Privacy Policy
1. General
This Privacy Policy explains what data the Lyana mobile application (the “Application”) collects and processes, why the data is used, and how it is protected. Lyana is a business management application operated by Anastasiia Izhboldina, Ukraine (“we,” “us,” or the “Developer”). By using the Application, you acknowledge that you have read this Privacy Policy.
2. Who uses the Application
The Application is intended for owners, administrators, specialists, and other authorized personnel of small and medium-sized businesses. It is not intended for their customers to use directly.
Customers do not create accounts in the Application. Authorized business users enter customer information for legitimate business purposes, such as managing appointments and service history.
3. Data we process
3.1 Account and profile data
- Email address and authentication credentials. Passwords are handled by Supabase Authentication in a protected form; we do not have access to the plain-text password.
- Name, telephone number, date of birth, gender, and profile photo.
- Role and permissions in a business workspace, such as owner, branch administrator, or specialist.
3.2 Business data entered by users
- Customer information, including name, telephone number, notes, selected photos or sketches, attachments, appointment history, and service history.
- Services, working schedules, appointments, branches, and personnel records.
- Inventory, products, stock records, and related operational information.
- Internal financial records, including cash records, operational transactions, and staff remuneration calculations. These are business records, not users’ payment-card data. The Application does not process card payments.
3.3 Technical and diagnostic data
- A device or installation token used to deliver push notifications through Firebase Cloud Messaging.
- Crash and diagnostic information processed through Firebase Crashlytics, which may include the Application version, device model, operating-system information, technical identifiers, crash time, and technical logs needed to identify and fix errors.
3.4 Photos
The Application allows users to select photos from the device gallery for profile and business purposes. The Application receives the photos selected by the user and does not use them for advertising.
4. Why we process data
- To provide the Application’s core functions, including customer records, scheduling, appointments, cash records, inventory, and staff remuneration calculations.
- To create, authenticate, and protect user accounts and manage workspace permissions.
- To deliver relevant push notifications about business events.
- To maintain security and diagnose and correct technical errors.
- To respond to support, privacy, and account deletion requests.
- To comply with applicable legal obligations.
Depending on the circumstances and applicable law, processing is based on performing our agreement with the user, our legitimate interests in operating and securing the Application, consent where required, or compliance with legal obligations.
We do not sell personal data and do not use it for advertising.
5. Service providers
We use the following service providers only to operate and support the Application:
- Supabase — database hosting, authentication, and file storage. See the Supabase Privacy Policy.
- Google Firebase — push notification delivery through Cloud Messaging and crash reporting through Crashlytics. See the Google Privacy Policy.
These providers process data under their own privacy terms and applicable contractual and legal safeguards. We require service providers that process personal data on our behalf to protect it consistently with this Policy and applicable law.
6. Roles in relation to business customer data
For account, security, support, and diagnostic data, the Developer determines the purposes described in this Policy.
For customer data entered by a business, the relevant business owner is the data controller and determines why and how that information is collected. The business is responsible for having a lawful basis, providing required notices, and obtaining consent where required. The Developer acts as a technical service provider that supplies tools for storing and using the data and does not independently determine the business’s purpose for collecting it.
7. International processing
Our service providers may process data in countries other than the user’s country. Where required, such processing is subject to appropriate legal and contractual safeguards. The specific location may depend on the infrastructure and project region used by the relevant provider.
8. Data security
We use reasonable technical and organizational measures designed to protect data. Access is restricted using workspace roles and database-level controls, including Row Level Security in Supabase. Data is transmitted over encrypted HTTPS connections. No method of electronic storage or transmission can, however, be guaranteed to be completely secure.
9. Retention and deletion
Data is generally retained while an account or business workspace remains active and for as long as needed for the purposes described in this Policy.
- When a specialist or other staff account is deleted, that user’s account and personal profile data are deleted. Business records created or managed as part of the workspace may remain under the control of the business.
- When the owner deletes the organization account, the organization’s related data is deleted, including customer details, contacts, photos and attachments, appointments, inventory records, remuneration information, and other workspace information.
Some deleted information may remain temporarily in protected backups or technical logs until it is overwritten under the service providers’ normal retention cycles. Such information is not used for other purposes. We may retain limited information for longer where required by law, security, dispute resolution, or enforcement of our agreements.
10. Your rights and choices
Depending on applicable law, you may have the right to request access, correction, deletion, restriction, objection, or portability of your personal data, and to withdraw consent where processing is based on consent. You may also have the right to lodge a complaint with a competent data protection authority.
- You can view and edit profile information directly in the Application.
- You can delete your account in More → Delete Account.
- You can contact us about your data using the email address below.
If your request concerns customer data entered by a business, please contact that business first because it controls that data.
11. Children
Lyana is a business tool and is not designed or marketed as a service for children. User accounts are intended for people authorized to act for or work with a business. If a business enters information about a customer who is a minor, that business is responsible for having an appropriate legal basis and obtaining permission from a parent or guardian where required.
12. Changes to this Policy
We may update this Privacy Policy from time to time. We will update the effective date above and, where appropriate, notify users in the Application of material changes.
13. Contact
For privacy questions or requests, contact:
Anastasiia Izhboldina
Ukraine
ar.galkina99@gmail.com