KRYGA on Android
Addendum dated 5 October 2026. This policy also applies to KRYGA for WooCommerce on Android. Instead of iPhone, the local working copy of store data and photos stays on your Android phone; the primary data remains in WooCommerce on your website. The same secure-bridge practices, retention periods and your rights apply.
Notifications use Google Firebase Cloud Messaging. Google processes the app installation ID, notification token, technical device and delivery information, and brief notification content, not your full store database. Firebase Analytics and advertising identifiers are not used. Android Keystore protects connection secrets; store data stays in the app’s private storage. Notifications depend on Android permissions and settings; we do not request location or address book access.
On Android, go to More → Profile → Delete account to delete your profile. This removes that profile’s connections and downloaded data on this phone, not products, orders or customers on your website. You can also remove one store without deleting your profile. If you cannot access the app, email woo@kryga.com.ua; the deletion instructions also apply to Android.
KRYGA profile
We use your email and a one-time code to sign in and restore your profile. One email groups your stores in KRYGA, while access and roles are approved separately through each store’s WordPress account. Your email and profile ID are stored on the server to operate the service, not for advertising.
Who processes your data
The KRYGA team provides the service. Privacy questions: woo@kryga.com.ua.
The store owner decides how their customers’ data is used. KRYGA processes it on their behalf to provide app features. We use KRYGA profile data for service access and support.
Data we process
- From your store: products, photos, orders, reviews, coupons, and customer details needed to display them: names, contact and shipping details, purchase history, payment method and status.
- For connection: profile name, email and ID, store address, permissions, sessions, and an encrypted, separate WordPress application password.
- For notifications and security: device token, notification preferences, brief event summaries, IP address, request times and results, app version, and error records.
- For support: messages and attachments you choose to send.
We do not request bank card numbers, CVV codes, or online banking passwords.
Why we need it
To display store data, carry out your changes, synchronize them, send notifications, and protect your connection. We do not sell data, use it for advertising, or share it with third parties for their own purposes, including AI training.
Processing is based on providing the service, protecting it, legal requirements, and your consent where needed.
Where data is stored
On your WooCommerce website and your iPhone. Store data is kept in WooCommerce on your website. In the current version, a working copy of products, orders, customers, reviews, and coupons stays locally on your iPhone. KRYGA does not maintain a separate permanent server database of these records. Photos are optimized in transit and cached on iPhone, without storing image files on our server.
Our server keeps data needed to run the bridge. Profile, secure connection, sessions, synchronization, security, and notification records. A brief notification summary may include an order number, customer name, and amount. Change requests stay until the operation finishes, then their contents are cleared.
Earlier versions could retain a server-side working copy of the store. During migration, it is deleted after the iPhone download is confirmed; older connections use the previous approach until they migrate.
Transfers needed to run the service
We do not sell data or share it with third parties for their own purposes. The service needs technical transfers: between your website and iPhone through KRYGA’s server, through hosting infrastructure, to Apple for push notifications, and to the email provider for authorization and support messages. Apple receives a device token and notification content, not your full store database. Providers receive only data needed for the relevant function, with protection required to be at least equivalent to this policy and applicable law. Disclosure may also be required by a lawful request from a competent authority.
Providers’ infrastructure may be outside your country. International transfers are subject to safeguards required by applicable law.
How long data is kept
- Local data stays until you delete the store from the app. The photo cache can be cleared or limited separately.
- Profiles and connections stay until their deletion is confirmed.
- Event delivery receipts are removed after 7 days; change identifiers and ordinary event history after 30 days, during automatic cleanup.
- An open out-of-stock event stays until restock or product deletion; after closure it is removed according to the technical retention period.
- Minimal operation confirmations and security records remain to prevent repeated actions and investigate errors, without full copies of orders or products.
- Backups rotate within 14 days; deleted records may remain in them until rotation.
Support requests and records required by law or to protect rights are kept only for the necessary period.
Permissions and settings
Notifications require iOS permission; you can change categories and text previews. Photo selection grants access only to chosen images, and the camera is used for scanning. We do not request location or address book access.
The KRYGA website has no advertising trackers or analytics cookies. Technical logs support service operation and security.
Your rights and deletion
Go to More → Profile → Delete account to delete your KRYGA profile, sign-ins and notification subscriptions. The app clears downloaded data on this iPhone. WooCommerce data and other participants’ shared-store access are not deleted. Step-by-step instructions.
For data access, correction, deletion, a portable copy, or to object to or restrict processing, contact woo@kryga.com.ua. You may withdraw consent and contact a data protection authority. The scope of your rights depends on applicable law. We may ask you to verify your identity, but not to send passwords or access keys.
Security and policy updates
We use HTTPS, encrypted application passwords, Keychain, and iOS file protection. Access is checked separately for each store. This is not a guarantee of absolute security: protect your iPhone and WordPress account.
The app is for store owners and staff, not children. The current policy has an update date; we communicate material changes through an available channel.