Privacy
Policy
How YUMA Verifier collects, uses, stores, and protects your data. Your privacy is our priority.
This policy applies in accordance with the Information, Communications and Media Act 2018 of Bhutan and applicable data protection principles.
Information We Collect
We collect information necessary to provide automated receipt verification, internal bookkeeping, credit tracking, and secure platform access.
1A. Merchant & Device Information
Account Credentials: Username and BCrypt-hashed PINs provided during administrative manual provisioning.
Store Details: Merchant business name, store location, and public bank account/QR details displayed on public storefront standees.
Device Identifiers: Device hardware identifiers, approval status, and 30-day session security tokens to enforce per-device security.
1B. Transaction & Bookkeeping Data
Payment Receipts: Customer payment receipt screenshots uploaded by the Merchant.
Parsed Receipt Metadata: Extracted data points including paying bank name, journal/transaction number, merchant name, transaction amount, and timestamp.
Cash Sales & Expenses: Daily cash sales totals and scanned paper business expense receipts uploaded to the platform.
Credit Ledger Data: Customer names, phone numbers, running credit balances, and transaction entry logs (FIFO tracking).
How We Process Information & Third-Party Services
We process collected data through automated algorithms, localized parser routes, and specialized cloud processors to fulfill app functionality:
2A. OCR & LLM Parsing
Uploaded receipt screenshots and paper expenses are processed using Gemini-3.1-flash-lite and fallback models including GPT-4o mini solely to extract structured plain text (amounts, bank names, dates, journal numbers). Information processed through these LLMs is used strictly for real-time text extraction and is not used to train public machine learning models.
2B. Async Verification Engines
Extracted fields are evaluated against merchant inputs via background job queues (ocr_verification_job.rb) to flag potential mismatches or duplicate entries.
2C. Messaging Gateways
Customer phone numbers and tab balances are transmitted through third-party messaging integrations (e.g., WhatsApp API) solely to dispatch merchant-initiated credit reminder messages.
2D. Cloud Storage
Uploaded image files (receipts, expense slips) are securely stored using cloud storage services (AWS S3).
How We Use Your Information
We use the collected data strictly for operational, security, and administrative purposes:
- To verify point-of-sale customer payment screenshots and detect duplicate receipts.
- To organize merchant daily cash logs, paper expense records, and running credit customer tabs.
- To enforce authorized device locking, prevent unauthorized account access, and rate-limit API calls.
- To compute aggregate store performance statistics (daily, weekly, monthly, quarterly, and yearly summaries) within the Merchant Dashboard.
- To manage monthly subscription billing and account status.
Third-Party Data Sharing & Disclosure
We do not sell, rent, or trade merchant, transaction, or customer data to third parties. We share data only in the following limited circumstances:
- Service Providers: Infrastructure and technology vendors (AWS S3 for cloud receipt storage, AI parsing API providers, and WhatsApp messaging gateways) that process data on our behalf under strict confidentiality obligations.
- Legal Obligations & Law Enforcement: We may disclose data if required to do so by applicable Bhutanese law, a court order, or formal legal requests from regulatory or law enforcement bodies in Bhutan (e.g., the Royal Bhutan Police or Royal Monetary Authority).
Data Security & Storage Controls
We implement industry-standard technical and organizational security measures to protect your data:
- Password/PIN Protection: Account PINs are irreversibly hashed using BCrypt.
- Access Control: API endpoints are protected with device-level token authorization and Rack::Attack rate-limiting to block brute-force attacks.
- Encrypted Transmission: All network traffic between the Expo mobile app and the Rails 8 backend is encrypted in transit using standard Transport Layer Security (TLS).
Payment Notification Access
If you enable Auto-Verification, the app accesses notifications posted by supported banking apps on your device and transmits their content to Yuma Services' servers for the sole purpose of matching incoming payments to your sales. No other notifications are accessed. Notification content is not sold, shared with third parties, or used for advertising. You can revoke access at any time in Android Settings → Notifications → Notification access.
Data Retention and Account Deletion Rights
7A. Data Retention Policy
Receipt & Expense Images: Media uploaded to cloud storage (AWS S3) is retained for up to twenty-four (24) months, after which it may be permanently deleted.
Ledger & Account Data: Structured ledger data is retained for the duration of the active merchant subscription.
7B. Right to Access and Delete
Merchants have the right to request access to their stored data or request the complete deletion of their account, transaction history, customer ledger, and media files.
Upon receiving a deletion request, YUMA Services will permanently purge all store records from active databases and servers.
Statutory Compliance Responsibility: Deleting data from YUMA Verifier permanently removes cloud backups. Merchants remain solely responsible for preserving any physical or digital financial records required under Bhutanese tax laws (Department of Revenue and Customs).
Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our technology, legal obligations, or operational practices. Any updates will be communicated with reasonable notice within the App. Continued use of YUMA Verifier following notice of changes indicates acceptance of the updated policy.
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your data privacy, please contact:
YUMA Services
Email: yumaservices2026@gmail.com
Phone: +975 17838436