1. Introduction
Welcome to Zufan ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application (the "App"). Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the App.
2. Information We Collect
2.1 Personal Information
We may collect the following personal information:
- Account Information: Name, email address, phone number when you create an account or use Google Sign-In
- Company Information: Company name, business details, VAT information, and related business data
- Financial Information: Bank account details, transaction records, payment information, and financial data you enter into the App
- Contact Information: Contact names and phone numbers from your device's contact list (with your permission)
2.2 Automatically Collected Information
- SMS Messages: We read SMS messages from your device (with your permission) to automatically record bank transactions. This includes transaction amounts, dates, account numbers, and balances from SMS notifications sent by your bank.
- Device Information: Device type, operating system, unique device identifiers, and app version
- Usage Data: How you interact with the App, features used, and time spent in the App
2.3 Media and Files
- Images: Photos you take or select from your gallery for:
- Receipt scanning and OCR processing
- Product and inventory images
- Payment proof documentation
- Company logo and branding
3. How We Use Your Information
We use the collected information for the following purposes:
- Transaction Management: To automatically record and track your financial transactions from SMS notifications
- Financial Tracking: To provide balance tracking, expense categorization, and financial reporting
- Payment Processing: To facilitate payment requests, reminders, and loan management
- Inventory Management: To manage products, variants, stock levels, and inventory movements
- Receipt Processing: To scan and extract data from receipts using OCR technology
- User Communication: To send notifications, payment reminders, and important updates
- App Functionality: To provide, maintain, and improve the App's features and services
- Account Management: To authenticate users, manage accounts, and provide customer support
4. Permissions We Request
The App requires the following permissions to function properly:
4.1 SMS Permissions
- READ_SMS / RECEIVE_SMS: To automatically read and process SMS messages from banks for transaction recording. This permission is only used when you enable auto-recording in the App settings.
4.2 Camera Permission
- CAMERA: To take photos for receipt scanning, product images, and payment proof documentation.
4.3 Storage Permission
- READ_EXTERNAL_STORAGE: To access photos from your gallery for uploading receipts, product images, and other documents.
4.4 Contacts Permission
- READ_CONTACTS: To allow you to select contacts when sending payment requests or recording payments. Contact information is only accessed when you explicitly choose to use this feature.
4.5 Notification Permission
- POST_NOTIFICATIONS: To send you important notifications about transactions, payment reminders, and app updates.
5. Data Storage and Security
5.1 Cloud Storage
Your data is stored securely using:
- Firebase Services: We use Google Firebase for:
- Firestore Database: For storing your transactions, products, inventory, and business data
- Firebase Storage: For storing images (receipts, product photos, payment proofs)
- Firebase Authentication: For secure user authentication
- Firebase Cloud Messaging: For push notifications
- Local Storage: Some data is stored locally on your device for offline access and performance
5.2 Data Security
We implement appropriate technical and organizational security measures to protect your information, including:
- Encryption of data in transit and at rest
- Secure authentication using Firebase Authentication
- Access controls and user authentication
- Regular security audits and updates
6. Data Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:
- Service Providers: With trusted third-party service providers (such as Google Firebase) who assist us in operating the App and providing services
- Legal Requirements: When required by law, court order, or government regulation
- Business Transfers: In connection with a merger, acquisition, or sale of assets (with notice to users)
- With Your Consent: When you explicitly consent to sharing your information
7. Your Rights and Choices
You have the following rights regarding your personal information:
- Access: You can access and view your data within the App
- Correction: You can update or correct your information through the App settings
- Deletion: You can request deletion of your account and associated data by contacting us
- Permission Control: You can grant or revoke permissions through your device settings
- Auto-Recording Control: You can enable or disable SMS auto-recording in the App settings
- Data Export: You can export your transaction and financial data from the App
8. Data Retention
We retain your information for as long as necessary to provide our services and comply with legal obligations:
- Active Accounts: Data is retained while your account is active
- Deleted Accounts: Data may be retained for up to 30 days after account deletion for recovery purposes, then permanently deleted
- Legal Requirements: Some data may be retained longer if required by law (e.g., financial records for tax purposes)
9. Children's Privacy
The App is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.
10. Third-Party Services
The App uses the following third-party services:
- Google Firebase: For data storage, authentication, and cloud services. See Google's Privacy Policy
- Google Sign-In: For user authentication. See Google's Privacy Policy
- OCR Services: For receipt scanning and text extraction (if applicable)
These third-party services have their own privacy policies. We encourage you to review them.
11. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country. By using the App, you consent to the transfer of your information to these countries.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. You are advised to review this Privacy Policy periodically for any changes.
14. Consent
By using the App, you consent to our Privacy Policy and agree to its terms. If you do not agree with this policy, please do not use the App.