This Privacy Policy explains what information the Gümrah Saha application (the “App”) processes, where that information goes, what it is used for, and how it is protected. The policy applies to the iOS version of the App.
Gümrah Saha is a multi-tenant application for field sales teams, and not a service in its own right. Every business runs its own server installation; the App connects to that installation using the firm code you enter (or a server address you type in by hand). All the commercial data you see on screen — customer accounts, balances, statements, and stock — comes from that business's own systems and stays there.
Accounts cannot be created in the App. Your username, password, firm code, and connection key are defined by the business you use the App with, and are given to you by that business.
1. Summary
- The App contains noadvertising, advertising identifier, third-party tracking, analytics, or crash reporting. It bundles no third-party SDK; networking, decoding, and secure storage are all handled by the operating system's own frameworks (URLSession, Codable, Keychain).
- There is no central server. The App talks only to the server of the business you connect to; the developer is not a party to that traffic and cannot see your data.
- No location, camera, microphone, contacts, photo, calendar, health, or sensor permission is requested.
- Your username, password, session token, and firm connection key are held only in the device Keychain; they are not synced to iCloud and are excluded from device backups.
- The App has no push notification infrastructure and processes no device notification token.
- The commercial data the App displays is already your own company's data, made available to you within your permissions.
2. Who the Data Controller Is
The data controller for commercial and personal data is the business you use the App with. That business opens your account, its server decides which customer accounts you may see, and the data is stored on its own server.
Mehmet Gümrah is the developer and App Store publisher of the App. In that capacity he operates no central server and does not collect, store, or have any way to view your username, password, account data, or usage records. The only thing that reaches the developer is a support request you choose to send by email.
3. Data Processed
Account and Session Information
- Username and password (sent to the business's server with the sign-in request)
- User ID, full name, role, and representative code where applicable
- The list of operations disabled for your role (which screens are hidden)
- Session token and its expiry
Firm Connection Information
- Firm code and firm name
- Server address
- Connection key (the installation's API key, entered by the user)
- The firm's appearance settings: brand color and logo address
- The modules enabled for the firm and its screen visibility settings
Commercial Data
The data below is fetched from the business's server and displayed on screen; the App does not produce it, modify it, or send it anywhere else. What arrives depends on the modules enabled for the firm and on the user's permissions:
- Customer account code, title, and balance
- Account activity (statement): date, document details, debit / credit amount, and running balance
- Stock records: product code, name, quantity, and price
Which customer accounts a user may see is derived on the server, from the identity in the session token. The App sends no scope information; a request for a record outside that scope is rejected by the server.
Technical Data
- Application identifier and application version. Sent with every request to the business's own server only, for the server's minimum-version check.
- Network connection status. Read on the device only, to tell “no internet” apart from “server unreachable”; it is never transmitted.
The App uses no usage analytics, screen tracking, telemetry, or crash reporting service. Device model, operating system version, advertising identifier (IDFA), and similar identifiers are not collected.
Permissions Not Requested
The App does not request access to location, camera, microphone, contacts, calendar, photos, health, or sensor data, and does not collect such data. App Tracking Transparency permission is not requested; the App does not track.
4. Data Stored on the Device
The only data the App stores persistently is what is needed to keep your session and firm connection alive. It is held in two separate vaults in the device Keychain:
- Session vault: username, password, user details, and session token. The password is stored so that your session can resume by itself the next time the App launches; it is never sent to the server or to any third party, and it is deleted when you sign out.
- Firm vault:firm code, firm name, server address, connection key, and the firm's appearance settings. It is kept separate so that switching firms does not clear your session, and signing out does not clear the firm connection.
Both vaults are marked as accessible after the device's first unlock and valid on this device only: the entries are not synced through iCloud Keychain, are excluded from device backups, and are not migrated to a new device. On a new device the user connects the firm again and signs in again.
The customer and stock lists shown on screen are cached in memory only and are lost when the App closes. That data is never written to disk, exported, or shared with other apps. Uninstalling the App removes all local data, including the Keychain entries.
5. Purposes of Processing
- Connecting to the firm installation and applying its configuration (modules, screens, branding)
- Authenticating the user and managing the session
- Showing the user only the customer accounts they are authorised for, and the related data
- Presenting account statements, balances, and stock information
- Enforcing role-based access control and hiding screens the user is not permitted to see
- Performing the minimum application version check
Data is not used for advertising, ad targeting, profiling, or third-party marketing.
6. Network Communication and Security
- All server communication uses HTTPS (TLS). Even if you type the server address with
http://, it is rewritten to https; unencrypted connections are not allowed. - Requests are authorised with the installation's connection key and, for a signed-in user, a session token with an expiry.
- Server responses are not written to the system network cache; every request fetches fresh data, so no leftover copy of a response accumulates on the device.
- Session and firm information is stored in the operating system's Keychain (see Section 4).
- On the server, every request is validated against the set of records the user may access; a request for a record outside that scope is rejected.
7. Advertising, Analytics, and Tracking
Gümrah Saha shows no advertising and uses no ad network, social media tracking SDK, usage analytics, or crash reporting service. Because the App bundles no third-party library, no data flows from your device to any third party.
The Apple Advertising Identifier (IDFA) is not collected and App Tracking Transparency permission is not requested. The only identifier the App processes is the user ID, used for authentication and app functionality.
8. Third Parties
There is no third party the App shares data with. The parties involved are:
- The business you work for: the owner of the server installation the App connects to and the data controller for the data. Its own policies govern how that data is stored and processed.
- Apple:distribution and updates go through the App Store. Data related to downloads and updates is subject to Apple's own policies.
Data is never sold or transferred to third parties for marketing purposes.
9. Data Retention
Session information stored on the device is deleted when you sign out. The firm connection stays on the device until you switch firms or uninstall the App. Uninstalling removes all local data, including the Keychain entries.
How long commercial, financial, and operational data is retained on the server is governed by the data retention policies of the business you use the App with, and by applicable legal obligations (for example, legislation on the retention of commercial books and records).
10. Account Creation and Closure
New accounts cannot be created in the App. Accounts are defined by the business you use the App with. To request that your account be closed or your access revoked, contact that business; the developer has neither authority over nor access to those accounts.
11. User Rights
Users can:
- Sign out to delete the session information stored on the device.
- Switch the firm connection or uninstall the App to clear all local data from the device.
- Submit requests to access, correct, or delete their personal data, or to object to its processing, to the data controller — that is, the business they use the App with. Such requests are handled under the applicable legislation.
12. Children's Privacy
This application is intended solely for corporate users — employees authorised by a business. No data is knowingly collected from anyone under 18.
13. Changes to This Policy
This Privacy Policy may be updated as new modules are added to the App. The updated version is published on this page and the “Effective date” is changed.
14. Contact
Data controller:the business you use the App with. Contact the person who opened your account, or your company's system administrator.
Developer / App publisher: Mehmet Gümrah
Email: support@mgumrah.com
Web: mgumrah.com