Effective date: September 16, 2026
Last updated: September 16, 2026
1. Who we are
GemFort is a product of Orbitra Tech (Pvt) Ltd, based at 198/3 Sheikh Jamaldeen Road, Beruwala, Sri Lanka. GemFort provides a gem-trade directory and listing service called GemNet and a private business workspace called GemTrack for traders, lapidaries, and related businesses. GemFort does not process payments, subscriptions, or user-to-user transactions.
For privacy requests or questions, email orbitra.technology@gmail.com. This policy applies to the GemFort mobile applications, public GemFort links, and related services. It does not govern third-party sites or services that GemFort links to.
2. What GemFort does
Depending on your role and choices, GemFort lets you:
- browse public business profiles, gem listings, announcements, and external certificate-verification portals without an account;
- create a trader or lapidary account using email/password, Google, Apple, or phone verification where offered;
- apply for manual identity or business verification using business and identity documents;
- publish a business profile, contact channels, location, services, photos, and gem listings;
- manage private gem inventory, stones, costs, services, account balances, payment obligations, cheques, bills, trips, receipts, and contacts;
- create or respond to service requests, offers, custody and AP records, sale or transfer records, fraud reports, and other listing or business interactions; any actual user dealings occur outside GemFort;
- receive in-app and push notifications; and
- search for flights and follow third-party booking links.
3. Personal data we collect
We collect data you provide, data created by your use of GemFort, and data received from services you choose to connect.
A. Account and authentication data
This may include your name, email address, phone number, authentication-provider identifiers, role, verification status, preferred language and currency, date of birth where required for verification, account status, notification preferences, and account timestamps. Passwords are handled by the authentication provider and are not stored in the GemFort application database as readable passwords.
When you use Google, Apple, or phone sign-in, we receive the account information that the provider makes available for authentication and account setup. Phone verification may involve your phone number, a one-time code, device or carrier verification signals, and authentication security data.
B. Business and public-profile data
If you create or manage a business profile, we may collect the business name, owner name, business type, registration or licence identifiers, NGJA-related information, tax identifier, year established, description, address, city, district, province, country, map coordinates, public contact channels, social links, services, specialisations, price ranges, logos, cover images, gallery images, verification badges, and profile or listing engagement counters.
Verified active business profiles and public listings are designed to be visible to other users or visitors. If you publish a phone number, WhatsApp number, email address, website, social link, address, or exact map pin, it may be copied, indexed, shared, or used to contact you outside GemFort. Do not publish information that must remain confidential. Some legacy listings may remain readable by link until their access controls and existing records are corrected.
C. Verification and fraud-prevention data
For manual verification or fraud handling, we may collect your date of birth, business registration information, NGJA number, gem licence number, tax identifier, national identity document image, business-registration image, licence image, tax or address proof, business photos, other documents, submitted explanations, fraud reports, evidence files, review decisions, and administrative audit records.
Verification documents are sensitive information. They are intended for restricted access by the applicant and authorised GemFort administrators, and for the verification, safety, fraud-prevention, and legal-compliance purposes described here. Public profile reads do not include these private identifiers or documents.
D. GemTrack workspace and business-record data
GemTrack may contain confidential business records, including gem and AP-stone attributes, origin, mine, acquisition method and date, weights, colour, clarity, cut, shape, natural or treatment status, current location and custody, costs, asking, minimum, and sale prices, counterparties, profit information, private notes, tags, photos, service instructions, job records, bills, receivables, payables, payment records, cheque numbers and bank details, trip destinations and dates, cash or budget information, expenses, receipts, and related identifiers.
These records are intended for your private workspace, except when you deliberately share a record with a counterparty or use a GemFort flow that gives another participant access. Counterparties may see the data needed for a shared AP, service, offer, or business record. Any underlying purchase, sale, payment, or settlement occurs outside GemFort.
E. Contacts
If you choose to import phone contacts, GemFort can read selected contact names, company names, phone numbers, email addresses, contact photos, and device contact identifiers. Imported contact records and selected contact photos are stored in your GemTrack workspace and can be linked to a GemFort business.
Only import contacts when you have the authority to do so. The people in your address book may not use GemFort and may not know that you stored their information in your workspace. You are responsible for using imported contact information lawfully and fairly.
F. Photos, documents, and other files
When you choose to upload media or documents, we process the selected local file and store it in Firebase Cloud Storage. This can include gem photos, business logos and gallery images, verification documents, cheque images, trip or expense receipts, contact photos, and other files supported by the relevant feature.
G. Location
GemFort requests foreground location only when you choose to use location features. It can obtain a one-time device location, reverse-geocode it into a place label, and save the coordinates and place details to a business profile. A business map pin can be displayed publicly and can open Apple Maps or Google Maps. GemFort does not use the audited profile-location flow for continuous background tracking.
H. Notifications and device data
If you enable notifications, GemFort stores a push-token identifier and notification preferences and may send notifications containing titles, messages, actor names or photos, image URLs, and references to a listing, request, service, offer, verification, report, payment, cheque, or other event.
The app also uses security and operational data such as authentication tokens, App Check signals, request identifiers, timestamps, device and app information, and service logs. Firebase and Google Cloud may process technical information such as IP addresses and user-agent or similar security data to operate and protect their services.
I. Flight searches and third-party links
If you use flight search, GemFort may send search parameters such as origin, destination, travel dates, passenger or cabin selections, and currency to Travelpayouts or Aviasales services. GemFort can create or display an Aviasales booking link and may receive affiliate compensation if you use an eligible link. Booking, payment, ticketing, refunds, and the third-party website's privacy practices are controlled by the third party.
4. How we use personal data
We use personal data to:
- create and secure accounts, authenticate users, verify phone numbers, and recover or delete accounts;
- operate GemNet, GemTrack, profiles, listings, searches, requests, offers, transfers, services, reports, notifications, and other requested features;
- display information that you choose to publish and connect users with businesses or counterparties;
- review verification applications, prevent fraud, investigate abuse, enforce rules, and protect users and the platform;
- store and retrieve your workspace records, media, documents, receipts, and preferences;
- send operational, security, and optional notification messages;
- provide flight search and affiliate-link functionality;
- troubleshoot, monitor performance and security, maintain backups and audit records, and improve reliability;
- comply with legal obligations, lawful requests, tax and accounting requirements, and dispute or safety processes; and
- respond to support requests and exercise or defend legal rights.
The audited dependency set did not identify a dedicated advertising, analytics, or crash-reporting SDK. Firebase, Cloud Functions, hosting, app stores, and other infrastructure providers may still create ordinary technical or security logs.
5. Legal grounds and permissions
Where privacy law requires a legal basis, the basis may include performing a contract or providing a requested service, your consent, our legitimate interests in security and platform operation, compliance with law, and establishing or defending legal claims. The appropriate basis depends on the data and purpose.
Device permissions are optional unless a feature requires them. You can refuse or later withdraw access to contacts, location, photos or files, notifications, biometrics, or other device capabilities in system settings, but the related feature may stop working. We will not treat a permission refusal as permission to access the underlying data.
The audited source and Expo configuration found use of contacts, foreground location, photos and files, notifications, biometric authentication, and secure local storage. A release build still needs a separate permission review, and this policy must be updated if the released app requests additional permissions.
7. International processing
GemFort's Firebase project uses the asia-south1 Firestore and storage region, but Firebase Authentication is operated from United States data centres and many Firebase services use global Google infrastructure. Travel, identity, maps, app-store, and other providers may process information in their own countries. Where required, we will use an applicable transfer mechanism and contractual or organisational safeguards.
8. Retention and deletion
We keep personal data only for as long as reasonably necessary for the purposes in this policy, including account operation, security, fraud prevention, verification, dispute handling, legal compliance, accounting, and backup recovery. We begin verified deletion promptly and ordinarily complete deletion of active GemFort records within 30 days. Narrow security, fraud, dispute, legal, or regulatory records may be retained only as necessary and normally for no longer than seven years, unless applicable law or an active proceeding requires longer.
| Data category | Current handling summary |
|---|---|
| Account and profile data | Ordinarily deleted within 30 days after verified deletion, subject to applicable exceptions. |
| Verification and identity documents | Ordinarily deleted within 30 days, subject only to necessary fraud, regulatory, or dispute evidence retention. |
| Public listings and business content | GemFort-controlled records are ordinarily removed within 30 days; public copies, shared records, caches, and provider copies may persist. |
| GemTrack records | Owned live records are ordinarily deleted within 30 days; necessary legal, accounting, fraud, or dispute evidence may remain. |
| Contacts and contact photos | Owned records and managed files are ordinarily deleted within 30 days. |
| Notifications and operational logs | Current Cloud Logging configuration retains ordinary logs for up to 30 days and required audit logs for up to 400 days. |
| Backups and recovery copies | Firebase Storage soft-delete is configured for 7 days. Recovery copies are not used as live records and expire under provider settings; the exact Firestore recovery window must be verified. |
You can initiate account deletion from in-app account settings. The deletion workflow is intended to remove the account and associated records and files, while shared records may be retained in de-identified form where necessary. Shared company audit records, fraud or report records, legal evidence, and administrator audit records may be retained or anonymised where necessary and permitted by law.
For a request outside the in-app flow, use the GemFort account deletion page or contact us by email. Deletion does not automatically remove information another user lawfully copied from a public profile, listing, message, report, or shared record, nor does it control retention by independent third parties.
9. Your rights and choices
Subject to applicable law and reasonable identity verification, you may request access to, correction of, deletion of, restriction of, or information about the processing of your personal data. Depending on the law that applies to you, you may also object to particular processing, withdraw consent, request portability, or complain to a data-protection regulator.
To exercise a right, email orbitra.technology@gmail.com with the account email or UID, the request, and enough information to verify identity. We may refuse or limit a request where permitted by law, for example to protect another person's rights, preserve evidence, prevent fraud, or comply with a legal obligation.
If Sri Lanka's Personal Data Protection Act applies to the processing, you may also contact the Sri Lanka Data Protection Authority.
10. Security
GemFort uses Firebase Authentication, Firestore and Storage security rules, App Check, authenticated API requests, HTTPS and TLS, role checks, and restricted administrative access. No online service is completely secure. You are responsible for protecting your device, authentication factors, and any information you choose to publish or share.
GemFort continues to improve validation, access-control tests, deletion monitoring, and release-manifest review. The security audit linked from the repository identifies controls that must be completed before the Service is treated as production-ready.
11. Children
GemFort is a business and trading service and is not directed to children. Do not create an account or submit identity, financial, contact, or business data if you are not legally able to use the Service. If you believe a child provided personal data, contact us so we can investigate and delete it where appropriate.
12. Third-party services and links
GemFort may open external certificate portals, maps, travel sites, app-store services, identity providers, or other third-party links. Those services have their own terms and privacy policies. GemFort does not control their data practices and is not responsible for content or transactions completed outside GemFort.
13. Changes
We may update this policy when the service, law, or data practices change. We will post the updated version with a new "Last updated" date and, where required, provide additional notice or request consent. Continued use after the effective date of an update is subject to the updated policy to the extent permitted by law.
14. Contact
Privacy requests and general support
orbitra.technology@gmail.comGemFort by Orbitra Tech · 198/3 Sheikh Jamaldeen Road, Beruwala, Sri Lanka
Controller: Orbitra Tech (Pvt) Ltd.