Privacy Policy

Last updated: 12 June 2026

This Privacy Policy explains what information PEYEM collects, why, and how it is protected. It covers both the business users who sign in to the Service and the customer records those businesses keep inside their workspaces.

1. Information we collect

  • Account information — name, email address, role, and password (stored as a secure hash, never in plain text).
  • Business records — the products, sales, purchases, suppliers, and customer details your business enters while using the Service.
  • Technical data — logs needed to operate and secure the Service, such as request timestamps and approximate IP-based request origins used for rate limiting and audit trails.

2. How we use information

We use this information solely to provide the Service: authenticating logins, storing and displaying your business records, generating your reports, preventing abuse, and providing support. We do not sell personal data, and we do not use your business records for advertising.

3. Customer records you keep

When your business stores customer information (names, phone numbers, balances) in the Service, your business is the controller of that data and PEYEMprocesses it on your behalf. You are responsible for collecting it lawfully and honouring your customers' requests about it; we provide the tools to view, edit, export, and delete those records.

4. Tenant isolation

Every workspace's data is segregated by company at the database level (row-level security). Staff of one business cannot access another business's records, and role permissions inside a workspace limit who can see costs, profits, and settings.

5. Where data lives and who processes it

The Service runs on vetted infrastructure providers: our database and authentication are hosted by Supabase (PostgreSQL, EU region), the application is served by Netlify, code and encrypted backups are stored with GitHub, and rate limiting uses Upstash. Each provider processes data only as needed to run the Service.

6. Security

All traffic is encrypted in transit (HTTPS). Passwords are hashed. Database backups are encrypted before storage. Access to production systems is limited to the platform operator. No system is perfectly secure, but we apply current good practice and review security regularly.

7. Retention

Workspace data is retained while your account is active and during any paused period (e.g. after a trial ends) so you can resume without loss. Audit logs are kept for 12 months. Encrypted backups are kept for 30 days. After verified account closure and deletion request, workspace data is removed from the live database, and ages out of backups within the backup retention window.

8. Your rights

Subject to applicable law (including the Nigeria Data Protection Act), you may request access to, correction of, export of, or deletion of your personal data. Account owners can exercise these rights for their workspace directly in the app or by contacting support.

9. Cookies

The Service uses only essential cookies: keeping you signed in (authentication session) and a short-lived flag that reduces repeated permission checks. There are no advertising or cross-site tracking cookies.

10. Changes to this policy

We may update this policy as the Service evolves. Material changes will be announced through the Service or by email with reasonable notice, and the "last updated" date above will change.

Questions about this document? Contact internal system Your Company. See also our Terms of Service and Privacy Policy.