Privacy Policy
Effective: May 20, 2026
urayf LLC ("urayf," "we," "our," or "us") is committed to protecting the privacy of our clients and the data they share with us. This Privacy Policy explains what information we collect, how we use it, and the choices you have regarding that information.
If you have questions about this policy, contact us at privacy@urayf.com.
1. Who We Serve
urayf is a business intelligence firm. Our clients are independent retailers, franchisees, and small business owners who hire us to analyze their store operations and produce regular reports. This policy applies to data we receive in the course of providing those services, and to information collected through urayf.com.
2. Information We Collect
From Our Clients (Account Holders)
When you become a urayf client, we collect:
- Your name, email address, and contact information
- Your business name(s) and store identifier(s)
- A password (stored in encrypted form — we never see your plaintext password)
- Optional profile information you provide (display preferences, avatar image)
From Our Clients' Operations
To produce the reports our clients pay for, we receive operational data from our clients' point-of-sale and inventory systems. This includes:
- Point-of-sale (POS) transaction data
- Invoice summary reports
- Daily merchandise reports
- Electronic journal reports
- Shift data, including employee names where present in the original data
This data is provided to us by our clients, who are responsible for having lawful authority to share it with us under their agreements with their own employees, vendors, and customers. We do not contact, market to, or otherwise interact with the individuals named in this data.
From Visitors to urayf.com
Our public website may collect:
- Standard server logs (IP address, browser type, pages visited, timestamps)
- Information you voluntarily submit (e.g., when you email us)
We do not currently use third-party analytics, advertising trackers, or social media pixels on urayf.com.
3. How We Use the Information
We use the information we collect to:
- Operate the urayf service and deliver the reports our clients pay for
- Communicate with our clients about their account, their reports, and service-related matters
- Improve our analysis methodologies and report quality
- Comply with legal obligations
- Detect and prevent fraud or abuse
We do not:
- Sell client data to third parties
- Share client data with advertisers
- Use client data to train AI models for other clients or for any purpose outside of generating that specific client's reports
- Contact, market to, or analyze individuals identified in our clients' operational data for any purpose other than producing the client's report
4. How We Share Information
We share information only in these limited circumstances:
With your authorization. If you ask us to share information with a third party (e.g., your accountant), we will.
With our service providers. We use third-party infrastructure providers to operate urayf — currently including Supabase (database and authentication) and Vercel (web hosting). These providers process data on our behalf under contracts that require them to protect it. They do not have rights to use your data for any other purpose.
When required by law. We will disclose information if required by valid legal process (subpoena, court order). When permitted, we will notify the affected client before disclosure.
With a successor. If urayf is acquired, merged, or sold, your information may be transferred to the successor entity. Any successor will be bound by the terms of this policy.
5. Data Security
We protect your information using industry-standard practices:
- Data is encrypted at rest (AES-256) and in transit (TLS 1.3)
- Passwords are hashed using bcrypt; we never store or have access to plaintext passwords
- Access to client data is restricted to urayf personnel who need it to perform their job
- Our infrastructure providers (Supabase, Vercel) maintain SOC 2 Type II compliance for the services we use
We do not currently maintain SOC 2, ISO 27001, or HIPAA certification for urayf itself. If your business has compliance requirements that need certification, please contact us before becoming a client so we can discuss whether urayf is the right fit.
6. Data Retention
We retain client data for as long as you are a urayf client, plus a reasonable period afterward to allow for account recovery and to meet our legal and accounting obligations (typically up to 7 years for financial records, shorter for other data categories).
You can request deletion of your data at any time by contacting privacy@urayf.com. We will honor deletion requests within 30 days, except where we are legally required to retain certain records.
7. Your Rights
Depending on your location, you may have rights regarding your personal information, including the right to:
- Access the information we hold about you
- Correct inaccurate information
- Request deletion of your information
- Object to or restrict certain uses
To exercise any of these rights, contact privacy@urayf.com. We will respond within 30 days.
Illinois residents: urayf does not collect biometric information (fingerprints, face scans, retinal scans, voiceprints, or hand geometry) and is not subject to the Illinois Biometric Information Privacy Act.
8. Children
urayf is a business-to-business service. We do not knowingly collect information from individuals under 18. If you believe we have inadvertently collected information from a minor, contact privacy@urayf.com and we will delete it.
9. Changes to This Policy
We may update this policy from time to time. When we do, we will update the "Effective" date at the top. For material changes, we will notify clients by email at least 30 days before the changes take effect.
10. Contact
For any privacy-related questions or requests:
- Email: privacy@urayf.com
- Mail: urayf LLC, [your business address], [city], IL [zip]