Who we are
BuffyFlow (“BuffyFlow,” “we,” “us,” or “our”) is a mobile point-of-sale (POS), invoicing, and inventory application operated by Grapzian (Pvt) Ltd (“Company”).
Contact: support@grapzian.com · No 957/A/1, Paradise lane, Ragama · Website: buffyflow.grapzian.com
This Privacy Policy explains how we collect, use, store, share, and protect information when you use the BuffyFlow mobile app (Android/iOS) and related services (the “Service”).
Scope
This policy applies to:
- The BuffyFlow mobile application
- Account setup, business configuration, and optional cloud sync
- Communications related to the Service
It does not cover third-party websites, payment processors, or Google services beyond what we receive through Google Sign-In / Firebase.
1. Information we collect
A
Account & identity (Google Sign-In)
When you sign in with Google, we may receive:
- Google account identifier
- Name
- Email address
- Profile photo URL (if provided by Google)
We use Google Sign-In / Firebase Authentication. We do not receive or store your Google password.
B
Business & organization data
You or your organization may provide:
- Business/shop name and profile details
- Payment method preferences, bank details, VAT/tax identifiers (if entered)
- Invoice branding and display settings
- Organization/shop membership and plan-related settings
C
Operational / POS data (created by you)
Depending on how you use BuffyFlow, this may include:
- Products, SKUs, barcodes, prices, images, stock levels, batches
- Customers (e.g. name, mobile number, email, address, notes)
- Sales, quotations, invoices, payments, discounts, delivery amounts
- Inventory movements, restocks, adjustments
- Printer pairing preferences and similar device settings
Important: On Basic / offline use, much of this data is stored on your device. With paid cloud sync enabled, selected data may also be synced to our cloud systems.
D
Device & technical data
We may collect:
- Device identifiers generated by the app (e.g. install/device ID)
- Platform, OS version, model/manufacturer
- App version / build number
- Locale, timezone
- Approximate last-seen time for registered devices
- Push notification token (FCM/APNs), if notifications are enabled
- Basic diagnostics/crash/analytics events (when monitoring is enabled)
E
Network / sync metadata
When cloud features are enabled, we may process sync-related metadata such as sync status, timestamps, and conflict-resolution identifiers needed to keep devices consistent.
F
Permissions
With your permission, the app may access:
- Camera (product photos, barcode scanning)
- Photos/media (product images)
- Bluetooth (receipt/thermal printers)
- Notifications (alerts)
You can revoke permissions in device settings; some features may stop working.
2. How we use information
We use information to:
- Create and manage your account and organization
- Provide POS, inventory, invoicing, printing, and dashboard features
- Save data locally on your device and, where enabled, sync to the cloud
- Authenticate you securely via Google/Firebase
- Register devices for security, support, and (where applicable) plan/device limits
- Send push notifications you have allowed
- Improve reliability (crash reporting / analytics, if enabled)
- Comply with law and enforce our Terms
- Communicate service-related notices
We do not sell your personal information.
3. Legal bases (where applicable)
If required by applicable law (e.g. GDPR-style regimes), we process data based on:
- Contract — to provide the Service you requested
- Legitimate interests — security, fraud prevention, product improvement
- Consent — notifications, certain device permissions, optional analytics where required
- Legal obligation — where we must retain or disclose information by law
4. Where data is stored
On-device (local-first)
BuffyFlow is designed so sales, stock, and invoices can be stored locally on your phone/tablet first. Local storage may include databases and caches on the device.
Cloud (when enabled)
Depending on configuration and plan, we may use:
- Firebase (e.g. Authentication, configuration templates, monitoring)
- Supabase (e.g. organization/membership data and paid cloud sync of POS-related records)
Cloud infrastructure may be hosted in regions operated by those providers. Exact regions depend on our provider configuration.
6. Retention
- Account/profile data: while your account is active and as needed afterward for legal/security purposes
- Local device data: until you delete it in-app, clear app data, or uninstall (uninstall may not remove cloud copies)
- Cloud-synced business data: while your organization uses the Service and for a reasonable period after deletion/closure, unless law requires longer
- Device/push tokens: while the device is registered / active, and until refreshed or revoked
- Logs/diagnostics: for limited operational periods
If you request account deletion, we will delete or de-identify personal data we control, subject to legal retention needs and residual backups for a limited time.
7. Your choices & rights
Depending on your location, you may have rights to:
- Access, correct, or update your information
- Delete your account/data (in-app delete account flow may apply; irreversible)
- Export or receive a copy of certain data (where available)
- Withdraw consent (e.g. notifications/permissions)
- Object to or restrict certain processing
- Lodge a complaint with a supervisory authority
To exercise rights, contact support@grapzian.com. We may need to verify your identity.
Organization data: If you are a staff member, some requests may need to go through your business owner/admin.
8. Children
BuffyFlow is intended for business use by adults. We do not knowingly collect personal information from children under 16 (or the minimum age in your country). If you believe a child provided data, contact us to delete it.
9. Security
We use reasonable technical and organizational measures, including:
- Authentication via Google/Firebase
- Encrypted transit (HTTPS/TLS) for cloud communication
- Access controls and least-privilege practices for backend systems
- Local-device storage protections provided by the OS
No method of storage or transmission is 100% secure. Protect your Google account and device lock screen.
10. International transfers
If you access the Service from outside the country where our providers host data, your information may be transferred internationally. Where required, we rely on appropriate safeguards offered by our providers or applicable legal mechanisms.
11. Push notifications
If you enable notifications, we store a push token against your registered device to deliver messages (e.g. operational alerts). You can disable notifications in device settings; the token may remain until refreshed or cleared.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will revise the “Last updated” date and, where required, provide additional notice in the app or by email.
13. Contact
Privacy questions or requests: