Privacy Policy
Last Updated: August 5, 2026
1. Introduction & Overview
1.1 This Privacy Policy sets out how Keselip ("we", "us", or "our") collects, uses, stores, shares, and protects information about individuals ("personal data") when you interact with our website at keselip.bogorstore.com, our mobile application, and related services (collectively, the "Service").
1.2 We are committed to processing your personal data in accordance with applicable global data protection laws, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the EU General Data Protection Regulation (EU GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), the California Online Privacy Protection Act (CalOPPA), and the Children's Online Privacy Protection Act (COPPA).
1.3 For the purposes of applicable data protection legislation, Keselip acts as the Data Controller responsible for your personal data.
1.4 By accessing or using our Service, you acknowledge that you have read and understood the practices described in this Privacy Policy.
2. What Personal Data We Collect
We collect several types of personal data depending on how you interact with our Service:
2.1 Identity & Contact Data
- Name Details: First name and last name.
- Contact Information: Email address, telephone number, and full physical address (address, state, province, city, and ZIP/postal code).
2.2 Financial & Transaction Data
Payment details, order history, billing addresses, and records of products or services you have purchased from us (processed via third-party payment providers).
2.3 Mobile Device Permissions & Media Data
To deliver our core asset management and scanning capabilities, we request access to specific mobile device features:
- Location (GPS): Real-time geographic location data to enable regional lookup, smart spatial organization, and location-tagged asset tracking.
- Camera & Photo Library: Access to capture and upload images of physical items, receipts, and warranty cards for AI photo recognition and document parsing.
2.4 Technical & Usage Data
- Technical Information: Internet Protocol (IP) address, device identifiers, browser type and version, operating system, platform, and time zone settings.
- Usage Information: App feature interactions, screen navigation, crash logs, and performance metrics collected automatically during your session.
2.5 Special Category Data
We do not intentionally collect special categories of personal data (e.g., health data, biometrics, religious beliefs). However, if an image or receipt uploaded by you contains sensitive details, such data will only be processed to the extent necessary to display it back to you.
3. How We Collect Your Data
We use different methods to collect data from and about you:
- 3.1 Direct Interactions: You provide us with your identity, contact, and financial details by creating an account, filling in forms, capturing photos within the app, subscribing to services, or corresponding with us by email or support channels.
- 3.2 Automated Technologies: As you navigate our website or app, we automatically collect technical and usage data via cookies, server logs, analytics SDKs, and similar tracking technologies.
-
3.3 Third Parties & Integrated APIs: We receive personal data and technical insights from third-party services, including:
- Google Analytics & Firebase: For analytics, app performance monitoring, and crash reporting.
- Google Places API: To facilitate location lookup and address geocoding.
- Invisible reCAPTCHA: To protect web forms and API endpoints against automated spam and abuse.
4. How We Use Your Data & Legal Bases for Processing
We process your personal data only when the law permits. Under Article 6(1) of the UK/EU GDPR, we rely on specific legal bases for each processing activity:
| Purpose / Activity | Type of Data | Legal Basis for Processing |
|---|---|---|
| Account Registration & Service Management: Creating user accounts, managing settings, and providing storage tracking features. | Identity, Contact, Device Permissions | Performance of a Contract (Art. 6(1)(b)) |
| AI Photo & Receipt Processing: Auto-identifying items, purchase dates, prices, and setting warranty reminders. | Camera Data, User Uploads, Technical Data | Performance of a Contract (Art. 6(1)(b)) |
| Payment Processing: Managing subscriptions, billing, and order fulfilment. | Identity, Contact, Financial & Transaction Data | Performance of a Contract (Art. 6(1)(b)) |
| Security & System Protection: Guarding against abuse via Invisible reCAPTCHA and securing cloud infrastructure. | Technical Data, Usage Data | Legitimate Interests (Art. 6(1)(f)) – protecting our services against fraud and misuse |
| Service Improvement & Analytics: Analyzing app crash reports and user interactions via Firebase and Google Analytics. | Technical Data, Usage Data | Legitimate Interests (Art. 6(1)(f)) or Consent (Art. 6(1)(a)) where required |
| Communications: Sending administrative alerts, purchase receipts, and opt-in marketing newsletters. | Contact Data, Identity Data | Performance of a Contract (for transactional) / Consent (for marketing) |
| Legal Compliance: Satisfying tax, accounting, or regulatory requirements. | Identity, Financial, Transaction Data | Legal Obligation (Art. 6(1)(c)) |
5. Third-Party Analytics, Advertising, and Services
- 5.1 Analytics & Performance: We use third-party tools such as Google Analytics and Firebase to monitor app stability, crash rates, and user traffic patterns. These services process technical identifiers to help us evaluate Service usage.
- 5.2 No Third-Party Advertising: We do not show ads within our application, nor do we share or sell your data to ad networks (e.g., Google AdSense, AdMob, or MoPub).
- 5.3 No Remarketing: We do not use remarketing or retargeting services to advertise our business across third-party websites or apps.
6. Email Communications
- 6.1 Transactional Emails: We send necessary service-related communications (such as password resets, billing receipts, security alerts, and system updates) under our contractual obligation to serve you.
- 6.2 Promotional Emails: With your explicit opt-in consent, we may send you marketing materials regarding new features or product updates. You can opt out of marketing emails at any time by clicking the "Unsubscribe" link in any promotional message or contacting us directly.
7. Payment Processing
- 7.1 We offer paid products, subscriptions, and digital services within our platform.
-
7.2 We use third-party payment processors to manage financial transactions. We do not collect or store your payment card numbers directly on our servers. Financial details are submitted directly to specialized payment processors governed by their respective privacy policies:
- Apple Store In-App Purchases
- Google Play In-App Purchases
- Stripe & Direct Bank Transfer Gateways
8. Sharing and Disclosing Your Data
We do not sell your personal data. We may share your personal information with the following categories of trusted third parties strictly for the operational purposes set out in Section 4:
- Infrastructure & Cloud Service Providers: Database hosting, cloud storage, and server administration partners.
- Analytics & Tool Providers: Google Analytics, Firebase, Google Places, and Google Invisible reCAPTCHA.
- Payment Processors: Apple, Google, and third-party payment gateways for billing execution.
- Professional Advisers: Lawyers, auditors, accountants, and bankers where necessary for professional advice or reporting.
- Legal Authorities: Regulatory authorities, courts, or law enforcement bodies when required by law or to protect legal rights.
- Business Transfers: Successors or acquirers in the event of a merger, acquisition, or asset sale.
All third-party processors are required by contract to protect your personal data, maintain strict confidentiality, and process it solely under our written instructions.
9. International Data Transfers
- 9.1 We operate globally, and your personal data may be transferred to, stored, and processed in countries outside the United Kingdom and European Economic Area (EEA), including servers located in the United States.
-
9.2 Whenever we transfer your personal data outside the UK or EEA, we ensure appropriate safeguards are implemented in accordance with law:
- Transfers to countries deemed to provide an adequate level of data protection by the UK Secretary of State or European Commission.
- Implementation of UK International Data Transfer Agreements (IDTAs), the UK Addendum to EU Standard Contractual Clauses (SCCs), or EU SCCs with relevant security measures.
10. Data Retention
- 10.1 We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including satisfying any legal, tax, accounting, or reporting obligations.
-
10.2 Retention Criteria:
- Account & Asset Data: Retained for the duration of your active account lifecycle. Upon account deletion, user assets and photos are permanently purged or anonymized within 30 days.
- Financial Transaction Records: Retained for up to 7 years in compliance with statutory tax and financial reporting legislation.
- Technical Logs & Analytics: Anonymized or aggregated for internal system diagnostics within 12 months.
11. Cookie Policy
- 11.1 Our website (keselip.bogorstore.com) uses cookies and similar technologies to distinguish you from other users and improve your browsing experience.
-
11.2 Categories of Cookies Used:
- Strictly Necessary Cookies: Essential for fundamental site operation, secure login, and session persistence.
- Analytical / Performance Cookies: Allow us to recognize visitor count and navigate popular content using tools like Google Analytics.
- Functionality Cookies: Store your preferences and regional settings across sessions.
- 11.3 Managing Cookies: You can adjust your browser settings to decline or clear cookies. Please note that disabling essential cookies may impact the operational features of our website.
12. Your Rights Under UK GDPR & EU GDPR
If you are located in the UK or the EU/EEA, you hold the following statutory rights regarding your personal data:
- Right of Access (Art. 15): Request a copy of the personal data we hold about you.
- Right to Rectification (Art. 16): Request correction of inaccurate or incomplete personal data.
- Right to Erasure / Right to be Forgotten (Art. 17): Request deletion of your personal data where no legal override exists.
- Right to Restrict Processing (Art. 18): Limit how we process your personal data in specific scenarios.
- Right to Data Portability (Art. 20): Receive your personal data in a structured, machine-readable format or transfer it to another controller.
- Right to Object (Art. 21): Object to processing based on legitimate interests or direct marketing.
- Rights Regarding Automated Decision-Making (Art. 22): Right not to be subject to decisions based solely on automated processing or profiling.
- Right to Withdraw Consent: Withdraw consent at any time where processing relies on consent.
To exercise any of these rights, please contact us using the information in Section 17. Requests are processed free of charge within one calendar month.
13. United States Regional Privacy Notice (CCPA/CPRA & CalOPPA)
This section applies to California residents pursuant to the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and CalOPPA.
A. Information We Collect and Disclose
In the past 12 months, we have collected the following categories of personal information:
- Identifiers: Name, email, phone number, postal address, IP address.
- Commercial Information: Purchase history and subscription transaction records.
- Geolocation Data: Precise GPS coordinates via mobile device permission.
- Visual Data: Camera images and photos uploaded for item and receipt scanning.
B. Sale and Sharing Disclosure
We do NOT sell your personal information, nor do we share your personal information with third parties for cross-context behavioral advertising.
C. Your California Rights
California residents have the right to Request Knowledge/Access, Request Deletion, Request Correction, and Opt-Out of Sensitive Personal Information Use without facing discriminatory treatment.
D. Do Not Track (DNT) Signals
Our Service currently does not respond to automated "Do Not Track" (DNT) browser signals due to the lack of a standardized global technological framework.
14. Children's Privacy (COPPA Compliance)
- 14.1 Our Service is strictly intended for individuals aged 13 and older. We do not knowingly collect or solicit personal data from children under the age of 13.
- 14.2 If we learn that we have inadvertently collected personal data from a child under 13 without verified parental consent, we will take immediate measures to delete that data from our infrastructure. If you suspect a child under 13 has submitted personal data to us, please contact us at [email protected].
15. Data Security
- 15.1 We implement robust technical, physical, and organizational security measures to protect your personal data against unauthorized access, loss, destruction, or alteration. These safeguards include SSL/TLS encryption for data in transit, secure database access control, and periodic vulnerability reviews.
- 15.2 We maintain incident response procedures to identify and contain suspected data breaches, and will notify you and applicable regulatory authorities whenever legally required.
16. Changes to This Privacy Policy
- 16.1 We may update this Privacy Policy periodically to reflect technological adjustments, legal updates, or operational changes.
- 16.2 Any updates will be published on this page with a revised "Last Updated" date. Significant changes will be communicated via email or prominent site notice.
17. How to Contact Us & Supervisory Authorities
17.1 Contacting Keselip
If you have any questions, concerns, or requests regarding this Privacy Policy or wish to exercise your legal rights, please reach out to us:
Email:
[email protected]Website Contact:
https://keselip.bogorstore.com/17.2 Regulatory & Supervisory Authorities
If you reside in the UK or EU and believe your data privacy rights have been infringed, you have the right to lodge a complaint with your supervisory authority:
UK Regulator (Information Commissioner's Office - ICO):
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
https://ico.org.ukEU Residents:
You may contact your national Data Protection Authority (DPA) within your EU Member State.