Privacy Policy
Effective date: August 16, 2026
This Privacy Policy explains how Katana handles information for the Katana mobile app and related web services.
Information we collect
Katana is used by authorized field sales, inventory, warehouse, and supervisor teams. We collect account and work information needed to provide the service, including name, email address, role, assigned route or van, customer and invoice records, inventory movement, payment collection records, day-end reports, app activity, device information, and authentication data.
When an authorized driver explicitly enables route tracking for an active work day, Katana collects precise location coordinates, capture time, accuracy, speed, and heading. Location may continue to be collected while the app is in the background. Recording stops when the driver stops tracking, ends the work day, signs out, or removes location permission.
We do not collect personal information for advertising and we do not sell personal information.
How we use information
We use information to authenticate users, operate route and inventory workflows, create invoices, record collections, prepare operational reports, maintain security, troubleshoot issues, and improve reliability for authorized business users.
Precise location is used only for app functionality: recording the assigned van route, calculating route playback and customer visit time, and giving authorized supervisors operational visibility. It is not used for advertising or cross-app tracking.
We use limited account identifiers, app/device context, and product interaction events to understand app reliability and feature usage. Route coordinates are not sent to our product analytics provider.
Sharing
Work records and route information are available to authorized users of the organization that provides the user access to Katana, such as warehouse administrators and supervisors.
We use service providers for hosting and infrastructure, Clerk for authentication, Expo for mobile build and update delivery, and PostHog for limited product analytics. They process information only to deliver, analyze, and protect the service under contractual and technical safeguards.
Retention and security
Raw precise-location samples are retained for up to 90 days and then deleted. Other operational records are retained for as long as needed by the customer organization, legal requirements, and service operations.
We use reasonable technical and organizational safeguards to protect information, including role-based access controls, authenticated access, and encryption in transit.
User choices
Route tracking requires device permission and can be declined. A user can stop tracking for the active day or revoke location access in device settings. Core account access remains available when location permission is declined, although route recording will not work.
Authorized users can request access, correction, or deletion of personal information through their organization administrator or by contacting us. Some business records may need to be retained for accounting, audit, security, or legal purposes.
Contact
For privacy questions, contact sakivksg@gmail.com.