Privacy Policy
Last updated: 4 August 2026
MaxHesabi respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how personal data is collected, used, stored and shared when you use the MaxHesabi website, mobile application and related services.
1. Who is responsible for your data?
For personal data relating to an organization’s employees, managers, shops, attendance, schedules and operational records, the organization using MaxHesabi may act as the data controller. MaxHesabi generally processes that information on the organization’s instructions.
Questions concerning how your employer or organization uses your data should also be directed to that organization.
2. Information we collect
Depending on how you use MaxHesabi, we may collect:
Account information
- Name
- Email address
- Authentication identifiers
- Profile information
- Organization membership
- Assigned role and access permissions
Passwords are processed by our authentication provider and are not stored by MaxHesabi in readable form.
Employment and organizational information
- Employee identifier
- Job position and assigned shop
- Work schedule and shifts
- Attendance, clock-in and clock-out records
- Work hours and manager corrections
- Leave requests and approvals
- Tasks, assignments and completion status
- Salary, payroll or employment-related information entered by an authorized organization
- Activity history showing who created or changed a record
Location information
When you record attendance, MaxHesabi may request your precise foreground location to determine whether you are near the selected workplace.
We may store:
- Your location at the time of attendance
- Location accuracy
- Distance from the workplace
- Whether the attendance was within the configured workplace range
- Any location warning attached to the attendance record
MaxHesabi does not continuously track your location and does not collect background location. Attendance may still be recorded with a warning when permission is denied, location is unavailable or you are outside the workplace range.
Device and security information
To protect accounts and attendance records, we may collect:
- Device manufacturer and model
- Operating system and version
- App version
- Device or application installation identifier
- Notification token
- Notification and location permission status
- IP address
- Login and security activity
- Error and diagnostic information
A trusted or default device may be linked to an employee record for fraud prevention, attendance verification and account security.
Photos and uploaded content
When authorized by you, MaxHesabi may access the camera or photo library so you can attach:
- Terminal reports
- Receipts
- Expense evidence
- Daily reconciliation evidence
- Other operational documents
We only access photos you choose to upload or photos taken through the relevant application feature.
Financial and operational information
Organizations may enter or upload:
- Sales and reconciliation totals
- Daily expenses
- Payment and delivery totals
- Shop performance information
- Employee hours and payroll-related information
- Notes, reports and supporting files
MaxHesabi does not collect payment-card details through the mobile application.
Communications
We may process support requests, emails, feedback and other communications you send to us.
3. How we use personal data
We process personal data to:
- Create and maintain user accounts
- Authenticate users, including through Google or Apple where available
- Connect users with organizations, employees and shops
- Apply role-based permissions
- Record attendance and workplace proximity
- Manage shifts, working hours, leave requests and tasks
- Prepare operational, employee and reconciliation reports
- Send service, security and task notifications
- Store trusted-device and security information
- Detect misuse, fraud and unauthorized access
- Provide technical support
- Improve the reliability and security of the service
- Meet contractual and legal obligations
- Establish, exercise or defend legal claims
4. Legal grounds for processing
Where the GDPR applies, we process personal data on one or more of the following grounds:
- Performance of a contract
- Steps requested before entering into a contract
- Compliance with a legal obligation
- Our legitimate interests or the legitimate interests of the organization using MaxHesabi
- Your consent, where consent is required
- Establishment, exercise or defence of legal claims
You can withdraw consent for optional processing, such as notifications or device permissions, through your device settings. Withdrawal does not affect processing that occurred before consent was withdrawn.
5. Notifications
With your permission, MaxHesabi may send push notifications about tasks, attendance, invitations, requests, account security and other service activity.
A notification token is registered separately for each device. When you sign out, disable notifications or remove a device, MaxHesabi will attempt to remove the notification registration for that device without affecting your other devices.
You can change notification permission at any time through your device settings.
6. How we share information
We may share information with:
- The organization that invited you or manages your account
- Authorized administrators, managers and employees according to their permissions
- Authentication, hosting, database, storage, notification, mapping, email and technical-service providers
- Professional advisers where necessary
- Authorities where disclosure is legally required
- A buyer or successor in connection with a merger, acquisition or business transfer
Our service providers may include Supabase, Amazon Web Services, Expo, Google and other infrastructure or support providers.
We do not sell personal data.
7. International transfers
Some service providers may process data outside Poland or the European Economic Area. Where required, we use appropriate safeguards, such as adequacy decisions, Standard Contractual Clauses or another lawful transfer mechanism.
8. Data retention
We retain personal data only for as long as necessary for the purposes described in this Policy.
Generally:
- Account information is retained while the account is active and until deletion is completed.
- Push-notification tokens are retained until logout, permission withdrawal, device removal or token expiration.
- Location and attendance information is retained according to the organization’s employment and record-retention obligations.
- Financial, accounting, payroll and reconciliation records may be retained for the period required by applicable law.
- Security and activity logs may be retained for up to [12/24] months, unless longer retention is necessary to investigate misuse or comply with law.
- Deleted information may remain in protected backups for up to [90] days before being overwritten.
- Data required for legal obligations or legal claims may be retained for the applicable limitation period.
Organizations using MaxHesabi may establish additional lawful retention requirements for employee and business records.
9. Account deletion
You can initiate account deletion in the mobile application:
Settings → Delete account
You can also request deletion at:
or by emailing info@maxhesabi.com from the address connected to your account.
Deleting an account removes the user’s authentication account and personal data that MaxHesabi is not legally required to retain. Certain business, employment, accounting or security records may be retained where required by law or by the organization acting as data controller. Where possible, retained records will be limited, anonymized or separated from the deleted account.
We may verify your identity before completing a deletion request.
10. Your rights
Subject to applicable law, you may have the right to:
- Access your personal data
- Correct inaccurate or incomplete data
- Request deletion
- Restrict processing
- Object to processing based on legitimate interests
- Receive portable data
- Withdraw consent
- Lodge a complaint with a supervisory authority
In Poland, the supervisory authority is the President of the Personal Data Protection Office, or Prezes Urzędu Ochrony Danych Osobowych (UODO).
To exercise your rights, contact info@maxhesabi.com. We may need to verify your identity.
11. Security
We use technical and organizational safeguards intended to protect personal data, including access controls, authentication, encrypted communication and role-based permissions.
No electronic service is completely secure. You are responsible for protecting your password, device and account access and for notifying us promptly if you suspect unauthorized use.
12. Children
MaxHesabi is intended for business and workplace use. It is not directed to children under 16, and children must not create accounts unless their use is lawful and properly authorized by a parent, guardian or organization.
13. Changes to this Policy
We may update this Privacy Policy to reflect changes to the service, legal requirements or processing activities. We will update the date at the top and provide additional notice where required.
14. Contact
For privacy questions or requests:
Max Hesabi
Email: info@maxhesabi.com