This Privacy Policy explains how expire365 (the "Service") collects, uses, and shares personal data when you use our website and app.
If you have questions, contact us through the Contact form. Where EU/EEA or UK GDPR applies, this Policy also describes your rights.
1. Who we are
The operator of expire365 is the data controller for personal data processed through the Service, unless we process data only on behalf of an organization customer as described below.
For organization accounts, the organization typically decides what inventory and team data are stored; in that case the organization is the controller and we act as a processor for that Customer Data.
2. Data we collect
Depending on how you use the Service, we may process:
- Account data: username, password hash, role, organization membership, and language preference
- Business / location data: store or home location names, addresses, and related settings you enter
- Inventory and product data: barcodes, names, quantities, expiry dates, SKUs, photos, and import/OCR document content
- Support messages: topic, message text, and optional email or phone (including guest contact without an account)
- Technical data: IP address, device/browser type, approximate timestamps, session cookies, and push-notification subscription endpoints
- Usage and security logs: sign-in attempts and important admin or inventory actions for security and abuse prevention
3. How we use data
We use personal data to:
- Provide, secure, and maintain the Service
- Authenticate users and manage team access
- Send expiry digests and other notifications you enable
- Respond to support requests
- Improve reliability, detect fraud or abuse, and meet legal obligations
4. Legal bases (GDPR)
Where GDPR applies, we rely on: performance of a contract (providing the Service you requested); legitimate interests (security, product improvement, basic analytics that do not override your rights); consent (for optional push notifications and similar optional features); and legal obligation when the law requires retention or disclosure.
5. Sharing
We do not sell your personal data. We may share data with:
- Infrastructure and hosting providers that process data on our instructions
- Members of your organization according to roles you configure
- Authorities when required by law or to protect rights and safety
- Professional advisors under confidentiality where needed
6. Cookies and local storage
We use essential cookies/local storage for session authentication and to remember your language preference. These are required for the Service to work as expected. We do not use third-party advertising cookies.
7. Retention
We keep account and Customer Data while your account is active and for a reasonable period afterward for backups, dispute resolution, and legal compliance. Support tickets are kept as long as needed to handle your request and for security records. You may request deletion subject to legal retention duties.
8. Security
We use technical and organizational measures appropriate to the risk, including hashed passwords and access controls. No method of transmission or storage is completely secure; please use a strong unique password and protect your devices.
9. International transfers
If we process or store data outside your country, we will use appropriate safeguards required by applicable law (such as standard contractual clauses) where needed.
10. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or objection to certain processing. Where we rely on consent, you may withdraw it at any time (for example by disabling notifications). You may also lodge a complaint with your local data protection authority (in Bulgaria: the Commission for Personal Data Protection).
To exercise rights, use the Contact form and describe your request. We may need to verify your identity.
11. Children
The Service is not directed to children under 16. Do not create an account for a child under that age. If you believe we have collected such data, contact us so we can delete it.
12. Changes
We may update this Privacy Policy. The "Last updated" date will change when we do. Material changes may also be signaled in the app or on the website.
13. Contact
Privacy requests: use the Contact form on the website or in the app. We will reply using the contact details you provide.