Legal

BuffyFlow Privacy Policy

How we collect, use, store, share, and protect information when you use the BuffyFlow mobile app and related services.

Last updated:
8 September 2026
Effective date:
8 September 2026

Who we are

BuffyFlow (“BuffyFlow,” “we,” “us,” or “our”) is a mobile point-of-sale (POS), invoicing, and inventory application operated by Grapzian (Pvt) Ltd (“Company”).

Contact: support@grapzian.com · No 957/A/1, Paradise lane, Ragama · Website: buffyflow.grapzian.com

This Privacy Policy explains how we collect, use, store, share, and protect information when you use the BuffyFlow mobile app (Android/iOS) and related services (the “Service”).

Scope

This policy applies to:

  • The BuffyFlow mobile application
  • Account setup, business configuration, and optional cloud sync
  • Communications related to the Service

It does not cover third-party websites, payment processors, or Google services beyond what we receive through Google Sign-In / Firebase.

1. Information we collect

A

Account & identity (Google Sign-In)

When you sign in with Google, we may receive:

  • Google account identifier
  • Name
  • Email address
  • Profile photo URL (if provided by Google)

We use Google Sign-In / Firebase Authentication. We do not receive or store your Google password.

B

Business & organization data

You or your organization may provide:

  • Business/shop name and profile details
  • Payment method preferences, bank details, VAT/tax identifiers (if entered)
  • Invoice branding and display settings
  • Organization/shop membership and plan-related settings

C

Operational / POS data (created by you)

Depending on how you use BuffyFlow, this may include:

  • Products, SKUs, barcodes, prices, images, stock levels, batches
  • Customers (e.g. name, mobile number, email, address, notes)
  • Sales, quotations, invoices, payments, discounts, delivery amounts
  • Inventory movements, restocks, adjustments
  • Printer pairing preferences and similar device settings

Important: On Basic / offline use, much of this data is stored on your device. With paid cloud sync enabled, selected data may also be synced to our cloud systems.

D

Device & technical data

We may collect:

  • Device identifiers generated by the app (e.g. install/device ID)
  • Platform, OS version, model/manufacturer
  • App version / build number
  • Locale, timezone
  • Approximate last-seen time for registered devices
  • Push notification token (FCM/APNs), if notifications are enabled
  • Basic diagnostics/crash/analytics events (when monitoring is enabled)

E

Network / sync metadata

When cloud features are enabled, we may process sync-related metadata such as sync status, timestamps, and conflict-resolution identifiers needed to keep devices consistent.

F

Permissions

With your permission, the app may access:

  • Camera (product photos, barcode scanning)
  • Photos/media (product images)
  • Bluetooth (receipt/thermal printers)
  • Notifications (alerts)

You can revoke permissions in device settings; some features may stop working.

2. How we use information

We use information to:

  • Create and manage your account and organization
  • Provide POS, inventory, invoicing, printing, and dashboard features
  • Save data locally on your device and, where enabled, sync to the cloud
  • Authenticate you securely via Google/Firebase
  • Register devices for security, support, and (where applicable) plan/device limits
  • Send push notifications you have allowed
  • Improve reliability (crash reporting / analytics, if enabled)
  • Comply with law and enforce our Terms
  • Communicate service-related notices

We do not sell your personal information.

4. Where data is stored

On-device (local-first)

BuffyFlow is designed so sales, stock, and invoices can be stored locally on your phone/tablet first. Local storage may include databases and caches on the device.

Cloud (when enabled)

Depending on configuration and plan, we may use:

  • Firebase (e.g. Authentication, configuration templates, monitoring)
  • Supabase (e.g. organization/membership data and paid cloud sync of POS-related records)

Cloud infrastructure may be hosted in regions operated by those providers. Exact regions depend on our provider configuration.

5. Sharing of information

We may share information with:

  • Service providers acting on our instructions (Firebase/Google, Supabase, hosting, analytics/crash tools, email)
  • Organization admins / members within your business account (they may see shared business/POS data)
  • Professional advisors or authorities when legally required
  • A buyer or successor if we undergo a merger, acquisition, or asset transfer (with notice where required)

We do not share customer/sale data with advertisers for third-party ads.

Third parties (Google, printer manufacturers, OS vendors) have their own privacy policies for their services.

6. Retention

  • Account/profile data: while your account is active and as needed afterward for legal/security purposes
  • Local device data: until you delete it in-app, clear app data, or uninstall (uninstall may not remove cloud copies)
  • Cloud-synced business data: while your organization uses the Service and for a reasonable period after deletion/closure, unless law requires longer
  • Device/push tokens: while the device is registered / active, and until refreshed or revoked
  • Logs/diagnostics: for limited operational periods

If you request account deletion, we will delete or de-identify personal data we control, subject to legal retention needs and residual backups for a limited time.

7. Your choices & rights

Depending on your location, you may have rights to:

  • Access, correct, or update your information
  • Delete your account/data (in-app delete account flow may apply; irreversible)
  • Export or receive a copy of certain data (where available)
  • Withdraw consent (e.g. notifications/permissions)
  • Object to or restrict certain processing
  • Lodge a complaint with a supervisory authority

To exercise rights, contact support@grapzian.com. We may need to verify your identity.

Organization data: If you are a staff member, some requests may need to go through your business owner/admin.

8. Children

BuffyFlow is intended for business use by adults. We do not knowingly collect personal information from children under 16 (or the minimum age in your country). If you believe a child provided data, contact us to delete it.

9. Security

We use reasonable technical and organizational measures, including:

  • Authentication via Google/Firebase
  • Encrypted transit (HTTPS/TLS) for cloud communication
  • Access controls and least-privilege practices for backend systems
  • Local-device storage protections provided by the OS

No method of storage or transmission is 100% secure. Protect your Google account and device lock screen.

10. International transfers

If you access the Service from outside the country where our providers host data, your information may be transferred internationally. Where required, we rely on appropriate safeguards offered by our providers or applicable legal mechanisms.

11. Push notifications

If you enable notifications, we store a push token against your registered device to deliver messages (e.g. operational alerts). You can disable notifications in device settings; the token may remain until refreshed or cleared.

12. Changes to this policy

We may update this Privacy Policy from time to time. We will revise the “Last updated” date and, where required, provide additional notice in the app or by email.

13. Contact

Privacy questions or requests:

support@grapzian.com

Grapzian (Pvt) Ltd

No 957/A/1, Paradise lane, Ragama

← Back to BuffyFlow