Privacy Policy
Last updated: 12 July 2026
This Privacy Policy explains what personal data we collect when you use the Rasfor platform, how we use it, and your rights. By using the platform you accept this policy.
1. Data we collect
Account information: first name, last name, e-mail address and your password (passwords are stored irreversibly hashed; plain-text passwords are never kept).
Business data: the feeds, ingredients, nutrient values, prices, stock, rations and farm records you enter into the platform. This data belongs to you.
Payment data: payments are processed by Stripe. Your card number never reaches our servers and is never stored by us; we keep only subscription status and invoice records.
Technical logs: limited request logs (IP address, request time and request path) are kept for security and troubleshooting. Request contents (form data, passwords) are never logged.
Support records: requests you send via the 'Contact Us' tool and, if you opt in when reporting a bug, screen-interaction metadata (clicked elements and called service addresses — never their contents).
2. How we use data
To provide the service and run calculations, manage your subscription and billing, answer support requests, keep the platform secure, and send service e-mails (verification codes, password resets, notifications).
We do not use your data for advertising and we never sell it to third parties.
3. Cookies and local storage
A strictly necessary authentication cookie (jwt_token) is used to keep you signed in.
Preferences such as language and currency are kept in your browser's local storage (localStorage).
No third-party advertising or tracking cookies are used.
4. Third-party processors
Stripe (payment processing), Google (optional 'Sign in with Google'), e-mail delivery infrastructure (service e-mails), Hetzner (hosting and data storage — Germany/EU) and Cloudflare (content delivery and image services).
These providers process your data only to deliver their respective service.
5. Data location and security
Your data is hosted in data centres within the European Union (Germany).
All traffic is encrypted (HTTPS/TLS), databases and file storage are not publicly reachable, image storage is private, and administrative access is permission-controlled.
6. Data sharing
Your personal data is shared only with the processors listed above and, where legally required, with competent authorities.
Within the company account feature, data sharing is fully under your control: the account owner decides which data types are shared with team members.
7. Retention and deletion
Your data is retained for as long as your account is active.
You can delete your account from your profile page and export your data beforehand. When the account is deleted your business data is permanently removed; invoice records subject to statutory retention are kept for the legally required period.
Technical logs are kept for a limited period and cleaned up automatically.
8. Your rights
You have the right to access, correct, delete, export (portability) and object to the processing of your data (under the GDPR and Turkish KVKK).
To exercise these rights, contact us at the e-mail address on the Contact page; requests are answered within 30 days at the latest.
9. Children's privacy
The service is not directed at people under 16 and we do not knowingly collect data from children.
10. Changes and contact
This policy may be updated; material changes are announced through the platform. For questions, reach us via the Contact page.