Privacy Policy
Last updated: 1 September 2026
1. Information we collect
1.1 Information you provide
Account and business details:
- Business name and profile details you choose to add.
- Owner and staff names, email addresses and, optionally, phone numbers.
- The sign-in method you use — password, email one-time code, WhatsApp, or Google sign-in.
- Your password, if you set one — stored only as a bcrypt hash, never in readable form. We cannot recover it.
- Passkey credentials, if you enable biometric sign-in or the app lock — only the public key and credential ID issued by your device. The private key and your fingerprint or face data never leave your device and are never sent to us.
- Your WhatsApp phone number, if you sign in or verify a number over WhatsApp (see section 3.3).
- Role assignments within your business (owner, staff).
Operational data you enter:
- Orders and order line items, including status history and timestamps.
- Vendor and customer records — names, contact numbers, categories, notes.
- Deliveries and goods-receipt records, including any photos you upload.
- Invoices, payments and statement data.
- Uploaded files: purchase order PDFs, invoice files and delivery photos.
Billing information (paid plans):
- Billing name, email and country, collected at checkout by Paddle.
- Card and payment details are handled entirely by Paddle as merchant of record. They are never sent to, or stored on, our servers.
- We receive only subscription and transaction status from Paddle — plan, renewal date, and whether a payment succeeded.
1.2 Information collected automatically
- Server logs: IP address, request path, user agent and timestamps, used to operate, debug and secure the Service.
- Session cookie: a single cookie that keeps you signed in.
- Web-push subscription details (a browser-issued endpoint and keys) — only if you turn on notifications.
We do not use advertising cookies or cross-site tracking pixels. With your consent (the cookie banner), we use Google Analytics to understand how the Service is used — see section 8.
2. How we use your information
- To provide the Service — store and display your orders, vendors, customers, deliveries, invoices and payments, and keep your team's access working.
- To authenticate you — send one-time sign-in codes and team invitations by email, and maintain your session.
- To let you share documents — generate secure expiring links to purchase orders and statements, and pre-fill WhatsApp messages you send from your own device.
- To notify you — optional web-push notifications about order activity, if you enable them.
- To bill you — manage your subscription on a paid plan.
- To secure and improve the Service — detect abuse, debug faults and understand which features are used.
Legal bases (GDPR): performance of a contract (providing the Service), legitimate interests (security, service improvement), consent (push notifications) and legal obligation (tax and accounting records).
4. Tenant isolation
OrderBookApp is multi-tenant: many businesses share one system. We isolate your data from every other business by:
- Database-level row-level security (RLS) in PostgreSQL — every request runs under a restricted database role with your business's tenant context, so rows belonging to other businesses are not returned even if application code is wrong.
- Two-sided access rules — a business can see an order only where it is the buyer or the vendor on that order.
- Application-level checks — authentication and role checks validate business membership on every request.
- Scoped file access — uploaded files are served through authenticated, per-business checks or through expiring share links you create deliberately.
5. Security
- In transit: all traffic is served over HTTPS/TLS.
- At rest: database and object storage are encrypted by our infrastructure providers.
- Authentication: passwordless one-time codes or Google sign-in; session cookies are HTTP-only, secure and same-site.
- Access control: owner and staff roles limit what each user can see and do inside your business.
- Application hardening: input validation, parameterised queries, CSRF and rate-limiting protections on sensitive routes.
No method of transmission or storage is completely secure. If a breach affects your personal data, we will notify affected users and, where applicable, the relevant supervisory authority within 72 hours of becoming aware of it.
6. Data retention and deletion
- While your account is active: we keep your data so the Service works.
- Deleting your account: you can delete it any time under Settings → Delete account. This removes your user record and personal data. If you cannot sign in, see orderbookapp.com/delete-account for an email-based deletion request.
- Last user of a business: the business and the records it owns are removed as well.
- Shared orders: where another business still holds its own side of an order with you, your identifying details are erased while that counterparty's own records are preserved — they need them for their books.
- Backups: residual copies may persist in encrypted backups for a short period before being overwritten.
- Financial records: billing and tax records may be retained for up to 7 years where law requires it; invoices raised through Paddle are also retained by Paddle.
7. Your rights
7.1 For users in the EU/EEA and UK (GDPR)
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data; most fields are editable directly in the app.
- Erasure — delete your account and personal data.
- Portability — receive your data in a machine-readable format.
- Objection and restriction — object to processing based on legitimate interests, or ask us to restrict it.
- Withdraw consent — turn off push notifications at any time in your browser or device settings.
7.2 For users in California (CCPA/CPRA)
- The right to know what personal information we collect and how it is used.
- The right to delete personal information.
- The right to opt out of sale or sharing — note that we do not sell or share personal information.
- The right not to be discriminated against for exercising these rights.
To exercise any of these rights, email [email protected]. We respond within 30 days (GDPR) or 45 days (CCPA).
9. International transfers and children
Our infrastructure and service providers may process data in countries other than your own. Where personal data is transferred out of the EU/EEA or UK, we rely on the Standard Contractual Clauses or an equivalent safeguard offered by the provider, together with encryption in transit and at rest.
OrderBookApp is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16 (or the minimum age set by your local law).
10. Changes and contact
We may update this policy. Material changes will be notified by email or in-app notice, and the "Last updated" date at the top of this page will change. Continued use after the change takes effect constitutes acceptance.
- Privacy and support: [email protected]
- Website: https://orderbookapp.com
- Related policies: Terms of Service and Billing & Refund Policy
Questions about this page? Email [email protected]. Version 1.0 — last updated 1 September 2026.