Privacy Notice
Last updated: 31 July 2026
This notice explains how Hargeisa apps development ("we", "us") handles personal data in the Hargeisa Apps Development application. We act as the data controller for the personal data described below. Where you use the app to store data about your own customers, you are the controller of that data and we process it on your behalf.
Data we collect
- Account data: name, username, email address, phone number, business name and role.
- Authentication data: hashed credentials, two-factor settings, trusted-device records, sign-in events.
- Business content you enter: sales, invoices, receipts, inventory, suppliers, expenses and customer records.
- Support messages you send us.
- Technical and usage data: device and browser information, IP address, approximate location derived from IP, activity and audit logs, and synchronisation status.
Why we use it and our legal basis
- Creating and administering accounts and providing the Service — performance of our contract with you.
- Billing and subscription management — performance of our contract and legal obligation.
- Security, fraud prevention, admin monitoring and audit logging — our legitimate interest in keeping the Service and your business data secure.
- Customer support — performance of our contract and our legitimate interest in supporting users.
- Improving reliability and features — our legitimate interest, using aggregated or minimal data.
- Service and marketing emails — contract performance, or consent where required.
Who we share data with
- Service providers and subprocessors: our cloud hosting, database, storage and email delivery providers.
- Paddle.com, our Merchant of Record, for the sale of subscriptions, payments, subscription management, invoicing and tax compliance.
- Professional advisers such as legal and accounting advisers, where necessary.
- Public authorities where we are required to do so by law.
We do not sell personal data.
Retention
We keep account and business data for as long as your account is active, and for up to 30 days after termination so you can request an export, after which it is deleted or anonymised. Deleted business accounts are held in a recycle bin for 24 hours before permanent removal. Security, audit and billing records are kept for as long as needed to meet legal and accounting obligations.
Your rights
Subject to applicable law, you may request access to your personal data, correction of inaccurate data, deletion, restriction of processing, portability, and you may object to processing based on legitimate interests or withdraw consent where consent applies. Contact support@hargeisapps.app and we will respond within one month. If you are in the UK or EEA you may also complain to your local supervisory authority.
International transfers
Our providers may process data outside your country, including outside the UK and EEA. Where that happens we rely on appropriate safeguards such as standard contractual clauses or adequacy decisions.
Security
We apply appropriate technical and organisational measures, including encryption in transit, row-level access controls in our database, role-based permissions, optional two-factor authentication, automatic session timeout and audit logging.
Cookies and local storage
We use strictly necessary cookies and browser storage to keep you signed in, remember trusted devices, and store data locally so the app works offline. We do not use advertising cookies. You can clear this data in your browser settings, though the app may stop working offline.
Contact
Hargeisa apps development — support@hargeisapps.app.
