Privacy Policy — Qorebook
Last updated: 31 August 2026
This Privacy Policy explains how Qorebook, “we”, “us”, or “our” collects, uses, discloses, and safeguards your information when you access and use the Qorebook web application, Android application, and iOS application (collectively, the “Service”). Qorebook is a multi-tenant business-management and accounting platform.
By accessing or using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with the practices described herein, please do not use the Service.
1. Data Controller and Data Processor Roles
Data-protection law distinguishes between a “controller” (who decides why and how data is processed) and a “processor” (who acts solely on instructions).
Controller Role: Operating under the laws of Ghana, Qorebook is the data controller for account identification, user profile data, subscription records, and system diagnostic metrics.
Processor Role: For business records entered into a workspace (an “Organization”) — including customer details, employee payroll inputs, inventory, and accounting ledgers — the Organization owning the workspace acts as the data controller. Qorebook acts solely as a data processor on that Organization’s behalf and under its direct instructions.
For all data-protection enquiries, contact our Data Protection Officer at: info@qorebook.com
2. Information We Collect
2.1 Information You Provide Directly
- Account Identity: Name, email address, password (hashed securely by our authentication provider), and basic profile details returned during federated login via Google Sign-In or Apple Sign-In (name, email, profile photo, provider user ID).
- Organization & Profile Data: Business name, physical address, logo, tax identifiers, default currency, team member names, staff email addresses, and assigned administrative roles.
- Business Records: Data created or uploaded within the Service — including customers, suppliers, employee details and payroll inputs, products, inventory, invoices, bills, expenses, point-of-sale transactions, journal entries, and general ledgers. These records may contain personal data belonging to your staff, clients, or third parties.
- Support Communications: Messages, feedback, attachments, and contact information provided during customer support interactions.
2.2 Information Collected Automatically
- Device & Usage Data: IP address, hardware device model, operating system version, app build number, browser type, pages viewed, time spent on features, and system interaction timestamps.
- Diagnostics & Performance: Crash reports, error traces, and runtime performance metrics used to maintain operational stability and debug code faults.
- Cookies & Local Storage: Strictly necessary cookies and local browser storage (such as IndexedDB and session tokens) to maintain authentication states, track your active Organization workspace, and enable offline data synchronization. We do not use third-party tracking or advertising cookies.
2.3 Camera and Device Hardware Permissions
On our Android and iOS applications, camera access is requested only when triggered explicitly by you to run the point-of-sale barcode scanner or capture business receipts. Image processing for barcode scanning occurs directly on device memory. Images are transferred to cloud storage only when you explicitly attach a scanned receipt to an accounting entry. Camera streams are never used for biometric tracking, facial recognition, or unauthorized monitoring.
3. How We Use Information & Legal Bases (GDPR)
If you are accessing the Service from the European Economic Area (EEA) or United Kingdom (UK), we process your personal data under the following legal bases under Article 6 of the General Data Protection Regulation (GDPR):
| Purpose of Processing | Legal Basis (GDPR Art. 6) |
|---|---|
| Authenticating accounts, maintaining active sessions, enforcing role-based permissions, and serving operational data. | Contractual Necessity: Essential to fulfill our agreement to provide the Service. |
| Sending essential transactional communications (email verification, password resets, team invites, billing invoices). | Contractual Necessity: Required to deliver core software functions. |
| Monitoring app health, maintaining audit logs, preventing fraudulent access, and fixing software errors. | Legitimate Interests: Operating a secure, reliable, and fault-tolerant cloud platform. |
| Complying with tax compliance, statutory accounting rules, and legal regulatory orders. | Legal Obligation: Compliance with applicable statutory requirements. |
4. Service Providers & Third-Party Sub-Processors
We do not sell, rent, or trade your personal data. We share data strictly with vetted sub-processors that perform core operational infrastructure tasks under contractual data-processing agreements:
| Provider | Purpose | Data Categories Involved |
|---|---|---|
| Google Firebase (Auth, Firestore, Storage, Hosting) | Identity management, real-time primary database, file storage, and static web app hosting. | Account credentials, workspace data, uploaded files, session tokens, IP address. |
| Google & Apple Identity Services | Optional federated authentication (Single Sign-On). | Name, email address, profile picture, unique provider identifier. |
| Resend | Transactional email delivery and system alerts. | Recipient name, email address, and contextual email body contents. |
| Sentry | Application crash reporting and performance diagnostics. | Stack traces, device specs, OS version, IP address, technical runtime errors. |
We may also disclose information where legally mandated by court order, statutory regulation, or law enforcement request; to enforce our Terms of Service; or during a corporate merger, acquisition, or asset sale (with prior notice sent to account administrators).
5. International Data Transfers
Our third-party infrastructure providers operate global datacenters, including in the United States and European Union. When data originating in the EEA, UK, or Ghana is transferred internationally, we ensure standard regulatory protection mechanisms are enforced — including standard contractual clauses (SCCs) approved by the European Commission, relevant Data Processing Addendums (DPAs), and equivalent statutory frameworks under Ghana’s Data Protection Act, 2012 (Act 843).
6. Data Retention and Account Deletion
- Account Data: Stored continuously while your account remains active.
- Business Records: Retained for the lifespan of the owning Organization workspace, and thereafter only as required by law for legal, tax, or statutory financial auditing.
- Security & Audit Logs: Stored in append-only administrative log databases to maintain audit trails and protect workspace integrity.
- Backups & Diagnostic Cache: Diagnostic records and temporary database backups automatically expire on rolling schedules (typically within 30 to 90 days).
How to Delete Your Account
In accordance with Apple App Store and Google Play requirements, you can initiate account deletion at any time directly within the application by navigating to Settings > Delete Account, or by submitting a request via our dedicated Account Deletion page at https://qorebook.com/delete-account. Upon account deletion, your personal authentication records are purged within 30 days. If your account is linked to an active business Organization, workspace ownership must be transferred or dissolved prior to account deletion.
7. Your Legal Rights
Depending on your jurisdiction, you hold specific statutory privacy rights regarding your personal data:
- Right to Access: Request a copy of the personal data held about you.
- Right to Rectification: Edit incomplete or inaccurate profile information via Settings.
- Right to Erasure (“Right to be Forgotten”): Request complete deletion of your personal records.
- Right to Restrict or Object: Limit or object to specific processing of your information.
- Right to Data Portability: Request an export of your workspace data in a structured format (JSON/CSV).
- Right to Withdraw Consent: Withdraw consent at any time where processing relies on consent.
To exercise any of these rights, contact us at info@qorebook.com. Under Ghana’s Data Protection Act, 2012 (Act 843), you have the right to lodge complaints with the Data Protection Commission (DPC). For EEA/UK users, you may lodge complaints directly with your local supervisory authority.
8. Security Measures
We protect your information through technical and organizational defenses, including HTTPS transport-layer encryption, HTTP Strict Transport Security (HSTS), Content Security Policies (CSP), hashed credential storage, short-lived authentication tokens, role-based access control, and multi-tenant database isolation. While we employ robust measures, no cloud service can guarantee absolute cryptographic security.
9. Children’s Privacy
Qorebook is strictly intended for enterprise and commercial operations. The Service is not directed to, nor do we knowingly collect data from, individuals under 18 years of age. If we learn that personal data from a minor has been collected without parental consent, we will take prompt steps to delete it.
10. Updates to This Policy
We may update this Privacy Policy to reflect changes in our legal obligations or system architecture. When material changes occur, we will notify you via in-app banner alerts or administrative emails prior to enforcement. The “Last updated” timestamp at the top of this document indicates the current effective date.