with the subject line "California Privacy Request". We will verify your identity before processing the request and respond within 45 days.

EEA, UK, and Swiss Residents (GDPR)

If you are located in the European Economic Area, United Kingdom, or Switzerland, our lawful bases for processing your personal data are: (a) performance of a contract with you, (b) your consent, (c) compliance with legal obligations, and (d) our legitimate interests in providing and improving our services. You have the right to lodge a complaint with your local data protection authority.

10. Children's Privacy

Our services are intended for users aged 18 and older. We do not knowingly collect personal information from children under 18. If we become aware that we have collected data from a child under 18, we will take steps to delete that information.

11. International Data Transfers

Your data may be transferred to and processed in countries other than your country of residence, including the European Union and the United States. We ensure appropriate safeguards are in place for such transfers.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Effective date" above and, where appropriate, through in-app notifications. Continued use of our services after changes constitutes acceptance of the updated policy.

13. Apple App Store Users

If you downloaded Budy POS from the Apple App Store, the following additional terms apply:

  • Apple, Inc. is not a party to this Privacy Policy and is not responsible for Budy or its content.
  • Apple receives limited data through the App Store (download history, in-app purchases) governed by Apple's Privacy Policy.
  • You can manage iOS permissions (camera, Bluetooth, notifications, location) at any time via Settings → Budy on your device.
  • To revoke Budy's access to your Apple ID (if you signed in with Apple), go to Settings → [Your Name] → Sign in with Apple on your device.

14. Data Breach Notification

In the unlikely event of a data breach that may affect your personal information, we will notify affected users without undue delay and in accordance with applicable laws (including within 72 hours where required by GDPR).

15. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, contact us at:

Budy

Email: privacy@budy.app

Website: budy.app