Privacy Policy — Smallbee
Last updated: 15 June 2026
This Policy explains how LLC "Code 380" (ТОВ «Код 380»), a company registered in Ukraine under EDRPOU 46293424 ("code380", "we", "us", or "our"), collects, uses, shares, and protects personal data when you use the Smallbee application and related services (the "Service"). It supplements the Smallbee Terms of Service. Our registered-company details, including our postal address, are listed on our Contacts page.
Most personal data in Smallbee is provided by the business that uses it, about itself and its employees. In data-protection terms we generally act as a processor for data about team members (the business is the controller) and as a controller for data about the account holder and the operational data needed to run the Service. This Policy is written to align with the Ukrainian Law "On the Protection of Personal Data" and, where relevant, the EU General Data Protection Regulation (GDPR).
1. What we collect
We collect only what is needed to operate the functionality described below.
- Account & identity. Email address (from email/password sign-up, or from Google when you use Google Sign-In), display name, organisation name, role, and a stable authentication identifier.
- Authentication & security. A password hash (we never see your plain-text password), a hash of your device-unlock PIN (PBKDF2-HMAC-SHA256; never stored or transmitted in the clear), session tokens, and sign-in events (date/time, IP address, user agent, success/failure) used for security and rate-limiting.
- Device & technical. A push-notification device token, and — only when the app crashes — device model, OS and app version, locale, the crash stack trace, and the signed-in user's identifier, for diagnosis.
- Business operational data ("Customer Data"). Site details and optional Telegram bot configuration; team-member records (name, role, assigned sites, pay rules, employment status, optional Telegram ID); supplier and catalog data; orders; daily shift reports (cash, terminal totals, expenses); and ledger entries (accruals, bonuses, fines, payouts), plus an audit log of administrative actions.
- Subscription & billing. A purchase token or receipt from Google Play or the Apple App Store, the product/tier identifier, and renewal dates and subscription state. We do not receive or store card numbers or banking details — all payment processing is handled by the app store (Google Play or Apple).
- Preferences & cached state. Your notification and theme preferences, on-device cached data for fast start-up, and which accounts on a device have seen the onboarding tour.
- Support communications. The contents of any message you send us and anything you share with it (e.g. account email, screenshots, error messages).
What we do not collect: we do not collect device location or GPS, your contacts, camera, microphone, or photos, special-category data (health, biometric, ethnicity, religion, etc.), advertising identifiers, or behavioural-analytics events. We use no advertising or analytics SDK; crash reporting records crashes only, not usage.
2. How we use data
- To provide the Service — create and manage your account and organisation, authenticate sign-in and PIN unlock, compute payroll/ledger/shift results, sync your data, deliver notifications, manage your subscription, and provide support. Legal basis: performance of our contract with you.
- To keep the Service secure — detect and prevent fraud and unauthorised access, investigate crashes and incidents, and enforce our Terms. Legal basis: our legitimate interest in a secure service.
- To comply with legal obligations — retain financial records for the period required by tax law, and respond to lawful requests. Legal basis: compliance with a legal obligation.
- To improve the Service — diagnose crashes and bugs and test new features in limited testing tracks. Legal basis: our legitimate interest in improving the Service.
We do not use your data for advertising, do not sell personal data, do not carry out profiling with legal effect, and do not use Customer Data to train AI models.
3. Who can see your data
Within an organisation, access is role-based: Owners and Admins see organisation-wide data, while Workers see only data scoped to their assigned sites and shifts, including their own salary data. Other organisations cannot see your data — multi-tenant isolation is enforced at the database layer (Postgres row-level security). A limited number of code380 staff may access your data only to investigate a support request, look into a suspected violation of our Terms, respond to a lawful request, or perform essential maintenance; such access is limited to what the task requires.
4. Sub-processors
We use the following sub-processors, each engaged under a data-processing agreement consistent with this Policy and applicable law:
- Supabase Inc. — database, authentication, storage, real-time sync, and edge functions (hosts all Customer Data, account, authentication, and subscription data).
- Google LLC / Firebase — push notifications, crash reporting, and Google Sign-In (push token, crash diagnostics with the signed-in user's identifier, and Google email and basic profile for sign-in).
- Google Play — subscription payment processing and receipt verification on Android (the email associated with your Google Play account, the purchase token, and the product id).
- Apple — subscription payment processing and receipt verification on iOS (the App Store transaction id / receipt and the product id).
- Telegram — bot dispatch, only when configured by the Owner (the bot token, the relevant chat id, and notification contents).
We do not share personal data with any other third party except where required by law (see section 8).
5. International transfers
Personal data may be transferred to and processed in countries other than Ukraine — including the EU and the United States — where our sub-processors operate. Where we make such transfers we rely on adequacy decisions where they apply, the European Commission's Standard Contractual Clauses where they do not, and the equivalent protections under Ukrainian data-protection law. You can request a copy of the relevant safeguards by contacting us.
6. Data retention
We keep personal data only as long as needed for the purposes above. In general: active-account data is kept for the life of the account; an account you delete is soft-deleted at once and permanently purged 30 days later; subscription and billing records are kept for the period required by tax and accounting law; crash reports and sign-in events follow our providers' standard retention; and support communications are kept for a limited period after our last reply unless a longer period is legally required. After the applicable period, data is permanently deleted or anonymised.
7. Your rights
Subject to applicable law, you have the rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent, and the right to lodge a complaint with a supervisory authority (in Ukraine, the Ukrainian Parliament Commissioner for Human Rights; in the EU, your national data-protection authority). To exercise any of these, email support@code380.com with the subject line "Data request"; we will respond within 30 days and may need to verify your identity first. The application also lets you act directly: edit your display name, delete your account (soft-deleted immediately and purged after 30 days), sign out, and turn push notifications off.
8. Disclosure to authorities
We may disclose personal data when we believe in good faith it is necessary to comply with a court order or other lawful request, meet a tax or audit obligation, protect the rights, property, or safety of code380, our users, or the public, enforce our Terms, or address fraud or security issues. We push back on overbroad requests, seek to narrow what is disclosed, and, where lawful, notify affected users.
9. Children
The Service is intended for adults using it in a business context. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us and we will delete it without delay.
10. Push notifications
The app sends push notifications for events relevant to your role — shift reports, orders, ledger transactions, and subscription state. You can turn them off at any time in the app's settings or in your device's system settings; doing so does not affect any other part of the Service.
11. Cookies and local storage
The application does not use cookies. It does use on-device storage — your session token, a local database that mirrors cloud data for offline use, and your preferences — which is essential to the Service, is not shared with third parties, and is erased when you uninstall the app, delete your account, or clear the app's storage.
12. Security
We use technical and organisational measures to protect personal data, including encryption in transit (TLS), encryption at rest provided by our infrastructure providers, database-level multi-tenant isolation (row-level security), cryptographic hashing of passwords and PINs, least-privilege staff access, and due diligence on our sub-processors. No system is perfectly secure; if we become aware of a personal-data breach likely to put your rights at risk, we will notify you and the relevant supervisory authority as required by applicable law.
13. Changes to this Policy
We may update this Policy from time to time. If a change is material, we will notify you through the application and at your registered email at least 30 days before it takes effect. The "Last updated" date above shows when the current version became effective; prior versions are available on request. Continued use of the Service after the effective date constitutes acceptance of the updated Policy.
14. Contact
Questions about this Policy or how we handle your data? Email support@code380.com (use the subject line "Data request" for rights requests).