Privacy Policy
This Privacy Policy explains how the Hopfen Seller mobile application (“App”) and its backend services process personal data of users—sales staff acting on behalf of Hopfen (“we”, “Operator”).
1. Who may use the App
The App is for authorized employees (sellers) only. Accounts are created by an employer administrator. Self-registration is not available.
2. Data we collect and why
2.1. Account and authentication
- Login and password (you enter) — sign-in. Passwords are stored hashed on the server.
- Full name, role, assigned warehouse (from server/admin) — identification and access control.
- Access and refresh tokens — session management. Tokens on the device are stored in secure storage (Flutter Secure Storage).
2.2. Sales and catalog operations
- Barcode / product code (from camera or manual entry) — product lookup. Barcode scanning runs on device; we do not upload camera images to the server for scanning—only the recognized product code.
- Product details, quantity, price, sale amount, timestamp, warehouse, seller name — sales recording and employer reporting.
- Product photos may be downloaded from our server for display when available in the catalog.
2.3. Work status and location
When you set status to “At work”, the App may request location permission (while using the App) and send to the server:
- latitude and longitude;
- status and change time;
- calculated distance to your assigned warehouse (worksite check).
Location is not collected continuously in the background and is not used for advertising. Denying permission may prevent setting “At work” per employer rules.
Status history is stored on the server and visible to administrators.
2.4. Technical data
Standard network data (IP address, request time, client type) is processed for security, stability, and troubleshooting.
3. Device permissions
| Permission | Purpose |
|---|---|
| Internet | API communication |
| Camera | Barcode scanning |
| Location (when in use) | “At work” status and warehouse distance check |
The App does not request contacts, SMS, microphone, or photo library upload for personal photos.
4. Legal bases (GDPR / applicable law)
- Performance of employment / contract with employer (sales records, attendance rules where applicable).
- Legitimate interests (security, fraud prevention).
- Consent where required (e.g., OS location permission dialog).
5. Storage and sharing
- Data is stored on Operator-controlled servers Ukraine.
- Authorized employer administrators access data via a web admin panel.
- We do not sell personal data.
- No third-party advertising or analytics SDKs in the current App version.
- Processors (hosting, IT support) may process data under confidentiality agreements.
6. Retention
- Account: while employment is active or until deleted by admin.
- Sales and status history: per employer record-keeping policy and law.
- On-device tokens: until logout or App removal.
7. Your rights
Depending on applicable law, you may request access, correction, restriction, or deletion, and lodge a complaint with your data protection authority (e.g., Ukrainian DPA).
Contact: mail@hopfen.ua. Account changes may also require your employer’s administrator.
8. Security
We use HTTPS, password hashing, and access controls. No method of transmission is 100% secure.
9. Children
The App is not directed at children under 16 and does not knowingly collect their data.
10. Changes
We may update this Policy. The current version is always available at the published URL of this page.