Privacy Policy
Última actualización: September 4, 2026
Este documento está disponible en inglés.
This Privacy Policy explains what personal data Invenva collects when you use the Invenva app for iPhone and iPad, the Invenva web app and the invenva.com website, why we collect it, who we share it with and what rights you have. We never sell personal data and we run no advertising. The English version of this policy is the binding version.
1. Who is responsible
Invenva (the Service) is operated by Individual Entrepreneur Baran Yildiz, registered in Georgia (we, us, the controller). This policy covers the Invenva iOS app, the Invenva web app at invenva.com/app and the invenva.com website. Questions and privacy requests go to support@invenva.com.
2. Account data
You sign in with Apple or Google. Those providers give us your name, your email address (Apple may give a private relay address instead) and, with Google, your profile photo. You may add a contact email and a profile photo of your own; these are shown to the members of your workspaces. We store a unique account identifier, the time of your sign-ups and sign-ins, your app language and your time zone.
3. Inventory content
Everything you enter to run your business is stored for you: workspaces and their settings, items with quantities, prices, barcodes, SKUs, photos, notes, tags and custom fields, a shelf or location label and, if you place one, a map pin, every stock movement with who made it and when, stock counts, orders and stock lists, the names of customers, suppliers and other people you record, and the balances and loans you keep with them. This content belongs to you. For the personal data of your own customers, suppliers and staff that you type into Invenva you are the controller and we process it on your behalf, only to provide the Service.
4. Technical data
To deliver alerts we store push notification tokens for each device or browser you enable them on, together with the language and time zone used to send them at the right hour and in your language. The iOS app sends crash reports (app version, device model, operating system version and the state of the app at the crash) to Firebase Crashlytics. Our servers and Cloudflare keep short-lived request logs that include IP addresses for security. Integrity checks (Apple App Attest and DeviceCheck in the iOS app, Cloudflare Turnstile in the web app, Firebase App Check on both) confirm that requests come from a genuine copy of Invenva; they do not identify you personally.
5. Usage data
We record how the Service is used so we can see where people get stuck and improve it: which screens are opened, which actions are taken, how long steps take, errors, and counts and flags such as how many items a workspace holds or whether a photo was attached. The names of custom fields you create are recorded because they tell us which features are missing. We never record item names, prices, quantities, customer or supplier names, search text, notes or any other content you type. This data is stored with your account, kept for 120 days and reviewed only in aggregate or to understand a problem you reported. The iOS app also sends anonymous aggregate events to Firebase Analytics; the website and the web app run no analytics at all.
6. Payments
Purchases made inside the iOS app are processed by Apple under Apple’s privacy policy; we receive only your subscription status and an anonymous transaction identifier, never your payment details. Purchases made on invenva.com are processed by Paddle, our merchant of record, which collects your email address, billing country and address, payment details and tax information under Paddle’s own privacy policy; we receive your email, country, subscription status and a transaction reference, never your card number. RevenueCat keeps the subscription status of your account so that a subscription bought on one platform works on the other. Purchase records are kept by Apple, Paddle and us for as long as tax and accounting law requires.
7. Camera, photos and location
Barcode scanning uses the camera on your device or in your browser; frames are analysed on the device and are never stored or sent to us. Photos you attach to items or to your profile are uploaded to our storage and shown to the members of your workspace. A map pin is stored only when you place one yourself; in the web app the browser asks for your location only when you tap “My location”, and we keep just the coordinates you save. You can revoke camera, photo and location permissions in your device or browser settings at any time.
8. Messages you send us
Support requests, feedback and “what is missing” messages are stored with the text you wrote, the time, your app version and platform and, if you were signed in or chose to give one, your account or email address so we can reply. Feedback can be sent without an account. We keep these messages for up to two years.
9. Why we process data and on what basis
We process data to operate, sync and secure the Service, to keep a shared history for your team, to send the alerts you enabled, to confirm subscriptions, to answer you, to improve the product and to meet legal duties. Where the GDPR or similar laws apply, our legal bases are: performance of our contract with you (the account, inventory content, sync, subscriptions); our legitimate interests in keeping the Service secure and reliable and in understanding how it is used (technical data, usage data, crash reports, abuse prevention); your consent (push notifications, camera, photos, location, which you can withdraw at any time); and compliance with legal obligations (tax and accounting records, lawful requests). We make no decisions about you by automated means that have legal or similarly significant effects, and we do not profile you for advertising.
10. Who can see your data
Members of a workspace you belong to see your name, profile photo, contact email, role and the actions you take in that workspace, including the history entries that carry your name. The workspace owner and admins control who is a member and what each member may do; a person joining with an invite code or link starts as a viewer. When you leave a workspace or delete your account, the history of that workspace keeps your name on the entries you made so the team’s records stay complete. When you transfer stock between two of your workspaces, the item’s details are copied to the destination workspace.
11. Service providers
We use a small number of providers who process data on our instructions under data processing agreements. Google LLC (Firebase): sign-in, the Firestore database, server functions, push delivery, crash reports, App Check and the analytics named above, and the storage of photos uploaded before September 2026; data is held in Google Cloud data centres in the United States and other regions. Cloudflare, Inc.: hosting of the website and the web app, network security and bot protection (Turnstile), and the storage and delivery of item and profile photos (R2, served from photos.invenva.com) across Cloudflare’s global network. Apple Inc.: Sign in with Apple, App Store payments and push delivery to Apple devices. Google: Sign in with Google. Paddle.com Market Ltd (United Kingdom) and Paddle.com Inc. (United States): merchant of record for purchases on invenva.com, acting as an independent controller for payment and tax data. RevenueCat, Inc. (United States): subscription status across platforms, keyed on your account identifier. We may also disclose data when the law requires it, to protect the rights and safety of users or of the Service, or to a successor if the Service is transferred in a merger, acquisition or sale of assets, in which case this policy continues to apply.
12. Cookies and browser storage
The invenva.com website sets no cookies of its own and runs no analytics, advertising or tracking scripts. The web app keeps your sign-in session, an offline copy of your workspace data and your preferences (language, theme, remembered filters and drafts) in your browser’s local storage and IndexedDB so it can start instantly and work without a connection; this storage is strictly necessary to provide the Service, is not shared with anyone and is cleared when you sign out or clear the site’s data in your browser. Cloudflare may set a strictly necessary security cookie to distinguish people from bots. The checkout on invenva.com runs in a frame provided by Paddle and uses cookies under Paddle’s policy. Because we use no non-essential cookies we do not show a consent banner; if that ever changes we will ask for your consent first.
13. Notifications
Low stock, expiry, delivery and payment reminders are sent only if you turn notifications on. iOS notifications are delivered through Apple, browser notifications through Firebase Cloud Messaging; some reminders are scheduled locally on the device that created them and never leave it. You can turn notifications off in the app’s or browser’s settings or in your device settings at any time, and the token for a device is removed when you sign out or delete your account.
14. International transfers
We are established in Georgia and our providers process data in the United States and other countries. Where data of people in the European Economic Area, the United Kingdom or Switzerland is transferred outside those areas, we rely on providers that are certified under the EU-US, UK and Swiss-US Data Privacy Frameworks or on the European Commission’s Standard Contractual Clauses and equivalent UK and Swiss safeguards. You can ask us for details of the safeguards used.
15. Retention and deletion
We keep your data for as long as your account is active. Items and lists you delete are kept as deleted markers for 60 days so that every device in the workspace learns of the deletion, then removed permanently. Usage sessions are removed after 120 days and crash reports after 90 days; server request logs are kept for a few weeks. You can delete your account in Settings on either platform: this removes your profile, your sign-in identity, your usage sessions and notification tokens, and every workspace you alone own together with its items, history, lists, counts, balances, loans and photos. Workspaces that have other members are not deleted, because the data belongs to that team; you must leave them or hand them over first. Purchase records held by Apple, Paddle and us, and messages you sent us, are kept for the periods stated above. Backups are overwritten within 30 days.
16. Your rights
Depending on where you live, and in particular under the GDPR and UK GDPR, the Turkish Personal Data Protection Law (KVKK), the Brazilian LGPD and the California Consumer Privacy Act, you have the right to access the personal data we hold about you, to correct it, to have it deleted, to restrict or object to its processing, to receive it in a portable form, to withdraw a consent you gave, and to complain to your data protection authority. Most of this you can do yourself: your name, photo and contact email are edited in your profile, your inventory can be exported to Excel or PDF from the app, and your account can be deleted in Settings. For anything else write to support@invenva.com; we may ask you to confirm your identity and we answer within one month. We do not sell personal data and do not share it for cross-context behavioural advertising, so there is nothing to opt out of; we do not discriminate against anyone for exercising their rights. If you are a member of someone else’s workspace, some requests about that workspace’s data must go to its owner, who controls it.
17. Security
All connections are encrypted in transit and our providers encrypt data at rest. Access to a workspace is enforced by server-side security rules that check your membership and role on every request, sensitive team changes run through server functions rather than the client, photo uploads are verified against your membership, and integrity checks keep tampered clients out. Our staff access is limited to what is needed to run the Service and to help you. No system is perfectly secure, so please keep your Apple or Google account protected and tell us at support@invenva.com if you believe your account has been misused.
18. Children
Invenva is a business tool and is not intended for anyone under 16. We do not knowingly collect data from children; if you believe a child has created an account, contact us and we will delete it.
19. Changes to this policy
We may update this policy as the Service changes. The date at the top shows the current version. For material changes we will give notice in the app, on the website or by email before they take effect.
20. Contact
Individual Entrepreneur Baran Yildiz, Georgia. Email: support@invenva.com. Please include the email address of your Invenva account so we can find your data.