This Privacy Policy explains how POPPIFY collects, uses, stores, shares, and protects your information. Where Bhutanese law does not yet specify a particular data-protection requirement, this policy follows internationally accepted marketplace privacy standards as an operating standard POPPIFY has chosen to follow.
1. Introduction
This Privacy Policy explains how POPPIFY ("POPPIFY," "we," "us," or "our") collects, uses, stores, shares, and protects information when you use the POPPIFY mobile application and related services (the "Platform"). POPPIFY is a marketplace platform based in the Kingdom of Bhutan that connects verified businesses with customers for browsing, ordering, and communicating about products and services.
By creating an account or otherwise using the Platform, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with this policy, please do not use the Platform.
This policy applies to both Customer accounts and Business accounts. Where a section applies only to one account type, that is stated explicitly.
2. Information We Collect
We collect information in three ways: information you give us directly, information generated automatically as you use the Platform, and information created through your activity on the Platform (such as orders and messages). The categories below describe what we collect and why.
Profile Information. When you create an account, we collect your full name, email address, and phone number. Customers may also add a profile photo, saved delivery addresses (including dzongkhag/district), and notification preferences.
Contact Information. Phone numbers and email addresses you provide — including a business's public contact phone, email, and website shown on its storefront — are used to enable communication between customers, businesses, and POPPIFY support, and to deliver account-related and transactional notifications.
Bhutan CID Collection. Businesses applying for verification must submit the business owner's Citizenship Identity Document (CID) number and a photo or scan of the CID card. We collect this to confirm that a business is operated by a real, identifiable person, which is core to the trust and safety promise of the Platform. CID information is used solely for identity verification and is never displayed publicly on a business's storefront or shared with other users.
Business License Collection. Businesses must submit their business registration number, license expiry date, and a photo or scan of their business license as part of verification. This confirms the business is a legitimate, registered entity in Bhutan.
Business Verification Documents. In addition to the CID and license, we may collect store photographs, the business address, GPS coordinates, and other supporting documents submitted during the verification process. All verification documents are securely stored and used solely for identity verification, fraud prevention, regulatory compliance, and maintaining marketplace trust. They are reviewed by authorized POPPIFY administrators only.
Payment Screenshots, Journal IDs, and Transaction IDs. POPPIFY does not process or hold funds (see Section 3). When a customer pays a business directly via bank QR transfer, the customer may upload a screenshot of the payment confirmation and enter the bank journal reference number or transaction ID so the business can verify the payment was received. This information is shared with the business the payment was made to, and is retained as a transaction record for both parties and for POPPIFY's fraud-prevention and dispute-resolution purposes.
Uploaded Images. We collect images you choose to upload, including profile photos, business logos and cover photos, product and service photos, store photos, chat image attachments, and payment screenshots. Product, service, and storefront images are public by design. Chat images and payment screenshots are only visible to the sender, the recipient, and, where necessary, POPPIFY staff investigating a report or dispute.
Order History. We retain records of orders you place or receive, including items ordered, quantities, prices, fulfillment method, delivery address (for delivery orders), order status history, and any notes exchanged about the order.
Chat Messages. Messages, images, and shared product/order references sent through in-app chat between a customer and a business are stored so the conversation history remains available to both parties. POPPIFY does not read chat messages except when investigating a report, a legal request, or a security incident.
Reviews. When you submit a review or rating for a business, the review text, star rating, and your display name are stored and shown publicly on the business's storefront. Businesses may publicly respond to reviews.
Saved Businesses and Saved Products. We store the businesses and products you bookmark so you can find them again from your account.
Device Information. We automatically collect limited technical information such as device type, operating system and version, app version, and a device identifier used to deliver push notifications. This information helps us diagnose crashes, secure accounts, and ensure the app functions correctly on your device.
Analytics. We may collect aggregated, non-identifying usage data (such as which screens are used most and how often) to understand how the Platform is used and to improve it. Analytics data is used in aggregate and is not used to build an individual advertising profile of you, and POPPIFY does not sell personal data to advertisers.
Push Notifications. If you enable notifications, we collect a device push token (via Firebase Cloud Messaging) used solely to deliver order updates, chat message alerts, and account notifications to your device. You can disable push notifications at any time in your device settings or in-app Notification Preferences.
3. POPPIFY Does Not Process or Hold Your Payments
POPPIFY is not a payment processor and is not the merchant of record for any transaction. Payments are made directly between customers and businesses using Bhutanese bank QR-code transfers or other methods the business accepts. POPPIFY never receives, holds, or has access to your banking credentials, card numbers, or bank account balances. The payment screenshots, journal IDs, and transaction IDs described above are proof-of-payment records exchanged between customer and business through the Platform — they are not payment instructions and do not give POPPIFY the ability to move funds.
If POPPIFY introduces an integrated payment gateway in the future, this Privacy Policy will be updated in advance to describe what additional payment data would be collected and how it would be protected, and your continued use of any such feature will be subject to that updated disclosure.
4. How We Use Your Information
We use the information described above to:
- Create and manage your Customer or Business account
- Verify business identity and legitimacy before a storefront goes live
- Enable browsing, ordering, and direct communication between customers and businesses
- Display order status, send order and shipment notifications, and support customer service
- Facilitate reviews and ratings
- Detect, investigate, and prevent fraud, scams, counterfeit listings, and abuse
- Respond to support requests, reports, and legal obligations
- Maintain the security, integrity, and reliability of the Platform
- Improve features based on aggregate usage patterns
5. Third-Party Services
POPPIFY relies on the following third-party service providers to operate the Platform. Each provider processes data only as necessary to provide its service to POPPIFY and is bound by its own privacy and security terms.
Supabase (database, authentication, file storage, and realtime messaging infrastructure). Supabase hosts our production database, user authentication records, uploaded files (verification documents, product images, chat media, payment screenshots), and powers realtime features like chat and live order status. Row Level Security is enabled on every table so that, at the database level, users can only access data they are authorized to see.
Firebase Cloud Messaging (push notifications). Firebase delivers push notifications to your device using a device token generated by your device — Firebase does not receive your name, email, or in-app content as part of this process.
Resend (transactional email). Resend sends account-related emails such as email confirmation and password-reset codes. Resend processes your email address solely to deliver these messages.
We do not sell your personal information to third parties, and we do not share your personal information with advertisers for targeted advertising purposes.
6. Future Payment Providers
POPPIFY may in the future integrate a licensed third-party payment gateway to offer in-app payment processing as an option alongside direct bank transfers. Should this happen, any payment provider we integrate will be a regulated financial service provider, and this Privacy Policy will be updated to disclose what data that provider would collect (which may include card or account details processed directly by the provider, not by POPPIFY) before the feature becomes available to you.
7. Security Measures
We apply industry-standard safeguards to protect your information, including:
- Encryption of data in transit (HTTPS/TLS) between the app and our servers
- Row Level Security policies on every database table, enforced at the database level so a user's access is restricted to their own data (or data they are authorized to see, such as a business viewing orders placed with it) regardless of how a request is made
- Private storage buckets for sensitive files such as verification documents and payment proofs, accessible only to authorized parties
- Authentication via Supabase Auth with hashed, salted password storage — POPPIFY never stores your password in plain text and cannot see it
- Restricted administrative access — verification documents and reports are reviewed only by authorized POPPIFY administrators
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a data breach affecting your personal information, we will take reasonable steps to notify affected users and relevant authorities as required by applicable law.
8. Data Retention
We retain personal information for as long as your account is active and as needed to provide the Platform to you. Specifically:
- Account and profile information is retained for the life of your account
- Order history, payment proof records, and transaction records are retained after order completion to support dispute resolution, accounting, and fraud investigation, and to comply with applicable recordkeeping obligations
- Business verification documents (CID, business license, supporting documents) are retained for the duration of the business's active status on the Platform and for a reasonable period afterward to support regulatory and fraud-prevention needs
- Chat messages are retained for as long as the related conversation exists, unless deleted by a party to the conversation (deletion removes the message from view; see Section 9)
We may retain limited data beyond account deletion where necessary to comply with a legal obligation, resolve a dispute, enforce our agreements, or prevent fraud, as described in Section 9.
9. Data Deletion
You may request deletion of your account and associated personal data at any time using the Delete Account option in your Profile. Deletion requests are reviewed and approved by a POPPIFY administrator before they take effect. Once approved, your account is deactivated and your personal details are anonymized. When your deletion is approved:
- Your profile information, saved addresses, saved businesses/products, and notification preferences are permanently deleted
- Your ability to sign in is permanently removed
- Order records, payment proof records, and review content connected to completed transactions may be retained in a de-identified or minimal form as required for financial recordkeeping, fraud prevention, and legal compliance, even after your account is deleted
- Content you contributed that is also part of another user's record (for example, a message you sent in a chat with a business) may remain visible to the other party, since deleting your account does not delete their copy of a shared conversation
If you delete a single message, it is marked as deleted and its content is hidden from both parties in the chat, but a record of the deletion event may be retained internally for safety purposes.
10. Your Rights (Customers and Businesses)
Subject to applicable law, you have the following rights regarding your personal information:
- Access — request a copy of the personal information we hold about you
- Correction — update inaccurate or incomplete information via Profile → Edit Profile, or by contacting support for information you cannot edit yourself
- Deletion — request deletion of your account as described in Section 9
- Withdrawal of consent — where our processing relies on your consent (such as push notifications), withdraw that consent at any time through in-app settings
- Portability — request your order history and account data in a commonly used format
- Objection — object to certain uses of your data, such as analytics, by contacting support
To exercise any of these rights, contact us using the details in Section 14. We will respond within a reasonable time and may need to verify your identity before processing certain requests.
11. Business Rights
Business accounts additionally have the right to:
- Review and correct their business verification information prior to approval
- Request a copy of the verification documents on file for their business
- Request deletion of their storefront and business data, subject to the same retention obligations described in Section 8 for completed orders and financial records
- Control what business information (hours, contact details, photos, description) is publicly displayed
Verification review notes and admin decisions (such as a rejection reason) are shared with the business they concern but are not made public.
12. Children's Privacy
The Platform is not directed at children and is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children under 18. Creating a Customer or Business account requires the ability to lawfully enter into a binding agreement, which generally requires being of legal age under Bhutanese law. If we become aware that we have collected personal information from a child without appropriate consent, we will take steps to delete that information.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Platform, or applicable law. When we make a material change, we will update the "Last updated" date shown at the top of this document and, where required, ask you to re-accept the updated policy before continuing to use the Platform. We encourage you to review this policy periodically.
14. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or your personal information, contact us at:
WhatsApp: +1 672-971-9002
We aim to respond to privacy-related requests within 24 hours on business days (Bhutan Standard Time).