Who does this policy cover?
Service operator : Tifakti
This policy covers Tifakti visitors, account holders, their team members and people whose information appears on receipts. The Tifakti operator manages the data needed to run the service. Each business using Tifakti decides which customer information it enters and whom it shares documents with. If you are a customer of one of these businesses, you can also contact that business about your receipt.
Data we use
Depending on your use, Tifakti processes your name, email address, hashed password and optional profile photo; your business contact details, tax identifier, logo, signature and links; your customers’ names and contact details; receipt lines, dates, currencies, discounts, amounts and statuses; and catalog products, services, images and quantities. It also stores team invitations and roles, subscription information and payment references, and security data such as IP address, browser information and login attempts. Only enter information necessary for your activity.
Why data is used
This data is used to create and manage your account, produce and retrieve receipts, reuse your catalog, track quantities when you enable this option, manage your team and subscription, send service messages and handle support requests. Security data helps prevent abusive access and diagnose incidents. Where applicable law requires a legal basis, these uses rely, as appropriate, on performing the requested service, applicable legal obligations or a legitimate interest in securing the service. Consent is requested when required for an optional use.
Receipt links and WhatsApp
Sharing a receipt creates a link that can be viewed without signing in. Anyone with the link can view and download the receipt information, and a recipient can forward it. Exported PDF or JPG files can also be kept and shared by recipients. The WhatsApp option prepares a message and opens WhatsApp; you choose whether to send it. Information you send to WhatsApp is then subject to its own privacy terms. Check the recipient and content before sharing.
Retention and deletion
Account information and documents remain stored while needed to use the service, unless deleted or handled through an appropriate request. Retention depends on the type of data, the user relationship, security needs and applicable retention obligations. Disabling a user does not delete their data. Removing a catalog item hides it from the list but preserves its reference for existing receipts and stock corrections. Files already downloaded by a recipient cannot be remotely erased. Password reset links expire after 60 minutes; expired or used requests are cleaned up when new reset requests are made.
Protecting your information
Tifakti uses measures including password hashing, account and company access controls, form protections and login attempt limits. Production pages are intended to be served over HTTPS. No measure guarantees absolute security. Use a unique password, limit team access and report suspicious activity.
Your choices and rights
You can edit your profile and some company information in your account, according to your access rights. Depending on applicable law, you may request access, rectification, erasure, restriction, objection or portability of your data, and withdraw consent where processing relies on it. Proportionate identity verification may be necessary. Some requests may be limited by legal retention obligations or other people’s rights. You may also complain to the competent data protection authority where that right applies to you.
Changes to this policy
This page may change as the service and applicable rules evolve. Its update date identifies the version presented. Changes requiring specific notice or consent will be addressed through the appropriate steps.
Your privacy requests
For questions about your data or to exercise your rights, contact:
Tifakti contact@tifakti.com