Privacy policy

What Shofol holds

Shofol runs a business's books, its stock, its staff and its field team, so it holds a great deal about that business and about the people in it. This says what, why, who can see it, and what leaves the system.

Version
Version 2026-09-20
Effective
Effective 20 September 2026
Publisher
Appifly BD Ltd.

Whose data, and whose responsibility

Two different relationships run through this document, and most confusion comes from mixing them up.

The data a business puts into Shofol — its customers, suppliers, employees, invoices — belongs to that business. The business decides what to collect and who may see it. Appifly holds and processes it on their instructions, to run the service. In data-protection language, they are the controller and we are the processor.

The account itself — who signed up, the billing address, what was invoiced, sign-in records — is ours to answer for. There we are the controller.

What we hold

WhatWhy it is there
Account and billingCompany name, owner's name, email, phone; the plan and modules in use; invoices between you and us.
Business recordsCustomers, suppliers, products, prices, stock, orders, invoices, payments, vouchers and the ledger built from them. This is the service.
People at the businessThe users invited to the account: name, email, phone, role, branch, the photo they upload.
Employee recordsOnly where the HR module is in use — see Data about employees.
Files uploadedLogos, product photographs, receipts and attachments put on an expense, a voucher or a support ticket.
Sign-in and activityWhen somebody signed in, from which IP address and browser, and what they changed — see The audit trail.

We do not buy data about you from anybody, and we do not enrich your records from outside sources.

Data about employees

A business running payroll in Shofol enters a good deal about the people who work for it: name, contact details, date of birth, national ID, bank account, address, photograph, salary, attendance and leave.

This is entered by the employer, for the employer's purposes. We hold it so the service can do payroll and attendance, and for no other reason. It is not used to build any profile, and it does not leave the business's own account.

It is not visible across companies. Every record in Shofol is scoped to the company that owns it, and staff confined to a branch see only that branch's records.

Location and photographs

Two modules collect things people are entitled to be told about plainly.

Field force

Where an employer has switched on tracking for a rider, the Shofol GO app reports the phone's position while that person is working, including while the app is closed. Visits, orders and collections can carry a photograph and a location.

The rider is shown this is happening — a permanent notification on Android, the system indicator on iOS. The full detail is in the Shofol GO privacy policy.

Attendance

Where the employer requires it, clocking in or out records a selfie and the location it was taken at. This is the employer's choice, not ours.

The audit trail

Shofol records who changed what, when, and from which IP address and browser. It is how a business answers questions about its own books later, and it is the reason a figure can be traced back to the person who entered it.

Each entry is chained to the one before it, so an entry edited or removed afterwards no longer adds up and a nightly check says so.

Personal identifiers are kept out of it. Editing an employee used to write their national ID and bank account into the trail in plain text — a second copy of the most sensitive data in the system, in the one table nothing deletes from. Those fields are now redacted as the entry is written: the trail records that the value changed, not what it was. Passwords and security secrets are dropped entirely.

What leaves the system

Shofol is not an advertising business. Nothing here is sold, and nothing is shared for marketing. Data reaches a third party only where the service cannot work without it:

WhoWhat reaches them
Hosting and storageEverything, at rest — the servers and file storage the service runs on, including the bucket uploads are kept in where a business has configured one.
Email deliveryThe address a message goes to, and the message. Invoices, password resets, alerts.
Payment gatewaysWhere an online store takes payment: the order amount and reference. Card and wallet details are entered on the gateway's own page and never reach Shofol.
MapsCoordinates, to draw a route or place a customer on a map.
An AI providerOnly where the AI features are used — see below.
The lawWhere we are legally required to disclose something. We will tell you unless we are forbidden to.

The AI features

Shofol has features that summarise, draft and answer questions about a business's own figures. These are the one part of the system where business data is sent outside it, so it is described plainly.

  • Text is sent to an AI provider only when somebody uses one of those features. Nothing is sent in the background.
  • What is sent is the question and the figures needed to answer it — not the account's whole database.
  • The provider is a configuration choice. A business that would rather nothing left the building can run against a local model, or leave the AI features switched off.

How it is protected

Stated as what is actually in place, rather than as a list of words:

  • Traffic is encrypted in transit. Session cookies are encrypted and marked secure on an HTTPS deployment.
  • Passwords are hashed, never stored or recoverable. Two-factor authentication is available and recovery codes are issued with it.
  • Second-factor secrets and mail credentials are encrypted in the database.
  • Every record is scoped to the company that owns it, and can be narrowed further to a branch.
  • Changes are recorded in the tamper-evident audit trail described above.
  • Backups are taken and can be encrypted with a password held separately from the storage credentials.

How long we keep it

  • Business records stay for as long as the account is open. They are yours; we do not thin them out.
  • The audit trail is kept for one year by default and pruned nightly beyond that. A business can ask for a different window.
  • After an account closes, data is kept for 30 days so an account closed by mistake can be brought back, then deleted from the live system. Backups age out on their own cycle.
  • Invoices between you and us are kept as long as the law requires.

Your rights

You can export your data at any time while the account is open, and you do not need to ask us to do it.

For the account data we are responsible for, you can ask what we hold, ask us to correct it, and ask us to delete it where we are not required to keep it. Write to the address below; we answer within 30 days.

If you are an employee of a business using Shofol, those requests go to your employer, not to us. We will help them answer you.

Changes

This policy carries a version, shown at the top. When it changes in substance we raise the version and tell customers by email before it takes effect. The version in force when somebody signed up is recorded against their account.

Contact

Appifly BD Ltd.
Email: support@appiflybd.com

See also the Terms of Service, and the app policies for Shofol HR and Shofol GO.