Privacy Policy
Last updated: July 16, 2026
This Privacy Policy explains what information Navoxa ("we", "us") collects when you use navoxaapp.com (the "Service"), how we use it, and the choices you have.
1. Information we collect
- Account information — company name, your name, email address, and password (stored in hashed form by our authentication provider; we never see your plain password).
- Workspace content — the orders, inventory, clients, processes, and other business data you and your team choose to store in the Service.
- Billing information — subscription payments are processed by Stripe. Card details go directly to Stripe and are never stored on our systems; we keep only your subscription status and a customer reference.
- Technical data — basic logs and identifiers needed to operate the Service securely (such as authentication tokens and request metadata).
2. How we use information
- to provide, secure, and improve the Service;
- to process subscription payments and manage your plan;
- to communicate with you about your account (such as password resets or important service notices);
- to comply with legal obligations.
We do not sell your personal data or your workspace content, and we do not use your workspace content for advertising.
3. Service providers
We rely on a small number of processors to run the Service:
- Google Firebase (Google LLC) — authentication and database hosting for your account and workspace data.
- Stripe — payment processing and subscription management.
- Appwrite — web hosting infrastructure for the application.
These providers process data on our behalf under their own security and privacy commitments. Data may be processed on servers located outside your country.
4. Data isolation
Each company's workspace is isolated: your data is only accessible to your company's accounts, according to the roles you assign. Platform administration access is limited to the operator of the Service for support and billing purposes.
5. Retention and deletion
We keep your data while your account exists so the Service can work. If you cancel, your data is retained so you can return; you may request deletion of your company account and its data at any time by contacting us, and we will delete it within a reasonable period except where retention is required by law (for example, billing records).
6. Security
Data is encrypted in transit, access is controlled through authentication and per-company security rules, and payment data is handled exclusively by Stripe. No system is perfectly secure; please use a strong, unique password and manage your team accounts carefully.
7. Your rights
Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data, or to object to certain processing. Contact us and we will respond in accordance with applicable law. Where your plan includes exports, you can download your workspace data yourself at any time.
8. Children
The Service is intended for businesses and is not directed at children under 16. We do not knowingly collect data from children.
9. Changes to this policy
We may update this policy from time to time; the date above reflects the latest revision. Material changes will be announced on this page.
10. Contact
Privacy questions or requests? Reach us on Instagram.