Privacy Policy

Last updated: June 24, 2026

Privacy Policy

Effective Date: June 24, 2026  ·  Version 1.0

At Dukana, your privacy is important to us. This Privacy Policy describes how we collect, use, store, and share information when you use the Dukana mobile application and related services ("Service"). By using our Service, you agree to the practices described in this policy.

1. Overview

Dukana is a store management platform designed to help small and medium business owners manage sales, inventory, customers, and team members. In the course of providing this Service, we collect and process certain personal and business data.

We are committed to:

  • Collecting only the data we need to provide the Service.
  • Never selling your personal data to third parties.
  • Giving you control over your data, including the right to access, correct, and delete it.
  • Using industry-standard security practices to protect your information.

2. Data We Collect

We collect data in the following categories:

a) Account & Identity Data

  • Name and email address (required for registration).
  • Profile photo (optional).
  • Authentication data (managed securely via Firebase Authentication).

b) Business Data (Your Data)

This is data you enter into Dukana to run your store:

  • Store name, description, and settings.
  • Products, categories, pricing, and inventory levels.
  • Sales records, including quantities, revenue, and cost of goods.
  • Customer names and contact information.
  • Team member names, email addresses, and assigned roles.

You retain full ownership of this data. We process it only to provide and improve the Service.

c) Usage & Technical Data

  • Device type, operating system version, and app version.
  • App feature usage patterns (to improve product experience).
  • Crash reports and error logs.
  • IP address and approximate location (country/region level).
  • Push notification tokens (for sending alerts like low-stock notifications).

d) Payment Data

Subscription payments are processed entirely through Apple App Store or Google Play Store. We do not collect or store your credit card number, bank account details, or payment card information. We receive only a subscription status confirmation from the app stores and RevenueCat.

3. How We Use Data

We use the data we collect for the following purposes:

  • Providing the Service: Storing and displaying your business data, processing sales, generating reports and dashboard insights.
  • Account Management: Creating and maintaining your account, authenticating your identity, and managing team members and permissions.
  • Notifications: Sending you push notifications such as low-stock alerts, daily summaries, and product updates (you can control these in app settings).
  • Improving the Service: Analyzing usage patterns and crash reports to fix bugs, improve performance, and develop new features.
  • Customer Support: Responding to your requests and resolving issues.
  • Legal Compliance: Meeting our legal obligations and enforcing our Terms of Service.

We do not use your data for targeted advertising, and we do not build advertising profiles based on your usage.

4. Data Sharing

We do not sell, rent, or trade your personal data. We share your data only in the following limited circumstances:

Service Providers

We work with trusted third-party providers who process data on our behalf, under strict data processing agreements:

  • Firebase (Google): Authentication, real-time database hosting, and push notifications.
  • RevenueCat: Subscription management and entitlement verification.
  • Cloud hosting providers: Secure storage and processing of your business data.

These providers are contractually obligated to use your data only to provide their services to us and not for their own purposes.

Within Your Workspace

Team members you invite to your Dukana workspace can see store data according to the permissions assigned to their role. As the workspace Owner, you control who has access and at what level.

Legal Requirements

We may disclose your information if required to do so by law, regulation, court order, or governmental authority, or when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, or investigate fraud.

Business Transfers

In the event of a merger, acquisition, or sale of all or substantially all of our assets, your data may be transferred. We will provide notice before your data is transferred and becomes subject to a different privacy policy.

5. Data Storage & Security

We take the security of your data seriously. We implement the following measures:

  • All data transmitted between the app and our servers is encrypted using TLS (Transport Layer Security).
  • Data at rest is encrypted using industry-standard encryption.
  • Authentication is handled via Firebase, which provides secure token-based authentication.
  • Access to production data is restricted to authorized personnel only.
  • We regularly review and update our security practices.

Despite our efforts, no system is 100% secure. If you believe your account has been compromised, please contact us immediately at support@dukana.app.

6. Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. Specifically:

  • Active accounts: We retain your data for the duration of your account and as needed to fulfill the purposes described in this policy.
  • Account deletion: When you delete your account, we delete or anonymize your personal data within 30 days, except where we are required to retain it for legal, compliance, or fraud-prevention purposes (typically up to 5 years).
  • Backups: Your data may persist in encrypted backups for up to 90 days after deletion, after which it is purged from all backup systems.

Business data (sales records, product data, etc.) associated with a deleted account is anonymized and may be retained in aggregate form for analytics purposes.

7. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your personal data ("right to be forgotten"). You can initiate this from Account Settings → Delete Account within the app.
  • Portability: Request an export of your data in a common machine-readable format.
  • Restriction: Request that we restrict the processing of your data in certain circumstances.
  • Objection: Object to the processing of your data for certain purposes.
  • Withdraw consent: Where processing is based on consent, withdraw that consent at any time.

To exercise any of these rights, contact us at privacy@dukana.app. We will respond within 30 days (or sooner, as required by applicable law).

If you believe we have not handled your data appropriately, you have the right to lodge a complaint with the relevant data protection authority in your jurisdiction.

8. Children's Privacy

Dukana is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children under 18. If we become aware that we have inadvertently collected such data, we will take steps to delete it promptly.

If you believe a child under 18 has provided us with personal information, please contact us at privacy@dukana.app.

9. Push Notifications

Dukana may send push notifications to your device for purposes such as:

  • Low-stock alerts for your products.
  • Daily or weekly business summary reports.
  • Important account or security notifications.
  • App updates and new feature announcements (where consented).

You can manage or disable push notifications at any time through your device settings or within the Dukana app under Settings → Notifications. Disabling certain types of notifications (such as low-stock alerts) may affect your experience of the Service.

10. Third-Party Services

The Service integrates with third-party services that have their own privacy practices:

We encourage you to review the privacy policies of these third parties to understand how they handle your data.

11. International Data Transfers

Your data may be processed and stored on servers located outside of your country of residence. By using Dukana, you consent to the transfer of your data to servers in other jurisdictions, which may have different data protection laws than your own.

Where applicable, we implement appropriate safeguards such as standard contractual clauses to ensure that international data transfers are compliant with applicable data protection laws.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page.
  • Notify you via push notification or in-app message for significant changes.

We encourage you to review this policy periodically. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.

13. Contact Us

If you have questions, concerns, or requests related to this Privacy Policy or how we handle your data, please contact us:

We are committed to resolving privacy concerns promptly and will respond to your request within 30 days.