# FarmWallet Privacy Policy (Draft)

Last updated: 2026-09-04

Important: This draft is a starting point and must be reviewed by FarmWallet owner and legal counsel before publication.

## 1. Who we are
FarmWallet provides software for farm operations, financial management, inventory, machinery records, and electronic invoicing workflows (including SIFEN-related processing where applicable).

Controller/contact details: To be confirmed by FarmWallet owner.

## 2. Scope
This policy applies to:
- FarmWallet website
- FarmWallet application (web/mobile)
- FarmWallet API services

## 3. Data we may process
Depending on account usage, FarmWallet may process:
- Account data: username, email, login identifiers
- Company and farm data: company profile, farm/workspace records
- Financial and accounting data: documents, installments, account/category records
- Invoicing/SIFEN-related data: electronic document metadata and processing records
- Uploaded files: business documents, company logos, supporting files
- Authentication data: session tokens, login provider claims
- Operational logs: error/diagnostic records

Items requiring owner confirmation:
- Exact analytics/telemetry providers in production
- Exact retention durations by data category

## 4. Social login data
FarmWallet supports Google Sign-In and Apple Sign-In.
- FarmWallet receives identity token information and account profile fields needed for authentication.
- OAuth private secrets and signing keys must remain server-side and are not stored in the mobile app code.

Owner confirmation required:
- Whether additional provider attributes are stored long-term.

## 5. How data is used
Data is used to:
- Authenticate users and secure access
- Provide workspace, farm, inventory, machinery, and finance features
- Process invoicing/SIFEN workflows where configured
- Operate, maintain, and secure the service
- Send operational emails (for example alerts/notifications)

## 6. Storage and processors
Based on project configuration, FarmWallet may use:
- Hosting infrastructure: VPS/Coolify stack
- Database: PostgreSQL
- Object storage: Cloudflare R2
- Email sending: Amazon SES
- DNS/edge: Cloudflare

Owner confirmation required:
- Exact legal entities and regions for each processor in production.

## 7. Security
FarmWallet uses technical and organizational controls intended to protect data.
Examples in codebase include private file storage paths, encrypted model fields for sensitive company credentials, and token-based API authentication.

No method of transmission or storage is 100% secure.

## 8. Data retention
Retention depends on account lifecycle, legal obligations, operational needs, and owner-defined policy.

Owner confirmation required:
- Retention schedule for user accounts, financial records, SIFEN records, uploads, and logs.

## 9. Data sharing
FarmWallet shares data with service providers only as needed to operate the service.
No sale of personal data is represented in this draft.

Owner confirmation required:
- Jurisdictions and legal transfer mechanisms for cross-border processing.

## 10. Your rights
Depending on jurisdiction, users may have rights to:
- Access personal data
- Correct inaccurate data
- Request deletion
- Object/restrict certain processing
- Request data portability

Requests can be submitted through FarmWallet support contact channels.

## 11. Account deletion
Account deletion procedures are described in the Data Deletion Policy draft.
Some records may be retained where required by law or legitimate compliance/accounting needs.

## 12. Children
FarmWallet is intended for business and agricultural operations, not for children-directed use.

## 13. Changes to this policy
FarmWallet may update this policy and publish a revised date.

## 14. Contact
Support/privacy contact information: To be confirmed by FarmWallet owner.
